
DPA Review Tool: Risks Marked on the Processor Agreement
Upload the vendor DPA. The same file comes back with flags on roles, sub-processors, transfers and deletion, plus a short explanation.
A vendor DPA arrives as PDF or DOCX on the eve of go-live, and you cannot see on that paper whether you are named as controller, whether sub-processors can be swapped without notice, whether UK transfers rest on an IDTA or Addendum rather than EU SCCs, or whether data is deleted or only returned if requested. Checkory is a data processing agreement review tool: you upload their processor agreement and get the same file back with flags.
This is not an attestation
Dedicated DPA pages in the search results usually sell an extract of fields, an Article 28 tick-list, a findings report with suggested revisions, or a compliance inventory. Checkory returns a different artefact: the vendor processor agreement you uploaded, with risks marked on the same file, sitting on the clause itself.
This page is for one document type — the inbound DPA or data processing addendum they asked you to accept before personal data moves. It is not a before-signing checklist article, and it is not a GDPR or SOC 2 certificate. The job is to mark the processor paper you are about to rely on.
First pass on the vendor DPA, not a GDPR or SOC 2 certificate
You upload the PDF or DOCX they sent. You open the same pages, in their order, with flags on the wording they asked you to take. Controller and processor naming, sub-processor appointment, restricted transfers, and deletion or return stay on the sentence that creates the risk. A detached score or a framework percentage pulls the issue off the page. The useful object here is the annotated source file, so you and a solicitor or DPO can read the surrounding paragraph.
The first pass is a list of questions on their draft. It does not rewrite the DPA, it does not invent an Article 28 band, and it does not tell you personal data can leave.
Same file with flags, not a compliance inventory
Search neighbours often extract roles, SCCs and deletion into a report, or store signed DPAs as a vendor inventory. That is a different job. Here the flag stays on their wording. You do not get a Word add-in, a CLM repository, or a chatbot thread. You get the pages they sent, with the risk still sitting on the clause.
A reading list still has a place when you want the Article 28 hunt as a human walk. That path is the data processing agreement checklist before signing. Use it when you need a method. Use this page when you need flags on this vendor file.
Marks on the processor agreement, not a certificate
Unnamed roles, silent sub-processors, EU SCCs with no UK IDTA or Addendum on a restricted transfer, or deletion only if requested is a solicitor or DPO question. The marked file is the pack you send. It is not an ICO stamp and not permission to process.
Marks on the vendor DPA: roles, sub-processors, SCCs versus IDTA, and deletion.
| Mark on the DPA | What the wording often does | What you do with the flag |
|---|---|---|
| Controller and processor roles | Both parties labelled controllers, or the processor never named, on a form that claims to be Article 28 | See whether this is a processor paper at all; send unnamed roles as High |
| Sub-processors and onward flow | General authorisation with no notice or objection right, and no flow-down of equivalent duties | Know whether the chain can change after signature; Art. 28(4) liability stays with the first processor |
| Transfers, SCCs and the UK IDTA | EU SCCs only, worldwide processing, or silence on a UK restricted transfer | Challenge the safeguard before data leaves the UK; EU SCCs are not valid on their own |
| Deletion or return on exit | Return-only, destruction if requested, or no end-of-contract sentence | Diary the lever when the SaaS ends; silence is a High question, not a cleanup plan |
Checkory on this DPA
Pros
- ✓Same uploaded processor file back with flags on roles, sub-processors, transfers and deletion
- ✓Short explanation plus a UK GDPR or ICO pointer on the clause
Cons
- ✗One file per pass — a security addendum or privacy policy is a later upload or a solicitor question
- ✗A person still verifies every flag; High items still go to a solicitor or DPO
Article 28 tick-list
Pros
- ✓Fast method when you already know the mandatory topics and want detected versus not-detected
- ✓Useful before you have their PDF, or as a second pass after the marks
Cons
- ✗No flags on the wording they asked you to accept
- ✗A tick-list cannot show you the silent sub-processor sentence in its paragraph
Security addendum checklist
Pros
- ✓Right artefact when the file is TOMs, encryption, or audit logistics rather than Art. 28 processing
- ✓Keeps Article 32 security on its own reading path instead of pretending the DPA is a badge
Cons
- ✗A security paper does not bind controller and processor roles on the DPA
- ✗A SOC 2 or ISO badge is not a deletion lever and not a UK transfer safeguard
Roles, sub-processors, SCCs and deletion
Four clusters decide whether this vendor may touch personal data on your documented instructions, or whether the paper is a security addendum in disguise. The table names the mark. The sentences below are the proof you came for: a transfer or sub-processor line highlighted on their DPA, with a pointer to UK GDPR and the ICO — not a detected/not-detected score.
