Saltar al contenido principal
Este contenido solo está disponible actualmente para Alemania.

KMU & Agenturen · Check a DPA

Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit

SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.

Empiece gratis

Fecha límite vista

Before processing starts

Art. 28 DSGVO

Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.

Riesgos típicos en este caso

A qué prestamos especial atención

Seleccionados a partir de casos reales. La comprobación de IA resalta exactamente estos puntos en su documento.

  • TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).

  • Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.

  • Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.

  • Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.

  • Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).

  • Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.

  • Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.

  • Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).

Lo que usted puede hacer aquí en 5 minutos

Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.

Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.

Cómo funciona

Tres pasos para el resultado

1

Upload the DPA

Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.

2

GDPR check

Mandatory Art. 28 content, specification of the TOMs, third-country transfers.

3

Annotated version

For each clause: compliant / renegotiate / critical.

Lo que usted recibe
  • Upload the DPAIncluding the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
  • GDPR checkMandatory Art. 28 content, specification of the TOMs, third-country transfers.
  • Annotated versionFor each clause: compliant / renegotiate / critical.
Lo que no es
  • No on-site audit of TOMs at the processor.
  • No preparation of a record of processing activities.
  • No DPIA (data protection impact assessment).

Preguntas frecuentes

Preguntas frecuentes sobre este caso

Transparencia

Qué comprueba la IA — y qué solo puede decidir un abogado

Una IA solo es tan buena como la pregunta. Por eso le mostraremos abiertamente dónde es fiable su respuesta y dónde debería hablar sin falta con un abogado.

For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.

Comenzar gratis
Sin tarjeta de crédito
Comenzar ahora