Ga naar de hoofdinhoud
Deze inhoud is momenteel alleen beschikbaar voor Duitsland.

KMU & Agenturen · Check a DPA

Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit

SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.

Gratis aan de slag

De deadline in het oog houden

Before processing starts

Art. 28 DSGVO

Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.

Typische risico's in dit geval

Waar wij in het bijzonder op letten

Samengesteld op basis van echte gevallen. De AI-controle markeert precies deze punten in uw document.

  • TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).

  • Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.

  • Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.

  • Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.

  • Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).

  • Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.

  • Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.

  • Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).

Wat u hier in 5 minuten kunt regelen

Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.

Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.

Zo werkt het

In drie stappen naar het resultaat

1

Upload the DPA

Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.

2

GDPR check

Mandatory Art. 28 content, specification of the TOMs, third-country transfers.

3

Annotated version

For each clause: compliant / renegotiate / critical.

Wat u krijgt
  • Upload the DPAIncluding the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
  • GDPR checkMandatory Art. 28 content, specification of the TOMs, third-country transfers.
  • Annotated versionFor each clause: compliant / renegotiate / critical.
Wat het niet is
  • No on-site audit of TOMs at the processor.
  • No preparation of a record of processing activities.
  • No DPIA (data protection impact assessment).

Veelgestelde vragen

Veelgestelde vragen over deze zaak

Transparantie

Wat de AI controleert — en wat alleen een advocaat kan beslissen

Een AI is altijd maar zo goed als de vraag. Daarom laten wij u duidelijk zien wanneer ons antwoord betrouwbaar is en wanneer u beslist een advocaat moet raadplegen.

For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.

Gratis aan de slag
Geen creditcard
Nu beginnen