Data Processing Agreement

Beantworte ein paar Fragen und hol dir einen Auftragsverarbeitungsvertrag zum Herunterladen und Bearbeiten

100 % kostenlos. Läuft vollständig in deinem Browser: deine Dateien und Daten verlassen dein Gerät nie, und es wird nichts auf einen Server hochgeladen.

Vorlage, keine Rechtsberatung. This is a template, not legal advice. It covers the clauses Article 28(3) requires, but the schedule is what an auditor reads, and only you know what is really in it. Where personal data leaves the UK or EEA you also need a transfer risk assessment alongside the clauses referred to here - that assessment is a separate piece of work this cannot do for you.

Mit einem Beispiel starten

Füllt jede Antwort mit einem durchgerechneten Beispiel, das du bearbeiten kannst. Nimm das, das deinem Geschäft am nächsten kommt.

0 of 10 details filled
The parties
What the processing is for
The processing may only be done for this. Anything vague here becomes a wide permission.
The schedule

Article 28(3) requires this. It is also the part an auditor reads first, and the part generic templates leave blank.

Article 28(3) requires this list. A DPA without it fails an audit.
Sub-processors and transfers
Name, purpose and country. The country is what decides whether the transfer clause below applies.
Operational terms
The Controller has 72 hours to tell the regulator, so a processor notice period longer than 48 hours is not workable.

Data Processing Agreement

15 sections · 1335 words · updates as you type

Data Processing Agreement

Last updated: 19 September 2026

Parties

This Data Processing Agreement ("DPA") is made on 19 September 2026 between:

[Controller] of [Controller address] ("the Controller")

and

[Processor] of [Processor address] ("the Processor").

It forms part of, and is subject to, the main agreement between the Parties under which the Processor provides services to the Controller ("the Main Agreement"). Where this DPA conflicts with the Main Agreement on the processing of personal data, this DPA prevails.

Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU General Data Protection Regulation (EU) 2016/679, and any other law applicable to the processing under this DPA.

"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Data Protection Law.

"Sub-processor" means any third party engaged by the Processor to process Personal Data under this DPA.

Roles of the parties

The Controller determines the purposes and means of the processing. The Processor processes Personal Data only on behalf of the Controller.

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subject are set out in the Schedule at the end of this DPA.

The Controller is responsible for ensuring it has a lawful basis for the processing it instructs, and that any notice or consent required has been given. The Processor is entitled to rely on the Controller instructions in that respect.

Processing on documented instructions

The Processor shall process Personal Data only on the Controller documented instructions, including as to transfers to a third country, unless required to do otherwise by law - in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so.

The Main Agreement, this DPA and the use of the service in its ordinary way constitute the Controller initial documented instructions. Further instructions must be given in writing.

The Processor shall tell the Controller immediately if, in its opinion, an instruction infringes Data Protection Law. The Processor may suspend the affected processing until the instruction is confirmed, corrected or withdrawn.

Confidentiality of personnel

The Processor shall ensure that every person authorised to process Personal Data under this DPA is bound by an appropriate duty of confidentiality, whether by contract or by statute, and that the duty survives the end of their engagement.

Access is limited to those who need it to deliver the services, and is removed when they no longer do.

Security of processing

Taking account of the state of the art, the cost of implementation and the risk to data subjects, the Processor shall implement appropriate technical and organisational measures under Article 32, including as appropriate:

  • encryption of Personal Data in transit and at rest;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems;
  • the ability to restore availability and access to Personal Data promptly after an incident;
  • a process for regularly testing and evaluating the effectiveness of those measures;
  • role-based access control, with access granted on a need-to-know basis and reviewed periodically;
  • logging of access to and changes affecting Personal Data.

The Processor shall not materially reduce the level of protection these measures provide during the term of this DPA.

Sub-processors

The Controller gives general authorisation for the Processor to engage Sub-processors, and the Processor maintains a current list which it makes available to the Controller on request.

The Processor shall give the Controller at least 30 days notice before adding or replacing a Sub-processor. The Controller may object on reasonable data protection grounds within that period; if the Parties cannot resolve the objection, the Controller may terminate the affected part of the services without penalty.

The Processor shall impose on every Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor obligations.

Assisting with data subject rights

Taking account of the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, so far as possible, in responding to requests to exercise data subject rights - access, rectification, erasure, restriction, portability and objection.

Where the Processor receives such a request directly, it shall not respond to it itself, other than to confirm receipt and direct the person to the Controller, and shall pass the request to the Controller without undue delay.

Assisting with security, breaches and assessments

The Processor shall assist the Controller in complying with its obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to the Processor. That includes assistance with data protection impact assessments and with any prior consultation with a supervisory authority.

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Personal Data processed under this DPA. The notification shall describe, as far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, the Processor shall provide information in phases rather than delay the first notification.

The Processor shall not make any public statement about a breach affecting the Controller Personal Data without the Controller prior written agreement, unless required to by law.

Return or deletion at the end

On the Controller written request, and in any event on the end of the provision of services, the Processor shall at the Controller choice delete or return all Personal Data and delete existing copies, unless the law requires it to keep them.

