Check that the agreement names you as controller and the vendor as processor, rules out training on your data, lists sub-processors with advance notice and a right to object, sets a breach-notice deadline (48 hours or less is good), states how long prompts and outputs are kept and deleted, covers international transfers, and promises audit evidence such as a SOC 2 report.
Before any of that, check that your plan has a DPA at all. Many AI tools only offer one on business plans. OpenAI offers a data processing addendum for ChatGPT Business, ChatGPT Enterprise and its API, not for Free or Plus. Anthropic's DPA is built into its commercial terms for Claude Team, Enterprise and the API, and doesn't cover Free, Pro or Max. If your staff paste customer details into a consumer account, the best DPA in the world on your business plan doesn't help.
How AI vendors hand over their data processing agreement
A data processing agreement (sometimes "addendum", DPA for short) is the contract in which a supplier that handles personal data for you (the processor) promises how it will do so. Data-protection law such as the GDPR sets out what that contract must cover in Article 28: processing only on your documented instructions, confidentiality for staff, security, rules for sub-processors, help with people's rights requests and breaches, deletion or return at the end, and information to show compliance.
AI vendors deliver it in one of three ways, and you need to know which applies to you:
- Built into the commercial terms. You accept it when you accept the terms. Anthropic works this way. Download a copy on the day you sign, because the live version may change later.
- A form you complete. OpenAI provides a form to execute its DPA. Nothing is signed until you do it.
- A click-through in the admin settings or on request. Common with smaller vendors. If you can't find it, email and ask; a vendor that can't produce one for a business plan has answered an important question.
File the version you agreed to, with the date, alongside your other contracts. It's also worth reading the vendor's privacy terms in the same sitting; what to check in an AI tool's privacy policy and terms covers the consumer-facing side.
The checklist, grouped by what can go wrong
Each item has why it matters, where to look, and what acceptable wording looks like. Real clauses from Anthropic's DPA are quoted where they make a useful benchmark; they're examples of good practice, not the only acceptable answer.
Roles and scope
- You are the controller, the vendor is the processor. Why: the processor may only use the data on your instructions. Look in the definitions or the first section. Good: an explicit statement that for business accounts the customer is controller. Watch for vendors that say they act as controller for "service improvement", which lets them decide their own uses.
- The data and purposes are described. Why: vague scope makes every other promise vague. Look for an annex listing categories of data (names, contact details, message content) and people (your customers, staff). Good: a list you recognise as matching what you'll actually put in.
- Processing only on your documented instructions. Why: it's the core legal requirement and what stops unexpected uses. Good: "processes Customer Personal Data only on Customer's documented instructions", with the agreement and your use of the product counting as those instructions.
What the AI does with your content
- No training on your data. Why: this is the AI-specific question generic DPAs miss. Look in the DPA, the commercial terms and the business data page. Good: an explicit statement that customer content isn't used to train models by default. The large vendors' business plans say this; smaller tools built on top of them vary.
- Retention of prompts, outputs and logs. Why: "zero data retention" and "30 days" are very different, and vendors change these. A real example: since 9 June 2026 Anthropic keeps prompts and outputs on its most capable "covered" models for 30 days even for zero-retention customers, with a by-application route back to zero retention added in September 2026. Good: a stated period, what it's for (abuse monitoring, for instance) and whether you can shorten it. The trade-offs are explained in what zero data retention means.
- Human review. Why: some vendors let staff read flagged conversations for safety. Good: review limited to specific purposes, by trained staff bound by confidentiality, and stated in writing.
Sub-processors
- A published list, including the AI model provider. Why: a scheduling or chatbot tool may send your data to a model company and a cloud host. Look for a sub-processor page linked from the DPA. Good: named companies, what each does and where. If the tool uses a large language model and no model provider appears, ask.
- Notice of new sub-processors and a right to object. Why: you need time to react before a new company gets access. Benchmark: Anthropic gives reasonable notice before a new sub-processor gets access, and customers have 15 days to object on reasonable privacy or security grounds. Good: a notice method you'll actually see (email or a subscribable page) and an objection route.
