What is a DPA for AI tools?
Definition
A DPA regulates processing of personal data on behalf of a controller under Art. 28 GDPR. For AI tools, it is especially important because prompts, files, metadata and outputs may contain personal or confidential information depending on usage.
The DPA is a contractual building block. It does not automatically answer every practical question around AI usage. It should therefore be connected with the GDPR checklist for AI in business, platform selection and internal rules.
DPA checklist for AI tools
| Checkpoint | Question |
|---|---|
| Clarify roles | Is the provider a processor, controller or both depending on function? |
| Define data types | Which personal, confidential or special-category data may be entered? |
| Review subprocessors | Which third parties, regions and services are involved? |
| Exclude training use | Are prompts, files or outputs used for model training? |
| Review deletion | How long are content, logs and metadata stored? |
| Secure auditability | Are logs, admin functions and traceable controls available? |
AI-specific DPA questions
For classic SaaS tools, processor agreements are often familiar. AI tools add extra questions: Are prompts stored? Are files analyzed? Are contents used to improve models? Can admins trace usage?
Lurus addresses these points through DPA information, No Training and Zero Data Retention and audit log mechanisms. This makes review more concrete, but does not replace individual assessment.
Distribution asset
DPA checklist for AI tools
The checklist can guide privacy officers, IT and procurement: review roles, data types, subprocessors, training use, deletion and auditability.
Discuss DPA questions with Lurus →Review DPA, cost and provider choice together
A low list price helps little if privacy review, training and governance need to be built separately later. Compare pricing, security features and rollout effort together. For structured selection, use the guide to choosing an AI platform for business.
Source and legal date
Date: 2026-05-12. Basis is especially Art. 28 GDPR on processor agreements. This page is not legal advice and does not replace review of the concrete use case.