Article 28
Article 28 DPA: what the agreement must contain
Article 28 of Regulation (EU) 2016/679 requires a contract between the controller and its processor. A B2B customer who puts data in your SaaS will ask for it, often with the annex of further processors.
The StackLégal template follows the expected structure: subject matter and duration, documented instructions, confidentiality, security measures (Article 32) with no invented ISO/SOC 2, help with rights, breach notice without undue delay, bounded audits, deletion or return, transfers outside the EU, liability. Annex 3 lists only the vendors you tick.
This is not the DPA of StackLégal as a service (that one is at /dpa). Here you generate yours for your customers. 39 € incl. VAT, Markdown ZIP plus App Router. Templates in this language are dated 6 October 2026 and follow the GDPR in general. Review before you sign — not legal advice.
The vendor entries (data, DPA, Data Privacy Framework, clause to paste) are on /en/gdpr — for example Vercel, AWS, OVHcloud. To assemble several clauses: check your stack.