This base does not vary from one supplier to another: it is the law which sets it, not a commercial policy. What varies is the level of precision with which each clause is fulfilled: a quantified or vague notification period, subcontractors named or passed over in silence. This guide details each mandatory clause, with Aurabase's public DPA as a concrete example, and draws on our GDPR and EU sovereignty guide for the broader legal framework.
The essentials
- A DPA is mandatory as soon as personal data processing exists (Art. 28 GDPR), regardless of the price level subscribed.
- Eight clauses are set by the law itself (Art. 28 §3): documented instructions, confidentiality, security, subcontractors, assistance with rights, security assistance, fate of data at the end of the contract, right to audit.
- The GDPR does not impose any numerical deadline for the notification of a violation by the subcontractor to the controller (“without undue delay”): a serious DPA adds a precise figure.
- The list of sub-processors must be named, with notice of change and a right to object, not a vague “our partners” type of formula.
- The Aurabase DPA can be signed in one click from the Studio (Pro plan); Self-service PDF export is not yet available at the time of writing.
What is a DPA, and when does it become mandatory?
A DPA is the contract which legally governs a supplier acting as a subcontractor of personal data, within the meaning ofarticle 28 of the GDPR. It becomes mandatory as soon as a data controller, you or your company, entrusts the processing of personal data to a third party. This is systematically the case with a backend as a service: user accounts, emails, IP addresses, application content all pass through its infrastructure.
The DPA is not the general conditions of use. The T&Cs cover the general commercial relationship: invoicing, ownership of content, termination. The DPA specifically covers the processing of personal data, with clauses set by law and non-negotiable in principle. Their precise wording may vary from one supplier to another. A supplier who only offers CGU, without a separate DPA, does not meet the requirement of Article 28.
The eight clauses that a backend DPA must contain
Article 28 §3 of the GDPR sets eight obligations that the contract must impose on the subcontractor, from the documented instruction to the right of audit of the manager. These eight clauses come from the regulatory text itself. A supplier cannot remove them or replace them with something vaguer.
(a)Processing on documented instruction
The processor only processes the data on the written instructions of the controller, including for transfer to a third country without an adequacy decision.
(b)Staff confidentiality
The persons authorized to process the data undertake contractually to confidentiality.
(c)Security measures (Art. 32)
Encryption, access control, regular tests: technical and organizational measures appropriate to the risk of processing.
(d)Subprocessors
Prior authorization, general or specific, and notification of any change with the manager's right to object.
(e)Assistance to people’s rights
The processor helps the controller respond to requests for access, rectification, erasure and portability.
(f)Security assistance and notification
Assistance with violation notification, impact analysis and prior consultation with the authority if necessary.
(g) Disposition of data at end of contract
Deletion or restitution of all data at the discretion of the person responsible, unless there is a legal retention obligation.
(h) Audit right of the manager
Provision of the information necessary to demonstrate compliance, with the subcontractor's right to audit.
What distinguishes a truly functioning DPA from a copy-pasted model without adaptation is the precision with which each clause is completed, not their simple presence in the summary of the document.
Why the list of subcontractors must be named, not generic
Obligation (d) requires a named list of sub-processors, not a generic formula such as “our technical partners”. The data controller must be able to identify each third party who touches their data, their precise function and their location.
The Aurabase public DPA lists, for example, six named subcontractors, classified by function. Infrastructure hosting brings together Scaleway and Hetzner, two EU-based providers, with Mollie (Netherlands) for payment. The authentication SMS goes through Twilio (Ireland), push notifications through Apple and Google, and TLS certificates through Let’s Encrypt. Any change of subcontractor is subject to 30 days' notice with the right to object, as documented on the page.
At the time of writing, the production infrastructure verified in Aurabase code remains hosted at Hetzner (Germany, Finland). The list of subcontractors of a DPA can change between two versions. Always check the date of the version in force before citing it in your own processing register (Art. 30 GDPR), regardless of the provider evaluated.
When a sub-processor processes data outside the EU, the DPA must reference a recognized transfer guarantee, most often the standard contractual clauses adopted by the European Commission (decision 2021/914). The nationality of the company that hosts or processes your data also matters, regardless of the region chosen, see our article on the nationality of the provider and the CLOUD Act.
How the DPA should cover the rights of data subjects
Obligation (e) requires the subcontractor to assist the controller in responding to requests from data subjects: access, rectification, erasure, portability, opposition, limitation. In practice, this assistance is measured by two concrete things: a documented contact channel, and a quantified response time.
The GDPR sets this deadline at one month for the data controller, extendable by two months for complex requests (Art. 12 GDPR). The Aurabase DPA uses this same deadline, approximately 30 days, for any request addressed to privacy@aurabase.cloud. A machine-readable export remains available via the CLI command aura export --user <email> --format jsonl, for access and portability requests.
A structured export (JSON, CSV) counts as portability within the meaning of Article 20 of the GDPR. An unstructured PDF export is generally not sufficient to fulfill this obligation.
The notification period: what the law requires, what a serious DPA adds
The GDPR distinguishes two notification obligations, often confused. The data controller must notify the supervisory authority (the CNIL in France) within 72 hours of becoming aware of a violation likely to create a risk for individuals (Art. 33 §1). The subcontractor must notify the person responsible “without undue delay” (Art. 33 §2): the law does not set any precise figure for this second deadline.
This is where a serious DPA adds precision that the law alone does not provide. The Aurabase DPA commits to a maximum period of 48 hours to notify the person responsible, with a detailed incident report within five working days. A DPA that does not quantify any deadline transfers a risk of reactivity that the manager cannot control himself.
What should the DPA provide for the fate of the data at the end of the contract?
Obligation (g) requires the deletion or restitution of all personal data at the end of the contract, at the choice of the person responsible, with destruction of existing copies unless there is a legal retention obligation. This clause must specify a concrete deadline, not just the principle.
| Category | Data concerned | Duration |
|---|---|---|
| Application content | Any data stored in the project's Postgres tables | Project duration + 30 days after deletion |
| Files | Binary objects in storage buckets | Project duration + 30 days |
| Billing | Name, address, VAT number, history | 10 years (legal obligation) |
Precise durations, rather than a “within a reasonable time” type formula, are what you should look for in a supplier’s DPA before signing. An unquantified duration complicates your own proof of compliance in the event of an inspection.
Checklist before signing a DPA with a backend as a service
This checklist concerns the content of the DPA itself. For the broader selection of a compliant backend provider (hosting, parent company, security), see our complete GDPR compliance checklist for a BaaS.
- Are all eight clauses of Article 28 §3 present, or do some refer to a third-party document that cannot be found?
- Are sub-processors named individually, with their function and location?
- Is the breach notification timeframe measured in hours, or does it remain “as soon as possible”?
- Does the fate of the data at the end of the contract specify an exact duration of deletion, not just the principle?
- Does the DPA reference standard contractual clauses for any transfer outside the EU identified in the list of subcontractors?
- Is the document dated, with a visible last update date?
FAQs
The DPA is just one piece of a backend’s GDPR compliance. The complete checklist, which also covers hosting, parent company and security posture, is detailed in our GDPR compliance checklist for a BaaS.