A DPA (Data Processing Agreement) is the processor contract required by Article 28 GDPR. It binds the controller (the client) and the processor (the SaaS) and must contain 8 mandatory clauses. Sub-processing (LLM providers) requires prior authorisation and publication of the sub-processor list (Article 28(4)).
Legal basis
The DPA (Data Processing Agreement) is required by Article 28 GDPR. It is mandatory as soon as a processor handles personal data on behalf of a controller. Without a signed DPA, the processing is unlawful.
8 mandatory clauses (Article 28(3))
- Subject matter and duration of the processing
- Nature and purpose of the processing
- Type of personal data
- Categories of data subjects
- Obligations and rights of the controller
- Documented instructions from the controller to the processor
- Confidentiality undertaking by staff
- Technical and organisational measures (Article 32)
Sub-processing (Article 28(4))
When a processor engages another processor (sub-processor), it must:
- Obtain the controller's prior authorisation (general or specific).
- Publish the list of sub-processors (at minimum: name, role, location).
- Notify any addition or removal of a sub-processor, with reasonable time to object.
- Flow down the same contractual obligations to sub-processors.
GEO/AEO tools — concrete case
Every GEO/AEO tool calls LLMs through an aggregator (OpenRouter) or directly via OpenAI, Anthropic, Google. These vendors are sub-processors. The DPA must list precisely:
- The aggregator's role (transit, no training, no persistent logs).
- Each LLM provider involved, its jurisdiction and CLOUD Act status.
- Filtering options (e.g. exclude non-EU judges for regulated sectors).
Best practices
- Signed DPA downloadable directly from the customer account (not "on request" by email).
- Public list of sub-processors accessible without authentication.
- Automatic email notification before any change.
- Time-stamped versions accessible after the fact.
AI Labs Audit case
AI Labs Audit provides a signed DPA downloadable from the client area, a public list of its processors (OVH SAS, OpenRouter, email providers) and automatic notification on any change. See GDPR and AI compliance and CLOUD Act.
Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.