For businesses, service providers and data protection officers
Create a top-quality data processing agreement (DPA)
An AI guides you in a chat through every relevant aspect of drafting a data processing agreement under Art. 28 GDPR. Developed by IT law specialist Dr. Thomas Helbing.
- High acceptance among contracting partners: based on the official EU standard contractual clauses
- With a memo explaining the clauses and next steps
- Create it for free and see the preview, buy only if you like it
Free account · no subscription required
A service of matterius GmbH. Not a law firm, no legal advice.

Who is behind it
Developed by one of Germany’s leading data protection lawyers

„As a lawyer, I have worked on hundreds of contracts, concepts and data protection assessments. The same questions, the same pitfalls, again and again. That knowledge now lives in the GDPR-Giraffe: specialist templates, instructions and workflows that you can use yourself, quickly and at a fair price.“
Dr. Thomas Helbing
Specialist lawyer for IT law, Munich


- Handelsblatt “Germany’s Best Lawyers”, IT law and data protection law, 2020–2026
- Kanzleimonitor.de “Leading lawyers for data protection and IT law”, 2024–2026
- Kanzleimonitor.de “Top 100 lawyers”, 2024/25
The GDPR-Giraffe is a legal tech product of matterius GmbH, Munich. Its content was developed by Dr. Thomas Helbing. matterius GmbH is not a law firm and does not provide legal advice.
How it works
Three steps to your result
Sign up for free
Create a free account with the GDPR-Giraffe. The matching use case opens right after you sign in.
Answer questions in the chat
The Giraffe guides you through every relevant point like a conversation. You can upload documents, links and contracts.
See the preview, buy if you like it
You see the result first as a free, partly redacted preview. Only if it fits do you buy it and download it right away.
A service of matterius GmbH. Not a law firm, no legal advice.
Price
Pay once, use it for good
Data processing agreement
€149
one-time · net plus VAT
- DPA with annexes (parties, processing, TOMs, sub-processors)
- Memo with explanatory notes and next steps
- No subscription required
- Free preview before you buy
- Available immediately after purchase
- Download as Word (.docx), PDF and Markdown
A service of matterius GmbH. Not a law firm, no legal advice.
This offer is aimed exclusively at businesses.
Optional: if you want to use the Giraffe regularly for further data protection topics, you can take out a subscription. It is not required for this work result.
FAQ
Frequently asked questions
A service of matterius GmbH. Not a law firm, no legal advice.
Comparison
What makes the Giraffe different
Contractual basis
Typical generator: Often in-house templates that contracting partners first review and frequently negotiate
GDPR-Giraffe: Official EU standard contractual clauses with considerably higher acceptance than in-house templates, supplemented with fitting additional provisions
Deliverables
Typical generator: Usually just the agreement
GDPR-Giraffe: Agreement plus a comprehensive memo with explanations and next steps
Scope
Typical generator: Usually just a DPA as a single document
GDPR-Giraffe: A comprehensive data protection AI: if you wish, it first checks whether a DPA is needed at all and optionally enables follow-up documents such as a privacy notice or an entry in your records of processing
Foundation
Typical generator: Often a questionnaire that assembles text modules
GDPR-Giraffe: A guided conversation based on more than 100 pages of specialist instructions, templates and workflows
Before you buy
Typical generator: Content often only visible after purchase
GDPR-Giraffe: Free preview, buy only if you like it
Pricing model
Typical generator: Often a subscription model
GDPR-Giraffe: One-time price. Subscription only optional, embedded in a comprehensive data protection tool rather than an isolated generator
Provider and review
Typical generator: Not always clear who the provider is and what review is included
GDPR-Giraffe: Clearly labeled legal tech product. A lawyer’s review is optional and available separately from the HELBING law firm
The comparison describes typical features of common document generators and does not refer to any specific provider.
A service of matterius GmbH. Not a law firm, no legal advice.
Knowledge
Data processing agreements: what matters in practice
A data processing agreement (DPA) is mandatory as soon as a service provider processes personal data on your behalf and on your instructions, from cloud hosting and payroll to remote maintenance. Here are the key points for controllers and service providers.
When is a DPA required?
What matters is who decides on the purposes and essential means of the processing. If a service provider processes the data only for you and on your instructions, it is a processor (Art. 4(8), Art. 28 GDPR). Typical examples are hosting and SaaS, IT support with data access, payroll, newsletter delivery and document destruction. No DPA is needed if the provider acts on its own responsibility, such as lawyers, banks or postal services. If you determine purposes and means jointly, an arrangement on joint controllership under Art. 26 GDPR is required instead. The benchmark for this distinction is the European Data Protection Board’s (EDPB) Guidelines 07/2020.
Misclassification causes harm in both directions. Without a required DPA, fines are possible and the disclosure to the provider loses its privileged status. A DPA concluded without need suggests a role that does not actually exist. Mixed roles are tricky: if a provider also uses the data for its own purposes, such as benchmarks or product improvement, it is a controller to that extent. Such own use is carved out of the DPA, not “permitted” in it.
