Our Expert in Ireland
No results available
Last reviewed: 08 August 2026
Understanding how to draft a DPA, a data processing agreement that satisfies Article 28 of the GDPR and the guidance issued by the Irish Data Protection Commission (DPC), is now a front-line procurement skill for every organisation that outsources personal-data handling to a third-party vendor. Article 28(3) of Regulation (EU) 2016/679 mandates that processing by a processor “shall be governed by a contract … that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.
” The Irish Data Protection Act 2018 gives domestic effect to the GDPR across all sectors, and the DPC has made clear that the absence of an adequate controller–processor contract is itself a compliance failure. This guide delivers a clause-by-clause DPA drafting checklist, sample language, negotiation positions for both controllers and processors, and step-by-step instructions for integrating Standard Contractual Clauses (SCCs), managing subprocessors and structuring audit rights.
Before opening a blank document, map every required element of Article 28(3) GDPR to a named clause in your draft. The table below shows each mandatory item, the clause it belongs in, and whether the wording is typically non-negotiable (“must-have”) or open to commercial compromise (“negotiable”).
| Article 28(3) element | Recommended DPA clause | Must-have or negotiable? |
|---|---|---|
| Subject-matter and duration | Clause 1, Scope & Term | Must-have |
| Nature and purpose of processing | Clause 2, Processing Description | Must-have |
| Types of personal data | Schedule / Annex A, Data Mapping | Must-have |
| Categories of data subjects | Schedule / Annex A, Data Mapping | Must-have |
| Obligations and rights of the controller | Clause 3, Controller Instructions | Must-have |
| Confidentiality commitments | Clause 4, Confidentiality | Must-have |
| Technical and organisational measures | Clause 5, Security (Article 32) | Must-have (detail negotiable) |
| Subprocessor controls | Clause 6, Subprocessing | Must-have (mechanism negotiable) |
| Assistance with data-subject rights | Clause 7, DSARs & Notifications | Must-have |
| Deletion or return of data | Clause 8, End-of-Term Obligations | Must-have |
| Audits and inspections | Clause 9, Audit Rights | Must-have (scope negotiable) |
Use this checklist as a skeleton: create a clause for every row, then flesh out each one using the detailed guidance below. If your organisation needs a ready-made data processing agreement template, a downloadable annotated version is available as a companion resource.
Article 28(3) GDPR lists specific terms that every controller–processor contract in Ireland must include. The DPC expects these to be reflected in clear, enforceable language, not relegated to vague recitals. Below, each mandatory element is mapped to a drafting note, a sample clause and a short negotiation commentary.
State what the processor will do and for how long. Tie the DPA’s term to the underlying services agreement so both expire together.
Sample clause: “This DPA applies to the Processor’s processing of Personal Data on behalf of the Controller in connection with the Services Agreement dated [●] and remains in effect for so long as the Processor processes Personal Data under that agreement.”
Describe the processing activities in operational terms (e.g., “hosting and backup of customer-account records for the purpose of providing the SaaS platform described in Schedule 1”).
List these in a data-mapping annex. Common categories include contact details, financial identifiers, employee records and end-user behavioural data. Identify data subjects explicitly, employees, customers, website visitors, because the risk profile (and required TOMs) varies with each group.
Article 28(3)(a) requires the processor to process personal data “only on documented instructions from the controller.” Draft a clear instruction mechanism, typically the DPA itself plus written amendments, and oblige the processor to inform the controller immediately if, in the processor’s opinion, an instruction infringes the GDPR or Irish data-protection law.
Under Article 28(3)(b), the processor must ensure that persons authorised to process personal data have committed to confidentiality or are under a statutory obligation of confidence. Reference existing staff NDAs or include a standalone confidentiality undertaking.
Clause 5 should cross-reference Article 32 GDPR and attach a TOMs annex (see the Security section below). In practice in Ireland, the DPC has emphasised that controllers must verify, not merely accept, the processor’s stated security measures before signing a controller processor contract.
Article 28(2) and 28(4) require prior written authorisation before a processor engages a subprocessor. Detailed guidance appears in the Subprocessors section below.
