Every data processing agreement, and the ones that are missing

Put every data processor next to its agreement and the gaps stop hiding. Register the agreement once, point at it from the assets and processing activities that rely on it, and change it in one place.

Unlimited users  •  Free onboarding and support  •  No commitment

A row of processor plates each paired with an agreement card, with two of the pairs standing as empty outlined slots so the missing ones are the visible thing
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
A custom list of companies in .legal showing each one's type and the documents held on it, with the document column empty on six of the eight rows so the missing agreements are what stands out

Data processing agreements Sofie can name the processors Meridian has no agreement with

Sofie Bruhn is group DPO at Meridian Nordic, three legal entities and around 1,200 active suppliers and processors between them. The agreements existed. They were just spread across a shared drive, a signing tool and four inboxes, so the question she quietly dreaded was never "show me the agreement with this processor". It was "which processors have we got no agreement with at all". Now every vendor sits in the platform as a legal entity with a type on it, so the data processors line up in one list with their agreements beside them, and the rows that are empty are the work.

  • Every legal entity marked as a data processor, with its agreement next to it, so a gap is a row rather than a suspicion.
  • Two routes to the same result, one for teams who have Contract Management and one for teams who don't.
  • The agreement is registered once, and the assets and processing activities that rely on it point at it.
  • When a processor takes on a new sub-processor, the platform asks before it carries the change across.

  • The gaps are visible

    Line up every legal entity marked as a data processor with its agreement, and the rows with nothing next to them are the ones to chase.

  • Two routes, your choice

    With Contract Management the agreement is a contract with terms on it. Without it, a version-controlled document on the vendor. Same job.

  • Registered once

    The agreement exists in one place and everything else points at it, so a correction is one edit rather than twelve.

  • Sub-processors, on your say-so

    Register a new sub-processor and the platform asks before it carries it across. Nothing is written until you say yes.

A filing rack of processor plates with the agreement slot beside each one, three of the slots drawn as empty outlines

Data processing agreements The list that shows the gaps

An agreement you cannot find is a nuisance. An agreement you never signed is the actual risk, and it is much harder to notice, because nothing in a filing system draws attention to something that isn't there.

  • Every vendor sits in the platform as a legal entity and carries a type, so the data processors can be pulled out from the rest.
  • Put the agreement in the column beside them, and a processor with nothing beside it stops being invisible.
  • Processor and sub-processor roles are tagged automatically from how an entity is linked to your processing activities and assets, so the tagging isn't a separate job.
One master service agreement open in .legal on its documents tab, with the data processing agreement listed among its documents as a signed agreement of its own type, alongside the contract and its appendices

Data processing agreements Route one, the agreement as a contract

If you have Contract Management, each data processing agreement is a contract in its own right. It then inherits everything the contract record already knows how to do.

  • The party on the contract points at the legal entity that is your processor, so the relation reads from either end.
  • Where the agreement was signed as an annex to a larger contract, register it that way instead. Same result.
  • Filter a list of every agreement, its terms and who it is concluded with, then keep the filter and columns as a custom view. Custom views need the Custom Lists add-on.
A vendor's documents tab in .legal holding one data processing agreement, with its document type, its version number and its active marking all visible on the row

Data processing agreements Route two, the agreement as a document on the vendor

No Contract Management, no problem. This is the version we would rather explain properly than sell around, because for a lot of teams it is the right one.

  • Upload the agreement as a document on the vendor under a document type you define, databehandleraftale, where it is version controlled and can be marked active or not.
  • A document carries less metadata than a contract does, so the list you build from it carries fewer details.
  • The function is the same, including referencing the agreement from an asset or a processing activity.
One agreement card at the centre with thin lines running out to several assets and processing activities, each holding a pointer rather than a copy

Data processing agreements Registered once, referenced everywhere

Whichever route you take, the agreement exists in one place. Everything that depends on it points at it instead of holding a copy of its own.

  • On an asset or a processing activity you point at the agreement as documentation that one exists with that processor.
  • Change it where it lives and every reference is current, which turns a renegotiated agreement into one edit rather than an afternoon.
  • Every change to a legal entity is logged with the date, the time, the user, and the value before and after.
The sub-processor step on a vendor in .legal, listing one registered sub-processor with its address, above the setting that governs whether sub-processors are carried across to the processing activities the vendor is used in

Data processing agreements When a processor takes on a new sub-processor

This is the event that quietly makes an agreement wrong. It arrives as an email from your processor, and it is worth being honest that it doesn't arrive as a signal from us.

