aivalet.nu, a Swedish guide
🆕 New guide Winningtemp price 2026: how much it costs Read →

HomeGuides › Get started

🚀

Get started

How to sign a data processing agreement (DPA)

The word is more complicated than the thing. A DPA usually takes five minutes to put in place. Here is when you need one, where to find it and what to look for.

GDPRPractical

Short answer: A data processing agreement (DPA) is required under GDPR Article 28 as soon as a tool processes personal data on your behalf. Almost all serious suppliers have a ready-made standard agreement: search for "DPA" on their site and approve it, done in five minutes.

As soon as a tool processes personal data on your behalf, the supplier is your data processor. This applies, for example, to customers in a newsletter tool, employees in a payroll system or clients in a booking system. GDPR Article 28 then requires a written agreement: a data processing agreement, usually called a DPA.

Sounds heavy? In practice it is usually a checkbox.

How it works

Checklist

  1. Find the supplier’s standard DPA. Almost all serious services have one. Search for “DPA”, “Data Processing Agreement” or “personuppgiftsbiträdesavtal” together with the tool’s name. You can also look under Legal or Trust on their site.
  2. Approve it. With Brevo and Mailchimp, for example, the DPA is included in the terms or activated in account settings. Swedish tools like Bokio handle it in their user terms. Save a copy.
  3. Done. You rarely need to negotiate: the standard agreement is built to satisfy Article 28.

Quick check: what a good DPA contains

  • What the supplier may do with the data (only what you instruct).
  • Sub-processors listed, with your right to object to changes.
  • Security measures, confidentiality and assistance with incidents.
  • Deletion or return of data when the agreement ends.
  • For transfers outside the EU/EEA: standard contractual clauses (SCC) or another valid basis. This is especially important with American suppliers (read why in our CLOUD Act guide).

Most common mistakes

  • No DPA at all with tools that obviously process personal data. This is most common with small and new AI services. If you cannot find a DPA from the supplier, that is a warning sign in itself.
  • Free tools for sensitive data. Consumer versions of AI chats often have no processing agreement at all. Personal data should not go there.
  • Forgotten sub-processors. An EU tool can send data to American AI models behind the scenes. The sub-processor list reveals that.

Five minutes per tool. Make it a habit for every new account, and that part of the GDPR work is done.

Sources

Tools mentioned

Bokio

Bokio

4,3 Very good
Swedish Bookkeeping From approx 269 SEK/month EU data storage ✓

Swedish accounting program from Gothenburg that reads receipts and books automatically. Affordable and simple, but the old free tier is now a 14-day trial.

  • Reads receipts and books automatically
  • Simple interface, built for non-accountants
  • No longer free, subscriptions from SEK 269/month

Best for: Sole traders and small businesses that want to handle accounting easily themselves.

Brevo

Brevo

3,3 Good
GDPR-friendly
EU/EEA Marketing Freemium EU data storage ✓ ISO 27001

French email and SMS platform with EU data storage, a GDPR-friendly Mailchimp alternative.

  • EU data storage
  • Generous free tier
  • Less polished interface

Best for: Newsletters with data inside the EU.

Mailchimp

Intuit

3,3 Good
Outside EU Marketing Freemium ISO 27001

Newsletters and email marketing with AI help for copy and timing.

  • Easy to get started
  • Free tier
  • Becomes expensive as the list grows

Best for: Newsletters to the customer list.

Related articles

This is general information, not legal advice. See How we review.