Vada al contenuto principale
Questi contenuti sono attualmente disponibili solo per la Germania.

KMU & Agenturen · Check a DPA

Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit

SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.

Inizia gratuitamente

Scadenza in vista

Before processing starts

Art. 28 DSGVO

Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.

Rischi tipici in questo caso

A cosa prestiamo particolare attenzione

Selezionato da casi reali. Il controllo IA evidenzia esattamente questi punti nel Suo documento.

  • TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).

  • Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.

  • Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.

  • Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.

  • Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).

  • Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.

  • Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.

  • Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).

Cosa può fare qui in 5 minuti

Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.

Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.

Come funziona

Tre passaggi per il risultato

1

Upload the DPA

Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.

2

GDPR check

Mandatory Art. 28 content, specification of the TOMs, third-country transfers.

3

Annotated version

For each clause: compliant / renegotiate / critical.

Cosa riceve
  • Upload the DPAIncluding the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
  • GDPR checkMandatory Art. 28 content, specification of the TOMs, third-country transfers.
  • Annotated versionFor each clause: compliant / renegotiate / critical.
Cosa non è
  • No on-site audit of TOMs at the processor.
  • No preparation of a record of processing activities.
  • No DPIA (data protection impact assessment).

Domande frequenti

Domande frequenti su questo caso

Trasparenza

Cosa controlla l'IA — e cosa può decidere solo un avvocato

Un'IA è valida solo quanto la domanda. Ecco perché Le mostreremo apertamente dove la Sua risposta è affidabile e dove dovrebbe assolutamente parlare con un avvocato.

For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.

Inizia gratuitamente
Nessuna carta di credito
Inizia