Policy Register

Data processing agreement

The terms every processor signs: instructions, confidentiality, security, sub-processors, assistance, deletion and audit.

How the register reads it

Also calledDPA, processor terms
FamilyPrivacy
Document typeRecord. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenGDPR or ISO 27701 is ticked and no line resolves to it.
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

2 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 A.1.2.7 Contracts with PII processors

The organization must have a written contract with every processor it uses and must ensure those contracts address implementation of the appropriate processor controls, requiring the processor to implement them in light of the risk assessment and the scope of processing it performs, with all such controls assumed relevant by default and any decision not to require one justified in the Statement of Applicability, responsibilities being allocable differently between the parties provided every control is considered and documented.

Evidence an auditor accepts: Written contract with every processor, with a register reconciling contracts to processors actually used; contract terms addressing the processor control set; justification for any processor control not required, recorded in the Statement of Applicability
Common gap: Processors engaged under standard purchasing terms with no privacy schedule
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an auditor accepts: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; the Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract
Common gap: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Cookie policy · Data protection impact assessment procedure