Controller and processor roles
UK GDPR Article 28 applies where processing is on behalf of a controller. If the vendor DPA never names who is who, or calls both parties controllers on a processor form, the first question is whether this is a processor paper at all. The official starting point is UK GDPR Article 28: the processor must be governed by a contract that sets out subject-matter, duration, nature, purpose, types of data, categories of data subjects, and the controller’s rights and obligations. The cite is a pointer, not a finding that this file fails Article 28.
Joint-controller language on a processor template is a High flag. Do not treat a heading that says Data Processing Agreement as proof that roles are bound. Read the naming sentence. If it is missing, the mark stays on that gap.
Sub-processors and onward flow
A general authorisation that lets the vendor appoint subprocessors without notice, or without an objection right, is the sentence to walk before go-live. Article 28(4) requires equivalent obligations on any other processor; the initial processor remains fully liable. The ICO list of what the contract must include is what needs to be included in the contract: documented instructions, confidence, Article 32 security, sub-processors, data-subject assistance, end-of-contract provisions, and audits. A missing notice right is not a finding of absence in law. It is a flag on their wording.
Transfers, SCCs and deletion on exit
If the transfer clause cites EU SCCs only, or stays silent on a UK restricted transfer, the ICO position is blunt: EU SCCs are not valid on their own for restricted transfers under the UK GDPR. Use the IDTA or the Addendum. The official page is the UK IDTA and the Addendum. The ICO plans to update those clauses in 2026; current versions remain usable. Worldwide processing with no safeguard named is the same High cluster.
Where there is no adequacy regulation, UK GDPR Article 46 is the pointer for appropriate safeguards, including Commissioner-issued standard clauses. It is not a verdict that this DPA fails Article 46. Deletion follows the same honesty: return-only, destruction if requested, or silence is a mark against the ICO end-of-contract provisions under Article 28(3), not a cleanup certificate.

“We may appoint subprocessors without notice. International transfers rely on the EU Standard Contractual Clauses.”
See the marks on the vendor DPA
Upload the vendor DPADPA vs a security addendum
A security addendum can look like the processing contract because it talks about encryption, audits, and Article 32. It is a different paper. This URL is the processor agreement. The security-addendum hunt stays on the vendor security addendum review checklist. Do not clone that checklist here. Link it, then come back to the DPA they sent.
This URL is the processor agreement
If the file in your inbox is titled DPA, Data Processing Addendum, or Processor Terms, this is the upload. Flags sit on roles, sub-processors, transfers and deletion. A Trust Centre badge, a SOC 2 letter, or an ISO certificate is not that sentence. If the DPA points at a later security schedule for Article 32, keep the pointer on this file and walk the schedule separately.
Security addendum stays on the checklist article
Privacy-notice matching is another neighbour. When the live site and the notice disagree, that walk is the privacy policy review checklist. Named-region pins and backups are a residency how-to, not this tool. This page stays on the vendor processor file.
AI DPA review on the vendor file
The short query dpa review tool and the cluster ai dpa review land on the same commercial intent: software that will look at this processor paper. Neighbours return an extract, a tick-list, suggested revisions to paste to the vendor, or a Word playbook. The wedge here is flags and cites on the file you uploaded.
Flags and cites, not an Art. 28 tick-list
A paste-box that reports ten Article 28 topics as detected or not-detected is a method. It is honest when it says not-detected is a prompt to look, not a finding of absence. It is still not this pass. Checkory keeps the risk on their sentence so you can read the surrounding paragraph with a colleague. A general chatbot summary of a DPA is one phrase of contrast and then we leave it: a transcript is not the annotated file.
The SRA warning notice on misuse of AI, published 17 August 2026, states that generative AI includes summaries, drafts, research and chatbots, and can invent fictitious cases and references. Treat every cite as this provision may be relevant, then read the official text and the clause together. If they do not match, the mark is a question, not an answer.
Not a redline to paste back to the vendor
Proposed language you can drop into an email is a different product. This pass does not generate a vendor-ready markup and does not claim the DPA meets Article 28. List what to challenge from the flags. Send a human markup if you push back. High unnamed roles, silent sub-processors, EU SCCs only on a UK restricted transfer, or deletion if requested still leave this pass.

A checklist or vendor attestation is a different artefact
The objection “an Article 28 scan or a GDPR attestation is enough; I do not need flags on this processor agreement” misses the object. A tick-list does not mark this file. A SOC 2 letter does not bind deletion. You still need flags on the paper that lets the vendor touch personal data.
