Vendor DPA review checklist (template)
18 May 2026
Before a new vendor becomes one of your subprocessors, its Data Processing Agreement should clear a consistent bar. Reviewing every DPA against the same checklist keeps your processing chain defensible and ensures you are passing down the obligations your own customers' DPAs require you to flow through. Use the checklist below as a manual gate when onboarding a vendor.
1. The eight Article 28(3) terms are present. A compliant DPA must bind the vendor to all eight mandatory terms: processing only on your documented instructions; confidentiality obligations on the vendor's staff; appropriate security measures under Article 32; conditions on the vendor engaging its own sub-processors; assistance with data-subject rights requests; assistance with your security, breach-notification, and impact-assessment obligations (Articles 32–36); deletion or return of data at the end of the service; and the provision of information and audit cooperation to demonstrate compliance. If any of the eight is missing or watered down, the DPA is not adequate — flag it before signing.
2. Sub-processing terms. Check whether the vendor uses its own subprocessors, whether it must notify you of changes, and whether you have a right to object. The vendor should be required to impose the same data-protection obligations on its subprocessors as it owes to you (flow-down), and to remain liable for them. A vendor that can add fourth parties silently is a blind spot in your chain.
3. International transfer mechanism. If the vendor processes data outside the EEA, confirm which safeguard applies: EU Standard Contractual Clauses (and, for UK data, the UK Addendum or IDTA), an adequacy decision, or a Data Privacy Framework certification. Check that the correct module of the SCCs is used for the relationship and that any required transfer impact assessment has been considered. A transfer with no valid mechanism is the most common serious gap.
4. Security measures. The DPA should describe, or reference an annex describing, the technical and organisational measures the vendor maintains — encryption in transit and at rest, access controls, logging, and so on. Look for evidence of independent assurance such as ISO 27001 or SOC 2, rather than vague promises. The measures should be specific enough that you could hold the vendor to them.
5. Breach notification. Check the timeline and the trigger. The vendor should commit to notifying you 'without undue delay' after becoming aware of a personal-data breach — ideally within a defined window — and to giving you enough information to meet your own 72-hour notification duty to supervisory authorities under Article 33. A DPA that only requires notice 'as required by law' pushes the risk back onto you.
6. Audit and information rights. You should be able to obtain the information needed to demonstrate compliance and to audit the vendor, whether directly or via a third-party report. Watch for terms that limit audits so tightly — excessive notice periods, narrow scope, the vendor's own auditor only — that the right becomes theoretical.
7. Deletion or return on termination. Confirm what happens to the data when the relationship ends: the vendor should delete or return it on your instruction, within a stated period, and certify deletion. Check any carve-outs for backups and legally-required retention, and that they are time-bound rather than indefinite.
8. Liability and onward terms. Read the liability and indemnity provisions in light of what your own customer contracts require you to pass down. A vendor whose DPA caps liability far below your exposure, or excludes data-protection claims entirely, may leave you carrying risk you have promised your customers you would cover.
Using the checklist. Run every prospective subprocessor through these eight points before onboarding, and keep the completed review alongside the signed DPA as part of your records. Where a term falls short, decide consciously whether to negotiate it, accept the risk with sign-off, or choose a different vendor — and write down which you chose. That paper trail is part of demonstrating the accountability Article 28 expects of you.
Related resources
Track what each DPA actually agreed to
Once a vendor is onboarded, subprocessor.io records each customer's contracted scope, notice period, and restrictions — so notifications always match the real agreement.
See variation tracking