CheckoryCheckory
DPA Review Tool: Risks Marked on the Processor Agreement

DPA Review Tool: Risks Marked on the Processor Agreement

Upload the vendor DPA. The same file comes back with flags on roles, sub-processors, transfers and deletion, plus a short explanation.

15 min readdocument typeCheckory

A vendor DPA arrives as PDF or DOCX on the eve of go-live, and you cannot see on that paper whether you are named as controller, whether sub-processors can be swapped without notice, whether UK transfers rest on an IDTA or Addendum rather than EU SCCs, or whether data is deleted or only returned if requested. Checkory is a data processing agreement review tool: you upload their processor agreement and get the same file back with flags.

This is not an attestation

Dedicated DPA pages in the search results usually sell an extract of fields, an Article 28 tick-list, a findings report with suggested revisions, or a compliance inventory. Checkory returns a different artefact: the vendor processor agreement you uploaded, with risks marked on the same file, sitting on the clause itself.

This page is for one document type — the inbound DPA or data processing addendum they asked you to accept before personal data moves. It is not a before-signing checklist article, and it is not a GDPR or SOC 2 certificate. The job is to mark the processor paper you are about to rely on.

First pass on the vendor DPA, not a GDPR or SOC 2 certificate

You upload the PDF or DOCX they sent. You open the same pages, in their order, with flags on the wording they asked you to take. Controller and processor naming, sub-processor appointment, restricted transfers, and deletion or return stay on the sentence that creates the risk. A detached score or a framework percentage pulls the issue off the page. The useful object here is the annotated source file, so you and a solicitor or DPO can read the surrounding paragraph.

The first pass is a list of questions on their draft. It does not rewrite the DPA, it does not invent an Article 28 band, and it does not tell you personal data can leave.

Same file with flags, not a compliance inventory

Search neighbours often extract roles, SCCs and deletion into a report, or store signed DPAs as a vendor inventory. That is a different job. Here the flag stays on their wording. You do not get a Word add-in, a CLM repository, or a chatbot thread. You get the pages they sent, with the risk still sitting on the clause.

A reading list still has a place when you want the Article 28 hunt as a human walk. That path is the data processing agreement checklist before signing. Use it when you need a method. Use this page when you need flags on this vendor file.

Marks on the processor agreement, not a certificate

Unnamed roles, silent sub-processors, EU SCCs with no UK IDTA or Addendum on a restricted transfer, or deletion only if requested is a solicitor or DPO question. The marked file is the pack you send. It is not an ICO stamp and not permission to process.

Marks on the vendor DPA: roles, sub-processors, SCCs versus IDTA, and deletion.

Mark on the DPAWhat the wording often doesWhat you do with the flag
Controller and processor rolesBoth parties labelled controllers, or the processor never named, on a form that claims to be Article 28See whether this is a processor paper at all; send unnamed roles as High
Sub-processors and onward flowGeneral authorisation with no notice or objection right, and no flow-down of equivalent dutiesKnow whether the chain can change after signature; Art. 28(4) liability stays with the first processor
Transfers, SCCs and the UK IDTAEU SCCs only, worldwide processing, or silence on a UK restricted transferChallenge the safeguard before data leaves the UK; EU SCCs are not valid on their own
Deletion or return on exitReturn-only, destruction if requested, or no end-of-contract sentenceDiary the lever when the SaaS ends; silence is a High question, not a cleanup plan

Checkory on this DPA

Pros

  • Same uploaded processor file back with flags on roles, sub-processors, transfers and deletion
  • Short explanation plus a UK GDPR or ICO pointer on the clause

Cons

  • One file per pass — a security addendum or privacy policy is a later upload or a solicitor question
  • A person still verifies every flag; High items still go to a solicitor or DPO

Article 28 tick-list

Pros

  • Fast method when you already know the mandatory topics and want detected versus not-detected
  • Useful before you have their PDF, or as a second pass after the marks

Cons

  • No flags on the wording they asked you to accept
  • A tick-list cannot show you the silent sub-processor sentence in its paragraph

Security addendum checklist

Pros

  • Right artefact when the file is TOMs, encryption, or audit logistics rather than Art. 28 processing
  • Keeps Article 32 security on its own reading path instead of pretending the DPA is a badge

Cons

  • A security paper does not bind controller and processor roles on the DPA
  • A SOC 2 or ISO badge is not a deletion lever and not a UK transfer safeguard

Roles, sub-processors, SCCs and deletion

Four clusters decide whether this vendor may touch personal data on your documented instructions, or whether the paper is a security addendum in disguise. The table names the mark. The sentences below are the proof you came for: a transfer or sub-processor line highlighted on their DPA, with a pointer to UK GDPR and the ICO — not a detected/not-detected score.

