Data processing agreements
Every vendor below publishes its own customer DPA — a data processing addendum, in the name many of them use for it. The link goes to the vendor's page, not to a copy of ours, and we open each one every night so a moved page is noticed rather than passed on.
A data processing agreement is the contract Article 28 of the GDPR requires whenever one organisation processes personal data on another's behalf. A data processing addendum is the same document: the two names are used interchangeably, and some vendors publish it as "processor terms" or "customer DPA". Which name is on the page does not change what the document has to contain.
Article 28(3) says it must set out the subject matter and duration of the processing, its nature and purpose, the categories of personal data and of data subjects, and the controller's rights; and it must bind the processor on confidentiality, security, sub-processors, assistance with data-subject requests, deletion at the end, and audits. A vendor's published DPA is the processor's side of that, offered on the same terms to everyone.
Two things it is not. It is not a transfer mechanism: sending personal data outside the EEA needs its own basis, and each vendor page below says which one that vendor relies on. And it is not a list of sub-processors — that is a separate page, which most of these vendors also publish and which changes far more often than the agreement does.
Not publishing one is not a failing: many vendors hand their DPA to a customer on request, or put it behind the contract. We say so rather than link to something that is not the agreement. Their pages carry everything else we hold — the contracting entity, the country, the transfer mechanism.
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.