Security and breaches
- Security measures described. Why: "industry standard" means nothing on its own. Look for a security annex covering encryption, access control and staff vetting.
- Breach notification deadline. Why: under the GDPR a controller must generally report a notifiable breach to the regulator within 72 hours of becoming aware, and you can't do that if the vendor tells you on day five. Benchmark: Anthropic commits to notify "without undue delay, but in any event within 48 hours". Watch for "without undue delay" with no outer limit.
End of the contract
- Deletion or return, with a timeframe. Why: you need to know when your data is gone and how to get a copy first. Benchmark: Anthropic deletes customer data within 30 days of termination or returns it on request. Good: a number of days, plus how backups are handled.
- Export before deletion. Why: deletion after cancellation is good privacy and bad news if you forgot to export. This links privacy to portability; see keeping your data and prompts portable.
Transfers and location
- A transfer mechanism. Why: data often leaves the country you operate in. Good: named mechanisms such as standard contractual clauses built into the DPA, as Anthropic's is. If you need data kept in a particular region, check whether the vendor offers data residency and on which plan.
Evidence, help and changes
- Audit evidence. Why: you can't inspect a data centre, but you can read an independent report. Benchmark: Anthropic provides audit reports or certificates such as a SOC 2 report, with further audits by agreement. SOC 2 and ISO 27001 explained shows what to look for in those reports.
- Help with people's rights requests. Why: if a customer asks for their data or its deletion, you may need the vendor's help to find it. Good: a promise to forward requests promptly and assist.
- Help with risk assessments. Why: for higher-risk processing you may need to carry out an impact assessment and need information from the vendor.
- How the DPA and defaults can change. Why: vendors do change terms mid-contract. SimplePractice's Note Taker, for example, began opting new users in by default to keeping de-identified transcripts from 16 June 2026. Good: notice of material changes and a right to terminate if you object.
Deciding how deep to check each AI tool you use
You don't need to run all 17 checks on every tool. Sort your AI tools by what personal data goes into them, then match the depth of checking to the risk.
| Tier | What goes in | Checks to run |
|---|---|---|
| High | Customer records, health or pet-health notes, payment history, staff files, anything about children | All 17, a saved copy of the DPA, and written answers to anything unclear |
| Medium | Names and contact details only, such as email drafting or meeting notes with clients | 1, 4, 5, 7, 10 and 11: roles, training, retention, sub-processors, breach notice, deletion |
| Low | No personal data: marketing copy, product descriptions, internal planning | Confirm it really is personal-data-free and write that rule down for staff |
Here's how that sorted out for a three-person photography studio, as an illustration. Its five AI tools were a client gallery platform with AI culling and face grouping (high: faces, client names, children at school shoots), a business email suite with built-in AI (medium), a meeting note-taker used on client calls (medium), a chat assistant on a team plan used for proposals (medium, since client names appear) and an image generator for social posts (low). The owner spent about two hours on the gallery platform, 20 minutes each on the three medium tools and five minutes confirming the low one. The gallery platform turned out to have no stated retention period for face data, which became the one question sent to a vendor that week.
Re-run the check when a vendor emails you about changed terms, when you move to a different plan, or once a year for high-tier tools. Terms change more often than most owners assume, and the date on your saved copy tells you at a glance how stale it is.
Wording that should make you pause
| If the agreement says | It may mean | Ask |
|---|---|---|
| "We may use aggregated or de-identified data to improve our services" | Your content, stripped of names, can feed product development or models | "Does this include training or fine-tuning models, and can we opt out?" |
| "Without undue delay" with no hours stated | No firm breach deadline | "What is the maximum time to notify us of a breach?" |
| "Sub-processors are listed on our website" with no notice clause | The list can change without telling you | "How and how far ahead do you notify changes?" |
| "Data is deleted in accordance with our retention policy" | The timeframe is set elsewhere and can change | "How many days after termination, including backups?" |
| "We act as controller for service analytics" | They decide some uses themselves | "Which data does that cover, and does it include message content?" |
| "Audits at customer's cost with 90 days' notice" and no reports offered | Evidence is practically unavailable to a small business | "Can you share a current SOC 2 or ISO 27001 report?" |
A dog groomer checks a booking app's new AI assistant
An illustration of the checklist in use. A grooming salon with three groomers uses a booking app that has added an AI feature: it drafts reminder texts and replies to booking messages. The owner wants to switch it on. The app holds customer names, phone numbers, addresses, pet health notes and payment history.
