Skip to main content
PRACTICE GUIDE · DATA PROTECTION

DPA Folders and Vendor Reviews

In almost every organization the data processing agreements sit as PDFs in a folder, and the deadlines that go with them sit in a calendar. We show why this filing does not carry the review obligations from Art. 28 GDPR and how the same process runs when it is structured.

How it works today in most organizations

The folder is called "DPA" and sits on the file share, usually one level below "Data protection". Inside it there are PDFs: "DPA_Payroll_signed.pdf", "dpa_crm_2021_final.pdf", "Scan_20230412.pdf". Some are signed by both parties, others by only one, and for some nobody remembers any more whether the countersignature ever came back.

The process behind it is quickly told. A department introduces a new tool and registers it – in the best case – with data protection. The provider sends its standard contract, management signs, the PDF moves into the folder. With that, the matter counts as done. The vendor was, in case of doubt, reviewed exactly once: during the selection. What comes after that is provided for nowhere.

Alongside this there is a second layer that is filed nowhere: the deadlines. Termination dates, automatic contract renewals and the date for the next review of a vendor sit in an Outlook calendar entry with a reminder, in a list called "Vendor_Overview.xlsx", or simply in the head of the person who concluded the contract back then. Every team knows the typical sentences: "That runs until the end of the year." "We do have the DPA, our colleague got hold of it." "We really ought to follow up on that again."

What the folder does not know

A folder can hold files, but no relationships. It does not know which processing activity a contract actually covers, which system the vendor operates and which data flow there. Nor does it know which vendors are actually in use in the organization – only which of them somebody has filed a PDF for. The toolkit that marketing subscribed to with a credit card does not appear there, in the nature of things.

Just as little does the folder record what would have to happen after signing: the check of whether the processor actually implements the technical and organizational measures (TOMs) it promised, the review of new sub-processors, the assessment of data transfers to third countries and, at the end, the evidence that the data were deleted or returned when the contract ended.

The moment it becomes obvious

This rarely shows up in day-to-day business. It shows up in four situations: when a customer asks for a list of all processors together with contracts and evidence of reviews, when an auditor wants to see the vendor review, when a provider announces a change to its sub-processors by email – or when the person leaves the organization in whose calendar the deadlines sat.

The question is then never "Do you have a DPA?" but "Which processing does it cover, when did you last review the vendor, and what was the outcome?" A folder full of PDFs has no answer to that question.

The analysis

Five gaps the DPA folder leaves open

They arise regardless of how carefully the contracts are filed – they are properties of the filing, not of the person.

View contract management in preeco

Contracts without a link to the processing

A PDF in a folder does not say which processing activity it covers. If a vendor is replaced, every affected processing activity has to be searched for one by one. When an authority or a customer asks, exactly this mapping is the real work.

Nobody sees where a contract is missing

The folder shows only what is there. A vendor without a DPA produces no empty file and therefore does not stand out. The gap typically becomes visible only when a customer asks for the complete list of processors.

Checking the measures without a cycle

Art. 28(1) GDPR requires working only with processors that provide sufficient guarantees for appropriate technical and organizational measures. Without a fixed cycle it stays with the check before the contract was concluded – years later it is unclear whether the assurances still hold.

Sub-processors and third countries unrecorded

Anyone who files the contract as a PDF keeps neither a list of sub-processors nor an overview of transfers to third countries. If a provider announces a change, neither the objection period nor the range of affected processing activities can be determined.

Deadlines hang on one person

Termination dates, renewals and review dates live in the calendar of a single person. If that person drops out or moves on, a contract renews tacitly, and at the end of the contract the evidence of deletion or return of the data is missing.

The target process in six steps

A sound approach to processors differs from the folder not by more contracts, but by a defined procedure. These six steps describe it – regardless of the tool you work with.

1. Record vendors instead of collecting contracts. The starting point is the list of vendors and systems in use, not the pile of existing PDFs. Only when both lists lie side by side does it become visible for which recipient a contract is missing. The existing folder is the basis for this, not the enemy.

2. Link contract and processing permanently. Every data processing agreement is mapped to the processing activities it covers. In preeco | data protection the system checks the match of role, company, first name and last name between the data recipient and the contract and creates the link automatically. The section "Contract relationships" then shows, for each processing activity and each system, which recipients are covered contractually.

3. Run the signing as a process. Instead of sending PDFs back and forth, the contract is signed with a signature workflow. Any number of signatories can be stored per contracting party; each person receives a link of their own, and the contract counts as signed only once everyone has signed. Reminders go specifically to the people still outstanding.

4. Schedule review dates instead of relying on reminders. Checking the technical and organizational measures of the processor gets a cycle – annually, depending on risk, or upon material changes. Follow-ups are a reminder to review your contracts and vendors, without anyone keeping a list in their head.

5. Document the review, do not just carry it out. A review date comes with an outcome: the certificate obtained, the audit report, the answer to the questionnaire. Tasks, comments, checklists and file attachments on the contract record who checked what and when. The activity log turns this into evidence in the sense of the accountability obligation under Art. 5(2) GDPR.