The processor must assist the controller in responding to data-subject access requests (DSARs) and in meeting breach-notification obligations under Articles 33 and 34 GDPR. Specify response timelines (e.g., “within 48 hours of becoming aware”) and allocate costs.
Article 28(3)(g) requires the processor, at the controller’s choice, to delete or return all personal data after the end of the provision of services and to delete existing copies unless EU or Member State law requires storage. State the format for return (e.g., CSV export), the deletion-certification deadline, and any statutory-retention carve-outs under Irish law.
Article 28(3)(h) obliges the processor to make available “all information necessary to demonstrate compliance” and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.” Detailed audit-rights drafting appears in its own section below.
The following table summarises common negotiation positions for three of the most contested DPA clauses:
| Clause / Topic | Controller position (typical) | Processor-friendly compromise |
|---|---|---|
| Audit rights | Broad on-site audit with 30 days’ notice and no frequency limit | Remote evidence first (SOC 2 / ISO 27001); on-site only for material breaches; limited to once per year; mutual confidentiality undertakings |
| Subprocessor authorisation | Controller approval required for each subprocessor | General written authorisation plus right to object to a specific new subprocessor within 10 business days |
| Liability cap for DPA breaches | Unlimited liability for data-protection fines and direct damages | Cap at the higher of 12 months’ fees or €1 million; carve-out for intentional or grossly negligent breaches |
Subprocessor obligations in Ireland track Articles 28(2) and 28(4) GDPR: the processor must not engage another processor without prior specific or general written authorisation from the controller. Flow-down obligations and a clear objection mechanism are central to any robust DPA.
Under general written authorisation, the controller pre-approves the processor’s use of subprocessors listed in an annex, subject to advance notice of any additions and a right to object. Under specific prior authorisation, every new subprocessor requires individual controller consent. The general-authorisation model predominates in SaaS and cloud-services contracts because it balances operational flexibility with controller oversight.
Article 28(4) requires the processor to impose on any subprocessor “the same data protection obligations as set out in the contract … between the controller and processor.” At a minimum, flow-down clauses must cover: documented instructions, confidentiality, TOMs equivalent to those in the primary DPA, audit rights, breach notification and deletion/return of data.
Maintain a current subprocessor register, published on the processor’s website or provided on request, listing entity name, processing location, processing activity and date of engagement. The objection process should follow a clear workflow:
| Trigger | Controller right | Recommended clause language |
|---|---|---|
| Processor proposes a new subprocessor | Written notice at least 30 days in advance | “Processor shall notify Controller of any intended addition or replacement of a Subprocessor at least 30 days before the new Subprocessor begins processing.” |
| Controller objects on reasonable data-protection grounds | Right to object within 10 business days | “Controller may object … by providing written reasons related to data protection within 10 business days of receipt of the notice.” |
| Parties cannot resolve the objection | Right to terminate without penalty | “If the objection is not resolved within 30 days, Controller may terminate the affected services without liability for early-termination fees.” |
Audit rights in a DPA must satisfy Article 28(3)(h) GDPR without creating an unworkable burden for processors that serve hundreds of controller clients. Industry observers expect the “evidence-first” model, where processors provide existing certifications and reports before any on-site inspection, to become the dominant pattern across Irish procurement contracts.
Draft the audit clause in tiers. First, the processor provides current SOC 2 Type II reports, ISO 27001 certificates, penetration-test summaries or EDPB-aligned audit questionnaires. Second, if those materials are insufficient or a material incident has occurred, the controller may commission an on-site or remote audit conducted by an independent third-party auditor, subject to reasonable notice (typically 30 days), confidentiality obligations and a frequency cap of once per 12-month period.
Controller-leaning version: “Controller or its mandated auditor may, on 30 days’ written notice, inspect Processor’s premises, systems and records to verify compliance with this DPA and applicable data protection law. Processor shall cooperate fully with such audit at no additional charge.”
Processor-friendly alternative: “Processor shall make available to Controller, on request and no more than once per calendar year, its then-current SOC 2 Type II report and a completed audit questionnaire. On-site inspections shall be limited to circumstances in which the Controller demonstrates, on reasonable grounds, that the documentary evidence is insufficient, and shall be conducted by a mutually agreed independent auditor bound by confidentiality.”
