Blog category
dpa
DPAFlow blog posts in dpa.
Search this category
Showing 1–7 of 7.
Posts
2026-07-29 · dpa
When a Vendor Has a Data Breach: Your GDPR Notification Duties
Your processor owes you notification without undue delay; you owe the supervisory authority a decision within 72 hours. What counts as a breach, what awareness means, the two different notification thresholds, and the one contract clause that determines how much of your 72 hours you actually keep.
2026-07-25 · dpa
What Is a Data Processing Addendum and When Do You Need One?
A Data Processing Addendum governs how a supplier may process personal data on your behalf. What the document does, the Article 28(3) content it must carry, when you need one, and when a supplier is not a processor at all.
2026-07-25 · dpa
Data Processing Agreement vs Data Processing Addendum
Both terms describe a contract satisfying GDPR Article 28(3), and neither appears in the regulation. The difference is structural, and it changes four things worth checking: precedence, unilateral change, liability, and what happens to data at the end.
2026-07-25 · dpa
Vendor Offboarding: Data Return, Deletion, and Evidence
The contract ends and the data often stays. How to make Article 28(3)(g) operate: choose return or deletion, map every system that holds data, bound the backup carve-out, and obtain written confirmation you can file.
2026-07-25 · dpa
Sub-processor Change Notifications Under GDPR
General authorization, notice mechanics, and the right to object: how sub-processor change notifications work under GDPR Article 28, and how to keep a silent page change from becoming an unassessed authorization.
2026-07-25 · dpa
GDPR Article 28: What Data Processing Agreements Must Cover
GDPR Article 28 sets mandatory content for every data processing agreement. This guide walks through each required clause, the sub-processing rules, the Commission's optional standard clauses, and common gaps in vendor DPAs.
2026-07-25 · dpa
DPA Review Checklist Before Signing
A clause-by-clause checklist for the sub-processing terms of a DPA: authorization model, notice and objection mechanics, list location, notification channel, flow-down, transfers, audit rights, and what to operationalize after signing.
Monitor subprocessor changes before they become audit work.
Create a vendor watchlist, receive risk-ranked alerts, and keep Article 28 evidence ready.