Skip to main content
Werkzeu.ge
Dashboard
RemarqueBuilds a data processing agreement per GDPR Art. 28 as a template. Whether it fits your actual setup is better checked by a privacy pro - not legal advice. Aucune information juridiquement contraignante.
PlusDocuments juridiques

AVV-Generator - Générateur de contrat de sous-traitance

As soon as a service provider processes personal data for you - newsletter tool, cloud host, payroll office - the GDPR requires a data processing agreement under Art. 28. It grows here from ready presets, with nine TOM categories, a third-country transfer clause, sub-processor management and a comparison against Art. 28. PDF export included. This page is a preview with an example and an explanation; the actual drafting opens after you sign in with Plus.

Un coup d'œil à l'intérieur

AVV-Generator - Générateur de contrat de sous-traitancePlus
AVV-Generator - Générateur de contrat de sous-traitance : capture d'écran de l'outil avec des données d'exemple
Aperçu avec des données d'exemple. L'utilisation s'ouvre après la connexion.

Cet aperçu sécurisé montre à quoi sert l'outil, sans exécuter d'actions liées à un compte.

Ce que sait faire AVV-Generator - Générateur de contrat de sous-traitance

The data processing agreement, DPA for short, is one of the most frequently overlooked GDPR obligations. Anywhere an external service provider processes personal data on your behalf, Art. 28 GDPR requires a written contract with a fixed minimum content. This affects more cases than most think: email marketing, cloud storage, accounting software, support systems, web hosting. Without the DPA the processing is formally unlawful and, in the worst case, subject to fines.

The DPA generator takes the drafting off your hands. It guides you in clear steps through the parties (controller and processor), the subject and nature of the processing, the categories of data subjects and data, the technical and organizational measures, the sub-processors and the legal clauses. Ready presets for typical service-provider constellations give you a sensible starting point.

The core is the technical and organizational measures, the TOMs under Art. 32 GDPR. The generator structures them into nine categories: the eight customary in practice (physical access, system access, data access, transfer, input, job, availability and separation control) plus review & organisation with regular testing under Art. 32(1)(d) GDPR, training and an incident process. For each category you select the fitting measures instead of formulating them from nothing.

A point where many DPAs fail is the third-country transfer. As soon as a service provider or its sub-processor sits outside the EU, you need a valid transfer mechanism - an adequacy decision or standard contractual clauses (SCC). The generator detects from the location whether a third-country transfer exists and points out whether and which transfer mechanism is needed, so you do not overlook it.

Sub-processors are managed systematically. When your service provider itself engages further providers, the DPA must govern this, including authorization and the passing on of duties. The generator manages the sub-processors as a list, checks their locations for third-country relevance and includes them in the contract. On top there is an Art. 28 checklist as a checking aid that shows which core points your form already covers.

Honesty is part of it: a generated DPA is a solid, GDPR-oriented foundation, but for delicate constellations it does not replace review by a data protection officer or specialist lawyer. For most standard cases with common service providers it is a solid working basis. Everything runs data-frugally, and you export the finished document as PDF, ready for signature by both sides.

Fonctionnalités

Art. 28 building blocks

The minimum content under Art. 28 GDPR as building blocks, from the parties to data subject rights. Review before signing.

Nine TOM categories

Physical, system, data-access, transfer, input, job and availability control, the separation requirement plus review & organisation per Art. 32 GDPR.

Third-country transfer check

The generator detects a third-country link from the location and then adds a clause under Art. 44-49 GDPR (adequacy decision such as the Data Privacy Framework, standard contractual clauses or Art. 49).

Sub-processor management

Manage sub-processors as a list, check their locations and include them cleanly in the contract.

Art. 28 checklist

A checking aid shows which core points of Art. 28 GDPR your form already covers. Not a legal assessment.

PDF export

Export the finished document as PDF, ready for signature by controller and processor.

Comment ça marche

  1. 1

    Pick a preset

    Pick a fitting preset for your service-provider type or start freely.

  2. 2

    Enter parties and processing

    Enter controller and processor, subject, nature and purpose of processing, plus data and subject categories.

  3. 3

    Select TOMs and sub-processors

    Select the fitting measures from the nine TOM categories and record sub-processors including their location.

  4. 4

    Check and export

    The Art. 28 checklist shows what is still missing in the form. Then download the PDF and review it before signing.

Pour qui

→Self-employed and companies using a newsletter or cloud tool.
→Agencies processing data on client instructions who need a DPA.
→Data protection officers standardizing DPAs with service providers.
→Businesses using providers outside the EU who must check SCC.
→Founders who want to document their processing landscape and have it professionally reviewed.

Questions fréquentes

When do I need a data processing agreement?

Whenever an external service provider processes personal data on your behalf, such as your newsletter tool, cloud host, payroll office or support system. Art. 28 GDPR requires a written contract with a fixed minimum content for this. Without a DPA the processing is formally unlawful and can trigger fines.

What are TOMs?

TOMs are the technical and organizational measures under Art. 32 GDPR with which the processor protects the data. The generator structures them into nine categories such as physical access control, data access control, availability control and review & organisation. For each you select the concrete measures your provider implements.

What about service providers outside the EU?

Then a third-country transfer exists, which needs a valid transfer mechanism, such as an EU Commission adequacy decision or standard contractual clauses (SCC). The generator detects from the location whether a third-country link exists and flags the required mechanism, so the transfer stays lawful.

How are sub-processors handled?

If your provider itself engages further providers, the DPA must govern this, including your authorization and the passing on of data protection duties. The generator manages the sub-processors as a list, checks their locations for third-country relevance and includes them in the contract.

Does the generated DPA replace legal advice?

No. It is a solid, GDPR-oriented foundation for standard cases with common service providers. For delicate or complex constellations, such as extensive third-country transfers or special data categories, review by a data protection officer or specialist lawyer is advisable.

Art. 30 DSGVO Helper - Aide pour l'art. 30 du RGPD

Erstelle dein Verarbeitungsverzeichnis nach DSGVO Art. 30. Alle Pflichtangaben, fertig zum Au…

TOMs Generator - Générateur de mesures techniques et organisationnelles

Erstelle dein TOMs-Dokument nach DSGVO Art. 32. Fragebogen ausfüllen, PDF herunterladen, fertig.

Löschkonzept Generator - Générateur de plan de suppression

Erstelle einen prüfbaren Entwurf für Datenkategorien, Fristen und Löschmethoden. Vor dem Eins…

DSFA Quick-Check - Contrôle rapide de l'analyse d'impact

Prüfe, ob eine DSFA nach Art. 35 DSGVO erforderlich ist. Kurzer Fragebogen, klares Ergebnis.

AGB Generator - Générateur de conditions générales

Erstelle nach deutschem Recht strukturierte AGB für Onlineshops, Dienstleister, SaaS, Handwer…

Klausel-Tauscher - Change les clauses du contrat

13 Vertragsklauseln in je 3 Schärfegraden (mild/standard/streng) kombinieren. Risikobewertung…

Prêt pour AVV-Generator - Générateur de contrat de sous-traitance ?

Sans installation. Inclus à partir de Plus. S’ouvre directement dans le navigateur.

Ouvrir maintenant