Skip to main content
intermediate

Data processing agreements for SaaS: an Article 28 worksheet

Build a controller-processor agreement from the actual service, instructions, security, subprocessors, rights support, deletion, and audits.

intermediate
11 min read
31 de enero de 2025
gdpr data processing agreement article 28 saas processors

A data processing agreement records the controller’s instructions and the processor’s duties. It is not a generic privacy policy, and it is not automatically the same instrument as standard contractual clauses for an international transfer.

Use this guide as a negotiation worksheet. The executed contract must match the real service and roles.

1. Confirm the roles

A controller determines purposes and essential means. A processor handles personal data on the controller’s behalf. The same company can be a processor for hosted customer content and a controller for its own billing, fraud prevention, or employment processing.

The European Commission’s controller and processor overview explains the distinction. Document it per activity rather than assigning one label to the whole relationship.

2. Complete the processing schedule

Article 28(3) of the GDPR requires the contract to set out:

  • subject matter and duration;
  • nature and purpose;
  • types of personal data;
  • categories of data subjects; and
  • controller’s obligations and rights.

Replace broad descriptions such as “service data” with an accurate schedule. Include support access, telemetry, backups, deletion queues, and any AI subprocessors.

3. Review each mandatory duty

The agreement should address:

  1. processing only on documented instructions, including transfer instructions;
  2. confidentiality obligations for authorised people;
  3. Article 32 security measures;
  4. conditions for engaging another processor;
  5. assistance with data-subject rights;
  6. assistance with security, breach, DPIA, and prior-consultation duties;
  7. deletion or return after the service, unless law requires storage;
  8. information needed to demonstrate compliance and permit audits; and
  9. notification if an instruction appears to infringe data-protection law.

Attach technical and organisational measures that are specific enough to evaluate. “Industry-standard security” does not show identity controls, encryption scope, logging, resilience, recovery, vulnerability management, or incident response.

4. Make subprocessor control usable

State whether authorisation is specific or general. With general authorisation, define advance notice of additions or replacements and a meaningful opportunity to object. Require equivalent data-protection obligations down the chain and keep the processor responsible for its subprocessor under Article 28(4).

Publish or supply the current list with legal entity, service, processing location, and purpose.

5. Separate Article 28 from transfers

An Article 28 contract governs controller-processor duties. A transfer from the EEA to a third country also needs a Chapter V route unless an exception applies.

The Commission has adopted one set of standard clauses for controller-processor relationships within the EU/EEA and another set of standard contractual clauses for international transfers. The appropriate transfer modules can also contain Article 28 obligations, but merely calling a DPA “SCCs” does not create a transfer safeguard.

Record the exporter, importer, destination, module, docking, supplementary measures, and transfer assessment where required.

6. Test exit and assistance

Before signature, ask:

  • How does the controller export data?
  • When do production copies and backups become inaccessible or deleted?
  • What evidence confirms deletion?
  • How quickly will the processor report a breach?
  • How will it help search, correct, restrict, or delete a person’s data?
  • What audit evidence is available, and what happens if it is insufficient?

Commercial limits can be negotiated, but they must not empty the Article 28 duties of practical meaning.

GDPR.Direct can generate an editable DPA draft from supplied details. It does not establish the parties’ roles, inspect security, complete a transfer assessment, negotiate terms, or sign the agreement. Obtain qualified contract review before relying on the draft.

This guide is educational information, not legal advice.

Ready to Create Your First Draft?

Use the free plan to create editable drafts, verify the facts, and publish only what an accountable owner approves.

Get Started Free