The GDPR has been in force for eight years, and yet in initial audits with mid-market companies we keep seeing the same three building blocks missing: a proper data processing agreement (DPA, German AVV) for every cloud tool, an up-to-date register of sub-processors, and a solid legal basis for third-country transfers after the Schrems II ruling and the EU-U.S. Data Privacy Framework. Companies that fail to document these three points risk not only fines, but increasingly lose B2B deals — larger customers now demand exactly these records in vendor due diligence.
This article covers the mistakes we most often encounter in audits and gives you a practical playbook to close the gaps systematically.
Mistake 1: No DPA for everyday cloud tools
The classic: a company uses Google Workspace, Microsoft 365, Slack, Notion, Zoom, Miro or a marketing tool like HubSpot — and no one has actually concluded or archived the data processing agreement under Art. 28 GDPR. In many cases the vendor’s Data Processing Terms or Data Protection Addendum (DPA) are sufficient, but acceptance must be active and the contract text must be archived. A screenshot of a Terms-of-Service checkbox does not count.
In practice, for every tool that processes personal data (which is basically every mailbox, chat or CRM), you need a PDF copy or a permanent link to the specific accepted DPA version, along with the date and the person who accepted it. In Microsoft this lives under Admin Center -> Billing -> Contracts, in Google under Account -> Legal, in Slack in the Workspace Owner area. With smaller SaaS providers you often have to ask by email — a vendor who does not deliver a DPA is not usable under GDPR.
The second trap is shadow IT. If Sales autonomously spins up a cold-email service like Apollo or Lemlist, Marketing uses a form tool like Typeform, and Finance uses an OCR invoice tool — then you have three data processing relationships management does not know about. A regular reconciliation of credit-card statement, SSO logs and DPA register reliably surfaces these gaps.
Mistake 2: Sub-processors not tracked
Under Art. 28(2) GDPR, the processor must inform you about every engagement or change of a sub-processor — and you must have the option to object. In reality practically every cloud vendor uses sub-processors: Microsoft uses its own data centres plus CDN partners, Slack runs on AWS, Notion on AWS and Cloudflare, HubSpot on AWS and Google Cloud. When AWS Frankfurt goes down for six hours, three of your tools can go dark at the same time — a good indicator of how many sub-processors you actually have.
Vendors publish these lists. You need to review them regularly and reflect changes in your own register. The most important pages at a glance:
| Vendor | Sub-processor list |
|---|---|
| Microsoft 365 | Microsoft Products and Services DPA, appendix |
| Google Workspace | workspace.google.com/terms/subprocessors |
| Slack | slack.com/trust/compliance/sub-processors |
| Notion | notion.so/subprocessors |
| HubSpot | legal.hubspot.com/subprocessors |
| Zoom | explore.zoom.us/en/subprocessors |
| Atlassian | atlassian.com/legal/sub-processors |
In practice we recommend reviewing these lists once per quarter. Some vendors offer RSS or email alerts — subscribe and route them into a mailbox that an actual person reads. If you move parts or all of your infrastructure to European alternatives such as a TrueNAS-based private cloud or a self-hosted Nextcloud, you shorten this chain considerably — the sub-processor is then yourself.
Mistake 3: Third-country transfer without Standard Contractual Clauses
Following the ECJ’s Schrems II ruling in 2020, transfers of personal data to the USA are only permitted with additional safeguards. The EU-U.S. Data Privacy Framework (adequacy decision by the Commission, 2023) helps, but only if the specific US vendor is listed in the DPF register. For all other third countries — or non-certified US recipients — you need:
- Standard Contractual Clauses (SCC) in the current 2021 version (not the old 2010 ones),
- a Transfer Impact Assessment (TIA) that documents the risks of the target jurisdiction, and
- where required, supplementary technical measures such as customer-side encryption with your own key.
A typical example: you use a US analytics service that is not DPF-certified. Then the SCC must be baked into the DPA (with most vendors via a checkbox or as an annex), and you have to produce a short TIA that records which data is transferred, which categories of data subjects are affected, and which additional measures apply. For analytics the standard answer is usually IP anonymisation plus cookie consent — for actual personal data this is not enough.
