AI Governance · Data Protection
The AI Vendor DPA, Explained
What GDPR Article 28 requires for an AI vendor specifically — and the clauses a standard template almost always misses.
A standard data processing agreement was written for a vendor that stores and transfers your data. An AI vendor does more — it can train on it, generate inferences from it, and retain the prompts you send it. If your DPA is silent on those three things, the risk defaults to you.
What Article 28 requires
- Sub-processor authorisation — Art. 28(3)Every sub-processor named and authorised, not buried in an unread schedule.
- Security measures — Art. 32Technical and organisational measures documented, not assumed.
- Breach notification timing — Art. 33A specific timeline, in writing.
- Data subject rights cooperation — Art. 12-22Access, erasure, and portability — including requests that touch a model, not just a database.
The AI-specific clauses to add
- Training-data useDoes the vendor train on your inputs? State it plainly.
- Inference-data handlingWhat happens to the outputs generated from your data?
- Prompt-input retention & deletionHow long are the actual prompts kept, and how are they deleted?
Get a free sample AI vendor DPA — no cost, just your email.
Email me the free sampleOr go straight to the full 12-clause agreement — $39, one-time.
Frequently asked
- Does GDPR Article 28 apply to AI vendors?
- Yes. Any AI vendor processing personal data on your behalf is a processor under GDPR, so Article 28 applies — it requires sub-processor authorisation, security measures, breach notification, and cooperation on data subject rights, the same as any other processor.
- Is a standard DPA template enough for an AI vendor?
- Usually not. A standard DPA is written for a vendor that stores and transfers data. It is typically silent on whether the vendor trains models on your inputs, what happens to inference outputs generated from your data, and how long prompt inputs are retained — all of which need their own explicit clauses for an AI vendor.
- What AI-specific clauses should an AI vendor DPA include?
- Three are commonly missing from generic templates: a training-data clause stating whether your inputs are used to train the vendor's models, an inference-data clause covering outputs generated from your data, and a prompt-input clause on retention and deletion.
- What does GDPR Article 28(3) require for sub-processors?
- Article 28(3) requires that any sub-processor engaged by the processor is authorised — either specifically or generally, with notice of changes — and bound by the same data protection obligations as the primary processor. For an AI vendor this commonly means a model provider, a hosting provider, and an analytics layer, not just one company.
This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.
Sources: Regulation (EU) 2016/679 (GDPR), Articles 12-22, 28, 32, 33 · Responsible AI Studio .