6. Close the end of the contract properly. When a contract ends, the deletion or return of the data under Art. 28(3)(g) GDPR has to be evidenced. As a scheduled task with stored evidence, this becomes a step in the process instead of an open flank.

Why the list of sub-processors is the sore point

The most frequent unplanned event in the processor process is not a new award of contract but a notice: a provider gives information about a new sub-processor. Anyone who has only filed PDFs now has to open every affected contract one by one, find the old list and work out the difference themselves.

In preeco | data protection the list of sub-processors can be updated across several contracts at once. Before saving, a summary shows per contract which sub-processors are added, dropped or changed; the notice to the contracting parties of signed contracts is pre-filled from templates and receives, per contract, an attachment with the list valid for it. Contracts that are currently out for signature or archived remain excluded. Every change ends up in the activity log.

Before and after in direct comparison

Criterion Before: DPA folder After: a managed contract process
Maintenance effort File PDFs, maintain file names, search when in doubt Create the contract once, status and links run along with it
Completeness Missing contracts do not stand out Vendors and contracts side by side, gaps visible
Link to the processing Only as a recollection in someone's head Link between contract, processing, system and measure
Vendor review Occasion-driven, usually once before signing A cycle with follow-up, documented outcome and evidence
Sub-processors A paragraph in the PDF, not evaluable A maintained list, bulk update with notice to the partners
Deadlines A calendar entry of one person Follow-ups for contracts and review dates
Evidence A scan without history A revision on approval and signature, activity log
Continuity risk The knowledge sits with one person Process, deadlines and history sit in the system

In practice

What this looks like in preeco | data protection

The three building blocks that carry the process described above.

What the switch means in practice

The most common objection is that all contracts would then have to be concluded anew. That is not the case. Existing, signed contracts remain valid; they are stored as a document, mapped to the vendor and to the processing activities, and given review dates. What is drawn up anew is only what is outdated in substance anyway.

The effort rarely lies in the technology. It lies in the clarification: which vendors do we actually use, who inside the organization owns the relationship, and which processing is behind it. Precisely this clarification is the real gain – the gaps become visible before a customer or a supervisory authority makes them visible.

Three mistakes that make the switch needlessly hard

Starting with the folder instead of the vendor list. Anyone who only transfers the existing PDFs transfers the gaps as well. The entry point is the list of systems and recipients in use; only the comparison shows where a contract is missing.

Understanding the review as a document instead of a date. A certificate obtained without a follow-up is worthless in two years. Only the scheduled cycle turns a one-off selection into ongoing control.

Leaving the department out of it. Whoever commissions a vendor knows best which data flow there. If the contract file stays with data protection alone, the same dependency on one person arises as before – only in a different interface.

How to tell that it is time

A folder of DPA PDFs is not a mistake. It becomes a risk only once at least one of these points applies:

  • You cannot say ad hoc for which vendors a contract is missing.
  • Review dates and notice periods sit in the calendar of a single person.
  • Customers regularly ask for your list of processors.
  • You have no documented evidence of a vendor review from the last twelve months.
  • Notices about new sub-processors sit around unanswered.

If none of this applies, the filing is fine. If two or more apply, it is already working against you.

FAQ

Frequently asked questions about DPAs and vendor reviews

For every vendor that processes personal data on your behalf and on your instructions – hosting, payroll, CRM, newsletter delivery or maintenance with access to data, for instance. A data processing agreement is not required where the partner processes the data under its own responsibility, as is usually the case for tax advisors, legal advisors or banks. The distinction is decided by whether the partner is bound by instructions, not by the industry.

The GDPR does not name a fixed cycle. Art. 28(1) GDPR does, however, require working only with processors that provide sufficient guarantees for appropriate technical and organizational measures – and that is a continuing requirement, not a one-off one before the contract is concluded. In practice a risk-based staggering has proven itself: critical vendors annually, non-critical ones at longer intervals, plus occasion-driven reviews after incidents or material changes.

A certificate or an audit report is a good element of the review, but on its own it is not evidence. What matters is that you assess the scope and the period of validity, document the outcome and set the next review date. A certificate without a follow-up and without a recorded assessment merely proves that it was available at some point.

First check what your contract provides for: a specific authorization, or a general authorization with a right to be informed and to object under Art. 28(2) GDPR. Then it has to be assessed whether the new sub-processor transfers data to a third country and on what basis. The decision and its date belong with the contract – as does the updated list of sub-processors, which in preeco | data protection can be maintained across several contracts at once.

No. Art. 28(9) GDPR requires written form, expressly including an electronic format. Digital signing is therefore permitted. More important in practice than the form is the traceability: who signed when for which contracting party, and which version of the contract applied at the time. In preeco | data protection an immutable revision is created automatically on approval or signature, and two versions can be compared.

Go through your contract file together with us

Bring your vendor list and your DPA folder with you. In 30 minutes we will show you where the gaps are and how the review cycle is set up.