[codicts-css-switcher id=”346″]

Global Law Experts Logo
how to draft a dpa

How to Draft a DPA in Ireland (2026): Article 28 Checklist, Sccs, Subprocessors & Audit Rights

By Global Law Experts
– posted 47 minutes ago

Last reviewed: 08 August 2026

Understanding how to draft a DPA, a data processing agreement that satisfies Article 28 of the GDPR and the guidance issued by the Irish Data Protection Commission (DPC), is now a front-line procurement skill for every organisation that outsources personal-data handling to a third-party vendor. Article 28(3) of Regulation (EU) 2016/679 mandates that processing by a processor “shall be governed by a contract … that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.

” The Irish Data Protection Act 2018 gives domestic effect to the GDPR across all sectors, and the DPC has made clear that the absence of an adequate controller–processor contract is itself a compliance failure. This guide delivers a clause-by-clause DPA drafting checklist, sample language, negotiation positions for both controllers and processors, and step-by-step instructions for integrating Standard Contractual Clauses (SCCs), managing subprocessors and structuring audit rights.

Quick-Start: How to Draft a DPA in Five Minutes, the Article 28 Compliance Checklist

Before opening a blank document, map every required element of Article 28(3) GDPR to a named clause in your draft. The table below shows each mandatory item, the clause it belongs in, and whether the wording is typically non-negotiable (“must-have”) or open to commercial compromise (“negotiable”).

Article 28(3) element Recommended DPA clause Must-have or negotiable?
Subject-matter and duration Clause 1, Scope & Term Must-have
Nature and purpose of processing Clause 2, Processing Description Must-have
Types of personal data Schedule / Annex A, Data Mapping Must-have
Categories of data subjects Schedule / Annex A, Data Mapping Must-have
Obligations and rights of the controller Clause 3, Controller Instructions Must-have
Confidentiality commitments Clause 4, Confidentiality Must-have
Technical and organisational measures Clause 5, Security (Article 32) Must-have (detail negotiable)
Subprocessor controls Clause 6, Subprocessing Must-have (mechanism negotiable)
Assistance with data-subject rights Clause 7, DSARs & Notifications Must-have
Deletion or return of data Clause 8, End-of-Term Obligations Must-have
Audits and inspections Clause 9, Audit Rights Must-have (scope negotiable)

Use this checklist as a skeleton: create a clause for every row, then flesh out each one using the detailed guidance below. If your organisation needs a ready-made data processing agreement template, a downloadable annotated version is available as a companion resource.

Clause-by-Clause: What the Article 28 GDPR Contract Must Contain

Article 28(3) GDPR lists specific terms that every controller–processor contract in Ireland must include. The DPC expects these to be reflected in clear, enforceable language, not relegated to vague recitals. Below, each mandatory element is mapped to a drafting note, a sample clause and a short negotiation commentary.

Subject-matter and duration

State what the processor will do and for how long. Tie the DPA’s term to the underlying services agreement so both expire together.

Sample clause: “This DPA applies to the Processor’s processing of Personal Data on behalf of the Controller in connection with the Services Agreement dated [●] and remains in effect for so long as the Processor processes Personal Data under that agreement.”

Nature and purpose of processing

Describe the processing activities in operational terms (e.g., “hosting and backup of customer-account records for the purpose of providing the SaaS platform described in Schedule 1”).

Types of personal data and categories of data subjects

List these in a data-mapping annex. Common categories include contact details, financial identifiers, employee records and end-user behavioural data. Identify data subjects explicitly, employees, customers, website visitors, because the risk profile (and required TOMs) varies with each group.

Controller obligations and documented instructions

Article 28(3)(a) requires the processor to process personal data “only on documented instructions from the controller.” Draft a clear instruction mechanism, typically the DPA itself plus written amendments, and oblige the processor to inform the controller immediately if, in the processor’s opinion, an instruction infringes the GDPR or Irish data-protection law.

Confidentiality

Under Article 28(3)(b), the processor must ensure that persons authorised to process personal data have committed to confidentiality or are under a statutory obligation of confidence. Reference existing staff NDAs or include a standalone confidentiality undertaking.

Technical and organisational measures (TOMs)

Clause 5 should cross-reference Article 32 GDPR and attach a TOMs annex (see the Security section below). In practice in Ireland, the DPC has emphasised that controllers must verify, not merely accept, the processor’s stated security measures before signing a controller processor contract.

Subprocessing controls

Article 28(2) and 28(4) require prior written authorisation before a processor engages a subprocessor. Detailed guidance appears in the Subprocessors section below.

