Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendum, controller-processor agreement, or data protection addendum involving sub-processors, breach notification, audits, international transfers, or SCCs.
Produces an Article 28-compliant DPA aligned with the governing service agreement, covering processing details, security, sub-processor controls, breach notice, audits, and deletion terms.
Quick Start
Gather before drafting:
Party details: legal names, addresses, registration numbers (Controller + Processor)
Add sub-processor governance (Art 28(2), 28(4)) with flow-down obligations.
Add audit and compliance evidence provisions (Arts 28(3)(h), 40, 42).
If data leaves the EEA, add international transfer terms (Art 46 SCCs, Art 47 BCRs, Art 49 derogations).
Add termination, return/deletion obligations, and backup handling.
Populate Schedules A-D from inputs; mark gaps as [REQUIRED].
Article 28(3) Mandatory Clause Checklist
GDPR basis
Clause
Required content
Art 28(3)(a)
Instructions
Process only on documented Controller instructions; notify if instruction violates law
Art 28(3)(b)
Confidentiality
Authorized personnel bound by confidentiality
Art 28(3)(c)
Security
Appropriate TOMs per Art 32
Art 28(3)(d)
Sub-processors
No sub-processing without authorization; flow-down equivalent obligations
Art 28(3)(e)
Data subject rights
Assist Controller with Chapter III requests
Art 28(3)(f)
Assistance
Assist with Art 32-36 obligations including DPIA and prior consultation
Art 28(3)(g)
Return/Deletion
Return or delete personal data at end of services; certify
Art 28(3)(h)
Audits/Info
Make information available; allow and contribute to audits
Key Decision Points
Decision
Options
Input needed
Sub-processor authorization
General / Specific
Controller policy, objection window
Audit model
On-site / Remote / Third-party / Certification
Vendor policy, existing reports
Breach notice SLA
24h / 48h / Other
Risk tolerance, incident playbooks
Data return format
CSV / JSON / Native export
System compatibility
Transfer mechanism
Adequacy / SCCs / BCRs / Art 49
Data flows and locations
Schedule Templates
Schedule A — Approved Sub-processors
Name
Location
Processing Activity
Authorization Type
Notice Period
TBD
TBD
TBD
General/Specific
30 days
Schedule B — Description of Processing
Field
Details
Subject matter
Duration
Nature of processing
Purpose
Processing operations
Categories of data subjects
Categories of personal data
Special categories (Art 9)
Criminal data (Art 10)
Processing locations
Schedule C — Technical and Organizational Measures
Domain
Measures
Access control
Encryption/pseudonymization
Logging/monitoring
Availability/resilience
Incident response
Testing/evaluation
Physical security
Schedule D — Audit/Certification Evidence
Evidence
Date
Scope
Reference
ISO 27001
SOC 2 Type II
Pitfalls
No absolute security promises. Use "appropriate" measures per Art 32; tie to risk profile.
Special categories / children's data require heightened safeguards and stricter access controls.
Missing transfer basis is a blocker. If any non-EEA transfer occurs, specify the mechanism and attach SCCs or equivalent before finalizing.
Schedule consistency. Keep schedules aligned with DPA body text; ensure sub-processor lists are current.
Order of precedence. Data protection terms must prevail over conflicting service agreement terms.
Mark uncertain legal citations with [VERIFY].
