Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit
SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.
Commencez gratuitement
Le délai en un coup d'œil
Before processing starts
Art. 28 DSGVO
Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.
Ce à quoi nous accordons une attention particulière
Sélectionnés à partir de cas réels. L'analyse par IA met précisément en évidence ces points dans votre document.
TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).
Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.
Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.
Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.
Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).
Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.
Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.
Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).
Ce que vous pouvez faire ici en 5 minutes
Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.
Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.
Trois étapes pour obtenir le résultat souhaité
Upload the DPA
Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
GDPR check
Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
Annotated version
For each clause: compliant / renegotiate / critical.
- Upload the DPA – Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
- GDPR check – Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
- Annotated version – For each clause: compliant / renegotiate / critical.
- No on-site audit of TOMs at the processor.
- No preparation of a record of processing activities.
- No DPIA (data protection impact assessment).
FAQ
Questions fréquentes concernant cette affaire
transparence
Ce que l'IA vérifie — et ce que seul un avocat peut décider
Une IA n'est jamais meilleure que la question qui lui est posée. C'est pourquoi nous vous indiquons clairement dans quels cas notre réponse est fiable et dans quels cas vous devriez impérativement consulter un avocat.
For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.
Autres courriers & vérifications
Législation sur la protection des données · AVV / DPA (Contrat de sous-traitance) · Redline (annotation du contrat) · Révision du contrat · Create your own DPA with AI
- Check a B2B NDAReceived an NDA from a business partner? We check the penalty, term, scope and place of jurisdiction — before you sign.
- Supplier termsNew supplier, thick annex of terms and conditions? We check the most important risk clauses before you conclude the framework agreement.
Prêt à régler votre affaire ?
Commencez gratuitement. Pas besoin de carte de crédit. C'est prêt en 2 minutes.
Commencer maintenant