
Data Processing Agreement Checklist Before You Sign
Use a data processing agreement checklist before signing: lock roles, test objection rights, name the UK transfer tool, then sign or walk.
Key takeaway in 30 seconds
A data processing agreement checklist before signing is the written processor contract you need before a vendor holds personal data. Confirm roles, instructions, sub-processors, and breach timing, then stack the DPA against the MSA cap.
You are one click from enabling a SaaS tool that will hold customer or employee data. Use this data processing agreement checklist before signing: confirm who decides purposes and means, reject an empty annex, test sub-processor notice plus a usable object, calendar breach hours, name the UK transfer tool, then sign, send four to six redlines, or walk.
In August 2026, Noor — UK SaaS founder, 14 people — is about to turn on a US analytics vendor. Procurement forwarded a 19-page DPA last night: Annex I says “as required to provide the services,” a silent sub-processor URL, and “promptly” for breach. Liability sits under the MSA — a master services agreement, the frame vendors hang order forms on — with a fees-paid cap and no breach carve-out. Typical mistake: treating 72 hours as the processor’s only duty.
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.
Who is the controller and who is the processor?
You are the controller if you decide the purposes and means of the processing. The vendor is the processor when it processes personal data on your behalf — for example a cloud analytics host. If the paper calls you a joint controller, or names the vendor a controller while it only hosts your data, stop: that role error is a High flag — an item scored high severity.
The ICO still wants a written contract before processing starts, plus an equivalent contract with each sub-processor. Freeze the packet — the exact file set that will be signed: DPA, MSA, order form, sub-processor list, and the security exhibit — an attached schedule or appendix. In practice a click-wrap the night before go-live is how Noor’s team skips roles.
- Do: match the contract to who decides purposes and means.
- Do not: enable the tool because the PDF says GDPR.

What does the processing annex actually need to name?
The contract must set subject matter, duration, nature, purpose, types of personal data, and categories of data subjects. “As required to provide the services” fails that test. If the annex is empty, write a one-page instruction sheet or refuse to enable the product.
That list is the Article 28 chapeau; the ICO eight minimum terms then sit on top, and parties may supplement, not subtract. Pair that with UK GDPR Article 28. An instruction may be email if you can save it. If the processor starts deciding purposes and means, it becomes a controller for that flow.
- Do: name data types, subjects, duration, and purpose.
- Do not: accept a blank processing annex and “we will confirm later.”
How do you test sub-processor notice and objection rights?
The processor needs prior specific or general written authorisation before it engages a sub-processor. General authorisation still requires prior notice of additions and a chance to object. A silent webpage edit is not notice, and flow-down must offer equivalent protection.
Keep a dated identity list. EDPB Opinion 22/2024 says keep those identities ready and scale verification with risk. You need not collect every sub-contract; the controller still decides whether to engage, and the processor stays liable for the chain. AWS on the list is not the problem. A URL that can change overnight, with no usable object, is.
- Do: demand prior notice, a usable object, equivalent flow-down, and processor liability.
- Do not: treat a public webpage as notice if it can be edited silently.

When to calendar breach hours, audits, and deletion?
The processor must tell you about a personal data breach without undue delay so you can still hit the 72-hour ICO clock. “Promptly” is not a number you can calendar. Audits mean information plus inspections, not a SOC 2 on request. You choose delete or return.
Under UK GDPR Article 33(2) the processor notifies you without undue delay. The ICO 72-hour clock is yours where the breach is notifiable. A 24–72 hour ask to you is commercial, not the statutory processor clock. Article 28 still wants information plus audits — SOC 2 on request with no for-cause step is a red flag — and you choose delete or return.
- Do: write hours you can operate, keep a for-cause audit, and lock delete-or-return.
- Do not: accept “as soon as practicable” or report-only audits.

