Data Processing Agreements (DPAs) explained: GDPR Article 28 in plain English
Why every SaaS contract now needs a DPA, what the eight required clauses are, and how to handle international data transfers in 2026.
Why DPAs exist
Under GDPR Article 28, when a controller (the company that decides why and how personal data is processed) hands data to a processor (a vendor that processes it on their behalf), there must be a written contract — a Data Processing Agreement — that sets out specific obligations. Without a compliant DPA, both parties are in breach, regardless of whether the underlying processing is otherwise lawful.
Who is the controller and who is the processor?
Rule of thumb: if you're a SaaS vendor providing a service to a business customer, you are the processor of any personal data your customer uploads. The customer is the controller — they decide what to upload, why, and for how long. There are edge cases (joint controllership, sub-processor relationships) but 90% of SaaS deals follow this pattern.
The eight Article 28 clauses
Every DPA must include: (1) subject matter and duration of processing, (2) nature and purpose of processing, (3) types of personal data and categories of data subjects, (4) controller's instructions (the processor only processes on documented instructions), (5) confidentiality (people processing the data are bound to confidentiality), (6) security measures under Article 32, (7) sub-processor authorization, and (8) assistance with data-subject rights, breach notification, and DPIAs.
Sub-processors are the most-litigated clause
Modern DPAs require the processor to (a) maintain a public list of sub-processors, (b) give 30 days' notice before adding a new one, (c) give the controller a right to object, and (d) flow down equivalent DPA terms to every sub-processor. The European Data Protection Board's Guidelines 07/2020 on the concepts of controller and processor are the authoritative reference.
Cross-border transfers after Schrems II
Transferring personal data outside the EU/EEA requires either an adequacy decision (the U.S. has one again as of 2023 via the EU-U.S. Data Privacy Framework), Standard Contractual Clauses (SCCs), or Binding Corporate Rules. SCCs require a Transfer Impact Assessment (TIA) — most SaaS vendors now publish one as a downloadable PDF. If your DPA doesn't reference SCCs or DPF, it's not export-ready.
UK and India specifics
The UK has its own version of GDPR (UK GDPR) and its own SCCs (the International Data Transfer Agreement / IDTA). India's Digital Personal Data Protection Act 2023 introduced a similar but distinct regime. Your DPA template should reference all applicable regimes by name, not just "GDPR".
Breach notification timing
GDPR requires controllers to notify the supervisory authority within 72 hours of becoming aware of a breach. Your DPA should require the processor to notify the controller "without undue delay" (usually defined as within 24–48 hours) — leaving the controller enough time to make the 72-hour deadline.
Where AI helps with DPA review
ContractScan AI auto-detects whether a contract is a controller-processor, joint-controller, or controller-controller relationship; checks for all eight Article 28 clauses; flags missing TIAs and SCCs; and produces a single-page DPA scorecard. For procurement teams reviewing dozens of vendor DPAs per quarter, that scorecard is the difference between a 30-minute review and a half-day.
Stop reading contracts. Start understanding them.
Upload any PDF or DOCX and get a plain-English summary, risk score, and negotiation suggestions in under 60 seconds.
Try ContractScan AI free