The owner spends 40 minutes with the app's terms, its DPA (found under "Legal" in the footer) and its sub-processor page, then fills in a short record:
Vendor: [booking app] Plan: Salon Checked: 18 Sep 2026
DPA exists for our plan? Yes, part of business terms (PDF saved)
Controller / processor Us / them - stated in section 2
Training on our content UNCLEAR - "de-identified data to improve
services". Asked by email 18 Sep.
Retention of AI prompts Not stated. Asked.
Sub-processors Cloud host, SMS provider, payments firm.
No AI model provider listed. Asked which
model powers the assistant.
Sub-processor notice Email to account owner, 30 days, may object
Breach notice "Without undue delay" - no hours. Asked.
Deletion at end 60 days after cancellation incl. backups
Transfers Standard contractual clauses, section 9
Audit evidence SOC 2 Type II summary on request
Decision HOLD until 3 answers received
Three days later the vendor replies: de-identified data is used for product analytics but not for training models; AI prompts are kept for 30 days; the assistant runs on a named large model provider that has now been added to the sub-processor list; breach notice is within 72 hours. The owner accepts the first three answers. The 72-hour breach notice is tighter than she'd like, since it could leave little of her own reporting window, but for a salon of this size she decides it's acceptable and notes it as the one known gap. She switches on the feature, with a note in her records of why.
That's a realistic outcome. Few small businesses get a perfect DPA; the point is knowing where the gaps are and deciding knowingly.
A short email for the answers you couldn't find
Subject: Data processing questions before enabling [AI feature]
Hello,
We're a [type of business] on your [plan] plan and plan to switch on
[AI feature], which will process customer names, contact details and
[other data]. Before we do, please confirm in writing:
1. Is any of our content, including de-identified or aggregated
content, used to train or fine-tune AI models? Can we opt out?
2. How long are AI prompts and outputs retained, and for what purpose?
3. Which company provides the AI model, and is it on your published
sub-processor list?
4. What is the maximum time between you becoming aware of a breach
affecting our data and notifying us?
5. How many days after cancellation is our data deleted, including
backups, and how do we export it first?
Thank you.
Keep the reply with the DPA. If the vendor won't answer in writing, treat that as your answer.
What a DPA doesn't cover for you
A signed DPA is necessary but not sufficient. It doesn't cover:
- Your own legal basis and transparency. You still need a reason to process the data and to tell customers, usually in your privacy notice, that you use service providers, including AI tools.
- What staff paste into other tools. A realistic failure: a business signs up to a team plan with a good DPA, but two staff keep using personal free accounts because they're already logged in. The DPA covers none of that. A written usage rule and removing the temptation matter as much as the contract.
- Whether the use itself is appropriate. A photography studio using an AI gallery tool that recognises faces to sort images by person may be processing biometric data, which the GDPR treats as a special category when used to identify people. The DPA governs how the vendor handles it; it doesn't decide whether you should be doing it, or whether you need consent.
The broader obligations are set out in GDPR and AI tools: what a small business must do.
When to bring in a solicitor or data-protection adviser
This checklist is enough to screen most tools. Get qualified advice, rather than relying on it, when any of these apply:
- The tool will process health information, children's data, biometric data or other special categories at any scale.
- You're processing large volumes of personal data or using AI to make decisions about people, such as recruitment or credit.
- The vendor refuses to answer the questions above, or its answers contradict the DPA.
- You're asked to sign a DPA the vendor has written specifically for you, or you want to negotiate changes.
- A breach has happened or you're unsure whether one has.
A useful way to make that conversation short and cheap is to arrive with the filled-in record above and the vendor's written replies. An adviser can then focus on the two or three clauses that matter instead of reading everything from scratch. The companion list of questions to ask before buying AI that touches client data is a good pre-purchase step to pair with it.