Which transfer tool and liability carve-out do you need?
For UK data leaving the UK, EU standard contractual clauses alone are not valid. You need the UK IDTA or the EU SCCs plus the UK Addendum. “DPF or SCCs at the vendor’s discretion” is a High flag.
The ICO transfer clauses page is explicit: EU SCCs are not valid on their own under the UK GDPR. If the deal is EEA data, cite EU GDPR and EDPB separately. ICO processor pages are under review after the Data (Use and Access) Act. The TOM annex must be filled, not “available on request.”
Then open the MSA cap. A fees-paid cap that swallows breach or fines with no carve-out is negotiate-or-walk. Signing is not due diligence done: EDPB Guidelines 07/2020 still want sufficient guarantees, continuously.
- Do: name IDTA or EU SCCs plus UK Addendum for UK data, and pull breach outside the fees cap.
- Do not: accept vendor-only choice of DPF or SCCs, or an empty TOM annex.
Vendor DPA red flags
| Severity | Clause pattern | Action |
|---|---|---|
| High | Roles inverted / joint controller while they only host | Walk until roles match who decides |
| High | Annex says “as required to provide the services” | Fail — write a one-page instruction sheet |
| High | Sub-processor URL, no prior notice or object | Negotiate notice + object; walk if refused |
| High | Audit = SOC 2 on request only | Demand for-cause inspection |
| High | Empty TOM annex / “available on request” | Fail — measures must sit in the packet |
| High | Fees-paid cap swallows breach and fines | Carve-out or super-cap; else walk |
| High | EU SCCs alone for UK restricted transfers | Name IDTA or EU SCCs + UK Addendum |
| Medium | Breach notice “promptly” | Replace with hours you can calendar |
Should you sign, negotiate, or walk?
Sign when every Article 28 minimum is present and operable. Negotiate four to six redlines: annex, notice plus object, hours, audit-for-cause, named transfer tool, breach carve-out. Walk if they refuse a written DPA, real objection rights, or a named transfer tool.
Vendors still claim they “don’t need a DPA.” Treat refusal of a written contract as a walk. Spend counsel — a qualified lawyer — only on High rows. A first-pass — the first machine pass that extracts clauses before a human reads every page — can highlight. Checkory can mark rows; a human still opens every High clause.
Success bar: mark each Article 28 item pass or fail, keep a one-page log (clause → severity → action), then sign, send 4–6 redlines, or walk. Workflow: packet → role check → Art. 28 minima → red flags → sign / negotiate / walk.
- Do: send counsel the High list, the frozen packet, and the redlines you want.
- Do not: escalate every Medium row, or copy the vendor template as your paper.

How to review a DPA before go-live
Freeze the packet
Lock DPA + MSA + order form + sub-processor list + TOM annex. Do not enable the product first.
Confirm roles
If you decide purposes and means, you are the controller. Walk if inverted.
Read the annex
Require subject matter, duration, nature, purpose, data types, and subjects.
Test sub-processors
Prior authorisation, prior notice, usable object, equivalent flow-down, processor liability.
Calendar breach, audit, deletion
Hours you can operate to you; for-cause inspection; you choose delete or return.
Name the transfer tool and the cap
UK data: IDTA or EU SCCs + UK Addendum. Ask for a TRA. Pull breach out of a thin fees cap.
Decide sign, negotiate, or walk
Sign if minima are operable. Send 4–6 redlines. Walk if they refuse a written DPA or a named transfer tool.
Frequently asked questions
When is a DPA required?▼
Should you accept a vendor DPA template as-is?▼
What if the vendor refuses audit rights?▼
Are EU standard contractual clauses enough for UK data?▼
What are common vendor DPA red flags?▼
How fast must a processor tell you about a breach?▼
Run a first-pass on the DPA you were sent
Upload the frozen PDF or DOCX. A human still opens every High clause.
Start document analysisWhat to do next
Review the frozen DPA
Upload the version you will sign and mark High rows before go-live.
ProductCheckory pricing
See plan limits before you run a pile of vendor DPAs through first-pass.
RelatedSaaS agreement red flags checklist
Read MSA + order form + DPA as one packet before you subscribe.
RelatedPrivacy policy review checklist
Match the live site to the notice before a processor holds the data.
RelatedHow to Review an MSA Liability Cap Before Signing
Return to the companion guide this article stacks with.
RelatedHow to Prepare a Contract Packet for First-Pass Review
Return to the companion guide this article stacks with.
RelatedVendor Contract Red Flags Checklist for Ops Teams
Return to the companion guide this article stacks with.
RelatedIndemnity Clause Review Checklist Before You Sign
Return to the companion guide this article stacks with.
RelatedHow to Keep a Confidential Contract Private When Using AI
Return to the companion guide this article stacks with.
Sources
Read also
Related guides