Controller and processor roles

UK GDPR Article 28 applies where processing is on behalf of a controller. If the vendor DPA never names who is who, or calls both parties controllers on a processor form, the first question is whether this is a processor paper at all. The official starting point is UK GDPR Article 28: the processor must be governed by a contract that sets out subject-matter, duration, nature, purpose, types of data, categories of data subjects, and the controller’s rights and obligations. The cite is a pointer, not a finding that this file fails Article 28.

Joint-controller language on a processor template is a High flag. Do not treat a heading that says Data Processing Agreement as proof that roles are bound. Read the naming sentence. If it is missing, the mark stays on that gap.

Sub-processors and onward flow

A general authorisation that lets the vendor appoint subprocessors without notice, or without an objection right, is the sentence to walk before go-live. Article 28(4) requires equivalent obligations on any other processor; the initial processor remains fully liable. The ICO list of what the contract must include is what needs to be included in the contract: documented instructions, confidence, Article 32 security, sub-processors, data-subject assistance, end-of-contract provisions, and audits. A missing notice right is not a finding of absence in law. It is a flag on their wording.

Transfers, SCCs and deletion on exit

If the transfer clause cites EU SCCs only, or stays silent on a UK restricted transfer, the ICO position is blunt: EU SCCs are not valid on their own for restricted transfers under the UK GDPR. Use the IDTA or the Addendum. The official page is the UK IDTA and the Addendum. The ICO plans to update those clauses in 2026; current versions remain usable. Worldwide processing with no safeguard named is the same High cluster.

Where there is no adequacy regulation, UK GDPR Article 46 is the pointer for appropriate safeguards, including Commissioner-issued standard clauses. It is not a verdict that this DPA fails Article 46. Deletion follows the same honesty: return-only, destruction if requested, or silence is a mark against the ICO end-of-contract provisions under Article 28(3), not a cleanup certificate.

Editorial collage: vendor DPA with EU SCCs only ticket and UK IDTA conflict mark on the same page
Roles, sub-processors, SCCs and deletion — the transfer sentence stays on their wording.

“We may appoint subprocessors without notice. International transfers rely on the EU Standard Contractual Clauses.”

See the marks on the vendor DPA

Upload the vendor DPA

DPA vs a security addendum

A security addendum can look like the processing contract because it talks about encryption, audits, and Article 32. It is a different paper. This URL is the processor agreement. The security-addendum hunt stays on the vendor security addendum review checklist. Do not clone that checklist here. Link it, then come back to the DPA they sent.

This URL is the processor agreement

If the file in your inbox is titled DPA, Data Processing Addendum, or Processor Terms, this is the upload. Flags sit on roles, sub-processors, transfers and deletion. A Trust Centre badge, a SOC 2 letter, or an ISO certificate is not that sentence. If the DPA points at a later security schedule for Article 32, keep the pointer on this file and walk the schedule separately.

Security addendum stays on the checklist article

Privacy-notice matching is another neighbour. When the live site and the notice disagree, that walk is the privacy policy review checklist. Named-region pins and backups are a residency how-to, not this tool. This page stays on the vendor processor file.

AI DPA review on the vendor file

The short query dpa review tool and the cluster ai dpa review land on the same commercial intent: software that will look at this processor paper. Neighbours return an extract, a tick-list, suggested revisions to paste to the vendor, or a Word playbook. The wedge here is flags and cites on the file you uploaded.

Flags and cites, not an Art. 28 tick-list

A paste-box that reports ten Article 28 topics as detected or not-detected is a method. It is honest when it says not-detected is a prompt to look, not a finding of absence. It is still not this pass. Checkory keeps the risk on their sentence so you can read the surrounding paragraph with a colleague. A general chatbot summary of a DPA is one phrase of contrast and then we leave it: a transcript is not the annotated file.

The SRA warning notice on misuse of AI, published 17 August 2026, states that generative AI includes summaries, drafts, research and chatbots, and can invent fictitious cases and references. Treat every cite as this provision may be relevant, then read the official text and the clause together. If they do not match, the mark is a question, not an answer.

Not a redline to paste back to the vendor

Proposed language you can drop into an email is a different product. This pass does not generate a vendor-ready markup and does not claim the DPA meets Article 28. List what to challenge from the flags. Send a human markup if you push back. High unnamed roles, silent sub-processors, EU SCCs only on a UK restricted transfer, or deletion if requested still leave this pass.

Editorial collage: marked processor agreement versus an Article 28 tick-list clipboard held aside
AI DPA review on the vendor file — flags and cites, not a tick-list or a paste-redline.
💡

A checklist or vendor attestation is a different artefact

The objection “an Article 28 scan or a GDPR attestation is enough; I do not need flags on this processor agreement” misses the object. A tick-list does not mark this file. A SOC 2 letter does not bind deletion. You still need flags on the paper that lets the vendor touch personal data.