Unless the Controller instructs otherwise, deletion takes place 30 days after the end of the services, giving the Controller a window to export its data. Where Personal Data remains in routine backups that are not readily accessible, the Processor shall isolate it from further processing and delete it on the ordinary backup cycle, and this DPA continues to apply to it until then.

The Processor shall certify deletion in writing on request.

Information and audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

The Controller may audit the Processor on reasonable written notice of at least 30 days, no more than once in any 12-month period unless a personal data breach or a regulator requires otherwise. Audits take place during business hours, are subject to confidentiality, and must not unreasonably disrupt the Processor business. The Controller bears its own costs.

International transfers

The Processor shall not transfer Personal Data outside the United Kingdom or the European Economic Area without the Controller prior written consent.

Where the Controller consents to such a transfer, the Processor shall first put in place a transfer mechanism valid under Data Protection Law, and shall tell the Controller which mechanism it relies on.

Liability and term

This DPA takes effect on the date above and continues for as long as the Processor processes Personal Data on the Controller behalf. The obligations of confidentiality, deletion and assistance survive its end.

Liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except where Data Protection Law does not permit that - in particular, nothing in this DPA limits either Party liability to a data subject or to a supervisory authority.

Schedule - details of the processing

Subject matter and purpose of the processing

[the services under the main agreement]

Nature of the processing

Collection, storage, organisation, retrieval, use, transmission and deletion of Personal Data, to the extent needed to provide the services.

Duration

For the term of the Main Agreement, plus the retention period of 30 days set out above.

Categories of data subject

  • [list the categories of individual whose data is processed]

Categories of personal data

  • [list the types of personal data processed]

Approved sub-processors

  • None at the date of this DPA.

Signed

For [Controller] (Controller)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

For [Processor] (Processor)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

Aus einem Template erzeugt. Keine Rechtsberatung - lies es, bevor du es veröffentlichst oder unterschreibst.

Andere Dokumente, die du erzeugen kannst

Die meisten Sites brauchen mehr als eines. Eine Datenschutzerklärung ohne AGB oder AGB ohne Rückerstattungsrichtlinie lässt die offensichtliche Lücke.

Privacy PolicyA privacy policy written from what your site actually does - GDPR and CCPA sections included only where they apply.Terms and ConditionsTerms of service built around what you actually sell - goods, subscription, downloads or services.Cookie PolicyA cookie policy with a real table - each cookie named, with its purpose and how long it lasts.Cookie Consent BannerGenerates a working consent banner - blocks tagged scripts until consent, Google Consent Mode v2, no dark patterns.Refund and Return PolicyA refund policy customers can follow and payment processors accept - windows, exclusions and statutory rights in plain words.Website DisclaimerA disclaimer that names the actual risk your site carries, plus affiliate and sponsorship disclosures.Accessibility StatementA WCAG accessibility statement that states what you actually meet, names known issues, and gives people a route to report problems.Non-Disclosure AgreementA mutual or one-way NDA with a real purpose clause, standard carve-outs and a defined term.Freelance ContractAn independent contractor agreement that pins down scope, revisions, IP ownership and what happens when payment is late.W-9 FormFills a substitute Form W-9 in your browser - your TIN is never uploaded, stored or sent anywhere.1099-NEC Contractor SummaryPrepares a 1099-NEC recipient statement and a payer summary - with a straight answer about what you can and cannot print yourself.Shipping PolicyA shipping policy Shopify and Amazon sellers can publish - origin, times, tracking, duties and who pays.DSAR Form GeneratorA data-delete and access request page you can host - GDPR and CCPA wording, no upload, no signup.

Über dieses Tool

Beantworte ein paar Fragen und das Dokument schreibt sich selbst. Es ist für SaaS-Anbieter, Agenturen und Entwicklerinnen, deren Unternehmenskunden nicht unterschreiben, bis ein AVV existiert, und in der Beschaffung, weil es meist das Dokument ist, das den Vertrag aufhält, sind zwanzig Minuten gut investiert. Ein Punkt trennt eine brauchbare Fassung von einer kopierten: Artikel 28(3) listet acht Dinge, die ein Auftragsverarbeitungsvertrag enthalten muss, und ein AVV, dem eines fehlt, ist kein AVV – es ist ein Dokument, das eine Prüfung nicht besteht. Alle acht sind hier unbedingt; was der Fragebogen ändert, ist der Anhang, den Prüfende wirklich lesen und den generische Vorlagen leer lassen. Nichts Irrelevantes steht drin. Eine Klausel, die für dich nicht gilt, entfällt, statt aufgefüllt zu werden – ein Dokument, das etwas beschreibt, das du nicht tust, ist selbst ein Problem. Nichts wird hochgeladen. Alles wird lokal zusammengesetzt, vertrauliche Angaben bleiben auf deinem Gerät, und es gibt kein Konto, das du später anlegen oder löschen müsstest.

