The list that shows the gaps
Every vendor is a legal entity with a type, so you can pick out the data processors and put the agreement beside them. A processor with nothing beside it stands out instead of hiding.
Put every data processor next to its agreement and the gaps stop hiding. Register the agreement once, point at it from the assets and processing activities that rely on it, and change it in one place.
Unlimited users • Free onboarding and support • No commitment
Sofie Bruhn is group DPO at Meridian Nordic, three legal entities and around 1,200 active suppliers and processors between them. The agreements existed. They were just spread across a shared drive, a signing tool and four inboxes, so the question she quietly dreaded was never "show me the agreement with this processor". It was "which processors have we got no agreement with at all". Now every vendor sits in the platform as a legal entity with a type on it, so the data processors line up in one list with their agreements beside them, and the rows that are empty are the work.
The gaps are visible
Line up every legal entity marked as a data processor with its agreement, and the rows with nothing next to them are the ones to chase.
Two routes, your choice
With Contract Management the agreement is a contract with terms on it. Without it, a version-controlled document on the vendor. Same job.
Registered once
The agreement exists in one place and everything else points at it, so a correction is one edit rather than twelve.
Sub-processors, on your say-so
Register a new sub-processor and the platform asks before it carries it across. Nothing is written until you say yes.
An agreement you cannot find is a nuisance. An agreement you never signed is the actual risk, and it is much harder to notice, because nothing in a filing system draws attention to something that isn't there.
If you have Contract Management, each data processing agreement is a contract in its own right. It then inherits everything the contract record already knows how to do.
No Contract Management, no problem. This is the version we would rather explain properly than sell around, because for a lot of teams it is the right one.
Whichever route you take, the agreement exists in one place. Everything that depends on it points at it instead of holding a copy of its own.
This is the event that quietly makes an agreement wrong. It arrives as an email from your processor, and it is worth being honest that it doesn't arrive as a signal from us.
We build the plan, not the filling-in. Three boundaries are worth saying out loud before anyone books a demo.
Every vendor is a legal entity with a type, so you can pick out the data processors and put the agreement beside them. A processor with nothing beside it stands out instead of hiding.
With Contract Management each agreement is a contract, with the party pointing at the legal entity that is your processor, or an annex on the main contract. Then filter every agreement, its terms and who it is with.
Without Contract Management the agreement is a document on the vendor under a document type you define, databehandleraftale, version controlled and marked active or not. Fewer details on the list, same job done.
On an asset or a processing activity you point at the agreement as documentation that one exists with that processor, so a change made centrally reaches every place that relies on it.
Register a new sub-processor on the vendor and the platform asks whether to carry it across the places you already use that vendor. Processor and sub-processor roles are tagged automatically from how the entity is linked.
Every change to a legal entity is recorded with the date, the time, the user and the value before and after, and a processor you stop using is deactivated rather than deleted so the history survives.
One obligation, and the paperwork it actually asks for.
GDPR
Article 28 is the obligation this page is about: an agreement with every processor you use, the sub-processors they bring with them, and being able to show both without a week's notice.
Where processing activities, assets, legal entities and documents live, so the agreement sits next to the processing it actually covers.
Explore GDPRRoute one. The agreement as a contract, with parties, terms, documents, versions and a list you can filter.
Explore Contract ManagementAsk a processor for the agreement without giving them a login, and run the supervision that follows.
Explore Vendor Managementcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
12 use cases
No use cases match that combination yet. Try removing a filter.
Not as an object with that name, and we would rather say so than let you find it out on a demo. What exists instead are two routes to the same result, and both end in a list you can filter. With Contract Management each agreement is a contract, so you can pull a list of every agreement, its terms and who it is concluded with. Without Contract Management the agreement is a document on the vendor, and you build the list from your legal entities instead. Either way the agreement exists once, and the list is yours to shape rather than a report we hand you.
You build the list. Every vendor sits in the platform as a legal entity and carries a type, so you pick out the ones marked as data processors and put the agreement next to them. The rows with nothing next to them are the processors nobody has got round to. That is the whole reason to build the list, and it is also why we describe you building it rather than us shipping it, because what belongs in the columns depends on how you have set yourselves up.
Yes, and this is the honest version rather than a sales answer. Upload the agreement as a document on the vendor, under a document type you define yourselves, databehandleraftale. The document is version controlled and can be marked active or not, so the one in force is obvious. A document carries less metadata than a contract does, so the list you build carries fewer details. The function is the same, including pointing at the agreement from an asset or a processing activity.
No. The agreement is registered once and everywhere else points at it. On an asset or a processing activity you reference the agreement as documentation that one exists with that processor, rather than uploading the file again. That is what turns a change into a single edit. Correct the agreement in the place it lives, and every reference to it is current.
You hear it from the processor, usually by email, and then you register the sub-processor on that vendor. At that point the platform asks whether it should carry the new sub-processor across the places you already use that vendor, and it fills them in once you say yes. Nothing is written before you do. We will not go into your documentation on your behalf, and nothing arrives into the platform from the outside, so the platform learns about the change when you tell it.
Keeping your records of processing audit-readyUp to a point, and it is worth knowing where the line runs. Every legal entity carries a complete change history recording what changed, the date and time, who did it, and the value before and after. A processor you stop using is deactivated rather than deleted, so the history stays. Whichever route you took, the agreement itself keeps its versions, so a superseded agreement is still sitting behind the current one. What none of that will tell you is why a particular clause was negotiated the way it was, because that conversation happened outside the platform, and we would rather point at the gap than paper over it.
Yes, with Vendor Management. You design a questionnaire that asks for both answers and specific documents, the agreement among them, and send it to the processor. They open a link in their own inbox, with no account to create and nothing to install, and what they upload lands on that vendor. Basic mapping of which processors you use sits in the Data Protection module. Actively auditing them is the part that needs Vendor Management, and we would rather be clear about that up front than at the end of a demo.
Running due diligence on your vendorsWith the Document Search and OCR add-on, yes. Scans, photographed documents and images with text in them are read on upload so they can be searched alongside documents that already carry a text layer, and a result shows the version, where the document sits, the matching passage and the page number. Two caveats worth having before you plan around it. It is a paid add-on rather than something every environment has, and a result expands to the first ten matches in a document before you have to open the file itself.
Not as a bulk upload, and we would rather say that than let you plan around it. Agreements go in one at a time. What we can do instead is load in whatever you can pull out in a spreadsheet, as part of getting you started, rather than leaving you to type it all in yourselves. Raise it when you book the demo, because how much there is to move changes the answer.
If the agreement is a contract, yes. Every contract can carry an end date and a notification a chosen amount of time before it, sent by email to the person who manages the contract, and that expiry notice is built into contracts and switched on per contract. Duties you define yourselves, an annual supervision of the processor for instance, are the Obligations add-on, and each one becomes a task with a deadline for a named colleague. Nothing starts a clock from something a processor sends you, because nothing arrives inbound.
Contract management with obligations and renewals
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.