Check a DPA / data processing agreement (AVV) — TOMs, third countries, audit
SaaS contract with a DPA attached? We check TOMs, sub-processors, third-country transfers and audit rights against Art. 28 DSGVO.
Zacznij za darmo
Termin w zasięgu wzroku
Before processing starts
Art. 28 DSGVO
Without a valid DPA, you are fully responsible yourself for every data processing operation carried out by the service provider.
Na co zwracamy szczególną uwagę
Dobrane na podstawie prawdziwych przypadków. Kontrola AI zaznacza dokładnie te punkty w Państwa dokumencie.
TOMs nur als "angemessen" beschrieben, ohne konkrete Maßnahmen (Verschlüsselung, MFA, Backup, Pseudonymisierung).
Sub-Auftragsverarbeiter "nach billigem Ermessen" änderbar, ohne Widerspruchsrecht.
Datentransfer in USA/Drittländer ohne SCC oder Transfer Impact Assessment.
Audit-Recht nur "nach Ankündigung von 90 Tagen, einmal pro Jahr, max. 1 Werktag" — faktisch wertlos.
Meldepflicht bei Datenpanne erst nach 72h+ (statt unverzüglich).
Rückgabe/Löschung nach Vertragsende "nach Wahl" des Auftragnehmers.
Haftung des Auftragnehmers auf 1× Jahresumsatz begrenzt.
Kein Mitwirkungsanspruch bei Betroffenenrechten (Art. 12 ff. DSGVO).
Co mogą Państwo tutaj zrobić w 5 minut
Data processing agreements (AVV/DPA) are mandatory under Art. 28 DSGVO — but their quality varies enormously. Vague TOMs, long lists of sub-processors, US data flows without SCCs: we check this against the EDPB requirements.
Upload the DPA — we check the nature and purpose of the processing, data categories, TOMs, sub-processors (including third countries), audit rights, notification obligations and the deletion concept.
Trzy kroki do rezultatu
Upload the DPA
Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
GDPR check
Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
Annotated version
For each clause: compliant / renegotiate / critical.
- Upload the DPA – Including the annexes on technical and organisational measures (TOMs) and the list of sub-processors.
- GDPR check – Mandatory Art. 28 content, specification of the TOMs, third-country transfers.
- Annotated version – For each clause: compliant / renegotiate / critical.
- No on-site audit of TOMs at the processor.
- No preparation of a record of processing activities.
- No DPIA (data protection impact assessment).
FAQ
Najczęściej zadawane pytania dotyczące tej sprawy
Przejrzystość
Co AI sprawdza — i co może zdecydować tylko prawnik
AI jest tylko tak dobre, jak zadane pytanie. Dlatego otwarcie pokazujemy Państwu, kiedy odpowiedź jest wiarygodna, a kiedy należy koniecznie porozmawiać z adwokatem.
For third-country transfers to unsafe countries, sensitive data (Art. 9 DSGVO), health or fintech contexts, or US services relevant under Schrems II, you should involve a data protection specialist.
Dalsze listy i sprawdzenia
Prawo dotyczące ochrony danych osobowych · DPA / DPA (Umowa o przetwarzaniu danych) · Redline (oznaczanie zmian w umowie) · Rewizja umowy · Create your own DPA with AI
- Check a B2B NDAReceived an NDA from a business partner? We check the penalty, term, scope and place of jurisdiction — before you sign.
- Supplier termsNew supplier, thick annex of terms and conditions? We check the most important risk clauses before you conclude the framework agreement.
Gotowi na wyjaśnienie sprawy?
Zacznij za darmo. Brak karty kredytowej. Gotowy do startu za 2 minuty.
Zacznij