Guide

What a Compliant DPA Must Include: An Article 28 Checklist

GDPR Article 28 lists specific provisions a Data Processing Agreement has to contain. Here's a practical checklist to run any vendor's DPA against before you sign it.

Published August 14, 2026·Last updated August 14, 2026

Most vendors hand you a pre-written DPA and expect you to accept it as-is. That’s usually fine, but it’s worth actually checking it against what Article 28 requires rather than assuming a professional-looking document covers everything. Here’s what to look for.

The required provisions

  1. Subject matter, duration, and purpose of processing. The DPA should specify what’s being processed and why, not just reference “the services” vaguely.
  2. Categories of personal data and data subjects. What kind of data (contact details, usage data, payment data) and whose (your customers, your employees, site visitors) should be identified, not left implicit.
  3. Processing only on documented instructions. The vendor must commit to processing data only as you instruct, not for its own independent purposes, this is the core distinction between a processor and a separate controller.
  4. Confidentiality commitments for anyone with access to the data, employees, contractors, sub-processors.
  5. Security measures, a commitment to implement appropriate technical and organizational measures (encryption, access controls, etc.), often referencing a separate security documentation page or SOC 2 report.
  6. Sub-processor terms, either general authorization with a notification/objection right, or specific authorization for named sub-processors. Covered in more depth in our sub-processor guide.
  7. Assistance with data subject rights, the vendor should commit to reasonably assisting you in responding to DSARs and other data subject requests, since you can’t fulfill a request involving data the vendor holds without their cooperation.
  8. Assistance with security and DPIA obligations, help with breach notification and, where relevant, data protection impact assessments.
  9. End-of-contract data handling, deletion or return of personal data when the relationship ends, this is commonly missed or left vague in DPAs that otherwise look thorough.
  10. Audit and information rights, your ability to verify the vendor’s compliance, discussed further in our audit rights guide.
Our recommendation

CookieYes

Running this checklist against your own vendors is easier when your consent platform's own DPA is a known-good reference point. CookieYes publishes a standard DPA covering these Article 28 provisions as part of its terms.

Try CookieYes

What’s commonly missing

In our own review of vendor DPAs while building this site’s vendor stack, the two most frequently weak or missing provisions were end-of-contract data deletion (often absent entirely) and specific sub-processor disclosure (frequently just a generic “we may use sub-processors” line with no list or notification mechanism). Both are worth flagging specifically if you’re negotiating rather than accepting a standard template.

If something’s missing

You don’t necessarily need to walk away from a vendor whose DPA is thin. Options in rough order of effort: ask if a more complete version exists (some vendors have an “enterprise” DPA they don’t publish by default), request the specific missing provision as an amendment, or, for a lower-risk vendor relationship, document the gap and accept the risk with sign-off from whoever owns compliance decisions at your business.

The bottom line

A DPA that exists is a good start, but existence isn’t the same as completeness. Running any vendor’s DPA against this checklist takes a few minutes and catches the gaps that a “yes, we have a DPA” answer alone won’t surface.

This guide is educational and not legal advice. For your specific vendor contracts, consult a privacy attorney.