DPA Generator
Genera un Data Processing Agreement conforme GDPR per i tuoi sub-processori.
Parti e Configurazione
Titolare del Trattamento (Controller)
Responsabile del Trattamento (Processor)
Trattamento
Tipologie di Dati Trattati
Misure di Sicurezza
Sub-Processori
Formato Output
DPA Generato
# Data Processing Agreement (DPA) **Redatto il:** 04 agosto 2026 ## Parti **TITOLARE DEL TRATTAMENTO (Controller):** [Nome Titolare] Indirizzo: [Indirizzo Titolare] Email: [email@titolare.com] **RESPONSABILE DEL TRATTAMENTO (Processor):** [Nome Responsabile] Indirizzo: [Indirizzo Responsabile] Email: [email@responsabile.com] --- ## 1. Oggetto e Finalita' del Trattamento Il presente Accordo disciplina il trattamento dei dati personali effettuato dal Responsabile per conto del Titolare, ai sensi dell'Art. 28 del Regolamento (UE) 2016/679 (GDPR). **Finalita' del trattamento:** [Descrizione finalita' del trattamento] ## 2. Tipologie di Dati Trattati - Dati anagrafici (nome, cognome) - Indirizzi email - Dati di accesso e log di sistema ## 3. Obblighi del Responsabile del Trattamento Il Responsabile si impegna a: - Trattare i dati personali esclusivamente sulla base delle istruzioni documentate del Titolare - Garantire che le persone autorizzate al trattamento abbiano assunto impegni di riservatezza - Adottare tutte le misure di sicurezza richieste ai sensi dell'Art. 32 GDPR - Non ricorrere a sub-responsabili senza previa autorizzazione scritta del Titolare - Assistere il Titolare nel garantire il rispetto degli obblighi di cui agli Artt. 32-36 GDPR - Cancellare o restituire tutti i dati personali al termine della prestazione dei servizi - Mettere a disposizione del Titolare tutte le informazioni necessarie per dimostrare il rispetto degli obblighi ## 4. Misure di Sicurezza (Art. 32 GDPR) Il Responsabile adotta le seguenti misure tecniche e organizzative: - Cifratura dei dati in transito (TLS 1.2+) - Cifratura dei dati a riposo (AES-256) - Controllo degli accessi basato su ruoli (RBAC) - Log e audit trail degli accessi - Backup regolari con test di ripristino - Vulnerability assessment periodico ## 5. Sub-Responsabili Autorizzati - Nessun sub-processore autorizzato Il Titolare autorizza il ricorso ai sub-responsabili elencati. Il Responsabile dovra' notificare eventuali modifiche (aggiunte o sostituzioni) con almeno 30 giorni di preavviso. ## 6. Notifica delle Violazioni dei Dati Il Responsabile notifichera' al Titolare qualsiasi violazione dei dati personali entro **72 ore** dalla sua scoperta, fornendo tutte le informazioni necessarie ai sensi dell'Art. 33 GDPR. ## 7. Diritti degli Interessati Il Responsabile assistera' il Titolare nell'evadere le richieste degli interessati (accesso, rettifica, cancellazione, portabilita', opposizione), compatibilmente con la natura del trattamento e nei tempi concordati. ## 8. Audit e Ispezioni Il Titolare ha il diritto di effettuare audit (o far effettuare audit da un revisore indipendente) per verificare il rispetto del presente Accordo, previo ragionevole preavviso e senza causare indebite interruzioni all'attivita' del Responsabile. ## 9. Durata e Cessazione Il presente Accordo ha la stessa durata del contratto di servizio principale tra le Parti. Alla cessazione, il Responsabile procedera' alla cancellazione sicura di tutti i dati personali trattati, salvo diversi obblighi di legge. ## 10. Legge Applicabile Il presente Accordo e' regolato dal Regolamento (UE) 2016/679 (GDPR) e dalla legge italiana. --- **Firma Titolare:** _________________________ Data: _____________ **Firma Responsabile:** _________________________ Data: _____________
Come utilizzare DPA Generator
Insert title and data protection officer
Fill in the Owner's name, address and email (who collects the data), and the Responsible person's details (who handles the data on behalf of the Owner, e.g., a SaaS provider).
Describe outcome, treated data and security measures
Indicate the end of treatment, add or modify data types involved and technical/organizational security measures (pre-filled lists that can be modified line by line).
Configure sub-respondents and notification breach times
List and authorize any secondary responsible parties (e.g., cloud providers), and set the time frame within which the Responsible must notify the Owner of a data breach.
Choose format and download document
Choose between Markdown or HTML output, preview generated content in real-time, then copy the text or download the ready-to-sign file.
Suggerimenti
- Customize your security list regularly to only include measures that are actually in use: A DPA with declared but not implemented measures exposes itself to liability in case of inspection or incident.
- Keep notifications violation time aligned between DPA and internal incident response procedure to truly meet the agreed-upon deadline with the Data Protection Authority.
- Update the list of sub-responsibles every time you change your cloud provider or third-party service that handles data on your behalf, and keep previous versions of signed documents.
Domande frequenti
What is a DPA and when does it need to be used?
Data Processing Agreement (Data Processing Agreement) and the contract required by Article 28 GDPR every time a Data Controller transfers personal data to an external Responsible, such as a cloud provider, SaaS service or technology partner who processes data on behalf.
Is this document legally valid as generated?
A basic model that covers the minimum elements required by Article 28 GDPR (subject, obligations, security measures, sub-respondents, notification of violations, audits, duration). Before signing, it must always be reviewed by a lawyer or DPO to adapt it to the specific case and existing contracts.
Why must I indicate the time for notification of data breach?
Article 33 GDPR requires the Data Controller to notify the Data Protection Authority within 72 hours of discovering a breach. The DPA must therefore set a deadline (typically equal to or less than 72 hours) by which the Responsible Person is required to inform the Controller, allowing them time to notify the Authority.
How do I handle under-resourced teams (e.g. AWS, Google Cloud)?
Listed in the designated section: The model assumes that the Principal authorizes the sub-responsibles explicitly and that the Responsible notifies with prior notice any additions or substitutions as required by Article 28(2) GDPR.
Should you choose Markdown or HTML?
Markdown and comfortable for versioning the document in a repository or easily converting it to PDF with external tools; HTML ready to be viewed or printed directly from the browser with pre-formatted layout (tables alongside sections, areas for signing).