A data processing agreement can look routine with commercial terms settled and boilerplate wording. But it’s worth paying attention to how a third party data processor handles personal data on your behalf, what happens after a personal data breach, and who pays when a safeguard fails.
The more contracts you have, the higher the stakes. Every new vendor you share personal data with, every renewal, every SaaS tool touching employee data or customer records brings its own data processing agreement DPA, most drafted for the supplier, with the data privacy and data security obligations that protect you watered down.
This is a contract review checklist for DPAs, written from the side of the data controller engaging a service provider, the company whose personal data is being processed. The checklist is available as a downloadable PDF at the end of this article, ready to use against your next DPA.
If your legal team is still spending hours on manual contract review, then try LEGALFLY. LEGALFLY cuts review time by up to 87.5%, turning a two hour review into 15 minutes, without taking control away from your team. Book a demo to see how it fits into the way your legal team already works.
Run a data processing agreement review in LEGALFLY in 15 minutes
You can use LEGALFLY to automatically apply a 21-point data processing agreement playbook to every DPA. A review that takes a senior lawyer two hours is done in about 15 minutes, in the same way every time, no matter who handles it.

1. Open the DPA in Microsoft Word
Launch the LEGALFLY add-in. Before any AI processing, LEGALFLY anonymises sensitive data at ingestion: counterparty names, entities, and identifiers become tokens, and the original document stays under your control.
2. Select the data processing agreement playbook
It holds the 21 review points in this article, configured with your preferred positions and fallback wording. Pick the variant that fits the deal.

3. Run the review
LEGALFLY reads the DPA clause by clause, applies your risk thresholds, and flags every deviation from your preferred position.

4. Review tracked changes with rationale
Each edit lands as a tracked change in Microsoft Word, tied to the playbook rule that triggered it. Accept, modify, or reject each one.
5. Export with a full audit trail
The document exports with a complete record of changes, rules applied, and approvals given, ready for internal governance or an external audit.
Most teams using LEGALFLY cut their contract review time in half within a few weeks of onboarding. Book a short demo to see how it works for your business.
For DPAs you handle in volume, run the review as an automated workflow through Agent Studio. Business teams raise the request from Slack, Microsoft Teams, or email; LEGALFLY routes the output to the right lawyer by contract type, risk level, or counterparty. You keep final approval throughout.
See for yourself why LEGALFLY is a top automated contract review software.

