Trust & compliance

What does the Plugsky Data Processing Agreement cover?

The standard Plugsky DPA covers GDPR Article 28 controller-processor terms, EU Standard Contractual Clauses for cross-border transfers, PDPL and DIFC/NSD alignment, sub-processor disclosure with change notice, data-subject rights, 72-hour breach notification, audit rights, and data return or deletion on termination. It is available on paid plans, with bespoke addenda on Enterprise.

Key facts

GDPRArticle 28 controller-processor terms
Cross-border transfersEU Standard Contractual Clauses (SCCs)
Regional law alignmentPDPL, DIFC and NSD alignment
Sub-processorsPublished list with change notification
Data subject rightsAccess, deletion and portability assistance
Breach notificationWithin 72 hours
Audit rightsAnnual and on-cause
AvailabilityPaid plans as click-through; bespoke addenda on Enterprise

TL;DR

  • Standard DPA is a click-through agreement on paid plans.
  • GDPR Article 28 terms and EU SCCs are included, not bolted on.
  • PDPL, DIFC and NSD alignment is documented for GCC buyers.
  • Breach notification is 72 hours; audit rights are annual and on-cause.
  • Enterprise addenda cover liability, localization, sub-processor limits and enhanced audit.

How it works, step by step

  1. Review the standard DPA terms before signing up for a paid plan.
  2. Check the current sub-processor list against your own policy.
  3. Confirm the data categories, purposes and retention periods that apply to you.
  4. Request the SOC 2 Type II report under NDA if your review requires it.
  5. For custom terms, route the addendum request through your account team.
  6. File the executed DPA with your vendor risk register and revisit on renewal.
1Review the standardDPA terms beforesigning up for a2Check the currentsub-processor listagainst your own3Confirm the datacategories,purposes and4Request the SOC 2Type II reportunder NDA if your5For custom terms,route the addendumrequest through6File the executedDPA with yourvendor risk

Try it yourself

Open the AI data residency checklist →

What the standard DPA includes

The standard agreement is written as controller-processor terms under GDPR Article 28 and includes the EU Standard Contractual Clauses for transfers outside the EEA. It documents the processing purposes, the categories of personal data involved, retention rules and the security measures applied to each processing activity. Regional alignment is explicit for PDPL, the DIFC Data Protection Law and NSD expectations, which matters when your regulator is in the GCC.

Operationally, the DPA commits to breach notification within 72 hours, data-subject rights assistance (access, deletion, portability), annual and on-cause audit rights, and return or deletion of data on termination.

Sub-processors and cross-border transfers

Plugsky publishes a sub-processor list and notifies customers when it changes — the live page states change notification, and 30 days is the norm in the wider documentation. For each sub-processor, you can see the service provided and the region involved, which is what most EU and GCC controllers need for their transfer analysis. If your policy requires prior approval or region restrictions, negotiate that as an Enterprise addendum rather than assuming the standard terms cover it.

Enterprise addenda

Enterprise contracts can include bespoke terms on top of the standard DPA: liability caps, data localization commitments, restricted or pre-approved sub-processors, enhanced audit rights and a right to terminate for material breach. This is the route for banks, government agencies and regulated SaaS teams whose procurement process cannot accept a click-through agreement. Requests go through your account team or legal contact.

What to verify before you sign

A DPA is necessary but not sufficient. Check that the security controls behind it match your requirements — encryption, key custody, access management and audit logging — and that residency claims line up with your jurisdiction. Ask for the SOC 2 Type II report, the current sub-processor list and a clear statement of the retention and deletion lifecycle.

Honest caveat: a signed DPA does not make a non-compliant data flow compliant. If you send special-category data to the wrong region, paper will not fix the architecture. Map your flows first, then match terms to them.

Honest comparison

TermPlugsky standard DPACommon SaaS baselineEnterprise addendum
GDPR Article 28IncludedCommonIncluded
EU SCCsIncludedOften separate annexCustom mechanics
GCC alignmentPDPL, DIFC, NSDVariesData localization terms
Sub-processorsPublished list and notificationVariesPre-approval and restrictions
Breach notification72 hoursVariesCustom
Audit rightsAnnual and on-causeVariesEnhanced rights

Frequently asked questions

Is the DPA available on the free plan?

The click-through DPA is available on paid plans. Free evaluation traffic should not carry production personal data unless your own policy allows it.

Does the DPA include EU SCCs?

Yes. The EU Standard Contractual Clauses are part of the standard DPA for cross-border transfers.

How do I get a custom DPA?

Enterprise customers can request bespoke addenda — liability caps, localization, sub-processor restrictions and enhanced audit rights — through their account team or the legal contact in the docs.

How quickly will I be notified of a breach?

The DPA commits to breach notification within 72 hours, matching GDPR Article 33 expectations.

Can I restrict which sub-processors process my data?

Restrictions and pre-approval are Enterprise addendum terms; the standard DPA discloses the list and notifies you of changes.

What happens to my data when I leave?

The DPA includes data return and deletion on termination, with assistance for data-subject access and portability requests.

Is the DPA enough for a bank or government procurement?

Usually not on its own. Expect to pair it with the SOC 2 Type II report, residency documentation, right-to-audit clauses and a security review.

Cite this page

Plugsky (2026). “Plugsky DPA — GDPR, PDPL and SCC Coverage”. Plugsky. Available at: https://plugsky.com/articles/dpa (last updated 2026-09-25).