GDPR Data Processing Agreement (Art. 28)
The contract every agency needs before touching a client's website data.
What's inside
- All Art. 28 mandatory clauses — subject matter, duration, nature and purpose of processing, data categories, documented instruction (Art. 28(3))
- Sub-processor terms — approval flow with ≥30 days notice and objection right
- EU-hosting clause — operational data and backups stay in the EU
- Security schedule — encryption, access control, credential rotation, quarterly restore tests, evidence retention
- Assistance clauses — data-subject requests and DPIA support within 5 business days
- Deletion/return within 30 days of termination
- Guidance comments on every clause — what it does, when to adjust it
Delivered as Markdown + PDF. Fill in the [BRACKETED] placeholders, paste onto your letterhead, done. For high-risk contracts have counsel review the result — minutes, not hours.
Note: Professional template with guidance comments — not legal advice.
Free preview — first two sections
# DATA PROCESSING AGREEMENT (DPA)
**ComplianceDocs** · v1.0, August 2026 · Not legal advice — have counsel review before use.
Template for controller→processor DPA following GDPR Art. 28. Placeholders in [BRACKETS].
## Parties
- **Controller:** [AGENCY LEGAL NAME], [address], [CVR/registration no.] ("Agency")
- **Processor:** [PROCESSOR LEGAL ENTITY], [jurisdiction] ("Processor")
## 1. Subject matter
Processor provides maintenance operations (updates, backups, security
patching, monitoring, recovery) on websites designated by Agency, including
storage of operational data and backups within the European Union, per the
Onboarding Manual referenced as Annex A.
## 2. Categories of data subjects and data
- Data subjects: visitors of Agency's client websites (only incidentally,
e.g. in backups/content), and admin users of those sites.
- Data categories: website content contained in backups (files + database),
admin credentials (held via secret manager, rotated), technical logs,
change-log metadata (timestamps, versions, operator identity).
## 3. Processor obligations
3.1 Processing only on documented instruction from Agency …
3.2 All persons authorized to process are bound by confidentiality.
3.3 Security measures: encryption in transit (TLS) and at rest for backups;
access limited to named operators; credential rotation after onboarding;
weekly malware scans; quarterly restore tests …
── Sections 3–9 continue in the full document ──
Sub-processors · Assistance · Deletion · Audit rights · Liability · Signatures
You've read the preview. The full document has 9 sections plus annex structure, ready to fill in.
Buy with confidence
14-day money-back guarantee. If the document doesn't fit your workflow, reply to your receipt within 14 days and you get a full refund. No forms, no questions.
- How do I receive the document?
- Instantly after checkout — download link on screen and by email.
- Who handles the payment?
- Lemon Squeezy acts as merchant of record and handles cards, PayPal, Apple Pay, VAT and sales tax worldwide.
- What's the license?
- Use the documents for yourself and for your own clients, as many times as you like. Reselling or republishing the template itself isn't allowed.
- Is this legal advice?
- No. These are professionally structured templates to adapt to your situation. For specific advice, consult a lawyer.