All services

Embed AI · Zahed Ashkara

Data processing agreement review

A data processing agreement is mandatory as soon as a supplier processes personal data on your behalf (Article 28 GDPR). I review the agreement the supplier proposes, draft your own template or negotiate the terms on your behalf. I compare the contract with the actual data flow, so that roles, responsibilities and liability match what happens in practice.

How I support your team

Roles first

Is the supplier a processor, an independent controller or a joint controller? The facts determine which contract is needed.

Review of supplier terms

Check of the mandatory elements of Article 28 GDPR and of the arrangements on sub-processors, transfers outside the EEA, security, audit, data breaches, retention and exit.

Your own template and negotiation

A data processing agreement or a set of standard terms for your organisation, and support in negotiating with suppliers.

Procurement and AI suppliers

For AI applications, also the arrangements on training data, model use and the provider’s role, in line with the AI supplier check.

How do we start?

  1. 01Discuss the supplier, the data flow and the documents proposed.
  2. 02Agree scope, planning and rate.
  3. 03Review, advise with concrete wording proposals and align with the supplier.

Who you engage

Zahed Ashkara is a legal counsel and freelance AI and privacy consultant, with assignments at Rabobank, Sanoma, drinking water utility PWN, central government and municipalities. Certified AI Compliance Officer and member of the NEN AI & Big Data standards committee.

View my experienceDownload profile (PDF)

Practical privacy and GDPR knowledge hub

Frequently asked questions

Is a data processing agreement always mandatory?

As soon as a party processes personal data on your behalf, yes. If the party processes the data for its own purposes, it is a controller and a different type of arrangement applies.

Can we simply sign the supplier’s standard agreement?

Often largely, but not blindly. Large suppliers offer their terms as a fixed package; the work is then in the additional arrangements and in the internal decisions on residual risk.

What if data is processed outside the EEA?

Then a valid transfer mechanism is required, such as an adequacy decision or standard contractual clauses with a transfer assessment. I assess this as part of the review.

Can you review an entire supplier list?

Yes. We then work with a fixed checklist and a risk-based prioritisation, so the most important suppliers come first.

What does a review cost?

The effort depends on the number of documents and the complexity of the data flow. We discuss the approach and the rate upfront.

Legal source: AVG / GDPR, including Articles 5, 6, 28 and 35.

Discuss your assignment

Include the desired start date, weekly hours and duration if known.