When personal data leaves the European Economic Area, Article 46 GDPR requires an appropriate transfer mechanism. For most Irish controllers, standard contractual clauses remain the primary tool. Integrating SCCs correctly into a DPA avoids duplication and ensures enforceability.
If the processor or any subprocessor is established outside the EEA (or routes data through a non-EEA jurisdiction), attach the relevant module of the European Commission’s SCCs, adopted by Commission Implementing Decision (EU) 2021/914, as a schedule to the DPA. Where multiple modules apply (for example, Module 2 controller-to-processor and Module 3 processor-to-processor for subprocessors), specify each one and complete the annexes with entity-specific details.
The CJEU’s judgment in Case C-311/18 (Data Protection Commissioner v Facebook Ireland and Maximillian Schrems) confirmed that SCCs alone may not suffice if the destination country’s laws undermine the protections they provide. The EDPB’s recommendations on supplementary measures require a transfer-impact assessment (TIA) for each transfer. In your DPA, allocate responsibility for the TIA, identify who monitors changes in destination-country law, and commit both parties to implementing supplementary technical measures (such as encryption in transit and at rest with controller-held keys) where the TIA reveals risk.
Sample clause: “To the extent that Processor processes Personal Data originating from the EEA in a country not subject to an adequacy decision by the European Commission, the parties agree that Module 2 (Controller to Processor) of the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 shall apply and are incorporated by reference in Schedule [●]. The Processor shall cooperate with the Controller in conducting a transfer-impact assessment and implementing any supplementary measures identified as necessary.”
| Transfer scenario | Required steps | DPA clause to include |
|---|---|---|
| Processor in EEA; no sub-transfer | No SCCs needed | Standard Article 28 DPA clauses only |
| Processor in EEA; subprocessor outside EEA (no adequacy) | Module 3 SCCs + TIA + supplementary measures | SCC schedule for subprocessor transfer; TIA responsibility clause; flow-down of encryption/access controls |
| Processor outside EEA (no adequacy) | Module 2 SCCs + TIA + supplementary measures | SCC schedule attached to DPA; TIA clause; supplementary measures annex |
| Processor in country with EU adequacy decision | No SCCs needed (adequacy provides safeguard) | Recital confirming adequacy; monitoring obligation for adequacy-decision review |
Data processing agreement requirements in Ireland demand that the TOMs annex goes beyond generic assurances. The DPC expects controllers to verify that stated measures are actually implemented and proportionate to the risk profile of the data being processed.
A minimum TOMs checklist should address:
For breach response, Article 33 GDPR requires notification to the supervisory authority (the DPC) “without undue delay and, where feasible, not later than 72 hours” after becoming aware of a personal-data breach. The DPA should oblige the processor to notify the controller within a shorter window, typically 24 to 48 hours, so the controller has time to assess, investigate and file the regulatory notification if required. Include a breach-response clause that specifies the minimum information the processor must provide: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
The following quick-reference positions help procurement teams and legal ops identify non-negotiable terms versus areas of acceptable compromise when learning how to draft a DPA that both sides will sign.
The following sample clauses can serve as starting points when building a data processing agreement template. Each should be adapted to the specific processing activities, data categories and risk profile of the engagement.
Knowing how to draft a DPA that meets the data processing agreement requirements in Ireland comes down to disciplined clause mapping against Article 28(3) GDPR, genuine verification of technical and organisational measures, and honest negotiation of the commercial terms that sit around those legal mandates. Start with the quick-start checklist, fill in each clause using the sample language and negotiation positions above, attach the TOMs annex and, where international transfers are in scope, the appropriate SCC module. Review the DPA at least annually or whenever the underlying processing activities change. For complex vendor relationships or cross-border data flows, specialist legal advice remains essential to ensure full compliance with DPC guidance and the evolving enforcement landscape.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Dean Cunningham at Cunningham Solicitors, a member of the Global Law Experts network.
posted 18 minutes ago
posted 41 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
posted 5 hours ago
posted 8 hours ago
posted 12 hours ago
posted 16 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message