Data processing agreements: common questions
Do I need a DPA if I only use ChatGPT or Claude for drafting?
If personal data about customers, staff or suppliers goes into the tool, data-protection law such as the GDPR generally expects a contract with the processor. Consumer plans don't come with one, which is a strong reason to keep personal data off them. If your drafting never includes identifiable people, the DPA matters less, but most businesses find some names creep in.
Can a small business negotiate changes to an AI vendor's DPA?
With the large AI vendors, rarely: their DPA is standard and forms part of the commercial terms. With smaller vendors, often yes, especially on breach notice times, sub-processor notice and deletion. Where you can't negotiate, the checklist still helps you decide whether the standard terms are acceptable or whether to choose another tool.
Is a SOC 2 report the same as a DPA?
No. A DPA is a contract setting out what the vendor may do with your data and what it must do to protect it. A SOC 2 report is an independent auditor's assessment of the vendor's security controls. A good DPA often points to SOC 2 or ISO 27001 reports as the evidence it will provide in place of an on-site audit.
What if the vendor's DPA and privacy policy disagree?
Contracts usually state which document wins in a conflict, and for business customers that is normally the DPA or commercial terms. Don't rely on that silently. Email the vendor, quote both passages, and ask which applies to your account. Keep the answer with your records, because it shows you checked.
Further reads
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How ChatGPT, Claude, Gemini and Copilot measure up on data protection.
- Questions to Ask an AI Vendor Before You Sign Anything — The wider set of questions to ask before signing anything.
- How to Stop AI Tools Training on Your Business Data — Switch off training in the tools your team already uses.
- How to Keep Customer Data Private When Your Team Uses AI — Day-to-day habits that keep customer data out of the wrong tools.
- How to Evaluate an AI Software Vendor: A Small Business Scorecard — Score a vendor on security, support and stability together.
- AI Software Contracts: Auto-Renewals, Price Rises, Notice Periods — The commercial terms that sit alongside the DPA.
- AI Literacy Requirements: What Your Staff Need to Know — A role-by-role checklist of what staff should know about AI, what Article 4 of the EU AI Act asks since the 2026 changes, and how to record it.
- AI Tool Approval Process: How Staff Request a New AI Tool — The request form staff fill in, the checklist the reviewer works through, and the three replies, so new AI tools get approved in days, not months.
- How to Mention AI Use in Client Contracts and Proposals — Sample proposal wording and contract clauses for disclosing AI use to clients, matched to how much AI touches the work, with an architect-practice example.
- Salon and Spa Software With Built-In AI: What to Compare — Five tests that separate useful salon and spa AI from a feature list, with September 2026 prices for Vagaro, GlossGenius, Boulevard, Mangomint and more.
- AI Booking Systems for Appointment Businesses: What to Check — A 24-point checklist for choosing an AI booking system, grouped by risk, with how to verify each item and a two-hour test script to run before you sign.
- Advice-Specific AI or ChatGPT: Which Should an Advice Firm Use? — What adviser-specific AI adds over a business ChatGPT plan, one meeting written up both ways, and how a four-adviser firm split its budget.
- Choosing a Mortgage CRM With AI Built In: What Actually Matters — A demo-ready checklist for mortgage CRMs with AI: document extraction, chasing, client-bank alerts, compliance logs, integrations and exit terms.
- AI Note Takers for Financial Advisers: Compliant Meeting Records — How advice firms set up AI note takers so every file note is checked, consented to, retained properly and able to survive a compliance review.
- AI Governance Checklist for Small Financial Advice Firms — Eight groups of checks, each with the evidence to keep, so a small advice firm can show how AI is approved, supervised and recorded.
- Is It Safe for an Accountant to Use ChatGPT With Client Data? — Which ChatGPT plans an accounting practice can defend for client data, what never goes in, and the engagement-letter wording to add.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Anthropic Data Processing Addendum and Anthropic's privacy help article on the DPA; OpenAI business data and data processing addendum pages; text of Article 28 of the GDPR; vendor notices on retention and default changes (Anthropic, SimplePractice), checked September 2026.