A clean entry in the DPA register can look like this:
tool: "HubSpot Marketing Hub Professional"
controller: "Example Ltd."
processor: "HubSpot Inc., 2 Canal Park, Cambridge MA"
data_categories: ["Lead contact details", "Email interactions"]
subject_categories: ["Prospects", "Existing customers"]
legal_basis: "Art 6 (1) f GDPR"
dpa_status: "DPA 2024-11 accepted, PDF in /compliance/dpa"
sub_processors_reviewed: "2026-06-30"
third_country_transfer: "USA"
transfer_mechanism: "DPF certification active, checked 2026-07-01"
tia_present: true
tia_date: "2026-04-15"
tom_reference: "TOM catalogue v3.2 section 7"
internal_contact: "privacy@example.com"
You can maintain such a register in a simple Git repository, a wiki or even a structured spreadsheet — what matters is that it is current and can be produced within minutes during an audit.
The consolidation lever: fewer tools, fewer processors
The most effective way to get your DPA landscape under control is reduction. Every SaaS tool means another DPA, another update cycle, another sub-processor list, potentially another third-country transfer and another control object in your TOM catalogue. In companies with 40 employees we routinely find 60 to 90 active SaaS tools — half of them shadow IT or barely used.
Consolidation approaches that work in practice:
- Collaboration and files on one platform: Microsoft 365 or Google Workspace or a European Nextcloud instance — not three in parallel.
- Chat and meetings bundled (Teams, Google Meet or a self-hosted Element/Matrix instead of Slack + Zoom + Discord).
- Internal knowledge base in ONE tool instead of Notion + Confluence + three SharePoint sites.
- Backups and internal file shares on your own infrastructure, e.g. a TrueNAS appliance with S3-compatible object storage and ZFS snapshots.
- Firewall, VPN and Zero-Trust access via OPNsense instead of a US-hosted VPN service.
- Virtualisation and internal apps on Proxmox, so that CRM, DMS or ERP do not have to run as SaaS.
Every tool fewer is one DPA fewer, one TOM record fewer and one potential third-country transfer fewer.
Checklist: eight weeks to a solid DPA register
- Week 1 — Inventory: capture every tool that processes personal data. Sources: SSO logs, credit-card statement, firewall logs, interviews with the business.
- Week 2 — Collect DPAs: archive the current contract text for every tool, with date and accepting person.
- Week 3 — Sub-processors: import the vendor lists into your register, set up alerts.
- Week 4 — Third-country transfers: check DPF status, SCC version, TIA.
- Week 5 — Align TOMs: encryption, access control, deletion concept for every tool.
- Week 6 — Consolidation potential: identify duplicates, draft a migration plan.
- Week 7 — Roles and processes: who reviews quarterly? Who archives new DPAs?
- Week 8 — Audit rehearsal: can someone produce the DPA, the TIA and the sub-processor list for a randomly chosen tool within 30 minutes? If yes, the register is solid.
DATAZONE support
DATAZONE supports mid-market companies in the Ingolstadt/Neuburg region and Germany-wide remotely on exactly this journey: from the initial tool inventory through the DPA register to concrete migration towards European, self-determined infrastructure — Proxmox, TrueNAS, OPNsense, Linux servers and orderly backups. If you want to get your DPA register on a solid footing or consolidate your shadow IT along the way, get in touch. Book a call via contact — we reply within one business day.
More articles
ISO 9001 for IT Service Providers: Realistic Preparation
ISO 9001 without theatrics: document processes, schedule internal audits sensibly, budget honestly -- a pragmatic guide for IT service providers with 10 to 20 staff.
TrueNAS Made in USA: Honestly Assessing the Data Privacy Debate for EU Customers
TrueNAS is developed in the US -- is that a GDPR problem? An honest look at CLOUD Act, telemetry, source-available code and support contracts for EU customers.
Matomo vs. Plausible: Privacy-Friendly Analytics Compared
Matomo and Plausible in practice: Docker deployment, GDPR-compliant configuration, feature scope and cost for self-hosting and cloud analytics.