  • Register the new sub-processor on the vendor once, and the platform asks whether it should carry it across the places you already use that vendor.
  • Say yes and those places are filled in. Say nothing and nothing moves, because we won't edit your documentation on your behalf.
  • Nothing comes into the platform from outside, so it knows what a processor has changed only when you tell it.
An open frame with the rails built and the panels absent, and one figure standing beside it holding a document it has written itself

Data processing agreements Rails, not the agreement itself

We build the plan, not the filling-in. Three boundaries are worth saying out loud before anyone books a demo.

  • We don't write your data processing agreement, and we don't judge whether the one you have is good enough. That is your call and your adviser's.
  • There is no object in the platform called a register of agreements. What there is, is a list you build from data you already keep.
  • Agreements go in one at a time. There is no bulk upload, though we can load in whatever you can pull out in a spreadsheet when you start.
.legal in practice

Features for data processing agreements

The list that shows the gaps

Every vendor is a legal entity with a type, so you can pick out the data processors and put the agreement beside them. A processor with nothing beside it stands out instead of hiding.

The agreement as a contract

With Contract Management each agreement is a contract, with the party pointing at the legal entity that is your processor, or an annex on the main contract. Then filter every agreement, its terms and who it is with.

The agreement as a document

Without Contract Management the agreement is a document on the vendor under a document type you define, databehandleraftale, version controlled and marked active or not. Fewer details on the list, same job done.

Referenced, not copied

On an asset or a processing activity you point at the agreement as documentation that one exists with that processor, so a change made centrally reaches every place that relies on it.

Sub-processors applied on approval

Register a new sub-processor on the vendor and the platform asks whether to carry it across the places you already use that vendor. Processor and sub-processor roles are tagged automatically from how the entity is linked.

A change history on the counterparty

Every change to a legal entity is recorded with the date, the time, the user and the value before and after, and a processor you stop using is deactivated rather than deleted so the history survives.

Data processing agreements Frameworks this covers

One obligation, and the paperwork it actually asks for.

  • icon-framework-GDPR

    GDPR

    Article 28 is the obligation this page is about: an agreement with every processor you use, the sub-processors they bring with them, and being able to show both without a week's notice.

    Read about GDPR
.legal compliance platform

Get on top of your data processing agreements with...

Do you need every processor lined up next to its agreement? We recommend the following modules for that task.

GDPR / Data Protection

Where processing activities, assets, legal entities and documents live, so the agreement sits next to the processing it actually covers.

Explore GDPR

Contract Management

Route one. The agreement as a contract, with parties, terms, documents, versions and a list you can filter.

Explore Contract Management

Vendor Management

Ask a processor for the agreement without giving them a login, and run the supervision that follows.

Explore Vendor Management

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
Use cases

Find the job you need done

Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.

Book demo

12 use cases

Compliance & GRC lead

Run awareness training that reaches every colleague

Send out training and policies, chase the stragglers automatically, and prove every colleague completed it. You bring the material, we run the rails.
See awareness training
Compliance & GRC lead

Manage compliance across a group of companies

Run every company in the group from one platform, document once at group level, and still report entity by entity. Delivered by the Group Companies add-on.
See group compliance
Legal counsel

Run due diligence on your vendors

Classify a vendor on your own criteria, get the answers and documents you need with no login for them, and move the approved ones straight into contracts.
See vendor due diligence
Compliance & GRC lead

Multi-framework compliance: do the work once

Do a control once and it counts across every framework it maps to, with a simulated score on the ones you haven't started yet.
See multi-framework compliance
CISO & IT security

Get NIS2-ready without starting from scratch

Build on the ISO 27001 work you've already done, switch NIS2 on, and let a simulated score show how far ahead you already are.
See NIS2 readiness
DPO

From twelve spreadsheets to one record of processing

Your GDPR documentation already exists, it just lives in spreadsheets. Export what you have and we structure it in .legal for you, typically inside two weeks.
See the move off spreadsheets
Compliance & GRC lead

Build one risk register for the whole organisation

One register across GDPR, NIS2, AI and information security, where each risk area keeps its own matrix, scale and appetite. Delivered by the Enterprise Risk Management add-on.
See the risk register
Executive & board

Give the board a risk picture it can act on

One management report across every risk area: entities assessed, risks above appetite, exposure now and once the open plans are done. Export it with your own comment on it.
See board risk reporting

Frequently Asked Questions about data processing agreements

Is there a data processing agreement register in .legal?

