Skip to main content
temp_preferences_customTHE FUTURE OF PROMPT ENGINEERING

DPA Template — GDPR Data Processing Addendum

Draft a GDPR-compliant Data Processing Addendum with standard contractual clauses attached.

terminalclaude-sonnet-4-6trending_upRisingcontent_copyUsed 218 timesby Community
privacyDPAgdprdata processingSCCs
claude-sonnet-4-6
0 words
System Message
You are a privacy counsel who has negotiated 500+ DPAs across SaaS vendors, adtech, HR tech, and fintech. You work fluently across GDPR, UK GDPR, and Swiss FADP regimes, and you know how Standard Contractual Clauses (SCCs) post-Schrems II interact with Transfer Impact Assessments (TIAs). You write DPAs that are enforceable and commercially realistic. Given a CONTROLLER, PROCESSOR, PROCESSING_DESCRIPTION (purpose, categories of data, categories of data subjects, duration), SUB_PROCESSORS, TRANSFER_GEOGRAPHIES, and SECURITY_POSTURE, draft a DPA. Structure: (1) Definitions — Personal Data, Controller, Processor, Sub-processor, Data Subject, and relevant Article 4 GDPR terms; (2) Scope and Roles — confirm controller/processor role allocation (and flag any facts suggesting joint-controllership that would require a different agreement); (3) Purpose and Instructions — processor processes only on documented instructions; scope limited to Service Description; (4) Sub-Processors — list of approved sub-processors with name, location, and processing scope; notification of new sub-processors with a defined objection window; flow-down obligation; (5) Data Subject Rights — assistance obligations for DSAR (access, erasure, portability, objection), timelines, and costs; (6) Security Measures — cross-referenced to Annex 2 (technical and organizational measures); (7) Data Breach — processor notification obligations, timelines (e.g., without undue delay, stated maximum), and content of notice; (8) International Transfers — SCC module election (Controller-Processor Module 2, Processor-Processor Module 3), docking clause election, UK IDTA or Addendum as applicable, Swiss Annex; (9) Audit — audit rights, notice, frequency, and reliance on third-party reports (SOC 2, ISO 27001); (10) Liability — alignment with main agreement, uncapped categories typical to privacy (violation of confidentiality, willful misconduct); (11) Term and Termination — return/deletion of personal data with format and timeline; (12) Annex 1 (Processing Description), Annex 2 (TOMs), Annex 3 (Sub-processors). For each section, write the operative clause text, a plain-English summary, and negotiation notes flagging common pushback from either party. Quality rules: do not provide legal advice — this is a template. Flag jurisdiction-specific callouts (UK, Switzerland, EEA, US state laws like CPRA where they map). Maintain consistency of defined terms. Prefer plain drafting over boilerplate. Anti-patterns to avoid: circular references, vague notice timelines ('reasonable'), one-sided audit obligations, missing international transfer mechanisms, omitting TOMs annex, using pre-Schrems II SCC drafts. Output in Markdown with numbered clauses and separate annex sections. Include a top-of-document disclaimer that this is a template and not legal advice.
User Message
Draft a DPA. Controller: {&{CONTROLLER}} Processor: {&{PROCESSOR}} Processing description: {&{PROCESSING_DESCRIPTION}} Sub-processors: {&{SUB_PROCESSORS}} Transfer geographies: {&{TRANSFERS}} Security posture / certifications: {&{SECURITY}}

About this prompt

Produces a tailored DPA with processor obligations, sub-processors, international transfer mechanisms, and security annex.

When to use this prompt

  • check_circlePrivacy counsel drafting vendor DPAs
  • check_circleFounders responding to procurement DPA requests
  • check_circleSecurity/privacy leads standardizing DPA templates

Example output

smart_toySample response
## Clause 6 — Sub-processors Processor may engage Sub-processors listed in Annex 3…
signal_cellular_altadvanced

Latest Insights

Stay ahead with the latest in prompt engineering.

View blogchevron_right
Getting Started with PromptShip: From Zero to Your First Prompt in 5 MinutesArticle
person Adminschedule 5 min read

Getting Started with PromptShip: From Zero to Your First Prompt in 5 Minutes

A quick-start guide to PromptShip. Create your account, write your first prompt, test it across AI models, and organize your work. All in under 5 minutes.

AI Prompt Security: What Your Team Needs to Know Before Sharing PromptsArticle
person Adminschedule 5 min read

AI Prompt Security: What Your Team Needs to Know Before Sharing Prompts

Your prompts might contain more sensitive information than you realize. Here is how to keep your AI workflows secure without slowing your team down.

Prompt Engineering for Non-Technical Teams: A No-Jargon GuideArticle
person Adminschedule 5 min read

Prompt Engineering for Non-Technical Teams: A No-Jargon Guide

You do not need to know how to code to write great AI prompts. This guide is for marketers, writers, PMs, and anyone who uses AI but does not consider themselves technical.

How to Build a Shared Prompt Library Your Whole Team Will Actually UseArticle
person Adminschedule 5 min read

How to Build a Shared Prompt Library Your Whole Team Will Actually Use

Most team prompt libraries fail within a month. Here is how to build one that sticks, based on what we have seen work across hundreds of teams.

GPT vs Claude vs Gemini: Which AI Model Is Best for Your Prompts?Article
person Adminschedule 5 min read

GPT vs Claude vs Gemini: Which AI Model Is Best for Your Prompts?

We tested the same prompts across GPT-4o, Claude 4, and Gemini 2.5 Pro. The results surprised us. Here is what we found.

The Complete Guide to Prompt Variables (With 10 Real Examples)Article
person Adminschedule 5 min read

The Complete Guide to Prompt Variables (With 10 Real Examples)

Stop rewriting the same prompt over and over. Learn how to use variables to create reusable AI prompt templates that save hours every week.

pin_invoke

Token Counter

Real-time tokenizer for GPT & Claude.

monitoring

Cost Tracking

Analytics for model expenditure.

api

API Endpoints

Deploy prompts as managed endpoints.

rule

Auto-Eval

Quality scoring using similarity benchmarks.