Create your DPA

For businesses, service providers and data protection officers

Create a top-quality data processing agreement (DPA)

An AI guides you in a chat through every relevant aspect of drafting a data processing agreement under Art. 28 GDPR. Developed by IT law specialist Dr. Thomas Helbing.

  • High acceptance among contracting partners: based on the official EU standard contractual clauses
  • With a memo explaining the clauses and next steps
  • Create it for free and see the preview, buy only if you like it
Create your data processing agreement

Free account · no subscription required

A service of matterius GmbH. Not a law firm, no legal advice.

From a chat with the GDPR-Giraffe to the finished contract

Who is behind it

Developed by one of Germany’s leading data protection lawyers

Dr. Thomas Helbing, specialist lawyer for IT law
„As a lawyer, I have worked on hundreds of contracts, concepts and data protection assessments. The same questions, the same pitfalls, again and again. That knowledge now lives in the GDPR-Giraffe: specialist templates, instructions and workflows that you can use yourself, quickly and at a fair price.“

Dr. Thomas Helbing

Specialist lawyer for IT law, Munich

Handelsblatt award “Germany’s Best Lawyers”, 2020–2026Recommended by kanzleimonitor.de 2024/2025: top 100 lawyers in Germany
  • Handelsblatt “Germany’s Best Lawyers”, IT law and data protection law, 2020–2026
  • Kanzleimonitor.de “Leading lawyers for data protection and IT law”, 2024–2026
  • Kanzleimonitor.de “Top 100 lawyers”, 2024/25

The GDPR-Giraffe is a legal tech product of matterius GmbH, Munich. Its content was developed by Dr. Thomas Helbing. matterius GmbH is not a law firm and does not provide legal advice.

How it works

Three steps to your result

  1. Sign up for free

    Create a free account with the GDPR-Giraffe. The matching use case opens right after you sign in.

  2. Answer questions in the chat

    The Giraffe guides you through every relevant point like a conversation. You can upload documents, links and contracts.

  3. See the preview, buy if you like it

    You see the result first as a free, partly redacted preview. Only if it fits do you buy it and download it right away.

Create your data processing agreement

A service of matterius GmbH. Not a law firm, no legal advice.

Price

Pay once, use it for good

Data processing agreement

€149

one-time · net plus VAT

  • DPA with annexes (parties, processing, TOMs, sub-processors)
  • Memo with explanatory notes and next steps
  • No subscription required
  • Free preview before you buy
  • Available immediately after purchase
  • Download as Word (.docx), PDF and Markdown
Create your data processing agreement

A service of matterius GmbH. Not a law firm, no legal advice.

This offer is aimed exclusively at businesses.

Optional: if you want to use the Giraffe regularly for further data protection topics, you can take out a subscription. It is not required for this work result.

FAQ

Frequently asked questions

Create your data processing agreement

A service of matterius GmbH. Not a law firm, no legal advice.

Comparison

What makes the Giraffe different

Contractual basis

Typical generator: Often in-house templates that contracting partners first review and frequently negotiate

GDPR-Giraffe: Official EU standard contractual clauses with considerably higher acceptance than in-house templates, supplemented with fitting additional provisions

Deliverables

Typical generator: Usually just the agreement

GDPR-Giraffe: Agreement plus a comprehensive memo with explanations and next steps

Scope

Typical generator: Usually just a DPA as a single document

GDPR-Giraffe: A comprehensive data protection AI: if you wish, it first checks whether a DPA is needed at all and optionally enables follow-up documents such as a privacy notice or an entry in your records of processing

Foundation

Typical generator: Often a questionnaire that assembles text modules

GDPR-Giraffe: A guided conversation based on more than 100 pages of specialist instructions, templates and workflows

Before you buy

Typical generator: Content often only visible after purchase

GDPR-Giraffe: Free preview, buy only if you like it

Pricing model

Typical generator: Often a subscription model

GDPR-Giraffe: One-time price. Subscription only optional, embedded in a comprehensive data protection tool rather than an isolated generator

Provider and review

Typical generator: Not always clear who the provider is and what review is included

GDPR-Giraffe: Clearly labeled legal tech product. A lawyer’s review is optional and available separately from the HELBING law firm

The comparison describes typical features of common document generators and does not refer to any specific provider.

Create your data processing agreement

A service of matterius GmbH. Not a law firm, no legal advice.

Knowledge

Data processing agreements: what matters in practice

A data processing agreement (DPA) is mandatory as soon as a service provider processes personal data on your behalf and on your instructions, from cloud hosting and payroll to remote maintenance. Here are the key points for controllers and service providers.

When is a DPA required?

What matters is who decides on the purposes and essential means of the processing. If a service provider processes the data only for you and on your instructions, it is a processor (Art. 4(8), Art. 28 GDPR). Typical examples are hosting and SaaS, IT support with data access, payroll, newsletter delivery and document destruction. No DPA is needed if the provider acts on its own responsibility, such as lawyers, banks or postal services. If you determine purposes and means jointly, an arrangement on joint controllership under Art. 26 GDPR is required instead. The benchmark for this distinction is the European Data Protection Board’s (EDPB) Guidelines 07/2020.

