CheckoryCheckory
Frozen DPA packet beside an enable toggle with an empty annex flagged

Data Processing Agreement Checklist Before You Sign

Use a data processing agreement checklist before signing: lock roles, test objection rights, name the UK transfer tool, then sign or walk.

9 min readArticle
💡

Key takeaway in 30 seconds

A data processing agreement checklist before signing is the written processor contract you need before a vendor holds personal data. Confirm roles, instructions, sub-processors, and breach timing, then stack the DPA against the MSA cap.

You are one click from enabling a SaaS tool that will hold customer or employee data. Use this data processing agreement checklist before signing: confirm who decides purposes and means, reject an empty annex, test sub-processor notice plus a usable object, calendar breach hours, name the UK transfer tool, then sign, send four to six redlines, or walk.

In August 2026, Noor — UK SaaS founder, 14 people — is about to turn on a US analytics vendor. Procurement forwarded a 19-page DPA last night: Annex I says “as required to provide the services,” a silent sub-processor URL, and “promptly” for breach. Liability sits under the MSA — a master services agreement, the frame vendors hang order forms on — with a fees-paid cap and no breach carve-out. Typical mistake: treating 72 hours as the processor’s only duty.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

Who is the controller and who is the processor?

You are the controller if you decide the purposes and means of the processing. The vendor is the processor when it processes personal data on your behalf — for example a cloud analytics host. If the paper calls you a joint controller, or names the vendor a controller while it only hosts your data, stop: that role error is a High flag — an item scored high severity.

The ICO still wants a written contract before processing starts, plus an equivalent contract with each sub-processor. Freeze the packet — the exact file set that will be signed: DPA, MSA, order form, sub-processor list, and the security exhibit — an attached schedule or appendix. In practice a click-wrap the night before go-live is how Noor’s team skips roles.

  • Do: match the contract to who decides purposes and means.
  • Do not: enable the tool because the PDF says GDPR.
DPA exhibit with sub-processor and deletion rows highlighted
Read the packet you will sign.

What does the processing annex actually need to name?

The contract must set subject matter, duration, nature, purpose, types of personal data, and categories of data subjects. “As required to provide the services” fails that test. If the annex is empty, write a one-page instruction sheet or refuse to enable the product.

That list is the Article 28 chapeau; the ICO eight minimum terms then sit on top, and parties may supplement, not subtract. Pair that with UK GDPR Article 28. An instruction may be email if you can save it. If the processor starts deciding purposes and means, it becomes a controller for that flow.

  • Do: name data types, subjects, duration, and purpose.
  • Do not: accept a blank processing annex and “we will confirm later.”

How do you test sub-processor notice and objection rights?

The processor needs prior specific or general written authorisation before it engages a sub-processor. General authorisation still requires prior notice of additions and a chance to object. A silent webpage edit is not notice, and flow-down must offer equivalent protection.

Keep a dated identity list. EDPB Opinion 22/2024 says keep those identities ready and scale verification with risk. You need not collect every sub-contract; the controller still decides whether to engage, and the processor stays liable for the chain. AWS on the list is not the problem. A URL that can change overnight, with no usable object, is.

  • Do: demand prior notice, a usable object, equivalent flow-down, and processor liability.
  • Do not: treat a public webpage as notice if it can be edited silently.
Sub-processor notice, usable object, equivalent flow-down, processor liability
Sub-processor notice, usable object, equivalent flow-down, processor liability

When to calendar breach hours, audits, and deletion?

The processor must tell you about a personal data breach without undue delay so you can still hit the 72-hour ICO clock. “Promptly” is not a number you can calendar. Audits mean information plus inspections, not a SOC 2 on request. You choose delete or return.

Under UK GDPR Article 33(2) the processor notifies you without undue delay. The ICO 72-hour clock is yours where the breach is notifiable. A 24–72 hour ask to you is commercial, not the statutory processor clock. Article 28 still wants information plus audits — SOC 2 on request with no for-cause step is a red flag — and you choose delete or return.

  • Do: write hours you can operate, keep a for-cause audit, and lock delete-or-return.
  • Do not: accept “as soon as practicable” or report-only audits.
Breach hours to the controller, for-cause audit, delete or return
Breach hours to the controller, for-cause audit, delete or return

Which transfer tool and liability carve-out do you need?

For UK data leaving the UK, EU standard contractual clauses alone are not valid. You need the UK IDTA or the EU SCCs plus the UK Addendum. “DPF or SCCs at the vendor’s discretion” is a High flag.