So verwendest du dieses Tool

  1. Beantworte die FragenVerantwortliche. Adresse der Verantwortlichen. Auftragsverarbeitende. Nichts, was du tippst, verlässt den Browser.
  2. Sieh zu, wie es sich zusammenbautKlauseln erscheinen und verschwinden, während du antwortest, sodass das Dokument zu dem passt, was du wirklich tust, statt zu einer generischen Vorlage.
  3. Kopieren oder herunterladenKopiere den Text oder lade als PDF, Word oder reinen Text herunter. Die Word-Version ist die zum Bearbeiten.

Warum es nutzen

  • Läuft vollständig in deinem Browser. Nichts hochgeladen, nichts gespeichert, kein Konto.
  • Kostenlos ohne Wasserzeichen, ohne E-Mail-Hürde und ohne Limit pro Dokument.
  • Aus deinen Antworten gebaut, sodass Klauseln, die du nicht brauchst, weggelassen statt aufgefüllt werden.
  • Lädt als PDF, Word oder reinen Text herunter - die Word-Datei ist ohne Schutz bearbeitbar.
  • Sagt klar, was es ist und was nicht, über der Vorschau statt in einer Fußzeile.

Häufige Anwendungen

  • Einer Anwältin einen Entwurf zur Prüfung geben, statt sie bei null anfangen zu lassen.
  • Ein kopiertes Dokument ersetzen, das ein anderes Geschäft beschreibt.
  • Vorbereiten, was eine Kundin, ein App Store oder ein Zahlungsanbieter sehen will.
  • SaaS-Anbieter, Agenturen und Entwicklerinnen, deren Unternehmenskunden nicht unterschreiben, bis ein AVV existiert.
  • Etwas in der Beschaffung in Stellung bringen, weil es meist das Dokument ist, das den Vertrag aufhält.

Tipps für bessere Ergebnisse

  • Behalte von jeder Fassung eine Kopie mit Datum. Wenn jemand fragt, was deine Bedingungen letzten März gesagt haben, muss die Antwort eine Datei sein, kein Erinnern.
  • Füll die Freitextfelder aus statt sie zu überspringen. Die benannten Listen - Auftragsverarbeiter, Ausschlüsse, Liefergegenstände - machen, dass es nach dir klingt statt nach einer Kopie.
  • Lies es, bevor du es veröffentlichst. Es ist ein Entwurf aus Standardklauseln, und nur du weißt, ob jede Zeile auf dich zutrifft.
  • Lade die Word-Version herunter, wenn du sie bearbeiten willst. Das PDF ist zum Veröffentlichen; das .docx zum Ändern.

Fehler, die du vermeiden solltest

  • Keine Unterauftragsverarbeitenden nennen. Ein AVV, dessen Unterauftragsverarbeitenden-Liste leer ist, während der Dienst auf AWS läuft und Mail über Dritte schickt, ist das Erste, was eine Sicherheitsprüfung fängt, und es blockiert den Deal statt ihn zu schließen.
  • Den Platzhaltertext stehen lassen. Alles in eckigen Klammern ist ein Feld, das du übersprungen hast, und Leserinnen merken das sofort.
  • Veröffentlichen und nie wieder anschauen. Die werden alt - du fügst ein Tool hinzu, wechselst den Anbieter, verkaufst woanders, und das Dokument beschreibt noch letztes Jahr.
  • Es verstecken. Ein Dokument, das niemand findet, erfüllt seine Aufgabe nicht - es gehört in die Fußzeile jeder Seite.

Häufig gestellte Fragen

Beantworte die Fragen links. Das Dokument entsteht beim Tippen, und du kannst es kopieren oder als PDF, Word oder reinen Text herunterladen, wenn es stimmt.

Nein. Es setzt einen Entwurf aus Standardklauseln zusammen, und jede Seite sagt das über der Vorschau. Fehlende oder schwache AVVs fallen in Vendor-Sicherheitsprüfungen auf, und das ist lange vor der Aufsicht ein Vertriebsproblem.

Ja - kostenlos, ohne Anmeldung, ohne E-Mail-Pflicht und ohne Wasserzeichen. Es läuft in deinem Browser, deshalb kostet es nichts, es anzubieten.

Im Großen und Ganzen SaaS-Anbieter, Agenturen und Entwicklerinnen, deren Unternehmenskunden nicht unterschreiben, bis ein AVV existiert. Der beste Zeitpunkt ist in der Beschaffung, weil es meist das Dokument ist, das den Vertrag aufhält.

Keine Unterauftragsverarbeitenden nennen. Ein AVV, dessen Unterauftragsverarbeitenden-Liste leer ist, während der Dienst auf AWS läuft und Mail über Dritte schickt, ist das Erste, was eine Sicherheitsprüfung fängt, und es blockiert den Deal statt ihn zu schließen.

Nein. Alles passiert auf deinem Gerät - nichts geht an einen Server, nichts wird gespeichert, und das Schließen des Tabs löscht es.

Ja. Lade die Word-Version herunter und ändere, was du willst - es ist ein normales .docx ohne Schutz.

Andere suchen auch nach

  • avv vorlage kostenlos
  • avv vorlage usa
  • avv vorlage uk
  • avv vorlage kleinunternehmen
  • avv vorlage vorlage
  • avv vorlage ohne anmeldung
  • avv vorlage

Related guides