VendorDPA Gatekeeper
12 of 18 requirements are weak or missing in the Cobaltline Analytics, Inc. DPA (score 59/100, 1 high risk); 12 fallback redline(s) drafted.
GDPR Art. 28(3), first subparagraph requires subject matter or nature and purpose, duration, types of personal data and categories of data subjects. All are found in Section 2.1.
Method1The agreement is split into sentences that keep their clause number; each requirement is graded from the sentences that evidence its elements.
2GDPR Art. 28(3)(a) to (h), the 28(3) second subparagraph, 28(2) and 28(4), and the description of processing required by 28(3): all elements present is Present, some is Weak, none is Missing. Limiting phrases (own-purpose use, discretionary security changes, audit limits, backup retention) make a clause Weak.
| Requirement | Citation | Law |
|---|---|---|
| Description of the processing | GDPR Art. 28(3), first subparagraph | GDPR |
| Processing only on documented instructions, including transfers | GDPR Art. 28(3)(a) | GDPR |
| Confidentiality of authorized persons | GDPR Art. 28(3)(b) | GDPR |
Data processing agreement text
Clause-by-clause risk scorecard and fallback redline language (Redline schedule for the vendor, Risk scorecard (CSV), Risk scorecard (JSON))
$3,000 / month, 30% to the referring partner
Read in memory for the session, never stored, never used to train a model.
Privacy and security findings are not legal advice or an audit opinion. Confirm them with privacy counsel or a qualified assessor. Letters, notices and legal analysis are drafts, not legal advice. Have a qualified lawyer review them before they are sent or relied on.