Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit
SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.
Inizia gratuitamente
Scadenza in vista
Before processing starts
Art. 28 DSGVO
Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.
A cosa prestiamo particolare attenzione
Selezionato da casi reali. Il controllo IA evidenzia esattamente questi punti nel Suo documento.
TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).
Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.
Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.
Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.
Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).
Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.
Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.
Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).
Cosa può fare qui in 5 minuti
Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.
Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.
Tre passaggi per il risultato
Upload the DPA
Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
GDPR check
Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
Annotated version
For each clause: compliant / renegotiate / critical.
- Upload the DPA – Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
- GDPR check – Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
- Annotated version – For each clause: compliant / renegotiate / critical.
- No on-site audit of TOMs at the processor.
- No preparation of a record of processing activities.
- No DPIA (data protection impact assessment).
Domande frequenti
Domande frequenti su questo caso
Trasparenza
Cosa controlla l'IA — e cosa può decidere solo un avvocato
Un'IA è valida solo quanto la domanda. Ecco perché Le mostreremo apertamente dove la Sua risposta è affidabile e dove dovrebbe assolutamente parlare con un avvocato.
For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.
Ulteriori lettere e verifiche
Legge sulla protezione dei dati · DPA / DPA (Accordo di Elaborazione dei Dati) · Redline (Markup del contratto) · Revisione del trattato · Create your own DPA with AI
- Check a B2B NDAReceived an NDA from a business partner? We check the penalty, term, scope and place of jurisdiction — before you sign.
- Supplier termsNew supplier, thick annex of terms and conditions? We check the most important risk clauses before you conclude the framework agreement.
Pronto a risolvere il Suo caso?
Inizia gratuitamente. Nessuna carta di credito. Pronto tra 2 minuti.
Inizia