Create a GDPR-Compliant Data Processing Agreement in Minutes
Generate a comprehensive DPA that meets GDPR Article 28 requirements. Define controller-processor relationships, security measures, and data subject rights with AI-powered drafting.
Starting at $10 during beta.
GDPR Article 28 Required Clauses
Our DPA templates include all mandatory provisions required by GDPR for controller-processor agreements.
Processing Instructions
Processor acts only on documented controller instructions
Security Measures
Technical and organizational measures to protect data
Sub-Processors
Terms for engaging additional processors
Data Subject Rights
Assisting with access, rectification, and erasure requests
Breach Notification
Timeline and process for reporting data breaches
Audit Rights
Controller right to audit processor compliance
Understanding Controller vs Processor
Data Controller
Determines the purposes and means of processing personal data.
- Decides what data to collect
- Determines how data is used
- Responsible for legal basis
- Handles data subject requests
Data Processor
Processes personal data on behalf of the controller.
- Acts only on controller instructions
- Implements security measures
- Assists with compliance
- Reports breaches to controller
When You Need a DPA
A DPA is required whenever you share personal data with a third-party processor.
SaaS Providers
When your software processes customer data on their behalf
Cloud Hosting
When using AWS, GCP, Azure, or other cloud providers
Marketing Tools
Email services, CRMs, and analytics platforms
Enterprise Clients
When large clients require DPAs for compliance
How to Create Your DPA
Describe the Processing
Tell us about the data types, data subjects, processing purposes, and security requirements.
AI Agents Draft & Review
Three AI agents collaborate: one drafts, one critiques GDPR compliance, one validates. Result: a comprehensive DPA.
Sign with Your Processor
Export your DPA and execute it with your data processor before sharing any personal data.
What is Included in Your DPA
Processing Details
Subject matter, duration, nature, and purpose of processing
Data Categories
Types of personal data and categories of data subjects
Security Measures
Technical and organizational measures (TOMs)
Sub-Processor Terms
Authorization and notification requirements
Data Subject Rights
Assistance with access, rectification, and erasure
Breach Notification
Timeline and process for reporting breaches
Audit Rights
Controller right to audit processor compliance
Data Return/Deletion
What happens to data when processing ends
Frequently Asked Questions
What is a Data Processing Agreement (DPA)?
A Data Processing Agreement is the contract GDPR Article 28 calls for when a data controller shares personal data with a data processor. It sets out how the processor handles that personal data, including security measures, sub-processor use, and data subject rights.
When do I need a DPA?
You need a DPA whenever you share personal data with a third party who processes it on your behalf. Common examples include cloud hosting providers, email marketing services, CRM platforms, payment processors, and analytics tools. If they process EU resident data, a DPA is required.
What is the difference between a controller and a processor?
A data controller determines why and how personal data is processed (e.g., your business collecting customer data). A data processor processes data on behalf of the controller (e.g., AWS hosting your database). Controllers have more obligations; processors must follow controller instructions.
What must a GDPR-compliant DPA include?
GDPR Article 28 requires: subject matter and duration of processing, nature and purpose of processing, type of personal data, categories of data subjects, controller obligations and rights, processor obligations including security measures, sub-processor terms, and data deletion/return requirements.
Can I use sub-processors under a DPA?
Yes, but the DPA must address sub-processor use. Typically, the controller must approve sub-processors (specific or general authorization), and the processor must ensure sub-processors are bound by equivalent data protection obligations. You must maintain a list of sub-processors.
Is this DPA ready to sign?
Pactlio generates professional DPA drafts using AI following GDPR Article 28 requirements. While our agreements follow standard legal formats and cover required clauses, we recommend having important legal documents reviewed by a licensed attorney. We provide drafts, not legal advice.
Ready to Ensure GDPR Compliance?
Create a comprehensive Data Processing Agreement in minutes. Starting at $10 during beta.
Create Your DPAStarting at $10 during beta. Takes less than 2 minutes.