Gixo Lex · deterministic analysis
DPA Article 28 Check
A DPA agreement check for the ten GDPR Article 28 topics; never emits a legal verdict.
What a DPA agreement must contain under GDPR Article 28
A data processing agreement is the contract a controller puts in place before a processor touches personal data, and Article 28(3) names the terms it has to carry. This checker looks for all ten in a pasted draft and tells you which ones it could not find:
- Documented instructions — the processor acts only on the controller's written instructions
- Confidentiality — everyone with access is under a duty of confidence
- Security measures — the Article 32 technical and organisational measures
- Subprocessors — authorisation, and flow-down of the same obligations
- Data-subject requests — assistance with access, erasure and the other rights
- Breach assistance — help meeting personal data breach notification duties
- DPIA assistance — help with data protection impact assessments
- Deletion or return — what happens to the data when the service ends
- Audit information — information and audits to demonstrate compliance
- International transfers — the transfer mechanism, e.g. standard contractual clauses
It reports how many of the ten it detected and lists the rest as not detected. Matching is literal, so a clause that covers a topic in wording the checker does not hold will read as missing — treat a "not detected" line as a prompt to look, not as a finding that the clause is absent.
Input
Details
How DPA Article 28 Check works
See what the tool accepts, what it checks, how to read the result, and where human review still matters.| Topic | Details | What to know |
|---|---|---|
| Input | Text input capped at 150,000 characters | The public endpoint rejects input outside its documented bound. |
| Processing | Deterministic rules; no AI model call | The same input and rules produce the same analysis. |
| Output | Complete analysis or attributed portable output | The free result is returned on the page rather than hidden behind an account. |
| Storage | Nothing stored | The submitted material is processed for the request only. |
What is a DPA agreement?
A data processing agreement — the contract required by GDPR Article 28 whenever a controller has a processor handle personal data on its behalf. It fixes the scope and purpose of the processing and binds the processor to the ten terms Article 28(3) lists, from documented instructions through to deletion or return of the data.
Is a DPA legally required?
Under the GDPR, yes: Article 28(3) requires a contract or other binding legal act wherever processing is carried out by a processor for a controller. This tool checks a draft for those topics; it does not tell you whether your agreement is adequate, and it is not legal advice.
Do I need an account to use DPA Article 28 Check?
No. The public tool runs without an account.
Does this tool call an AI model?
No. It applies deterministic parsing and validation rules.
Is my input stored?
No. The public tool does not save the submitted input.
What does the paid product add?
Lex turns the missing topics into a reviewable compliance working paper, evidence matrix, checklist, or policy draft while keeping the legal conclusion with the reviewer.