What is DPA (Data Processing Agreement)?
A contract between a data controller and a data processor required by GDPR Article 28.
A Data Processing Agreement (DPA) is the contract required by GDPR Article 28 between a controller (you) and a processor (your vendor) that defines the subject matter, duration, nature, purpose of processing, types of personal data, categories of data subjects, and obligations of the parties. PDF Verified provides a pre-signed DPA on every paid plan. For Enterprise customers we also support custom DPA negotiation and signed addenda.
Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.
What must be in a DPA
Per GDPR Article 28(3): subject matter, duration, nature, purpose; types of personal data and data subjects; processor obligations (process only on documented instructions, ensure confidentiality, take security measures, engage sub-processors only with consent, assist with data subject rights, delete/return data at end, allow audits).
Sub-processors
A DPA must list sub-processors (vendors of the processor that also touch data), for PDF Verified that includes Supabase (Postgres + storage), Resend (email delivery), Twilio/WhatsApp Business (messaging), Smile ID (KYC), Stripe + Paystack (billing). The full sub-processor list lives at /legal/dpa.
Cross-border data transfers
When personal data leaves the EU, the DPA must reference SCCs or an adequacy decision. PDF Verified uses 2021 SCCs (Modules 2 and 3) for transfers to non-EU sub-processors.
What PDF Verified is, and what it is not
PDF Verified is a tool for preparing, signing, stamping and checking documents. It is not a law firm, a compliance service or a forensic examiner, and nothing here is legal, financial or compliance advice. Requirements differ by country, by document type and by the party asking, so check what applies to your document before you rely on it, and take advice where the document matters. You are responsible for the documents you create, sign and send, and for having the authority to do so: signing or stamping in somebody else name, or as an organisation you do not represent, is forgery whatever tool is used. To the extent the law allows, we accept no liability for how a document made with this tool is used or relied on. The full position is in our terms of service.