Assistance with data-subject requests and breach notification

The processor must assist the controller in responding to data-subject access requests (DSARs) and in meeting breach-notification obligations under Articles 33 and 34 GDPR. Specify response timelines (e.g., “within 48 hours of becoming aware”) and allocate costs.

Deletion or return of data at end of contract

Article 28(3)(g) requires the processor, at the controller’s choice, to delete or return all personal data after the end of the provision of services and to delete existing copies unless EU or Member State law requires storage. State the format for return (e.g., CSV export), the deletion-certification deadline, and any statutory-retention carve-outs under Irish law.

Audit rights and record-keeping

Article 28(3)(h) obliges the processor to make available “all information necessary to demonstrate compliance” and to “allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.” Detailed audit-rights drafting appears in its own section below.

The following table summarises common negotiation positions for three of the most contested DPA clauses:

Clause / Topic Controller position (typical) Processor-friendly compromise
Audit rights Broad on-site audit with 30 days’ notice and no frequency limit Remote evidence first (SOC 2 / ISO 27001); on-site only for material breaches; limited to once per year; mutual confidentiality undertakings
Subprocessor authorisation Controller approval required for each subprocessor General written authorisation plus right to object to a specific new subprocessor within 10 business days
Liability cap for DPA breaches Unlimited liability for data-protection fines and direct damages Cap at the higher of 12 months’ fees or €1 million; carve-out for intentional or grossly negligent breaches

Subprocessors: Authorisation, Flow-Downs and Notification Workflows

Subprocessor obligations in Ireland track Articles 28(2) and 28(4) GDPR: the processor must not engage another processor without prior specific or general written authorisation from the controller. Flow-down obligations and a clear objection mechanism are central to any robust DPA.

General authorisation versus specific approval

Under general written authorisation, the controller pre-approves the processor’s use of subprocessors listed in an annex, subject to advance notice of any additions and a right to object. Under specific prior authorisation, every new subprocessor requires individual controller consent. The general-authorisation model predominates in SaaS and cloud-services contracts because it balances operational flexibility with controller oversight.

Required flow-down clauses

Article 28(4) requires the processor to impose on any subprocessor “the same data protection obligations as set out in the contract … between the controller and processor.” At a minimum, flow-down clauses must cover: documented instructions, confidentiality, TOMs equivalent to those in the primary DPA, audit rights, breach notification and deletion/return of data.

Subprocessor register and objection process

Maintain a current subprocessor register, published on the processor’s website or provided on request, listing entity name, processing location, processing activity and date of engagement. The objection process should follow a clear workflow:

Trigger Controller right Recommended clause language
Processor proposes a new subprocessor Written notice at least 30 days in advance “Processor shall notify Controller of any intended addition or replacement of a Subprocessor at least 30 days before the new Subprocessor begins processing.”
Controller objects on reasonable data-protection grounds Right to object within 10 business days “Controller may object … by providing written reasons related to data protection within 10 business days of receipt of the notice.”
Parties cannot resolve the objection Right to terminate without penalty “If the objection is not resolved within 30 days, Controller may terminate the affected services without liability for early-termination fees.”

Audit Rights in a DPA: Reasonable Scope, Practical Limits and IT Security Evidence

Audit rights in a DPA must satisfy Article 28(3)(h) GDPR without creating an unworkable burden for processors that serve hundreds of controller clients. Industry observers expect the “evidence-first” model, where processors provide existing certifications and reports before any on-site inspection, to become the dominant pattern across Irish procurement contracts.

Types of audit and evidence hierarchy

Draft the audit clause in tiers. First, the processor provides current SOC 2 Type II reports, ISO 27001 certificates, penetration-test summaries or EDPB-aligned audit questionnaires. Second, if those materials are insufficient or a material incident has occurred, the controller may commission an on-site or remote audit conducted by an independent third-party auditor, subject to reasonable notice (typically 30 days), confidentiality obligations and a frequency cap of once per 12-month period.

Sample audit clause with negotiation alternatives

Controller-leaning version: “Controller or its mandated auditor may, on 30 days’ written notice, inspect Processor’s premises, systems and records to verify compliance with this DPA and applicable data protection law. Processor shall cooperate fully with such audit at no additional charge.”

Processor-friendly alternative: “Processor shall make available to Controller, on request and no more than once per calendar year, its then-current SOC 2 Type II report and a completed audit questionnaire. On-site inspections shall be limited to circumstances in which the Controller demonstrates, on reasonable grounds, that the documentary evidence is insufficient, and shall be conducted by a mutually agreed independent auditor bound by confidentiality.”

