Practical guide
How to draft a Data Processing Agreement (DPA) with AI
5 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa
The Data Processing Agreement (DPA) represents the fundamental binding legal act governing the relationship between a Data Controller and a Data Processor, ensuring compliance with European data protection standards. Pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR), its execution is mandatory whenever an external party processes personal data on behalf of the controller in the context of a service. This document strictly defines the subject matter, duration, nature, and purpose of the processing, as well as the types of personal data and categories of data subjects involved. Failure to conclude the agreement in written or electronic form not only exposes the parties to severe administrative fines but also results in the unlawfulness of the data disclosure to the provider.
In brief
This technical guide details drafting a DPA with AI under Art. 28 GDPR. The agreement is the mandatory binding act between controller and processor to ensure European compliance. The document defines the subject matter, duration, nature, and purpose of processing, alongside security measures under Art. 32 GDPR. A written or electronic format is required for the lawfulness of data disclosure. Sub-processing requires written authorization. If the processor independently determines purposes and means, it assumes the status of a controller under Art. 28 par. 10.
The steps
- 1.
Identification of the parties and qualification of roles
The first step involves the precise identification of the Controller and the Processor, verifying that the nature of the service actually entails processing on behalf of a third party. Pursuant to Art. 28, par. 1, GDPR, it is necessary to ensure that the processor provides sufficient guarantees to implement appropriate technical and organizational measures. It is essential that the agreement is linked to the main service contract, of which it constitutes an inseparable technical annex. The qualification must be unambiguous: if the provider independently determines the purposes and means, they cannot be designated as a processor under Art. 28 GDPR.
- 2.
Defining the scope and processing details
The act must analytically specify the contents required by paragraph 3 of Art. 28 GDPR, avoiding generic descriptions or vague references. It is necessary to precisely list the categories of data processed, such as personal identifiers, personal data relating to criminal convictions and offences, or health data, and the categories of data subjects, such as employees, customers, or web users. The duration of the processing must be consistent with the provision of the main service and must provide for the fate of the data upon termination of the relationship. An incomplete mapping of these elements leads to the unlawfulness of the processing and the imposition of administrative fines under Union law.
- 3.
Structuring documented instructions
The Processor is obliged to process personal data only on documented instructions from the Controller, including transfers to third countries. Such instructions must be integrated into the agreement or provided subsequently in writing, ensuring the traceability of every processing operation. It is necessary to insert a clause requiring the processor to immediately inform the controller if an instruction violates the GDPR or other national provisions. Without a clear flow of instructions, the processor acts outside the scope of legitimacy, assuming the status of a controller with the relative civil and sanctioning liabilities.
- 4.
Implementation of security measures
The agreement must bind the processor to comply with Art. 32 GDPR, requiring the adoption of technical and organizational measures appropriate to the identified risk. These include pseudonymization, encryption, the ability to ensure confidentiality and system resilience, as well as procedures for regularly testing the effectiveness of the measures. A generic reference to the law is not sufficient: measures should be described in a specific technical annex that the processor commits to maintaining. The Controller must retain the right to verify the adequacy of such measures through periodic audits and inspections conducted directly or by appointed third parties.
- 5.
Regulation of sub-processing and assistance
The use of a sub-processor requires written authorization, specific or general, from the controller, according to the conditions set out in Art. 28 par. 2 and 4. In the case of general authorization, the processor must inform the controller of any changes regarding the addition or replacement of sub-processors, granting the right to object. The contract must also provide for the processor's obligation to assist the controller in responding to data subjects' requests for the exercise of their rights. This cooperation is vital to ensure that the controller can fulfill its legal obligations within the strict deadlines provided by the regulation.
Legal basis: art. 28 Reg. UE 2016/679 (GDPR)art. 32 Reg. UE 2016/679 (GDPR)
The template structure
The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.
Title and parties
Analytical identification of the Data Controller and the external Processor designated for the service.
Recitals
Contextualization of the main contractual relationship and definition of the privacy roles assumed by the parties.
Subject matter, duration, and nature of processing
Analytical detail of processing operations, data types, and categories of data subjects involved.
Documented instructions of the controller
Requirement for the processor to act exclusively based on the written directives issued by the controller.
Obligations of the processor
Regulation of confidentiality, security measures under Art. 32, and support in managing data subjects' rights.
Sub-processors
Conditions and procedures for the authorization to use third-party providers in the processing chain.
Extra-EU transfers
Legal guarantees and contractual instruments for the lawfulness of data flows to countries outside the European Economic Area.
Data breach, audit, and termination
Breach notification procedures, controller's inspection rights, and obligations to return or delete data.
Place, date, signature
Signature of the parties for formal acceptance and legal validity of the agreement in written form.
Mistakes to avoid
- Using generic clauses that fail to specify data types and categories of data subjects, violating the specificity requirement of Art. 28 GDPR.
- Failure to provide for the active assistance obligation in case of a data breach, which must occur without undue delay to allow the controller to meet the 72-hour notification deadline to the Authority.
- Absence of clear regulations for sub-processing, which leads to the illegality of any activities carried out by the processor's third-party vendors.
- Omission of the clause regarding the fate of data after contract termination, resulting in risks of unlawful retention or data loss.
Frequently asked questions
Is the Art. 28 GDPR agreement mandatory for freelancers too?
Yes, if the professional acts as a data processor on behalf of a controller client, concluding a contract or other legal act in writing is a mandatory requirement. The rule does not provide for size thresholds, applying to anyone processing data on behalf of others.
What happens if the processor does not follow the controller's instructions?
Pursuant to Art. 28 par. 10 GDPR, a processor that independently determines the purposes and means of processing by violating instructions is considered a data controller in its own right. This entails full liability for violations and the application of direct administrative fines.
Can the DPA be signed digitally?
Yes, the Regulation expressly provides that the agreement may be concluded in electronic form. The use of a digital signature or an advanced electronic signature ensures the certainty of the date and the integrity of the content required by law.

What edit.legal automates
- —Automatic generation of Art. 28 par. 3 tables with guided mapping of data types and data subjects.
- —Dynamic integration of security measures compliant with Art. 32 GDPR based on the risk category.
- —Automated compliance check of clauses for extra-EU transfers against European Commission standard models.
Put edit.legal to the test on actual cases
Try edit.legal for free on an active case. No credit card required.
Try edit.legal for freeThis guide is for informational purposes only and does not constitute legal advice for your specific case.