Audit vendor Data Processing Agreements against GDPR Art. 28.
Drop your CSV here
or click to browse your files · CSV only
When to use GDPR Article 28 DPA Clause Auditor
Procurement intake review for new SaaS and cloud vendors
Auditing legacy vendor DPAs for compliance with modern EDPB recommendations
Generating structured evidence ledgers for annual third-party risk assessments
How to export from Contract Management / Vendor Intake and clean in MiniJudge
Follow these steps to extract your raw spreadsheet and filter it without writing code:
The Danger of “Excel Purgatory” in GDPR Article 28 DPA Clause Auditor
The Regulatory Rejection Bottleneck
Whether submitting a 15-table DORA ICT register to the CSSF eDesk portal (Regulation EU 2024/2956) or maintaining an Article 30 RoPA for supervisory review, Excel cannot enforce relational integrity. A single malformed 20-character LEI, blank statutory retention period, or unmapped international transfer causes official package rejection and emergency legal review cycles costing €15,000+ in auditor fees.
The Missing Evidence Ledger
A simple “Yes” in an internal vendor questionnaire is no longer acceptable to auditors. Regulators demand verifiable provenance: Document → Page → Clause → Exact Excerpt → Status. Manual cross-referencing between 30-page PDF contracts and spreadsheets creates fatigue after just 5 documents, leaving critical subprocessor liabilities and AI training licenses undiscovered.
Hard Judge Schema
Deterministic regex checks ISO 17442 LEI syntax, date formats, required Article 30 columns, and cross-table foreign key constraints in microseconds.
Soft Clause Reasoning
Evaluates complex contractual text against GDPR Article 28(3) and EU AI Act obligations: subprocessor notice windows, audit access, and training opt-outs.
Typed Evidence Ledger
Assigns rigid regulatory statuses (VERIFIED, MISSING, CONFLICTING) with citation references.
Air-Gapped Export
Processes data 100% in-memory without persistent database storage, satisfying Luxembourg and Swiss banking confidentiality standards.
What MiniJudge appends to your spreadsheet
| Source / Item | Requirement | Status | Evidence Excerpt | Action Required |
|---|---|---|---|---|
| AWS_Cloud_DPA.pdf | Art. 28(3)(h) Audit Access | VERIFIED | “Allows for and contributes to audits...” | None (Compliant) |
| Shadow_Analytics.pdf | ISO 17442 LEI Syntax | MISSING | LEI field blank in contract register | Request vendor LEI before submission |
| FastMailer_DPA.pdf | Art. 28(3)(a) Subprocessors | CONFLICTING | “Vendor may add subprocessors without notice” | Require 30-day prior written notice |
MiniJudge vs. Enterprise GRC vs. Manual Excel
- • 4.5 hours per register audit
- • No relational validation across tables
- • High human fatigue & missed gaps
- • High risk of regulatory rejection
- • 3+ months enterprise procurement
- • Requires abandoning existing spreadsheets
- • Heavy overhead for mid-size teams
- • Expensive per-seat licensing
- • Zero setup: drop your existing CSV/XLSX
- • 12ms deterministic validation
- • Appends verified Evidence Ledgers
- • 100% ephemeral in-browser privacy
Frequently Asked Questions
What Article 28 requirements does MiniJudge evaluate?
MiniJudge checks for subprocessor prior notice, auditor inspection access, breach notice without undue delay, data deletion upon termination, and confidentiality commitments.