Passer au contenu principal
Ce contenu n'est actuellement disponible que pour l'Allemagne.

KMU & Agenturen · Check a DPA

Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit

SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.

Commencez gratuitement

Le délai en un coup d'œil

Before processing starts

Art. 28 DSGVO

Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.

Risques typiques dans ce cas

Ce à quoi nous accordons une attention particulière

Sélectionnés à partir de cas réels. L'analyse par IA met précisément en évidence ces points dans votre document.

  • TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).

  • Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.

  • Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.

  • Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.

  • Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).

  • Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.

  • Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.

  • Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).

Ce que vous pouvez faire ici en 5 minutes

Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.

Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.

Voici comment cela fonctionne

Trois étapes pour obtenir le résultat souhaité

1

Upload the DPA

Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.

2

GDPR check

Mandatory Art. 28 content, specification of the TOMs, third-country transfers.

3

Annotated version

For each clause: compliant / renegotiate / critical.

Ce que vous recevez
  • Upload the DPAIncluding the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
  • GDPR checkMandatory Art. 28 content, specification of the TOMs, third-country transfers.
  • Annotated versionFor each clause: compliant / renegotiate / critical.
Ce que ce n'est pas
  • No on-site audit of TOMs at the processor.
  • No preparation of a record of processing activities.
  • No DPIA (data protection impact assessment).

FAQ

Questions fréquentes concernant cette affaire

transparence

Ce que l'IA vérifie — et ce que seul un avocat peut décider

Une IA n'est jamais meilleure que la question qui lui est posée. C'est pourquoi nous vous indiquons clairement dans quels cas notre réponse est fiable et dans quels cas vous devriez impérativement consulter un avocat.

For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.

Commencez gratuitement
Pas de carte de crédit
Commencer maintenant