Legal — GDPR data processing agreement clause map
Clause map of a GDPR Article 28 data processing agreement: who owes what to whom, each clause tied to the Article it implements, with the deadlines and consequences of the obligations that actually run on a clock. Typed FlowScript for contract analysis. Keywords: contract, agreement, clause, obligation.
Make it your own.
// Clause map of a GDPR Article 28 data processing agreement: who owes what to whom, each clause tied to the Article it implements, with the deadlines and consequences of the obligations that actually run on a clock.
//
// Every string below is EXAMPLE text from a fictional agreement: replace it.
//
// Article 28(3) lists what a controller–processor contract must contain;
// each clause summary opens with the Article it implements, so a reviewer
// can check completeness by reading down the cards.
// The deadlines that matter in an incident are on the obligations strip:
// once told of a breach, the controller has 72 hours to notify the
// supervisory authority (Art. 33(1)), so the contract fixes the processor's
// notice at 48 hours and names the information it must carry.
//
// This is a map for review, not legal advice, and the clause texts are
// summaries. The signed agreement and its annexes (processing description,
// technical and organisational measures, approved sub-processors) govern.
agreement dpa {
title: "Data Processing Agreement — Helio Health Ltd and Stratus Cloud Analytics GmbH"
type: "DPA (GDPR Art. 28)"
governing_law: "Ireland"
effective: "2026-03-01"
}
party controller {
name: "Helio Health Ltd"
role: "controller"
jurisdiction: "Ireland"
}
party processor {
name: "Stratus Cloud Analytics GmbH"
role: "processor"
jurisdiction: "Germany"
}
// ── Processor clauses ──
clause instructions {
title: "Process only on documented instructions"
type: "obligation"
party: processor
summary: "Art. 28(3)(a): incl. transfers; flag unlawful orders"
section: "3.1"
}
clause confidentiality {
title: "Personnel bound by confidentiality"
type: "obligation"
party: processor
summary: "Art. 28(3)(b): every person with access"
section: "3.2"
}
clause security {
title: "Technical and organisational measures"
type: "obligation"
party: processor
summary: "Art. 28(3)(c), Art. 32: Annex II measures"
section: "4"
}
clause sub_processors {
title: "Sub-processors on general written authorisation"
type: "condition"
party: processor
summary: "Art. 28(2), (4): 30 days notice; flow-down"
section: "5"
}
clause data_subject_requests {
title: "Assist with data subject requests"
type: "obligation"
party: processor
summary: "Art. 28(3)(e): data within 5 business days"
section: "6"
}
clause controller_assistance {
title: "Assist with security, DPIAs and consultation"
type: "obligation"
party: processor
summary: "Art. 28(3)(f): Arts. 32 to 36, on request"
section: "6.2"
}
clause breach_notification {
title: "Personal data breach notification"
type: "obligation"
party: processor
summary: "Art. 33(2): within 48 hours, Art. 33(3) details"
section: "7"
}
clause transfers {
title: "International transfers under SCCs"
type: "covenant"
party: processor
summary: "Chapter V: SCCs Module 3 plus transfer assessment"
section: "8"
}
clause deletion {
title: "Delete or return data at the end of the services"
type: "obligation"
party: processor
summary: "Art. 28(3)(g): controller chooses; certificate"
section: "10.2"
}
// ── Controller clauses ──
clause lawful_basis {
title: "Lawful basis and transparency"
type: "warranty"
party: controller
summary: "Arts. 6 and 9: lawful basis for all of Annex I"
section: "2.2"
}
clause audit_right {
title: "Audit and inspection right"
type: "right"
party: controller
summary: "Art. 28(3)(h): yearly on 30 days notice"
section: "9"
}
clause objection_right {
title: "Right to object to a new sub-processor"
type: "right"
party: controller
summary: "Art. 28(2): object within the notice period"
section: "5.3"
}
// ── Obligations that run on a clock ──
obligation notify_breach {
party: processor
action: "Notify the controller of a personal data breach"
deadline: "48 hours after becoming aware"
penalty: "Uncapped liability for fines (s. 11.3)"
}
obligation notify_sub_processor {
party: processor
action: "Give notice of an added or replaced sub-processor"
deadline: "30 days before it receives data"
penalty: "Termination right (s. 5.3)"
}
obligation assist_dsar {
party: processor
action: "Provide the data needed to answer a data subject request"
deadline: "5 business days after the request"
}
obligation delete_data {
party: processor
action: "Delete or return all personal data and certify deletion"
deadline: "30 days after termination; backups 90"
}
obligation annual_audit_report {
party: processor
action: "Provide the ISO 27001 certificate and SOC 2 Type II report"
deadline: "30 days after each report is issued"
}
obligation document_instructions {
party: controller
action: "Keep processing instructions documented and current in Annex I"
deadline: "the start of any new processing"
}
view clauses: clause_map