International Transfers and Standard Contractual Clauses Inside a DPA

When personal data leaves the European Economic Area, Article 46 GDPR requires an appropriate transfer mechanism. For most Irish controllers, standard contractual clauses remain the primary tool. Integrating SCCs correctly into a DPA avoids duplication and ensures enforceability.

When to attach SCCs versus reference them

If the processor or any subprocessor is established outside the EEA (or routes data through a non-EEA jurisdiction), attach the relevant module of the European Commission’s SCCs, adopted by Commission Implementing Decision (EU) 2021/914, as a schedule to the DPA. Where multiple modules apply (for example, Module 2 controller-to-processor and Module 3 processor-to-processor for subprocessors), specify each one and complete the annexes with entity-specific details.

Practical steps following the Schrems II judgment

The CJEU’s judgment in Case C-311/18 (Data Protection Commissioner v Facebook Ireland and Maximillian Schrems) confirmed that SCCs alone may not suffice if the destination country’s laws undermine the protections they provide. The EDPB’s recommendations on supplementary measures require a transfer-impact assessment (TIA) for each transfer. In your DPA, allocate responsibility for the TIA, identify who monitors changes in destination-country law, and commit both parties to implementing supplementary technical measures (such as encryption in transit and at rest with controller-held keys) where the TIA reveals risk.

Sample SCC incorporation clause

Sample clause: “To the extent that Processor processes Personal Data originating from the EEA in a country not subject to an adequacy decision by the European Commission, the parties agree that Module 2 (Controller to Processor) of the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 shall apply and are incorporated by reference in Schedule [●]. The Processor shall cooperate with the Controller in conducting a transfer-impact assessment and implementing any supplementary measures identified as necessary.”

Transfer scenario Required steps DPA clause to include
Processor in EEA; no sub-transfer No SCCs needed Standard Article 28 DPA clauses only
Processor in EEA; subprocessor outside EEA (no adequacy) Module 3 SCCs + TIA + supplementary measures SCC schedule for subprocessor transfer; TIA responsibility clause; flow-down of encryption/access controls
Processor outside EEA (no adequacy) Module 2 SCCs + TIA + supplementary measures SCC schedule attached to DPA; TIA clause; supplementary measures annex
Processor in country with EU adequacy decision No SCCs needed (adequacy provides safeguard) Recital confirming adequacy; monitoring obligation for adequacy-decision review

Security Annex: Minimum TOMs and Breach-Response Obligations

Data processing agreement requirements in Ireland demand that the TOMs annex goes beyond generic assurances. The DPC expects controllers to verify that stated measures are actually implemented and proportionate to the risk profile of the data being processed.

A minimum TOMs checklist should address:

  • Encryption. Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
  • Access controls. Role-based access, multi-factor authentication for administrative accounts, least-privilege principle.
  • Logging and monitoring. Centralised logging of access events, automated alerting for anomalous activity, log retention of at least 12 months.
  • Data retention and disposal. Automated deletion schedules, certified destruction of physical media.
  • Business continuity. Documented backup and disaster-recovery procedures with defined recovery-time and recovery-point objectives.
  • Vulnerability management. Regular penetration testing, timely patching of critical vulnerabilities.

For breach response, Article 33 GDPR requires notification to the supervisory authority (the DPC) “without undue delay and, where feasible, not later than 72 hours” after becoming aware of a personal-data breach. The DPA should oblige the processor to notify the controller within a shorter window, typically 24 to 48 hours, so the controller has time to assess, investigate and file the regulatory notification if required. Include a breach-response clause that specifies the minimum information the processor must provide: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

Negotiation Playbook: Redlines for Controllers and Processors

The following quick-reference positions help procurement teams and legal ops identify non-negotiable terms versus areas of acceptable compromise when learning how to draft a DPA that both sides will sign.

  • Controller redline, documented instructions. The controller must retain the right to issue written processing instructions; no blanket delegation to the processor’s standard operating procedures.
  • Controller redline, breach notification. Insist on a 24- to 48-hour processor-to-controller notification window, not the full 72 hours allowed for controller-to-DPC reporting.
  • Controller redline, deletion certification. Require written certification of deletion within 30 days of contract termination, with an option for the controller to verify.
  • Processor fallback, audit frequency. Limit on-site audits to once per year; accept evidence-based reviews (SOC 2, ISO 27001) for interim periods.
  • Processor fallback, subprocessor changes. Use general written authorisation with a 30-day notice period and a structured objection process rather than per-engagement consent.
  • Processor fallback, liability. Propose a cap linked to annual contract fees; carve out deliberate misconduct and regulatory fines attributable to the processor’s own non-compliance.

