Skip to content
FlowScript templates

Legal — GDPR data processing agreement clause map

Clause map of a GDPR Article 28 data processing agreement: who owes what to whom, each clause tied to the Article it implements, with the deadlines and consequences of the obligations that actually run on a clock. Typed FlowScript for contract analysis. Keywords: contract, agreement, clause, obligation.

Template previewFlowScript
AGREEMENT · DPA (GDPR ART. 28)Data Processing Agreement — Helio Health Ltd and Stratus Cloud Analytics GmbHGoverning: IrelandPARTY · CONTROLLERHelio Health Ltd3 clausesWARRANTY§ 2.2Lawful basis and transparencyArts. 6 and 9: lawful basis for all of Annex IRIGHT§ 9Audit and inspection rightArt. 28(3)(h): yearly on 30 days noticeRIGHT§ 5.3Right to object to a new sub-processorArt. 28(2): object within the notice periodPARTY · PROCESSORStratus Cloud Analytics GmbH9 clausesOBLIGATION§ 3.1Process only on documented instructionsArt. 28(3)(a): incl. transfers; flag unlawful ordersOBLIGATION§ 3.2Personnel bound by confidentialityArt. 28(3)(b): every person with accessOBLIGATION§ 4Technical and organisational measuresArt. 28(3)(c), Art. 32: Annex II measuresCONDITION§ 5Sub-processors on general written authorisationArt. 28(2), (4): 30 days notice; flow-downOBLIGATION§ 6Assist with data subject requestsArt. 28(3)(e): data within 5 business daysOBLIGATION§ 6.2Assist with security, DPIAs and consultationArt. 28(3)(f): Arts. 32 to 36, on requestOBLIGATION§ 7Personal data breach notificationArt. 33(2): within 48 hours, Art. 33(3) detailsCOVENANT§ 8International transfers under SCCsChapter V: SCCs Module 3 plus transfer assessmentOBLIGATION§ 10.2Delete or return data at the end of the servicesArt. 28(3)(g): controller chooses; certificateEXECUTABLE OBLIGATIONSStratus Cloud Analytics GmbH — Notify the controller of a personal data breach · by 48 hours after becoming aware · penalty: Uncapped liability for fines (s. 11.3)Stratus Cloud Analytics GmbH — Give notice of an added or replaced sub-processor · by 30 days before it receives data · penalty: Termination right (s. 5.3)Stratus Cloud Analytics GmbH — Provide the data needed to answer a data subject request · by 5 business days after the requestStratus Cloud Analytics GmbH — Delete or return all personal data and certify deletion · by 30 days after termination; backups 90Stratus Cloud Analytics GmbH — Provide the ISO 27001 certificate and SOC 2 Type II report · by 30 days after each report is issuedHelio Health Ltd — Keep processing instructions documented and current in Annex I · by the start of any new processing

Make it your own.

// Clause map of a GDPR Article 28 data processing agreement: who owes what to whom, each clause tied to the Article it implements, with the deadlines and consequences of the obligations that actually run on a clock.
//
// Every string below is EXAMPLE text from a fictional agreement: replace it.
//
// Article 28(3) lists what a controller–processor contract must contain;
// each clause summary opens with the Article it implements, so a reviewer
// can check completeness by reading down the cards.
// The deadlines that matter in an incident are on the obligations strip:
// once told of a breach, the controller has 72 hours to notify the
// supervisory authority (Art. 33(1)), so the contract fixes the processor's
// notice at 48 hours and names the information it must carry.
//
// This is a map for review, not legal advice, and the clause texts are
// summaries. The signed agreement and its annexes (processing description,
// technical and organisational measures, approved sub-processors) govern.

agreement dpa {
  title: "Data Processing Agreement — Helio Health Ltd and Stratus Cloud Analytics GmbH"
  type: "DPA (GDPR Art. 28)"
  governing_law: "Ireland"
  effective: "2026-03-01"
}

party controller {
  name: "Helio Health Ltd"
  role: "controller"
  jurisdiction: "Ireland"
}
party processor {
  name: "Stratus Cloud Analytics GmbH"
  role: "processor"
  jurisdiction: "Germany"
}

// ── Processor clauses ──
clause instructions {
  title: "Process only on documented instructions"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(a): incl. transfers; flag unlawful orders"
  section: "3.1"
}
clause confidentiality {
  title: "Personnel bound by confidentiality"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(b): every person with access"
  section: "3.2"
}
clause security {
  title: "Technical and organisational measures"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(c), Art. 32: Annex II measures"
  section: "4"
}
clause sub_processors {
  title: "Sub-processors on general written authorisation"
  type: "condition"
  party: processor
  summary: "Art. 28(2), (4): 30 days notice; flow-down"
  section: "5"
}
clause data_subject_requests {
  title: "Assist with data subject requests"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(e): data within 5 business days"
  section: "6"
}
clause controller_assistance {
  title: "Assist with security, DPIAs and consultation"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(f): Arts. 32 to 36, on request"
  section: "6.2"
}
clause breach_notification {
  title: "Personal data breach notification"
  type: "obligation"
  party: processor
  summary: "Art. 33(2): within 48 hours, Art. 33(3) details"
  section: "7"
}
clause transfers {
  title: "International transfers under SCCs"
  type: "covenant"
  party: processor
  summary: "Chapter V: SCCs Module 3 plus transfer assessment"
  section: "8"
}
clause deletion {
  title: "Delete or return data at the end of the services"
  type: "obligation"
  party: processor
  summary: "Art. 28(3)(g): controller chooses; certificate"
  section: "10.2"
}

// ── Controller clauses ──
clause lawful_basis {
  title: "Lawful basis and transparency"
  type: "warranty"
  party: controller
  summary: "Arts. 6 and 9: lawful basis for all of Annex I"
  section: "2.2"
}
clause audit_right {
  title: "Audit and inspection right"
  type: "right"
  party: controller
  summary: "Art. 28(3)(h): yearly on 30 days notice"
  section: "9"
}
clause objection_right {
  title: "Right to object to a new sub-processor"
  type: "right"
  party: controller
  summary: "Art. 28(2): object within the notice period"
  section: "5.3"
}

// ── Obligations that run on a clock ──
obligation notify_breach {
  party: processor
  action: "Notify the controller of a personal data breach"
  deadline: "48 hours after becoming aware"
  penalty: "Uncapped liability for fines (s. 11.3)"
}
obligation notify_sub_processor {
  party: processor
  action: "Give notice of an added or replaced sub-processor"
  deadline: "30 days before it receives data"
  penalty: "Termination right (s. 5.3)"
}
obligation assist_dsar {
  party: processor
  action: "Provide the data needed to answer a data subject request"
  deadline: "5 business days after the request"
}
obligation delete_data {
  party: processor
  action: "Delete or return all personal data and certify deletion"
  deadline: "30 days after termination; backups 90"
}
obligation annual_audit_report {
  party: processor
  action: "Provide the ISO 27001 certificate and SOC 2 Type II report"
  deadline: "30 days after each report is issued"
}
obligation document_instructions {
  party: controller
  action: "Keep processing instructions documented and current in Annex I"
  deadline: "the start of any new processing"
}

view clauses: clause_map