Contracts

How to track data processing agreements without a CLM

Missing and expired DPAs are the most common vendor-risk finding for SMBs. Here is a lightweight system: statuses, owners, request letters, and alerts — without buying contract-lifecycle software.

Published 2026-08-24

A data processing agreement (DPA) under GDPR Article 28 is the contract that says a vendor processes personal data on your instructions. SMBs usually do not lack templates — they lack a chase process. The DPA is “with legal,” the vendor is already in production, and the questionnaire arrives anyway.

Minimum viable DPA hygiene

  • Every processor has a status you can filter.
  • Requested items have a date, so you can escalate after 14 days.
  • Signed items store a file or URL plus an expiry if the vendor issues term-limited terms.
  • Someone owns the row. Unowned contracts do not get signed.

Request letters beat vague Slack pings

A one-page letter that names the service, the personal data involved, and the Article 28 requirement is enough for most SaaS vendors. PrivyLedger generates that letter from the vendor record so you are not rewriting it from scratch. Log the send. If they only offer a trust-center click-through, record that as signed with the version date.

AI vendors change terms faster than the DPA

A signed DPA does not freeze training-on-data policies. Consumer ChatGPT, API, and enterprise tiers differ. Re-review AI processors on a 90-day cycle: same contract, possibly different residual risk.

Where PrivyLedger fits

The DPA chase board is a dedicated view of missing and requested agreements, with generated letters and due dates. Missing DPAs also raise the automatic vendor risk score, so the register and the chase list cannot drift apart.

PrivyLedger’s own Article 28 DPA is published at /dpa. Using the product does not replace your review of each vendor’s terms.

Questions

What DPA statuses should I use?

Missing, requested, signed, expiring, and not-required (for vendors that are not processors). Extra statuses people invent (“legal reviewing v3”) belong in a note, not the filter you use every week.

Can I use the vendor’s online DPA click-through?

Often yes, if it is an Article 28 instrument and you record the version and date. Still store a copy or URL in the vendor record so you can prove what you accepted.

When is a DPA not required?

When the other party is not processing personal data on your behalf (for example a pure controller-to-controller disclosure). Document the rationale so the next owner does not re-open the chase.

Related guides