Misclassification causes harm in both directions. Without a required DPA, fines are possible and the disclosure to the provider loses its privileged status. A DPA concluded without need suggests a role that does not actually exist. Mixed roles are tricky: if a provider also uses the data for its own purposes, such as benchmarks or product improvement, it is a controller to that extent. Such own use is carved out of the DPA, not “permitted” in it.

Mandatory content under Art. 28(3) GDPR

The agreement sets out the subject matter and duration, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller. In particular, it obliges the processor to:

  • process data only on documented instructions (point a)
  • ensure the confidentiality of the persons involved (point b)
  • take technical and organizational measures under Art. 32 GDPR (point c)
  • respect the conditions for engaging sub-processors (point d)
  • assist with data subject rights, security, breach notifications and data protection impact assessments (points e and f)
  • delete or return the data at the end of the contract (point g)
  • provide evidence and allow audits, including inspections (point h)

The official EU template as a basis

The European Commission has adopted standard contractual clauses for processing within the EU (Implementing Decision (EU) 2021/915, Art. 28(7) GDPR). They cover all mandatory content, are accepted by the supervisory authorities and spare you discussions about the core text. You only add what the template leaves open or what your case requires, such as costs, liability or fixed notification deadlines. These additions must not contradict the clauses.

In practice, the annexes determine the quality. Without a concrete description of the data, purposes, technical and organizational measures and sub-processors, even a complete contract text remains an empty shell.

Form and timing

The DPA must be in writing, which includes electronic form (Art. 28(9) GDPR). A handwritten signature is not required. Providers with high-volume business can incorporate the DPA into their terms, provided customers can take note of it before concluding the contract. For standard contractual clauses for international transfers, however, an express signature is advisable.

Timing is crucial: the agreement must be in place before the first access to the data. Concluding it afterwards does not cure a violation that has already occurred. The range of fines follows Art. 83(4)(a) GDPR.

Who provides the DPA?

The obligation to conclude the agreement applies to controller and provider alike. Usually the provider presents its own template, especially in high-volume business and with large cloud providers that rarely negotiate. Your own draft is still worthwhile as a controller: as a benchmark to spot deviations quickly and as a basis for negotiation. Providers, in turn, benefit from a uniform template they can offer to all customers.

The five negotiation points

Beyond the mandatory content, the parties usually negotiate the same points:

  • Sub-processors: specific authorization or general authorization with a right to object. Under a general authorization, the provider must actively inform about changes and allow a reasonable period. A mere online list without notification is not enough.
  • Audit rights: a tiered approach is permissible, starting with certificates and audit reports, then requests. On-site inspections must not be excluded, however.
  • Costs: whether support services and audits are paid for is negotiable. Cost provisions must not deter audits, though. A free allowance is a common compromise.
  • Liability: limitations of liability are critical from the controller’s perspective, because it is fully answerable to data subjects and authorities and its recourse would be cut short.
  • Notification deadline: the EU template requires personal data breaches to be notified “without undue delay”. A fixed deadline, such as 48 hours, helps the controller meet its own 72-hour deadline under Art. 33 GDPR.

Third countries: USA, Data Privacy Framework and TIA

If a US provider is certified under the EU-US Data Privacy Framework, a DPA based on the EU template is sufficient. It makes sense to add an obligation to maintain the certification and a fallback solution in case the framework ceases to apply. Without certification, and in other third countries without an adequate level of protection, the standard contractual clauses for international transfers are needed in the matching module (Implementing Decision (EU) 2021/914). In addition, a transfer impact assessment (TIA) evaluates the legal situation in the recipient country and must be repeated regularly.

Common mistakes

These weaknesses come up particularly often in practice:

  • Blanket data categories such as “customer data” instead of specific categories with examples
  • Overlooked sensitive data, including data on criminal offenses under Art. 10 GDPR
  • A TOM annex that merely repeats the wording of Art. 32 GDPR
  • Sub-processors listed by brand name instead of full company name, country and service, or a SaaS solution supposedly without any sub-processors
  • Permitting own use by the provider in the DPA instead of carving it out
  • Concluding the agreement only after processing has already started

What the GDPR-Giraffe’s DPA includes

  • Agreement: parties and subject matter, application of the EU standard contractual clauses, sub-processors, breach notification and final provisions, supplemented as you choose with audit rights, international transfers, remuneration and liability
  • Annexes I to IV: list of parties, description of the processing, technical and organizational measures, sub-processors
  • Where a third country is involved: an agreement on the standard contractual clauses for international transfers instead of a separate DPA
  • Internal memo: open points to complete, explanations of the chosen provisions and next steps

Get started

Create your data processing agreement now

Sign up for free, answer the questions, see the preview. You only buy what convinces you.

Create your data processing agreement

A service of matterius GmbH. Not a law firm, no legal advice.