Mandatory content under Art. 28(3) GDPR
The agreement sets out the subject matter and duration, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller. In particular, it obliges the processor to:
- process data only on documented instructions (point a)
- ensure the confidentiality of the persons involved (point b)
- take technical and organizational measures under Art. 32 GDPR (point c)
- respect the conditions for engaging sub-processors (point d)
- assist with data subject rights, security, breach notifications and data protection impact assessments (points e and f)
- delete or return the data at the end of the contract (point g)
- provide evidence and allow audits, including inspections (point h)
The official EU template as a basis
The European Commission has adopted standard contractual clauses for processing within the EU (Implementing Decision (EU) 2021/915, Art. 28(7) GDPR). They cover all mandatory content, are accepted by the supervisory authorities and spare you discussions about the core text. You only add what the template leaves open or what your case requires, such as costs, liability or fixed notification deadlines. These additions must not contradict the clauses.
In practice, the annexes determine the quality. Without a concrete description of the data, purposes, technical and organizational measures and sub-processors, even a complete contract text remains an empty shell.
Form and timing
The DPA must be in writing, which includes electronic form (Art. 28(9) GDPR). A handwritten signature is not required. Providers with high-volume business can incorporate the DPA into their terms, provided customers can take note of it before concluding the contract. For standard contractual clauses for international transfers, however, an express signature is advisable.
Timing is crucial: the agreement must be in place before the first access to the data. Concluding it afterwards does not cure a violation that has already occurred. The range of fines follows Art. 83(4)(a) GDPR.
Who provides the DPA?
The obligation to conclude the agreement applies to controller and provider alike. Usually the provider presents its own template, especially in high-volume business and with large cloud providers that rarely negotiate. Your own draft is still worthwhile as a controller: as a benchmark to spot deviations quickly and as a basis for negotiation. Providers, in turn, benefit from a uniform template they can offer to all customers.
The five negotiation points
Beyond the mandatory content, the parties usually negotiate the same points:
- Sub-processors: specific authorization or general authorization with a right to object. Under a general authorization, the provider must actively inform about changes and allow a reasonable period. A mere online list without notification is not enough.
- Audit rights: a tiered approach is permissible, starting with certificates and audit reports, then requests. On-site inspections must not be excluded, however.
- Costs: whether support services and audits are paid for is negotiable. Cost provisions must not deter audits, though. A free allowance is a common compromise.
- Liability: limitations of liability are critical from the controller’s perspective, because it is fully answerable to data subjects and authorities and its recourse would be cut short.
- Notification deadline: the EU template requires personal data breaches to be notified “without undue delay”. A fixed deadline, such as 48 hours, helps the controller meet its own 72-hour deadline under Art. 33 GDPR.
Third countries: USA, Data Privacy Framework and TIA
If a US provider is certified under the EU-US Data Privacy Framework, a DPA based on the EU template is sufficient. It makes sense to add an obligation to maintain the certification and a fallback solution in case the framework ceases to apply. Without certification, and in other third countries without an adequate level of protection, the standard contractual clauses for international transfers are needed in the matching module (Implementing Decision (EU) 2021/914). In addition, a transfer impact assessment (TIA) evaluates the legal situation in the recipient country and must be repeated regularly.
Common mistakes
These weaknesses come up particularly often in practice:
- Blanket data categories such as “customer data” instead of specific categories with examples
- Overlooked sensitive data, including data on criminal offenses under Art. 10 GDPR
- A TOM annex that merely repeats the wording of Art. 32 GDPR
- Sub-processors listed by brand name instead of full company name, country and service, or a SaaS solution supposedly without any sub-processors
- Permitting own use by the provider in the DPA instead of carving it out
- Concluding the agreement only after processing has already started
What the GDPR-Giraffe’s DPA includes
- Agreement: parties and subject matter, application of the EU standard contractual clauses, sub-processors, breach notification and final provisions, supplemented as you choose with audit rights, international transfers, remuneration and liability
- Annexes I to IV: list of parties, description of the processing, technical and organizational measures, sub-processors
- Where a third country is involved: an agreement on the standard contractual clauses for international transfers instead of a separate DPA
- Internal memo: open points to complete, explanations of the chosen provisions and next steps
Get started
Create your data processing agreement now
Sign up for free, answer the questions, see the preview. You only buy what convinces you.
Create your data processing agreementA service of matterius GmbH. Not a law firm, no legal advice.