Photo by Kindel Media from Pexels

If you run a marketplace, or even just buy SaaS tools through one, every vendor relationship that touches personal data needs a Data Processing Agreement (DPA). The problem is that most DPAs are 15-page PDFs stuffed with legalese, and marketplace teams rarely have in-house counsel sitting next to them during procurement. This checklist turns the review into a repeatable, step-by-step process you can finish in under an hour.

TL;DR

  • A DPA is legally required under GDPR Article 28 whenever a processor handles personal data on your behalf.
  • Missing or incomplete DPAs expose your marketplace to fines of up to EUR 10 million (lower tier) or 2 % of global turnover.
  • This checklist covers the 12 essential clauses every marketplace team should verify before signing.
  • Automated tools like Terms Doctor can flag red-flag clauses in vendor terms before you even open the DPA.
  • A DPA review is not a one-time task, schedule re-reviews whenever the vendor updates its terms.
0
Consumer-protection checks in Terms Doctor

Why marketplace teams need a DPA review process

terms of service document
Photo by RDNE Stock project from Pexels

Marketplaces sit in a unique position in the data-processing chain. You are typically the controller (you decide why and how personal data is processed), while each vendor, payment gateway, analytics provider, or fulfilment partner acts as a processor. Under GDPR Article 28, the controller must have a written contract, the DPA, with every processor. No exceptions.

Without a proper DPA in place, your marketplace is non-compliant from day one. Regulators do not need to prove that a data breach occurred; the mere absence of a compliant DPA is itself a violation. For marketplace teams juggling dozens of vendor relationships, this risk multiplies fast.

Common scenarios where a DPA is required include:

  • A third-party payment processor handling buyer credit-card data.
  • A customer-support tool storing buyer names, emails, and order histories.
  • An analytics or personalisation vendor receiving browsing behaviour from your marketplace.
  • A cloud-hosting provider storing your marketplace database that contains seller and buyer PII.
  • A shipping or logistics partner receiving delivery addresses.
Each of these relationships demands its own DPA, or at minimum a DPA addendum attached to the main service agreement.
Terms pages with hidden auto-renewal clauses
0%

The 12-point DPA review checklist

DPA review checklist for marketplaces teams process
Figure 1: DPA review checklist for marketplaces teams at a glance.

Use this checklist every time you onboard a new vendor or renew an existing contract. Print it, paste it into your project-management tool, or save it as a template.

DPA Review Checklist for Marketplace Teams

Your progress is saved automatically in your browser.

"A DPA missing any of these is not Article 28 compliant, which is itself a breach exposed to fines up to EUR 10 million or 2 percent of global turnover under the lower tier (GDPR Article 28, EUR-Lex)."
>, DPA Review Field Guide for In

How to run a DPA review: step by step

consumer reading fine print
Photo by Pixabay from Pexels

Below is a practical workflow you can adopt today. It assumes you do not have a dedicated legal team, just a marketplace operations or compliance lead.

  1. Gather all vendor agreements. Export a list of every active vendor, SaaS tool, and integration from your procurement or finance system. For each, note whether a DPA already exists.
  2. Prioritise by data sensitivity. Rank vendors by the volume and sensitivity of personal data they process. Payment processors and CRM tools usually sit at the top; a font-hosting CDN sits at the bottom.
  3. Request the vendor's standard DPA. Most established SaaS vendors publish a DPA on their website (often under "Legal" or "Trust Center"). Download it and save it with a date stamp.
  4. Walk through the 12-point checklist above. Open the DPA side by side with the checklist. Mark each item as present, partially present, or missing. Use colour coding: green, amber, red.
  5. Flag red-flag clauses. Watch for language that allows the processor to use data for its own purposes, limits liability for breaches to an unreasonably low cap, or silently permits unlimited sub-processors without notice.
  6. Negotiate or escalate. For any amber or red items, draft a short email to the vendor requesting amendments. If the vendor refuses to budge on critical points (e.g., no audit rights at all), escalate internally before signing.
  7. Sign and store centrally. Once the DPA is satisfactory, countersign and store it in a central contract repository. Tag it with the review date and the next scheduled review date.
  8. Set a re-review cadence. At minimum, re-review every DPA annually or whenever the vendor notifies you of a terms update. Tools like Terms Doctor can alert you when a vendor's terms of service change, which often signals a DPA update too.
Key takeaway: A DPA review is not a legal formality, it is the single document that determines who is liable when personal data is mishandled, and skipping even one clause can shift that liability squarely onto your marketplace.