Upload a vendor DPA for a first pass

The search phrase upload a vendor DPA is the same gesture this page sells. One processor file in. The same file back with flags. Then a human decision about whether personal data can move.

One file in, the same file back

Open /document-analysis with their DPA in hand. Send the PDF or DOCX. This pass is that file, not a pack of later security schedules and not a paste into a public chatbot. Walk each highlight on the clause. List what to challenge. Send High items to a solicitor or DPO.

Open the tool at document analysis

A processor agreement review tool is the same job under a synonym. Do not treat a named-region residency pin as this upload; that how-to is how to review a named-region data-residency pin. If the temptation is to paste the raw DPA into a consumer model, stop. That is a confidentiality decision of its own.

Start the first pass on the vendor DPA

1

Open the tool

Go to /document-analysis with the vendor processor file in hand.

2

Upload that DPA

Send the PDF or DOCX. This pass is one file, not the security-addendum stack.

3

Walk the marks

Read each highlight on roles, sub-processors, transfers and deletion. List what to challenge. Send High items to a solicitor or DPO.

Editorial collage: upload tray with vendor DPA PDF and flags returning on the same processor file
Upload a vendor DPA for a first pass — one file in, the same file back with flags.

When do High flags leave this pass

Success on this page is concrete. After the pass you can name which DPA sentences to challenge before personal data is sent, which High items go to a solicitor or DPO, and you do not treat the marked file as an ICO certificate, a SOC 2 badge, or permission to process.

Send the pack when roles are unnamed, sub-processors can change silently, transfers rest on EU SCCs with no UK IDTA or Addendum, deletion is if requested, or a statute pointer and the clause do not match. The Legal Services Act 2007 section 12 lists reserved legal activity; this product is not a solicitor and is not an ICO certification. Default cites are UK GDPR and the Data Protection Act 2018. EU GDPR Article 28 is a neighbour, not the default rule on this page.

Walk the marked file with a colleague. List the push-back. Keep High items on the solicitor clock. The first pass is the question list on their processor agreement, not a go-live stamp.

England and Wales pointers, then a person

Default cites are UK GDPR and ICO text used in England and Wales practice. Scotland and Northern Ireland are separate legal systems. The Legal Services Act 2007 lists reserved activities; this product is not a solicitor. The SRA warning notice on misuse of AI, published 17 August 2026, states that generative AI has no separate legal personality and can invent fictitious references. Treat every statute link as a starting point to verify.

FAQ

Can an Article 28 tick-list replace flags on this vendor DPA?

No. A detected/not-detected scan pulls the issue off the page. This pass returns the processor agreement you uploaded, with flags on roles, sub-processors, transfers and deletion, plus a short explanation and a UK GDPR or ICO pointer where a provision may relate.

Walk the sentence in its paragraph. A tick-list is a different artefact.

Does this pass issue a GDPR or SOC 2 attestation?

No. Checkory does not certify the vendor, score a framework percentage, or stamp the DPA as meeting Article 28. The useful object is the marked file.

Use it to see which sentences to challenge before personal data is sent. High items still go to a solicitor or DPO.

What if the transfer clause cites EU SCCs only?

Treat it as a High question on a UK restricted transfer. The ICO states that EU standard contractual clauses are not valid on their own under the UK GDPR; use the IDTA or the Addendum.

Read the mark next to the transfer sentence. Then decide whether to challenge the safeguard before data leaves, or send the pack to a solicitor.

When should a High flag on a DPA go to a solicitor or DPO?

Send the marked file when any of these is true:

  • controller and processor roles are unnamed or both parties are labelled controllers on a processor form
  • sub-processors can be appointed with no notice or objection right
  • transfers rest on EU SCCs with no UK IDTA or Addendum
  • deletion is return-only, “if requested”, or silent
  • a statute pointer and the clause do not match

The first pass is a list of questions, not an ICO certificate and not permission to process.

Does one upload also review the security addendum?

No. This pass is the processor agreement they sent. A security addendum, TOMs schedule, or privacy policy is a separate file and a separate reading path.

If the DPA points at a later security paper for Article 32, keep that pointer on this file, then walk the addendum on its own checklist — do not treat a badge as the processing contract.

Why does a mark point at UK GDPR rather than a compliance score?

A scorecard cites a framework percentage. Checkory points at official UK GDPR and ICO text so you can read the provision next to the clause.

The link is a starting point. Verify it. Scotland and Northern Ireland are separate legal systems. The Solicitors Regulation Authority warning notice on misuse of AI, published 17 August 2026, states that generative AI can invent fictitious references — treat every cite as a question.

Related guides

Related articles

Updated: September 14, 2026