ConsentPixel – Privacy · Verified

Data Processing Agreement Generator

Generate a GDPR Article 28 data processing agreement

If a vendor processes personal data on your behalf — a cloud host, a SaaS tool, an email platform — GDPR Article 28 requires a written data processing agreement before that processing begins. ConsentPixel generates one covering all eight mandatory clauses, plus SCCs for international transfers — and it's included in the document suite, not gated behind a separate paywall.

Creates your ConsentPixel account · 14-day free trial · no credit card · from $8.99/site per month after.

The honest part

A generated DPA is a starting point, not a done deal. It gives you a solid Article 28 baseline — but a DPA only has effect once it's reviewed for your situation and actually signed with each processor. An unsigned template in a folder protects no one. We give you the document; executing it with your vendors is the part only you can do.

Article 28
All 8 mandatory processor clauses covered
+ SCCs
For transfers outside the EEA · plus FADP & POPIA
Included
Part of the 5-document suite — often gated elsewhere

When do you actually need a DPA?

The trigger is simple: any time a third party processes personal data on your behalf. If a vendor touches your customers' or users' personal data while following your instructions, GDPR Article 28 requires a written data processing agreement with them — and it needs to be in place before the processing starts. In practice that covers a lot of the tools a typical business runs:

  • Cloud hosting — AWS, Azure, Google Cloud.
  • SaaS tools that process customer data — CRMs, help desks, analytics.
  • Email marketing platforms — anywhere your contact lists live.
  • Payroll and HR providers — processing employee data.
  • Any subprocessor handling personal data on your instructions.

Here's the part businesses underestimate: it's not one DPA, it's one per processor. As you add tools, the number of DPAs you need to have signed grows with them — and DPA gaps are among the first deficiencies flagged in a GDPR review. The absence of a written DPA is itself an Article 28 violation, independent of whether anyone was actually harmed.

What a GDPR DPA must contain

Article 28(3) doesn't leave the contents to chance. Beyond describing the processing (its subject matter, duration, nature and purpose, the types of personal data and categories of data subjects), it sets out eight specific obligations — and omitting any one makes the DPA deficient:

1

Documented instructions. The processor acts only on your written instructions.

2

Confidentiality. Everyone processing the data is bound to confidentiality.

3

Security. Appropriate technical and organisational measures are in place.

4

Sub-processors. No new sub-processor without your authorisation.

5

Data-subject rights. The processor helps you respond to access, deletion and other requests.

6

Breach assistance. The processor helps you meet breach-notification duties.

7

Deletion or return. Data is deleted or returned when the service ends.

8

Audits. You can audit and inspect the processor's compliance.

ConsentPixel's generator produces a DPA that covers all eight, so you start from a complete Article 28 baseline rather than a partial template you have to spot-check clause by clause.

International transfers, FADP & POPIA

If your processing sends personal data outside the EEA — which it does the moment you use a US-based cloud or SaaS tool — your DPA also needs to incorporate Standard Contractual Clauses (SCCs), the EU-approved terms that provide adequate safeguards for international transfers. ConsentPixel's DPA accounts for SCCs alongside Article 28, and covers the equivalent frameworks for Switzerland (FADP) and South Africa (POPIA) — so a business operating across those regions isn't stitching together three separate documents.

You controller DPA Article 28 · 8 clauses + SCCs · FADP · POPIA signed by both Your vendor processor
Illustration — a DPA binds controller and processor across Article 28 & transfer rules (not a screenshot).

DPA vs. NDA — they're not the same

These get confused constantly, and it's an expensive confusion, because an NDA does not satisfy your GDPR obligation. They protect different things:

 DPANDA
GovernsHow personal data is processedConfidential business information
Legal basisRequired by GDPR Article 28Voluntary contract
CoversPersonal data of individualsTrade secrets, business plans
When you need itSharing personal data with a processorSharing sensitive business info

You might well need both — but signing an NDA with a vendor doesn't cover the DPA requirement. Only a DPA does that.

Why it's included, not gated

A lot of tools treat the DPA as a premium upsell, gated behind a higher tier. ConsentPixel includes it in the same five-document suite as your privacy policy, terms, cookie policy and declaration — from the Starter plan. If you already need the other documents, the DPA comes with them rather than as a separate line item.

Generate yours

Generate an Article 28 DPA — then sign it with your processors

Start from a complete Article 28 baseline covering all eight clauses plus SCCs, FADP and POPIA. Review it for your situation, and execute it with each vendor.

Start free trial & generate →

Creates your ConsentPixel account · 14-day free trial · no credit card · from $8.99/site per month. Information, not legal advice.

DPA generator FAQ

When do I need a data processing agreement?

Whenever a third party processes personal data on your behalf — cloud hosts, SaaS tools, email marketing platforms, payroll providers, analytics. Under GDPR Article 28, if a vendor handles your customers' or users' personal data on your instructions, a written DPA is required before processing begins. This is information, not legal advice.

What must a GDPR DPA contain?

Article 28(3) requires the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, plus eight processor obligations: documented instructions, confidentiality, security, sub-processor authorisation, assistance with data-subject rights, breach assistance, deletion or return of data, and audit rights. Omitting any of the eight makes the DPA deficient.

Is a DPA the same as an NDA?

No. A DPA governs how personal data is processed and is required by GDPR Article 28. An NDA protects confidential business information and is a voluntary contract. They serve different purposes — an NDA does not satisfy your GDPR DPA obligation, and you may need both.

Does a generated DPA make me compliant?

No. A generated DPA is a starting point covering the Article 28 requirements — it still has to be reviewed for your situation and actually signed with each processor to have effect. A DPA sitting unsigned in a folder does nothing. ConsentPixel gives you a solid Article 28 baseline; executing it with your vendors is on you. This is information, not legal advice.

Does the DPA cover international data transfers?

Where you transfer personal data outside the EEA, your DPA needs to incorporate Standard Contractual Clauses (SCCs). ConsentPixel's DPA accounts for SCCs alongside GDPR Article 28, and also covers the FADP (Switzerland) and POPIA (South Africa) frameworks.

Disclaimer: ConsentPixel — Privacy · Verified provides information and tooling, not legal advice, and is not a law firm. A generated data processing agreement is a starting template covering GDPR Article 28 requirements; it does not by itself make you compliant, must be reviewed for your specific circumstances, and only takes effect once executed with each processor. Verify your obligations with qualified counsel.

Scroll to Top