Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit
SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.
Gratis aan de slag
De deadline in het oog houden
Before processing starts
Art. 28 DSGVO
Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.
Waar wij in het bijzonder op letten
Samengesteld op basis van echte gevallen. De AI-controle markeert precies deze punten in uw document.
TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).
Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.
Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.
Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.
Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).
Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.
Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.
Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).
Wat u hier in 5 minuten kunt regelen
Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.
Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.
In drie stappen naar het resultaat
Upload the DPA
Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
GDPR check
Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
Annotated version
For each clause: compliant / renegotiate / critical.
- Upload the DPA – Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
- GDPR check – Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
- Annotated version – For each clause: compliant / renegotiate / critical.
- No on-site audit of TOMs at the processor.
- No preparation of a record of processing activities.
- No DPIA (data protection impact assessment).
Veelgestelde vragen
Veelgestelde vragen over deze zaak
Transparantie
Wat de AI controleert — en wat alleen een advocaat kan beslissen
Een AI is altijd maar zo goed als de vraag. Daarom laten wij u duidelijk zien wanneer ons antwoord betrouwbaar is en wanneer u beslist een advocaat moet raadplegen.
For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.
Overige brieven en controles
Gegevensbeschermingswetgeving · AVV / DPA (Verwerkersovereenkomst) · Redline (contractmarkering) · Herziening van de overeenkomst · Create your own DPA with AI
- Check a B2B NDAReceived an NDA from a business partner? We check the penalty, term, scope and place of jurisdiction — before you sign.
- Supplier termsNew supplier, thick annex of terms and conditions? We check the most important risk clauses before you conclude the framework agreement.
Klaar om uw zaak op te lossen?
Gratis aan de slag. Geen creditcard nodig. Binnen 2 minuten klaar voor gebruik.
Nu beginnen