Skip to content
DPAFlow

Blog category

dpa

DPAFlow blog posts in dpa.

Search this category

Showing 1–7 of 7.

Posts

2026-07-29 · dpa

When a Vendor Has a Data Breach: Your GDPR Notification Duties

Your processor owes you notification without undue delay; you owe the supervisory authority a decision within 72 hours. What counts as a breach, what awareness means, the two different notification thresholds, and the one contract clause that determines how much of your 72 hours you actually keep.

2026-07-25 · dpa

What Is a Data Processing Addendum and When Do You Need One?

A Data Processing Addendum governs how a supplier may process personal data on your behalf. What the document does, the Article 28(3) content it must carry, when you need one, and when a supplier is not a processor at all.

2026-07-25 · dpa

Data Processing Agreement vs Data Processing Addendum

Both terms describe a contract satisfying GDPR Article 28(3), and neither appears in the regulation. The difference is structural, and it changes four things worth checking: precedence, unilateral change, liability, and what happens to data at the end.

2026-07-25 · dpa

Vendor Offboarding: Data Return, Deletion, and Evidence

The contract ends and the data often stays. How to make Article 28(3)(g) operate: choose return or deletion, map every system that holds data, bound the backup carve-out, and obtain written confirmation you can file.

2026-07-25 · dpa

Sub-processor Change Notifications Under GDPR

General authorization, notice mechanics, and the right to object: how sub-processor change notifications work under GDPR Article 28, and how to keep a silent page change from becoming an unassessed authorization.

2026-07-25 · dpa

GDPR Article 28: What Data Processing Agreements Must Cover

GDPR Article 28 sets mandatory content for every data processing agreement. This guide walks through each required clause, the sub-processing rules, the Commission's optional standard clauses, and common gaps in vendor DPAs.

2026-07-25 · dpa

DPA Review Checklist Before Signing

A clause-by-clause checklist for the sub-processing terms of a DPA: authorization model, notice and objection mechanics, list location, notification channel, flow-down, transfers, audit rights, and what to operationalize after signing.

Monitor subprocessor changes before they become audit work.

Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.

View evidence workflow