Practical Examples: Sample DPA Clauses

The following sample clauses can serve as starting points when building a data processing agreement template. Each should be adapted to the specific processing activities, data categories and risk profile of the engagement.

  • Instructions clause. “The Processor shall process Personal Data only in accordance with the Controller’s documented instructions as set out in this DPA and any subsequent written instructions agreed by the parties. If the Processor considers that an instruction infringes applicable data protection law, it shall promptly inform the Controller.”
  • Confidentiality clause. “The Processor shall ensure that all personnel authorised to process Personal Data are bound by a contractual or statutory obligation of confidentiality.”
  • Subprocessor flow-down clause. “Where the Processor engages a Subprocessor, it shall impose on that Subprocessor, by way of a written contract, data-protection obligations no less protective than those set out in this DPA.”
  • Audit clause. “The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice.”
  • SCC incorporation clause. “To the extent that the processing involves a Restricted Transfer, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2: Controller to Processor) are incorporated by reference as Schedule [●].”
  • Deletion/return clause. “Upon termination of the Services Agreement, the Processor shall, at the Controller’s election, return or securely delete all Personal Data within 30 days and provide written certification of deletion.”
  • Breach notification clause. “The Processor shall notify the Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data Breach, providing sufficient detail to enable the Controller to fulfil its obligations under Articles 33 and 34 GDPR.”
  • Liability allocation clause. “Nothing in this DPA limits either party’s liability for obligations that cannot be excluded or limited under applicable data protection law, including liability for administrative fines imposed directly on a party by a supervisory authority.”

Conclusion: Next Steps for Drafting Your DPA

Knowing how to draft a DPA that meets the data processing agreement requirements in Ireland comes down to disciplined clause mapping against Article 28(3) GDPR, genuine verification of technical and organisational measures, and honest negotiation of the commercial terms that sit around those legal mandates. Start with the quick-start checklist, fill in each clause using the sample language and negotiation positions above, attach the TOMs annex and, where international transfers are in scope, the appropriate SCC module. Review the DPA at least annually or whenever the underlying processing activities change. For complex vendor relationships or cross-border data flows, specialist legal advice remains essential to ensure full compliance with DPC guidance and the evolving enforcement landscape.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Dean Cunningham at Cunningham Solicitors, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Official text
  2. Data Protection Commission (Ireland), Controller and Processor relationships
  3. European Commission, Standard Contractual Clauses (SCCs)
  4. European Data Protection Board (EDPB), Guidelines and opinions
  5. Irish Statute Book, Data Protection Act 2018
  6. Court of Justice of the European Union (CJEU), Curia

FAQs

How do I create a data processing agreement?
Identify the parties and their controller/processor roles, map all processing activities, draft clauses covering every Article 28(3) requirement (instructions, confidentiality, TOMs, subprocessors, DSARs, breach notification, deletion/return, audits), attach SCCs where international transfers occur, and obtain evidence of the processor’s security controls before signing.
At a minimum: subject-matter and duration, nature and purpose of processing, types of personal data, categories of data subjects, controller/processor obligations and documented instructions, confidentiality commitments, technical and organisational measures, subprocessor controls, assistance with data-subject rights and breach notification, deletion or return of data on termination, and audit rights.
Require prior written authorisation (general or specific), impose flow-down obligations mirroring the primary DPA, maintain a current subprocessor register, give the controller a notice period before any new subprocessor is engaged, and include a right to object on data-protection grounds with a termination remedy if the objection is not resolved.
Yes, if personal data is transferred outside the EEA to a country that does not benefit from an adequacy decision by the European Commission. The SCCs adopted under Commission Implementing Decision (EU) 2021/914 should be attached as a schedule to the DPA, with completed annexes and a transfer-impact assessment.
An evidence-first approach is widely accepted: the processor provides current certifications (SOC 2, ISO 27001) and test reports; on-site inspections are reserved for high-risk scenarios or verified incidents; audits are limited to once per year with 30 days’ advance notice and mutual confidentiality protections.
A processor cannot contract out of direct liability for administrative fines imposed on it by a supervisory authority under the GDPR. DPA liability clauses should make this explicit and separately address the allocation of responsibility for fines, regulatory remediation costs and third-party claims.
The Data Protection Commission publishes guidance on controller and processor relationships on its website, covering Article 28 expectations, contractual obligations and enforcement priorities. The Irish Data Protection Act 2018 provides the domestic statutory framework that gives effect to the GDPR in Ireland.
ireland investor visa alternatives
By Jonathon Richards

posted 7 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Draft a DPA in Ireland (2026): Article 28 Checklist, Sccs, Subprocessors & Audit Rights

Send welcome message

Custom Message