The ICO transfer clauses page is explicit: EU SCCs are not valid on their own under the UK GDPR. If the deal is EEA data, cite EU GDPR and EDPB separately. ICO processor pages are under review after the Data (Use and Access) Act. The TOM annex must be filled, not “available on request.”

Then open the MSA cap. A fees-paid cap that swallows breach or fines with no carve-out is negotiate-or-walk. Signing is not due diligence done: EDPB Guidelines 07/2020 still want sufficient guarantees, continuously.

  • Do: name IDTA or EU SCCs plus UK Addendum for UK data, and pull breach outside the fees cap.
  • Do not: accept vendor-only choice of DPF or SCCs, or an empty TOM annex.

Vendor DPA red flags

SeverityClause patternAction
HighRoles inverted / joint controller while they only hostWalk until roles match who decides
HighAnnex says “as required to provide the services”Fail — write a one-page instruction sheet
HighSub-processor URL, no prior notice or objectNegotiate notice + object; walk if refused
HighAudit = SOC 2 on request onlyDemand for-cause inspection
HighEmpty TOM annex / “available on request”Fail — measures must sit in the packet
HighFees-paid cap swallows breach and finesCarve-out or super-cap; else walk
HighEU SCCs alone for UK restricted transfersName IDTA or EU SCCs + UK Addendum
MediumBreach notice “promptly”Replace with hours you can calendar

Should you sign, negotiate, or walk?

Sign when every Article 28 minimum is present and operable. Negotiate four to six redlines: annex, notice plus object, hours, audit-for-cause, named transfer tool, breach carve-out. Walk if they refuse a written DPA, real objection rights, or a named transfer tool.

Vendors still claim they “don’t need a DPA.” Treat refusal of a written contract as a walk. Spend counsel — a qualified lawyer — only on High rows. A first-pass — the first machine pass that extracts clauses before a human reads every page — can highlight. Checkory can mark rows; a human still opens every High clause.

Success bar: mark each Article 28 item pass or fail, keep a one-page log (clause → severity → action), then sign, send 4–6 redlines, or walk. Workflow: packet → role check → Art. 28 minima → red flags → sign / negotiate / walk.

  • Do: send counsel the High list, the frozen packet, and the redlines you want.
  • Do not: escalate every Medium row, or copy the vendor template as your paper.
Sign, negotiate four to six redlines, or walk the vendor
Sign, negotiate four to six redlines, or walk the vendor

How to review a DPA before go-live

1

Freeze the packet

Lock DPA + MSA + order form + sub-processor list + TOM annex. Do not enable the product first.

2

Confirm roles

If you decide purposes and means, you are the controller. Walk if inverted.

3

Read the annex

Require subject matter, duration, nature, purpose, data types, and subjects.

4

Test sub-processors

Prior authorisation, prior notice, usable object, equivalent flow-down, processor liability.

5

Calendar breach, audit, deletion

Hours you can operate to you; for-cause inspection; you choose delete or return.

6

Name the transfer tool and the cap

UK data: IDTA or EU SCCs + UK Addendum. Ask for a TRA. Pull breach out of a thin fees cap.

7

Decide sign, negotiate, or walk

Sign if minima are operable. Send 4–6 redlines. Walk if they refuse a written DPA or a named transfer tool.

Frequently asked questions

When is a DPA required?
Whenever you use a processor for personal data. The ICO still wants a written contract first. “DPA after go-live” is a walk.
Should you accept a vendor DPA template as-is?
No. A template can invert roles, leave the annex empty, hide a silent sub-processor page, or swallow breach.
What if the vendor refuses audit rights?
Treat SOC 2 on request as a red flag. Demand a for-cause inspection; walk on high-risk data if they refuse.
Are EU standard contractual clauses enough for UK data?
No. Use the UK IDTA or the EU SCCs plus the UK Addendum, plus a TRA. EU SCCs alone are not valid under the UK GDPR.
What are common vendor DPA red flags?
Wrong role, empty annex, silent sub-processor list, “promptly” breach, SOC 2-only audit, empty TOM, EU SCCs alone for UK data, or a fees cap on breach.
How fast must a processor tell you about a breach?
Without undue delay under Article 33(2), so you can still hit the 72-hour ICO clock. Replace “promptly” with hours you can calendar.

Run a first-pass on the DPA you were sent

Upload the frozen PDF or DOCX. A human still opens every High clause.

Start document analysis

What to do next

Sources

Read also

Related guides

Updated: August 27, 2026