Art. 28 Minimum Content
Are all legally required elements present? Subject matter, duration, purpose, data categories, instruction rights, confidentiality and accountability obligations.
Art. 28 GDPR - Mandatory for outsourced processing
Data Processing Agreements with all your external service providers - reviewed, complete and GDPR-compliant. We inventory, audit and close the gaps.
Coming soon
Vertrauen unserer Kunden
DPA Inventory Overview
Example view with fictitious status values.
Review Scope
Having a DPA is not enough. It must also be correct and complete - tailored to your specific situation.
Are all legally required elements present? Subject matter, duration, purpose, data categories, instruction rights, confidentiality and accountability obligations.
Are the agreed technical and organisational measures (TOMs) specific and adequate - or just generic boilerplate with no substance?
Which sub-contractors does the service provider use? Are they listed transparently? Do you have a right to object when sub-processors change?
Is data being transferred to countries outside the EU/EEA? If so: are EU Standard Contractual Clauses (SCCs) or other safeguards in place and up to date?
Is the DPA still current? Older contracts from before 2018 or prior to the Schrems II decision are often no longer adequate. We check for currency.
What happens to your data at the end of the contract? The DPA must contain clear provisions on deletion or return of all personal data.
Process
Structured, complete and gap-free - from inventory to audit-proof documentation.
Complete capture of all external service providers with access to personal data - including cloud services, SaaS tools, IT service providers and external personnel.
Review of existing DPAs for completeness, currency and compliance with Art. 28 GDPR and current case law (including Schrems II, SCCs 2021).
Drafting missing DPAs based on proven templates, renegotiating inadequate agreements with service providers, obtaining SCCs for third-country transfers.
Complete DPA overview as part of your data protection documentation - audit-proof, with version control and reminders for expiry dates.
Your contact
This service is launching soon. Leave your enquiry - we will get back to you personally to discuss your needs.
Aus dem Blog
Der Informationssicherheitsbeauftragte ist der Ansprechpartner für Informationssicherheit im Unternehmen. Diese Aufgaben hat er!
DSGVO-Compliance: Rechtsgrundlagen, Bußgeldrahmen, AVV, Datenpanne-Meldepflicht, DSFA und Verarbeitungsverzeichnis - mit Praxisbeispielen.
DSFA nach Art. 35 DSGVO: Wann Pflicht, Schritt-für-Schritt-Anleitung, Blacklist der Aufsichtsbehörden und typische Fehler in der Praxis.
We are launching our data protection practice shortly. Register your interest - and we will reach out as soon as we are ready.
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days