Data Processing Agreement (DPA) checklist for startups
Under GDPR Article 28, whenever another company processes personal data on your behalf — or you process it for a customer — a Data Processing Agreement must be signed before the data starts flowing. There is no “too small to need one” exemption.
Do you need a DPA?
You're a controller
You're a processor
Every EU/EEA data relationship
What a compliant DPA must contain
Subject-matter, duration, nature and purpose of the processing — plus the types of personal data and categories of data subjects.
Processing only on the controller’s documented instructions.
Confidentiality commitments from everyone authorised to process the data.
Security measures appropriate to the risk (Article 32).
Sub-processor controls — prior authorisation and flow-down of the same obligations.
Assistance with data-subject rights (access, rectification, erasure, objection).
Assistance with security, breach notification and data protection impact assessments (Articles 32–36).
Return or deletion of all personal data at the end of the service, including copies.
Audit and inspection rights to demonstrate compliance.
International-transfer safeguards — Standard Contractual Clauses (SCCs) or an adequacy decision for any data leaving the EEA.
A current sub-processor list and a change-notification process (usually an annex).
A description of the technical and organisational security measures in place (usually an annex).