Free template

DPA checklist

A procurement-oriented DPA review checklist for controller/processor details, subprocessors, safeguards, and audit rights.

  • Annex I: parties, processing purpose, data subjects, data categories
  • Annex II: technical and organizational measures
  • Annex III: subprocessors and international transfers
  • Audit rights: evidence review, request process, and response expectations
  • Last reviewed date: keep legal surfaces current

Use this as a starting point

This page is an educational checklist/template, not legal advice. PrivaBase helps turn the checklist into cited evidence, reusable answers, and a buyer-ready packet.