Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit
SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.
Empiece gratis
Fecha límite vista
Before processing starts
Art. 28 DSGVO
Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.
A qué prestamos especial atención
Seleccionados a partir de casos reales. La comprobación de IA resalta exactamente estos puntos en su documento.
TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).
Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.
Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.
Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.
Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).
Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.
Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.
Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).
Lo que usted puede hacer aquí en 5 minutos
Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.
Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.
Tres pasos para el resultado
Upload the DPA
Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
GDPR check
Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
Annotated version
For each clause: compliant / renegotiate / critical.
- Upload the DPA – Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
- GDPR check – Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
- Annotated version – For each clause: compliant / renegotiate / critical.
- No on-site audit of TOMs at the processor.
- No preparation of a record of processing activities.
- No DPIA (data protection impact assessment).
Preguntas frecuentes
Preguntas frecuentes sobre este caso
Transparencia
Qué comprueba la IA — y qué solo puede decidir un abogado
Una IA solo es tan buena como la pregunta. Por eso le mostraremos abiertamente dónde es fiable su respuesta y dónde debería hablar sin falta con un abogado.
For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.
Cartas y comprobaciones adicionales
Ley de protección de datos · DPA / DPA (Acuerdo de Procesamiento de Datos) · Redline (marcado de contrato) · Revisión del contrato · Create your own DPA with AI
- Check a B2B NDAReceived an NDA from a business partner? We check the penalty, term, scope and place of jurisdiction — before you sign.
- Supplier termsNew supplier, thick annex of terms and conditions? We check the most important risk clauses before you conclude the framework agreement.
¿Preparado para resolver su caso?
Empiece gratis. Sin tarjeta de crédito. Listo en 2 minutos.
Empezar ahora