Zum Hauptinhalt springen
Builds a data processing agreement per GDPR Art. 28 as a template. Whether it fits your actual setup is better checked by a privacy pro - not legal advice. Not legally binding.
PlusLegal Documents

DPA Generator

As soon as a service provider processes personal data for you - newsletter tool, cloud host, payroll office - the GDPR requires a data processing agreement under Art. 28. The DPA generator builds it from ready presets, with eight TOM categories, third-country transfer checks, sub-processor management and a compliance check against Art. 28. PDF export included.

A live look inside

Live preview. It becomes interactive with your account.

What DPA Generator does

The data processing agreement, DPA for short, is one of the most frequently overlooked GDPR obligations. Anywhere an external service provider processes personal data on your behalf, Art. 28 GDPR requires a written contract with a fixed minimum content. This affects more cases than most think: email marketing, cloud storage, accounting software, support systems, web hosting. Without the DPA the processing is formally unlawful and, in the worst case, subject to fines.

The DPA generator takes the drafting off your hands. It guides you in clear steps through the parties (controller and processor), the subject and nature of the processing, the categories of data subjects and data, the technical and organizational measures, the sub-processors and the legal clauses. Ready presets for typical service-provider constellations give you a sensible starting point.

The core is the technical and organizational measures, the TOMs under Art. 32 GDPR. The generator structures them into eight categories as is customary in practice: physical access control, system access control, data access control, transfer control, input control, job control, availability control and the separation requirement. For each category you select the fitting measures instead of formulating them from nothing.

A point where many DPAs fail is the third-country transfer. As soon as a service provider or its sub-processor sits outside the EU, you need a valid transfer mechanism - an adequacy decision or standard contractual clauses (SCC). The generator detects from the location whether a third-country transfer exists and points out whether and which transfer mechanism is needed, so you do not overlook it.

Sub-processors are managed systematically. When your service provider itself engages further providers, the DPA must govern this, including authorization and the passing on of duties. The generator manages the sub-processors as a list, checks their locations for third-country relevance and includes them in the contract. On top there is a compliance check that verifies whether your DPA covers the core requirements of Art. 28.

Honesty is part of it: a generated DPA is a solid, GDPR-oriented foundation, but for delicate constellations it does not replace review by a data protection officer or specialist lawyer. For most standard cases with common service providers it is a solid working basis. Everything runs data-frugally, and you export the finished document as PDF, ready for signature by both sides.

Features

Art. 28 GDPR covered

All mandatory components of a data processing agreement under Art. 28 GDPR are covered, from the parties to data subject rights.

Eight TOM categories

Physical, system, data-access, transfer, input, job and availability control plus the separation requirement per Art. 32 GDPR.

Third-country transfer check

The generator detects a third-country link from the location and flags the required transfer mechanism such as SCC.

Sub-processor management

Manage sub-processors as a list, check their locations and include them cleanly in the contract.

Art. 28 compliance check

A check verifies whether your DPA covers the core requirements of Art. 28 GDPR before you sign.

PDF export

Export the finished document as PDF, ready for signature by controller and processor.

How it works

  1. 1

    Pick a preset

    Pick a fitting preset for your service-provider type or start freely.

  2. 2

    Enter parties and processing

    Enter controller and processor, subject, nature and purpose of processing, plus data and subject categories.

  3. 3

    Select TOMs and sub-processors

    Select the fitting measures from the eight TOM categories and record sub-processors including their location.

  4. 4

    Check and export

    The compliance check shows gaps against Art. 28. Then download the finished PDF.

Who needs this

→Self-employed and companies using a newsletter or cloud tool.
→Agencies processing data on client instructions who need a DPA.
→Data protection officers standardizing DPAs with service providers.
→Businesses using providers outside the EU who must check SCC.
→Founders securing their processing landscape GDPR-compliant.

Frequently asked questions

When do I need a data processing agreement?

Whenever an external service provider processes personal data on your behalf, such as your newsletter tool, cloud host, payroll office or support system. Art. 28 GDPR requires a written contract with a fixed minimum content for this. Without a DPA the processing is formally unlawful and can trigger fines.

What are TOMs?

TOMs are the technical and organizational measures under Art. 32 GDPR with which the processor protects the data. The generator structures them into eight categories such as physical access control, data access control and availability control. For each you select the concrete measures your provider implements.

What about service providers outside the EU?

Then a third-country transfer exists, which needs a valid transfer mechanism, such as an EU Commission adequacy decision or standard contractual clauses (SCC). The generator detects from the location whether a third-country link exists and flags the required mechanism, so the transfer stays lawful.

How are sub-processors handled?

If your provider itself engages further providers, the DPA must govern this, including your authorization and the passing on of data protection duties. The generator manages the sub-processors as a list, checks their locations for third-country relevance and includes them in the contract.

Does the generated DPA replace legal advice?

No. It is a solid, GDPR-oriented foundation for standard cases with common service providers. For delicate or complex constellations, such as extensive third-country transfers or special data categories, review by a data protection officer or specialist lawyer is advisable.

GDPR Art. 30 Helper

Create your GDPR Article 30 records of processing activities. All required fields, ready to p…

TOMs Generator

Create your GDPR Article 32 TOMs document. Fill out the questionnaire, download PDF, done.

Deletion Concept Generator

Create a structured data deletion concept. Categories, retention periods, methods.

DPIA Quick Check

Check if a DPIA per Art. 35 GDPR is required. 12 questions, clear result.

Terms & Conditions Generator

Generate German terms and conditions (AGB) structured along German law for online shops, serv…

Clause Switcher

Combine 13 contract clauses in 3 severity levels (mild/standard/strict). Risk scoring, preset…

Ready to use DPA Generator?

No installation. No account needed to start. Open it right in your browser.

Open now