StackLégal

Article 28

Article 28 DPA: what the agreement must contain

Article 28 of Regulation (EU) 2016/679 requires a contract between the controller and its processor. A B2B customer who puts data in your SaaS will ask for it, often with the annex of further processors.

The StackLégal template follows the expected structure: subject matter and duration, documented instructions, confidentiality, security measures (Article 32) with no invented ISO/SOC 2, help with rights, breach notice without undue delay, bounded audits, deletion or return, transfers outside the EU, liability. Annex 3 lists only the vendors you tick.

This is not the DPA of StackLégal as a service (that one is at /dpa). Here you generate yours for your customers. 39 € incl. VAT, Markdown ZIP plus App Router. Templates in this language are dated 6 October 2026 and follow the GDPR in general. Review before you sign — not legal advice.

The vendor entries (data, DPA, Data Privacy Framework, clause to paste) are on /en/gdpr — for example Vercel, AWS, OVHcloud. To assemble several clauses: check your stack.

From 39 € incl. VATGenerate my DPA