Upload a vendor DPA for a first pass
The search phrase upload a vendor DPA is the same gesture this page sells. One processor file in. The same file back with flags. Then a human decision about whether personal data can move.
One file in, the same file back
Open /document-analysis with their DPA in hand. Send the PDF or DOCX. This pass is that file, not a pack of later security schedules and not a paste into a public chatbot. Walk each highlight on the clause. List what to challenge. Send High items to a solicitor or DPO.
Open the tool at document analysis
A processor agreement review tool is the same job under a synonym. Do not treat a named-region residency pin as this upload; that how-to is how to review a named-region data-residency pin. If the temptation is to paste the raw DPA into a consumer model, stop. That is a confidentiality decision of its own.
Start the first pass on the vendor DPA
Open the tool
Go to /document-analysis with the vendor processor file in hand.
Upload that DPA
Send the PDF or DOCX. This pass is one file, not the security-addendum stack.
Walk the marks
Read each highlight on roles, sub-processors, transfers and deletion. List what to challenge. Send High items to a solicitor or DPO.

When do High flags leave this pass
Success on this page is concrete. After the pass you can name which DPA sentences to challenge before personal data is sent, which High items go to a solicitor or DPO, and you do not treat the marked file as an ICO certificate, a SOC 2 badge, or permission to process.
Send the pack when roles are unnamed, sub-processors can change silently, transfers rest on EU SCCs with no UK IDTA or Addendum, deletion is if requested, or a statute pointer and the clause do not match. The Legal Services Act 2007 section 12 lists reserved legal activity; this product is not a solicitor and is not an ICO certification. Default cites are UK GDPR and the Data Protection Act 2018. EU GDPR Article 28 is a neighbour, not the default rule on this page.
Walk the marked file with a colleague. List the push-back. Keep High items on the solicitor clock. The first pass is the question list on their processor agreement, not a go-live stamp.
England and Wales pointers, then a person
Default cites are UK GDPR and ICO text used in England and Wales practice. Scotland and Northern Ireland are separate legal systems. The Legal Services Act 2007 lists reserved activities; this product is not a solicitor. The SRA warning notice on misuse of AI, published 17 August 2026, states that generative AI has no separate legal personality and can invent fictitious references. Treat every statute link as a starting point to verify.
FAQ
Can an Article 28 tick-list replace flags on this vendor DPA?
No. A detected/not-detected scan pulls the issue off the page. This pass returns the processor agreement you uploaded, with flags on roles, sub-processors, transfers and deletion, plus a short explanation and a UK GDPR or ICO pointer where a provision may relate.
Walk the sentence in its paragraph. A tick-list is a different artefact.
Does this pass issue a GDPR or SOC 2 attestation?
No. Checkory does not certify the vendor, score a framework percentage, or stamp the DPA as meeting Article 28. The useful object is the marked file.
Use it to see which sentences to challenge before personal data is sent. High items still go to a solicitor or DPO.
What if the transfer clause cites EU SCCs only?
Treat it as a High question on a UK restricted transfer. The ICO states that EU standard contractual clauses are not valid on their own under the UK GDPR; use the IDTA or the Addendum.
Read the mark next to the transfer sentence. Then decide whether to challenge the safeguard before data leaves, or send the pack to a solicitor.
When should a High flag on a DPA go to a solicitor or DPO?
Send the marked file when any of these is true:
- controller and processor roles are unnamed or both parties are labelled controllers on a processor form
- sub-processors can be appointed with no notice or objection right
- transfers rest on EU SCCs with no UK IDTA or Addendum
- deletion is return-only, “if requested”, or silent
- a statute pointer and the clause do not match
The first pass is a list of questions, not an ICO certificate and not permission to process.
Does one upload also review the security addendum?
No. This pass is the processor agreement they sent. A security addendum, TOMs schedule, or privacy policy is a separate file and a separate reading path.
If the DPA points at a later security paper for Article 32, keep that pointer on this file, then walk the addendum on its own checklist — do not treat a badge as the processing contract.
Why does a mark point at UK GDPR rather than a compliance score?
A scorecard cites a framework percentage. Checkory points at official UK GDPR and ICO text so you can read the provision next to the clause.
The link is a starting point. Verify it. Scotland and Northern Ireland are separate legal systems. The Solicitors Regulation Authority warning notice on misuse of AI, published 17 August 2026, states that generative AI can invent fictitious references — treat every cite as a question.
Related guides
Related articles





