August 2026. Processor agreements (DPAs) must align with ISMS, NIS2 chain and due diligence. Supervisors and customers compare DPA clauses with actual security controls — inconsistency triggers questions.
2026 checklist
- subprocessors: list, notification, audit rights;
- security measures: reference ISO 27001/SoA or annex with controls;
- breach: notification timelines aligned with GDPR and contract SLA;
- exit: data return, deletion, proof of format;
- location: EU/EEA, SCCs if third country.
ISMS link
Manage DPAs in the same register as vendor risk. Link to GDPR hub and vendor management. At renewal: check whether security posture changed since signing.
In 2026 enterprise customers ask for DPA + SOC/ISO evidence in one package. Version control and review date on each DPA are minimum.
