Przejdź do treści głównej
Te treści są obecnie dostępne tylko dla Niemiec.

KMU & Agenturen · Check a DPA

Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit

SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.

Zacznij za darmo

Termin w zasięgu wzroku

Before processing starts

Art. 28 DSGVO

Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.

Typowe ryzyka w tym przypadku

Na co zwracamy szczególną uwagę

Dobrane na podstawie prawdziwych przypadków. Kontrola AI zaznacza dokładnie te punkty w Państwa dokumencie.

  • TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).

  • Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.

  • Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.

  • Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.

  • Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).

  • Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.

  • Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.

  • Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).

Co mogą Państwo tutaj zrobić w 5 minut

Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.

Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.

Jak to działa

Trzy kroki do rezultatu

1

Upload the DPA

Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.

2

GDPR check

Mandatory Art. 28 content, specification of the TOMs, third-country transfers.

3

Annotated version

For each clause: compliant / renegotiate / critical.

Co Państwo otrzymują
  • Upload the DPAIncluding the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
  • GDPR checkMandatory Art. 28 content, specification of the TOMs, third-country transfers.
  • Annotated versionFor each clause: compliant / renegotiate / critical.
Czym to nie jest
  • No on-site audit of TOMs at the processor.
  • No preparation of a record of processing activities.
  • No DPIA (data protection impact assessment).

FAQ

Najczęściej zadawane pytania dotyczące tej sprawy

Przejrzystość

Co AI sprawdza — i co może zdecydować tylko prawnik

AI jest tylko tak dobre, jak zadane pytanie. Dlatego otwarcie pokazujemy Państwu, kiedy odpowiedź jest wiarygodna, a kiedy należy koniecznie porozmawiać z adwokatem.

For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.

Zacznij za darmo
Brak karty kredytowej
Zacznij