In depth data processing agreement review checklist: everything to verify before signing
Download the checklist here.
Signing a DPA without a proper read exposes you to regulatory enforcement, unrecoverable losses after a breach, and obligations you never agreed to carry. The seven areas below are where in-house teams should focus. Work through them in order; the early ones set the frame for the rest.
Under the General Data Protection Regulation, once a data controller hands personal data to a data processor, a written contract must govern the relationship. Article 28 fixes the mandatory content: a legally binding contract, supported by valuable consideration like any commercial agreement, setting out the subject matter, the duration, the nature and purpose of the processing, the types of personal data processed, and the categories of data subjects. The GDPR exists to protect identifiable natural persons; a gdpr data processing agreement that omits these elements is non-compliant on its face, whatever the parties involved do in practice.
The duty reaches past the European Union. Equivalent rules under other privacy laws sit in the UK Data Protection Act, the California Consumer Privacy Act, and the California Privacy Rights Act, each requiring a written contract that binds any service provider or third party processor handling personal data.
As your data privacy laws multiply across regions, the applicable data protection laws stack, and one DPA has to satisfy them all.
Your review does two jobs: clear the baseline that applicable laws demand, and push the negotiable terms toward positions that protect personal data and protect your organisation.
Confirm what is being processed, and why
Article 28 requires the DPA to record the basics of the processing. These descriptions cap what the processor may do with your data, so tighten anything vague.
Subject matter and duration
Check that the DPA states the subject matter and ties the duration of processing to the term of the main agreement. An open-ended duration lets processing outlive the service it supports.
Nature and purpose
Confine the purpose to delivering the contracted services. Avoid wording such as "and related purposes" that lets the processor use your data for its own business purposes.
Types of personal data and categories of data subjects
Ask for an itemised list of the types of personal data processed and the categories of data subjects. "Contact data" tells you nothing about whether sensitive data or employee data is in scope, and for certain services that distinction decides which obligations apply.
Lock down how the processor handles your data
The processor should do only what you instruct, and only the right people should see the data.
Documented instructions
Bind the processor to act on your written instructions and nothing more. Those documented instructions should extend to any international data transfers, and may be issued by electronic or other means, but the duty to follow them belongs in the contract as a binding term.
Personnel confidentiality
Require everyone authorised to process personal data to be under a strict duty of confidentiality, and confirm such data never travels beyond the documented purpose. Otherwise your data moves through staff and contractors unchecked, and the chain that demonstrates lawful processing to a supervisory authority breaks.
Pressure-test security and breach notification
Here secure processing becomes concrete: the safeguards the processor commits to, and how fast it warns you when they fail.
Technical and organisational measures
Require appropriate technical and organisational measures proportionate to the risk: access controls, access restrictions, encryption, password protection, and the wider information security and security requirements you expect of a serious security service provider. Make the processor take reasonable and appropriate steps to maintain them, and read any security annex it references. An "industry-standard" promise with nothing behind it is empty.
Breach notification
Insist on report of any personal data breach without undue delay, with a hard outer limit such as 48 hours; data breaches handled slowly become your compliance problem. Specify the content too: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the remediation taken.
You need that relevant information to meet your own reporting duties and to brief data subject contacts if individuals must be told.
Stop reading DPAs line by line. LEGALFLY applies your playbook to every data processing agreement and returns tracked changes in Microsoft Word, each tied to the rule behind it. Book a demo to see it run on your own contracts.
Keep control of sub-processors
A processor engaging other vendors is routine, and every layer of sub processing lengthens the chain of custody over your data.
Sub-processor authorisation
Pin down how new sub-processors get approved. The strongest position requires prior specific written authorisation for each one; the workable fallback is general written authorisation with advance notice and a real right to object.
Reject any clause that lets the processor add third party processors at will, and where general authorisation applies, set a notice period long enough for genuine due diligence on the incoming party.
Liability for sub-processors
Hold the processor fully liable to you for the acts and omissions of its sub processors. Cap or disclaim that liability, and a failure two layers down becomes yours, with no route to recovery.
LEGALFLY helps your team move faster: less time buried in contracts, more time on the work that actually matters. Book a call to see it in action.
Check the processor's assistance obligations
When a data subject exercises their rights, or you run a data protection impact assessment, the information you need usually sits with the processor.
Data subject rights
Require prompt, reasonable assistance with data subject rights requests, and rule out fees that turn a routine request into a negotiation.
DPIAs and supervisory authority consultations
Require the same assistance for data protection impact assessments and any prior consultation with a supervisory authority. These duties are how you discharge the controller's obligations under data protection law.
A processor that helps only at steep cost or after long delay undercuts your ability to respond in time.
Scrutinise international data transfers
Once personal data leaves the European Economic Area, the agreement needs a valid basis for the transfer, or the transfer is unlawful.
Transfer mechanism
Confirm the DPA incorporates the current version of a valid mechanism, such as the latest Standard Contractual Clauses. Confine any such transfer to a third country to a recognised mechanism.
Data flow mapping
Map where your data goes. Where the processor or its sub processors sit outside the European Union, a mechanism on paper means little if the real routes are uncovered.
Most teams cut DPA review time sharply within weeks of onboarding LEGALFLY. Book a demo to see how it fits your workflow.
Get exit, audit, and liability right
The last group governs what you can verify during the relationship and what you can reclaim when it ends.
Audit rights
Secure the right to test the processor's compliance through inspections you conduct or mandate, beyond a yearly certificate.
Confirm the processor must permit audits and hand over the information needed to demonstrate compliance.
Data return and deletion
On termination, take the choice between return or deletion of all personal data processed, with surviving copies deleted to the extent permitted by relevant laws.
Liability cap and carve-outs
Read who the cap shields. Push for a cap high enough to bite and reciprocal across the parties involved, with carve-outs that lift data protection and confidentiality breaches above the general cap so you can recover when the failure is a data breach.
Treat a low cap, or one running only to the processor's benefit, as a renegotiation.
Governing law and jurisdiction
Name a governing law and jurisdiction that work for you. A default to the supplier's home venue is a position to push back on.
Make data processing agreement review consistent across your team
The checklist below is a working form of the data processing agreement review checklist LEGALFLY runs across 110+ jurisdictions. Take it, set your preferred positions, and make it your team's standard.
LEGALFLY ships with 120 pre-built playbooks, 500+ verified legal sources, and ISO 27001 and SOC 2 Type II certification, so you can go from this checklist to an automated review without building from scratch.
Download the checklist.
When new regulation lands, the same standard runs in reverse: LEGALFLY's Multi-Review agent scans your portfolio and flags agreements that no longer comply, and Legal Radar tracks regulatory change across jurisdictions and tells you when an obligation touching your DPAs has moved.
Your document repository holds the agreements. LEGALFLY runs the review.
Book a LEGALFLY demo, and we will walk you through the data processing agreement playbook using contract types relevant to your portfolio.
Frequently asked questions
What is a data processing agreement?
A data processing agreement, or DPA, is a legally binding contract between a data controller and a data processor that governs how the processor handles personal data on the controller's behalf. Article 28 of the General Data Protection Regulation requires one wherever a processor processes personal data for a controller, and equivalent rules apply under the UK Data Protection Act, the California Consumer Privacy Act, and the California Privacy Rights Act.
What must a DPA include to comply with the GDPR?
A compliant gdpr data processing agreement sets out the subject matter, duration, nature, and purpose of the processing, the types of personal data and categories of data subjects, plus binding terms on documented instructions, confidentiality, security measures, sub-processor authorisation, assistance with data subject rights, breach notification, international data transfers, and deletion or return of data on termination.
Who is responsible, the controller or the processor?
Both parties involved sign, but the data controller carries primary accountability for putting a compliant contract in place and confirming the processor offers sufficient guarantees. The processor must process data only on documented instructions and meet the agreed security and assistance duties. In a direct business relationship, the controller should lead the review and renegotiate the processor's template wherever it falls short.
How long does a DPA review take?
A careful manual review of one DPA runs to roughly two hours. With a playbook-driven review in LEGALFLY it takes about 15 minutes, each flagged clause tied to the rule behind it, with a full audit trail for governance.






