Compliance

DPA Article 28 Clause Checker

Paste a data processing agreement and check it against every mandatory term Article 28(3) requires, with the specific wording each obligation needs and what is missing.

Last reviewed by the Radiatus Cloud team

Coverage appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Article 28(3) is a closed list, and most agreements miss part of it

The processor contract must set out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subject, and then impose eight specific obligations. That is not guidance; it is a mandatory minimum, and an agreement missing one of the eight is non-compliant regardless of how well drafted the rest is. The terms most often absent are the audit right, the obligation to assist with data subject requests, and the requirement to inform the controller when an instruction appears unlawful.

Deletion or return is a choice the controller must hold

Article 28(3)(g) requires that at the end of the service the processor deletes or returns the data at the controller's choice. Agreements frequently give the processor the choice, or specify deletion only, or stay silent and rely on a retention clause elsewhere. Each of those fails the requirement, and the failure surfaces at exit, when the controller has the least leverage to renegotiate.

Subprocessor terms are where flow-down actually breaks

The processor may engage a subprocessor only with authorisation, must impose the same obligations by contract, and remains fully liable for the subprocessor's performance. Agreements commonly grant blanket authorisation with no notice period and no objection right, which satisfies the letter of general authorisation only if the controller is genuinely informed of changes in time to object. A clause granting general authorisation without any notice mechanism does not meet that condition.

Related tools

Frequently Asked Questions

Which Article 28(3) terms are most often missing?

The audit and inspection right, the obligation to assist with data subject requests, and the duty to inform the controller if an instruction appears to infringe data protection law. All three are mandatory.

Can the processor decide whether to delete or return data?

No. Article 28(3)(g) puts the choice with the controller. An agreement specifying deletion only, or leaving the choice with the processor, does not meet the requirement.

Is blanket subprocessor authorisation allowed?

General authorisation is permitted, but only if the controller is informed of intended changes in time to object. Blanket authorisation with no notice mechanism does not satisfy that condition.

Does this read my contract for meaning?

No. It searches for the language each obligation typically uses and reports what it did and did not find. A clause written in unusual wording may be present and not detected, so treat a miss as a prompt to look rather than as a verdict.

Is anything uploaded?

No. The text stays in your browser and is never transmitted, which matters because contracts are usually confidential.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your data processing agreement to check its clause coverage.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.