Red flags to watch for in vendor DPAs

person reading legal document laptop
Photo by Mikhail Nilov from Pexels

Not all DPAs are created equal. Some vendors offer a DPA that technically exists but is riddled with loopholes. Here are the most common red flags marketplace teams encounter:

  • Blanket sub-processor permissions. The DPA says the processor "may engage sub-processors at its discretion" without any notification or objection mechanism. This violates Article 28(2) GDPR.
  • Vague security measures. Instead of listing specific TOMs, the DPA says the processor will implement "commercially reasonable" security. That phrase is nearly meaningless in a regulatory investigation.
  • No breach-notification deadline. The DPA requires notification "as soon as practicable" but sets no hard deadline. Best practice is 24–48 hours; anything beyond 72 hours puts your own notification obligation to the supervisory authority at risk.
  • Data retention after termination. Some DPAs allow the processor to retain personal data for "legitimate business purposes" after the contract ends. This can include marketing analytics or model training, exactly what you want to prevent.
  • Liability caps that exclude data-protection breaches. A vendor may cap its total liability at the fees paid in the last 12 months but carve out nothing for data-protection violations. If a breach costs your marketplace millions, you could be left holding the bill.
  • No audit rights or "audit by report only." Some vendors offer only a SOC 2 report as a substitute for audit rights. While SOC 2 is valuable, GDPR Article 28(3)(h) explicitly requires the right to conduct audits and inspections. A report alone may not satisfy a regulator.
  • Silent international transfers. The DPA does not mention where data is stored or processed. If the vendor uses cloud infrastructure in the US or other non-EEA countries, you need an explicit transfer mechanism.
Quick tip: Before you even open a vendor's DPA, run their website through Terms Doctor. The extension's 101 automated checks will flag clauses about data sharing, AI training, and sub-processor usage in the main terms of service, giving you a head start on what to look for in the DPA itself.

Keeping your DPA register up to date

A completed review is only useful if you maintain it. Marketplace teams should keep a simple DPA register, a spreadsheet or database, with the following columns:

  • Vendor name
  • Service description
  • Data categories processed
  • DPA version and date signed
  • Next review date
  • Review status (compliant / needs update / expired)
  • Link to stored DPA document
Set calendar reminders for each review date. When a vendor sends a "we've updated our terms" email, treat it as a trigger to re-check the DPA as well. Many vendors update their DPA alongside their terms of service, and the changes are not always highlighted.

Automated change-tracking tools make this far easier. Terms Doctor, for example, monitors terms-of-service pages for changes and alerts you when wording shifts. While it does not replace a full legal review of the DPA itself, it acts as an early-warning system so you never miss a critical update.

FAQ

Frequently Asked Questions

A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor. Under GDPR Article 28, it is required whenever a processor handles personal data on behalf of a controller. For marketplace teams, this means every vendor, SaaS tool, or integration that touches buyer or seller personal data needs a DPA in place before processing begins.
You can, but you should still review it against the 12-point checklist above. Many vendor-provided DPAs are written to minimise the vendor's obligations, not to maximise your compliance. Pay special attention to sub-processor controls, breach-notification timelines, and audit rights. If any critical clause is missing or weak, negotiate amendments before signing.
At minimum, review each DPA once a year. You should also trigger a review whenever the vendor notifies you of changes to its terms of service or privacy policy, when you expand the scope of data you share with the vendor, or after a security incident involving that vendor. Setting up automated alerts, through a tool like Terms Doctor, helps ensure you do not miss update notifications.
If a vendor refuses to enter into a DPA, you cannot lawfully use that vendor to process personal data under GDPR. In practice, this means you either find an alternative vendor or accept the compliance risk, which is not advisable given the potential fines. Most reputable SaaS vendors now offer a standard DPA; refusal is often a red flag about the vendor's overall data-protection maturity.
Terms Doctor focuses on terms of service, privacy policies, and similar public-facing legal pages. It does not parse standalone DPA documents. However, its 101 automated checks catch many of the same red flags, such as data-sharing permissions, AI-training clauses, and sub-processor disclosures, that appear in a vendor's main terms. This gives marketplace teams a fast preliminary scan before diving into the full DPA. Remember that automated checks are not legal advice; always consult a qualified professional for binding compliance decisions.

Let Terms Doctor do the first pass

Reviewing DPAs is essential, but it does not have to start from scratch every time. Install the free Terms Doctor extension for Chrome, Edge, Brave, Opera, or Vivaldi, and let it automatically find and grade vendor terms of service with its A-F scale and 101 consumer-protection checks. You will spot data-sharing red flags, forced-arbitration clauses, and auto-renewal traps before you even open the DPA, saving your marketplace team hours of manual reading.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Always consult a qualified legal professional for compliance decisions.

Additional Resources