1---2name: gdpr-dpa3description: Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendum, controller-processor agreement, or data protection addendum involving sub-processors, breach notification, audits, international transfers, or SCCs.4license: Apache-2.05---67# GDPR Data Processing Addendum (DPA)89Produces an Article 28-compliant DPA aligned with the governing service agreement, covering processing details, security, sub-processor controls, breach notice, audits, and deletion terms.1011## Quick Start1213Gather before drafting:1415- [ ] Party details: legal names, addresses, registration numbers (Controller + Processor)16- [ ] Underlying agreement reference (name, date, SOWs/order forms)17- [ ] Processing description: subject matter, duration, nature, purpose, operations18- [ ] Data inventory: data subject categories, personal data types, special categories (Art 9), criminal data (Art 10)19- [ ] Transfer map: processing locations, transfer mechanism (adequacy, SCCs, BCRs, Art 49)20- [ ] Security baseline: certifications, TOMs21- [ ] Sub-processor list + approval model (general vs specific) with objection window22- [ ] Incident response SLAs and audit preferences23- [ ] Termination: return/deletion formats, timelines, retention constraints2425## Drafting Workflow26271. Draft header, recitals, effective date, and order-of-precedence clause with the main agreement.282. Define GDPR terms: Controller, Processor, Personal Data, Processing, Sub-processor, Data Protection Laws, Personal Data Breach, Services.293. Insert Article 28(3) mandatory clauses (see checklist below).304. Add security (Art 32), breach notification (Arts 33-34), and assistance (Arts 32-36) clauses.315. Add sub-processor governance (Art 28(2), 28(4)) with flow-down obligations.326. Add audit and compliance evidence provisions (Arts 28(3)(h), 40, 42).337. If data leaves the EEA, add international transfer terms (Art 46 SCCs, Art 47 BCRs, Art 49 derogations).348. Add termination, return/deletion obligations, and backup handling.359. Populate Schedules A-D from inputs; mark gaps as `[REQUIRED]`.3637## Article 28(3) Mandatory Clause Checklist3839| GDPR basis | Clause | Required content |40|---|---|---|41| Art 28(3)(a) | Instructions | Process only on documented Controller instructions; notify if instruction violates law |42| Art 28(3)(b) | Confidentiality | Authorized personnel bound by confidentiality |43| Art 28(3)(c) | Security | Appropriate TOMs per Art 32 |44| Art 28(3)(d) | Sub-processors | No sub-processing without authorization; flow-down equivalent obligations |45| Art 28(3)(e) | Data subject rights | Assist Controller with Chapter III requests |46| Art 28(3)(f) | Assistance | Assist with Art 32-36 obligations including DPIA and prior consultation |47| Art 28(3)(g) | Return/Deletion | Return or delete personal data at end of services; certify |48| Art 28(3)(h) | Audits/Info | Make information available; allow and contribute to audits |4950## Key Decision Points5152| Decision | Options | Input needed |53|---|---|---|54| Sub-processor authorization | General / Specific | Controller policy, objection window |55| Audit model | On-site / Remote / Third-party / Certification | Vendor policy, existing reports |56| Breach notice SLA | 24h / 48h / Other | Risk tolerance, incident playbooks |57| Data return format | CSV / JSON / Native export | System compatibility |58| Transfer mechanism | Adequacy / SCCs / BCRs / Art 49 | Data flows and locations |5960## Schedule Templates6162**Schedule A — Approved Sub-processors**6364| Name | Location | Processing Activity | Authorization Type | Notice Period |65|---|---|---|---|---|66| TBD | TBD | TBD | General/Specific | 30 days |6768**Schedule B — Description of Processing**6970| Field | Details |71|---|---|72| Subject matter | |73| Duration | |74| Nature of processing | |75| Purpose | |76| Processing operations | |77| Categories of data subjects | |78| Categories of personal data | |79| Special categories (Art 9) | |80| Criminal data (Art 10) | |81| Processing locations | |8283**Schedule C — Technical and Organizational Measures**8485| Domain | Measures |86|---|---|87| Access control | |88| Encryption/pseudonymization | |89| Logging/monitoring | |90| Availability/resilience | |91| Incident response | |92| Testing/evaluation | |93| Physical security | |9495**Schedule D — Audit/Certification Evidence**9697| Evidence | Date | Scope | Reference |98|---|---|---|---|99| ISO 27001 | | | |100| SOC 2 Type II | | | |101102## Pitfalls103104- **No absolute security promises.** Use "appropriate" measures per Art 32; tie to risk profile.105- **Special categories / children's data** require heightened safeguards and stricter access controls.106- **Missing transfer basis is a blocker.** If any non-EEA transfer occurs, specify the mechanism and attach SCCs or equivalent before finalizing.107- **Schedule consistency.** Keep schedules aligned with DPA body text; ensure sub-processor lists are current.108- **Order of precedence.** Data protection terms must prevail over conflicting service agreement terms.109- Mark uncertain legal citations with `[VERIFY]`.
Run npx skillmds@latest add thomasmoreai/gdpr-dpa in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Drafts GDPR Article 28-compliant Data Processing Addenda with schedules ready for execution. Use when drafting or updating a DPA, vendor GDPR addendum, controller-processor agreement, or data protection addendum involving sub-processors, breach notification, audits, international transfers, or SCCs. It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.
ThomasMoreAI (@thomasmoreai) published this skill. Their other Agent Skills are listed on their SkillMD profile.