Not as an object with that name, and we would rather say so than let you find it out on a demo. What exists instead are two routes to the same result, and both end in a list you can filter. With Contract Management each agreement is a contract, so you can pull a list of every agreement, its terms and who it is concluded with. Without Contract Management the agreement is a document on the vendor, and you build the list from your legal entities instead. Either way the agreement exists once, and the list is yours to shape rather than a report we hand you.

How do we see which data processors we have no agreement with?

You build the list. Every vendor sits in the platform as a legal entity and carries a type, so you pick out the ones marked as data processors and put the agreement next to them. The rows with nothing next to them are the processors nobody has got round to. That is the whole reason to build the list, and it is also why we describe you building it rather than us shipping it, because what belongs in the columns depends on how you have set yourselves up.

We do not have Contract Management. Can we still do this?

Yes, and this is the honest version rather than a sales answer. Upload the agreement as a document on the vendor, under a document type you define yourselves, databehandleraftale. The document is version controlled and can be marked active or not, so the one in force is obvious. A document carries less metadata than a contract does, so the list you build carries fewer details. The function is the same, including pointing at the agreement from an asset or a processing activity.

Do we have to attach the agreement to every processing activity that uses that processor?

No. The agreement is registered once and everywhere else points at it. On an asset or a processing activity you reference the agreement as documentation that one exists with that processor, rather than uploading the file again. That is what turns a change into a single edit. Correct the agreement in the place it lives, and every reference to it is current.

What happens when a processor takes on a new sub-processor?

You hear it from the processor, usually by email, and then you register the sub-processor on that vendor. At that point the platform asks whether it should carry the new sub-processor across the places you already use that vendor, and it fills them in once you say yes. Nothing is written before you do. We will not go into your documentation on your behalf, and nothing arrives into the platform from the outside, so the platform learns about the change when you tell it.

Keeping your records of processing audit-ready

Can we show an auditor how an agreement came to say what it says?

Up to a point, and it is worth knowing where the line runs. Every legal entity carries a complete change history recording what changed, the date and time, who did it, and the value before and after. A processor you stop using is deactivated rather than deleted, so the history stays. Whichever route you took, the agreement itself keeps its versions, so a superseded agreement is still sitting behind the current one. What none of that will tell you is why a particular clause was negotiated the way it was, because that conversation happened outside the platform, and we would rather point at the gap than paper over it.

Can we ask a processor for the agreement through the platform?

Yes, with Vendor Management. You design a questionnaire that asks for both answers and specific documents, the agreement among them, and send it to the processor. They open a link in their own inbox, with no account to create and nothing to install, and what they upload lands on that vendor. Basic mapping of which processors you use sits in the Data Protection module. Actively auditing them is the part that needs Vendor Management, and we would rather be clear about that up front than at the end of a demo.

Running due diligence on your vendors

Can we search inside a scanned agreement?

With the Document Search and OCR add-on, yes. Scans, photographed documents and images with text in them are read on upload so they can be searched alongside documents that already carry a text layer, and a result shows the version, where the document sits, the matching passage and the page number. Two caveats worth having before you plan around it. It is a paid add-on rather than something every environment has, and a result expands to the first ten matches in a document before you have to open the file itself.

Can we load our whole archive of agreements in at once?

Not as a bulk upload, and we would rather say that than let you plan around it. Agreements go in one at a time. What we can do instead is load in whatever you can pull out in a spreadsheet, as part of getting you started, rather than leaving you to type it all in yourselves. Raise it when you book the demo, because how much there is to move changes the answer.

Does the platform tell us when an agreement is coming up for renewal?

If the agreement is a contract, yes. Every contract can carry an end date and a notification a chosen amount of time before it, sent by email to the person who manages the contract, and that expiry notice is built into contracts and switched on per contract. Duties you define yourselves, an annual supervision of the processor for instance, are the Obligations add-on, and each one becomes a task with a deadline for a named colleague. Nothing starts a clock from something a processor sends you, because nothing arrives inbound.

Contract management with obligations and renewals

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell