DPA for AI Tools: Checklist for Businesses

Compliance & Data Protection

Image

Dominik Keller

Founder, Kontinent

Cover image with the German headline “Der AVV für KI-Tools, Punkt für Punkt”: checklist (German labels): SERVERSTANDORT, SUBPROZESSOREN, KEIN TRAINING, LÖSCHFRISTEN, VERTRAGSENDE, SCCS, TOMS, MELDEPFLICHT.

A Data Processing Agreement (DPA) is a contract required under Art. 28 GDPR between you and a service provider who processes personal data on your behalf. In the case of AI tools, it is particularly sensitive because your data runs through a model. This checklist shows what you should look out for in the DPA for AI providers before you sign.

A Data Processing Agreement sounds like the kind of document you sign once and then never look at again. With classic SaaS tools, that might be true. With AI tools, this is an expensive mistake – because here, the provider does not just process your data; if in doubt, they run it through a model that was trained somewhere, whose behavior can change, and whose sub-processor chain is often longer than it appears at first glance.

Here is a checklist that you should go through with every AI provider before you sign – for self-assessment or to check off in the next compliance round.

Legally, the DPA is not a nice-to-have: according to Art. 28 GDPR, it is mandatory as soon as a service provider processes personal data on your behalf, and Art. 28 para. 3 prescribes the mandatory content. If it is missing or incomplete, fines of up to 10 million euros or 2% of the global annual turnover are possible (Art. 83 para. 4 GDPR).

Key Takeaways

  • A DPA according to Art. 28 GDPR is mandatory as soon as a service provider processes personal data on your behalf – including with AI tools.

  • Three points are critical with AI: training use, the sub-processor chain, and deletion periods.

  • If a third country is involved, the DPA is not enough: standard contractual clauses and a documented case-by-case assessment are also required.

  • The EDPB clarified in 2024 that a model trained with personal data is not automatically considered anonymous.

The Checklist

  • Is the server location for data processing explicitly mentioned?
    Not "distributed worldwide" or "subject to availability", but a specific country or region. For GDPR purposes, this should be the EU.

  • Are all sub-processors listed?
    An AI Gateway that itself accesses OpenAI, Anthropic, or other model providers automatically has a sub-processor chain. This must be fully and currently documented – not "available upon request".

  • Is there a policy on using your data for model training?
    This is the crucial difference between AI tools and classic software: might your prompts end up in the training dataset of the next model update? A good DPA explicitly excludes this instead of leaving it open.

  • Are retention and deletion periods clearly defined?
    How long are prompts and responses stored, for what purpose, and how are they deleted afterwards? "As needed" is not a deletion period.

  • Is it regulated what happens at the end of the contract?
    Will your data then be deleted or exported? And within what timeframe?

  • Are there Standard Contractual Clauses (SCCs) if sub-processors are located outside the EU?
    If the provider itself is based in the EU but forwards model requests to US providers, SCCs are additionally required for this part of the processing.

  • Are technical and organizational measures (TOMs) documented?
    Encryption, access controls, logging – a reputable DPA refers to a specific TOM document, not to general security promises.

  • Is there a contractual obligation to report data breaches?
    And within what timeframe must the provider inform you if something goes wrong?

Why this is more critical with AI tools than with normal software

The European Data Protection Board explicitly addressed this point in its EDPB, Opinion 28/2024 on AI models: The anonymity of a model trained with personal data is not automatically given, but is always a case-by-case evaluation. For the DPA, this means: The commitment "we do not train on your data" belongs in the contract in writing, not in the product description. Why technical redaction before the model call is the more robust safeguard is shown in Anonymizing personal data.

With a classic accounting tool, it is relatively clear what happens to your data: stored, processed, displayed. With an AI tool, the chain is longer and more confusing. A prompt can run through several systems – gateway, model API, logging and monitoring tools of the provider, if applicable – and at every station, a new question arises: Who is processing what here, and on what legal basis?

This is exactly why it is worth taking a second, closer look at the DPA for AI providers than you might do for a project management tool.

How kontinent.ai solves this

At kontinent.ai, the DPA is not a PDF attached after the fact, but is designed for these questions from the very beginning: EU server location, fully documented sub-processors, no use of your data for model training, clear deletion periods. The goal is for your legal department to be able to go through the checklist above in a single conversation, without you having to clarify open points afterwards.

If the provider processes outside the EU, the third-country regime under Art. 44–49 GDPR also applies. The three practical ways to solve this for OpenAI, Claude, and Gemini are described in Using OpenAI, Claude, and Gemini in Europe – without GDPR risk. How the AI Act affects this in addition is clarified in the AI Act Checklist for Gateways.

Frequently Asked Questions

Do I need a separate DPA for every AI tool?

Yes, for every provider that processes personal data on your behalf, a separate DPA according to Art. 28 GDPR is required.

Is a DPA sufficient if the provider uses servers in the USA?

No, in that case, Standard Contractual Clauses (SCCs) or another recognized transfer mechanism, plus an assessment of the level of protection in the destination country, are additionally required.

What happens if a provider does not offer a DPA?

Then the tool should not be used for processing personal data – this is a clear exclusion criterion, regardless of how good the product is otherwise.

How often should existing DPAs be reviewed?

At least once a year, and additionally whenever the provider's list of sub-processors changes or new features (e.g., new models) are added.

What is legally mandatory in a DPA?

Art. 28 para. 3 GDPR prescribes minimum content: subject matter and duration of processing, nature and purpose, categories of data subjects, obligations and rights of the controller, compliance with instructions, confidentiality, technical and organizational measures, regulations regarding sub-processors, assistance obligations, as well as deletion or return of data after the end of the contract.

Sources

As of: August 27, 2026 · kontinent.ai. Information in accordance with Art. 28 and 83 GDPR; not legal advice.

  • Border Shape
  • Border Shape