GDPR · Data processing agreements

DPA review for vendor decisions

A Data Processing Agreement is not a formality to be collected — it is the document that defines what a vendor is contractually obliged to do with your data. Governli reads the DPA against the data protection requirements you configure and records what is committed, what is silent and what is ambiguous.

Sample assessment

Example SaaS Ltd · Data Processing Agreement

Partial evidence
  1. AgreementEvidence found

    Signed DPA incorporating Article 28 terms

  2. Processing termsEvidence found

    Purpose, duration, categories of data and instructions documented

  3. Sub-processorsPartial evidence

    Published list, general written authorisation

    Eleven sub-processors named, with role and location per entry.

  4. TransfersEvidence requested

    Standard Contractual Clauses annexed

    A transfer impact assessment is referenced but was not supplied.

  5. NotificationManual review

    Personal data breach notification 'without undue delay'

    No committed timeframe is stated in the agreement.

This is contractual evidence review against your requirements. It is not legal advice.

Finding

Partial evidence

Sub-processor change notification

The agreement permits the processor to appoint new sub-processors. No notice period and no objection window are stated, so the controller cannot evidence an ability to object before processing begins.

Decision implication: Negotiate a notice period, or accept and record the rationale

"A DPA is in place" is a filing status, not an assessment

Almost every established SaaS vendor now offers a standard DPA, usually as an annex incorporated by reference. Because they are so consistently available, they are frequently treated as a box to tick: the annex is signed, the checklist records a DPA, and nobody reads it again until something goes wrong.

The difficulty is that standard DPAs are written to be acceptable to a wide range of customers, not to satisfy your specific requirements. Two vendors can both have perfectly reasonable DPAs while one commits to a thirty-day sub-processor objection window and the other reserves the right to change sub-processors with notice by website update only. Both documents exist. They support very different decisions.

Document present

A signed DPA exists and is stored. The procurement checklist is satisfied. Nothing is known about whether its terms meet the obligations your organisation carries as controller.

Requirement supported

A named requirement is mapped to specific contractual text, cited by clause, with a recorded status — supported, partially supported, unsupported or needing manual review — that a reviewer can challenge.

What the review looks at

Which of these matter depends on the processing and on the requirements in your catalogue. A single-user internal tool with no personal data does not need the same scrutiny as a platform handling employee or customer records.

Roles and instructions
Whether the parties are described as controller and processor in a way that matches the actual processing, and whether the processor is bound to act only on documented instructions.
Processing description
Purposes, duration, nature of processing, categories of data and data subjects. A description written for a different service is a common source of ambiguity.
Sub-processors
Whether authorisation is general or specific, how the list is maintained and published, what notice period applies to changes, and what your options are if you object.
International transfers
Whether processing or support access occurs outside the EEA, which mechanism is relied on, and whether supplementary measures are described.
Security commitments
What the agreement actually obliges the processor to maintain, and how that relates to the security evidence the vendor publishes separately.
Personal data breach
Notification trigger, timing, the channel used and the information you will receive — the practical inputs to your own notification obligations.
Return and deletion
What happens at termination, within what period, whether backups are covered and whether confirmation is provided.
Audit and information rights
Whether rights are exercisable in practice or limited to accepting existing third-party reports, and on what notice and cost basis.

Worked example: sub-processor change notification

Illustrative only. Your internal policy requires advance notice of new sub-processors with a genuine window to object before the change takes effect. The vendor's standard DPA grants general authorisation and states that the sub-processor list is maintained on a public web page, which customers "may subscribe to for updates".

Requirement

The processor must notify us of any intended addition or replacement of a sub-processor in advance, with a defined period in which we may object.

Evidence

DPA uploaded; the sub-processor clause and the referenced public list are recorded as evidence, with the clause text cited.

Finding

Partially supported. A notification route exists, but it is opt-in and no notice period or objection window is specified. Recommended follow-up: request a committed notice period, an email notification channel, and confirmation of what happens if an objection is raised.

Decision implication

Neither a blocker nor a pass. Depending on the sensitivity of the data, the reviewer can require an amendment, accept the terms with a documented compensating control such as a scheduled review of the published list, or escalate to legal. Whichever path is taken, the reasoning is attached to the requirement rather than lost in an email thread.

Contractual commitments and security evidence answer different halves

A DPA establishes obligation. It does not establish practice. When your requirement is that data is encrypted at rest, the DPA tells you the processor has undertaken to apply appropriate measures; an ISO 27001 certificate and Statement of Applicability or a SOC 2 Type II report tells you whether an independent party examined how that is done. Assessing both against the same requirement gives you obligation and evidence together, which is why data protection requirements usually sit inside a wider vendor due diligence assessment rather than being handled in isolation.

  • Clause-level citations back to the agreement
  • Findings for silent, partial or ambiguous terms
  • Recommended follow-up questions for the vendor
  • Decision Snapshot and exportable Decision Package

Where legal review is still required

Governli is not a law firm and does not provide legal advice. It structures contractual text against your requirements so that the questions worth escalating are visible and documented. Whether a clause is enforceable, whether a transfer mechanism is adequate for a particular processing operation, and whether a residual gap is acceptable for your organisation are determinations for your own legal and data protection functions.

Assessment conclusions also depend on what was supplied. If the DPA incorporates annexes, transfer documentation or a security schedule that was not uploaded, the review reflects that absence rather than assuming its content. Further reading: GDPR processor assessments, vendor security assessment and Requirements-to-Evidence Mapping. Browse all solutions.

DPA review FAQ

Does having a DPA mean the vendor is GDPR compliant?+

No. A signed DPA means the parties have agreed processing terms. Compliance depends on whether those terms cover your processing, whether they meet the obligations that apply to you as controller, and whether the vendor actually operates as described. A review establishes what the document commits the vendor to — it cannot establish practice on its own, which is why DPA terms are usually read alongside security evidence such as a certification or attestation report.

What should a buyer look for first in a vendor DPA?+

Start with the parts that are hardest to change later: the description of processing and its purposes, the sub-processor arrangement and how changes are notified, the transfer mechanism for any processing outside the EEA, breach notification timing, and what happens to the data at the end of the contract. Security commitments matter too, but they are often the section most easily supported by other evidence the vendor already publishes.

Is a review of the DPA a legal opinion?+

No. Governli maps contractual text to the requirements you configured and records where they are supported, partially supported, unsupported or ambiguous. Whether a residual gap is acceptable, and whether a clause achieves a particular legal effect, is a judgement for your own legal function or external counsel.

The vendor will not negotiate its standard DPA. Is the review still useful?+

Often more useful. Where terms are non-negotiable, the value of the review is an accurate, documented picture of what you are accepting: which requirements the standard terms satisfy, which they do not, and what compensating measures or internal approvals that implies. That record is what makes the acceptance a decision rather than an oversight.