Data Processing Agreement (DPA)
The GDPR Article 28 agreement your compliance team expects — with the DORA Article 30 annex a financial institution requires. Downloadable, editable, ready to sign.
What the document covers
The 8 obligations of GDPR Article 28(3)
Documented instructions, confidentiality, security, sub-processing (30-day notice), data subject rights assistance, breach notification, DPIA, return of data and audits.
Annexes 1-4: processing, security, sub-processors, transfers
Full description of the processing, technical and organisational measures actually in place, sub-processor list and transfer safeguards (SCCs 2021/914), with an "EU-only AI" option.
Annex 5: the 15 DORA Art. 30 provisions
The 9 provisions of Art. 30(2) for every arrangement, plus the 6 of Art. 30(3) where the service supports a critical or important function — with the details for your register of information.
Sub-processors covered by Annex 3
The same list as the one continuously published on our trust center — the contract and the website cannot drift apart.
A specific contractual requirement?
Quantified SLAs, DORA scope, "EU-only AI" option: tell us about your regulatory context.