How to answer
Can we execute a Data Processing Agreement (DPA)?
Under Article 28(3) the customer cannot use you without this contract, so the question is not really a question. What varies is whose paper it is signed on.
Yes. Our standard Data Processing Agreement is available at [URL] and incorporates the EU Standard Contractual Clauses along with our current subprocessor list. We can execute it alongside the main agreement.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- Your DPA template and the subprocessor list attached to it. If you have one ready to sign, this question costs you a sentence and a link.
- Evidence to attach
- The DPA itself, and the transfer mechanism it relies on.
- Where it is asked
- GDPR · Art. 28(3)SIG LiteBespoke vendor questionnaires
If your customer is a controller under the GDPR and you process personal data for them, Article 28(3) requires the arrangement to be governed by a contract. They are not asking whether you would like to sign one. They are telling you that procurement cannot complete without it, and finding out how much friction getting it will cost.
Have your own template, and offer it first. The company that arrives with a DPA ready signs its own terms. The company that does not gets sent the customer's paper, which will be drafted entirely in the customer's favour and will take your lawyer a week and a half. This is the single cheapest piece of leverage in the whole vendor review, and it is available to a two-person company as easily as to a large one.
Answer the three things the DPA question is actually made of. Do you have one, will you sign theirs if they insist, and what transfer mechanism covers data leaving the EEA. That last part is where these stall: if you or any of your subprocessors are outside the EEA, the DPA needs Standard Contractual Clauses or another lawful basis attached, and a reviewer who asks about a DPA will ask about transfers two rows later. Name the mechanism in the same answer and you have closed both.
Check the notification clause against what you can actually do. A DPA commits you to telling the controller about a personal data breach without undue delay, and many templates fix a number. Agreeing to 24 hours when your on-call process cannot reliably assess an incident in 24 hours creates a contractual breach on top of a security one. Put in the window your incident response plan can meet, and make sure the questionnaire answer, the DPA and the plan all say the same thing.
Keep the subprocessor list in one place. The DPA has one, your website probably has one, and the questionnaire will ask for one directly. Maintaining three copies means eventually publishing three different answers. Keep the list canonical somewhere, reference it from the DPA, and point every answer at the same source.
If you do not have a DPA yet, say when you will and offer to sign the customer's in the meantime. That is a workable answer. Silence on this row is not, because it is the row that blocks the purchase order.
How this one goes wrong
Specific to this question, not general advice.
- Saying yes with nothing drafted. The reviewer will ask for it that week, and a DPA written under deal pressure is where bad commitments get made.
- Promising a breach notification window you have not checked against your incident process. Contracts routinely say 24 hours where the regulation says 72, and you are bound by the contract.
- A subprocessor list in the DPA that does not match the one on your website or the answer you gave three rows earlier in the same questionnaire. Reviewers cross-check these, and the mismatch is what gets escalated.