A DPA is not a form you file so that it is filed. It is where you write down what a vendor may do with your recordings and what it may not. For transcription that means voice recordings, which is one of the most revealing categories of data there is: a voice is a biometric identifier, a meeting recording carries names, opinions and commercial secrets, and a clinical conversation carries health data under Article 9.
This article walks the mandatory content of Article 28(3), names the places where transcription vendors' agreements come apart in practice, and ends with a checklist you can run during a vendor assessment.
When you need a DPA, and when you already should have had one
You need one as soon as a vendor processes personal data on your behalf and on your instructions. With transcription that is the normal case: you decide which recording gets processed and why, the vendor executes.
Three misconceptions are remarkably durable.
"We only use the free tier." Price is irrelevant to Article 28. A free tool that you upload a meeting recording into is processing personal data on your behalf. Without a DPA that processing has no lawful basis, whether money changed hands or not.
"It was one interview." Article 28 has no de minimis threshold. A single recording is enough.
"The vendor says it is GDPR compliant." A self-declaration is not a contract. Article 5(2) puts the burden of demonstrating compliance on you as controller, and in an inspection you produce the agreement, not a screenshot of a landing page.
There is a case where a DPA is the wrong instrument entirely. If the vendor determines the purposes of the processing itself, for instance by using your recordings to train its own models, then for that activity it acts as a controller in its own right. Article 28(10) is explicit about it. So an agreement that grants the vendor training rights no longer describes the arrangement it purports to govern. That combination appears in more contracts than you would expect, usually inside a clause about "improving the services".
The mandatory content of Article 28(3)
The contract must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subjects, plus the controller's rights and obligations. And it must bind the processor to ten points.
| # | Obligation | What it means for transcription |
|---|---|---|
| 1 | Process only on documented instructions (a) | Transcribe yes, mine for the vendor's own purposes no. Third-country transfers only on instruction or legal obligation |
| 2 | Confidentiality of authorised persons (b) | Everyone with access is under a confidentiality obligation, administrators included |
| 3 | Security measures under Article 32 (c) | Encryption in transit and at rest, access control, logging. As a list of measures, not a statement of intent |
| 4 | Sub-processors only per (2) and (4) (d) | A list by name, advance notice of changes, a right to object |
| 5 | Assist with data subject rights (e) | Access, erasure, portability: the vendor has to be technically able, not merely willing |
| 6 | Assist with Articles 32 to 36 (f) | Breach notification, contributions to a data protection impact assessment |
| 7 | Delete or return at the end (g) | With a deadline, and including backups. "After termination" without a number is not a deadline |
| 8 | Provide information and allow audits (h) | An audit right, in practice usually satisfied through certifications and reports |
| 9 | Flag unlawful instructions (28(3), final sentence) | The vendor must tell you if your instruction breaches data protection law |
| 10 | In writing, electronic form suffices (28(9)) | Signing online is fine. A mention in the terms of service is not a DPA |
… deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.
That clause is the litmus test for a transcription vendor, because two things sit inside it that vendors like to keep apart: the audio file and the transcript. An agreement that promises deletion of "uploaded files" leaves the transcript untouched, and the transcript is the content that matters.
Where transcription vendors' agreements come apart
Read enough of the agreements circulating in this market and five patterns repeat.
Blanket consent to sub-processors
The clause reads roughly: "The processor may engage sub-processors; a list is made available on the website and may be updated at any time." That is the general authorisation under Article 28(2), and it is permitted, but only together with what the rest of the provision requires: notice of intended changes in advance, and a chance to object. Without both, you are signing a chain whose future links you will not see.
Model training as "service improvement"
Phrases like "to improve and develop the services" or "in aggregated and anonymised form" deserve a careful read. With voice recordings anonymisation is hard in practice, because the voice itself is the identifier. If a vendor wants your recordings for training, that is not processing on your behalf; it is the vendor's own processing, for the vendor's own purpose.
Deletion without a deadline
"Data will be deleted after termination of the contract" satisfies (g) on its face and cannot be verified. A usable clause gives a number, a trigger and a statement about backups: how many days, counted from which event, and when the copies follow.
Technical measures written as marketing
Annexes listing "state-of-the-art encryption" and "modern security architecture" describe nothing. Article 32 asks for measures appropriate to the risk, and for voice recordings the risk is high. An annex becomes checkable only with procedures and places: encryption in transit and at rest, who has access, how that access is logged, which data centre the data sits in.
The server location in the contract, the vendor in the United States
The most common pattern in this market: the DPA names a European hosting location while the sub-processor list names a US group. For the transfer question what counts is not where the bits are but who can reach them, which is what *Schrems II* turned on. Treated at length in GDPR-compliant meeting transcription for Zoom and Teams.
Sub-processors: the chain you co-sign
Article 28(4) imposes on every further processor the same obligations your counterparty carries. Externally your counterparty stays liable to you; internally it has to pass down what it promised.
In practice you are not assessing a vendor, you are assessing a chain. With a transcription service it usually has three links, and the third is where it gets interesting.
- Hosting for the application, database and files.
- Payments, if there is billing. For payment data, not content.
- The speech recognition itself. Does the vendor run it, or does it call a third-party API? This is where it is decided whether your recordings reach yet another company, and this is where the list is most often incomplete.
The question fits in one line: "Does any third party process our audio or transcripts, and if so, which one?" A vendor who will not answer by name has answered.
Third-country transfers: the DPA alone does not carry it
A DPA governs the relationship between controller and processor. Once processing leaves the EU, Chapter V applies on top, and that is a second, independent assessment: an adequacy decision, standard contractual clauses under Implementing Decision (EU) 2021/914, or another safeguard, plus an evaluation of whether the safeguard actually works in the destination country.
For voice recordings the cheaper route is usually to avoid the transfer rather than justify it. That is not legal timidity, it is effort arithmetic: a transfer impact assessment is work that has to be redone every time the legal position moves.
Professional secrecy is national, Article 28 is not
Article 28 applies identically across the EU. Professional secrecy does not, and where it applies it sits on top of data protection law with a different enforcement mechanism, often criminal rather than administrative.
Germany is the sharpest example: § 203 of the Criminal Code makes disclosure by a doctor, lawyer or tax adviser a criminal offence, and since a 2017 reform it permits involving IT service providers only under conditions, including a separate confidentiality undertaking from the provider. France has *secret professionnel*, Austria and Switzerland have their own equivalents, and lawyers everywhere have bar rules that outrank vendor paperwork.
The practical consequence for buyers in a regulated profession: your vendor's DPA, however good, does not by itself discharge these duties. You need the additional undertaking. Sector detail in Law firm transcription: privilege and GDPR and Medical dictation and confidentiality, plus the industry pages for law firms and medical and pharma.
A checklist for the vendor assessment
Ten questions answerable before a decision, each with an answer that lives in a document.
- Is a DPA available for signature before first use, without a sales call?
- Does it cover all ten points of Article 28(3)?
- Is there a sub-processor list, by name, in or attached to the agreement?
- Does it commit to advance notice and a right to object when that list changes?
- Is the speech recognition operated by the vendor, or does it run through someone else's API?
- Does the deletion clause state a deadline, a trigger and the treatment of backups?
- Does it cover audio files and transcripts?
- Does the agreement expressly rule out training on your data?
- Does the security annex describe procedures and places rather than adjectives?
- Under normal use, does anything leave the EU at all?
Question 5 is the most informative, because it cannot be answered evasively and because it largely determines the answers to 3, 4 and 10.
How DeepScript handles it
The DPA can be signed online, in the trust centre, with a form and a PDF, no prior conversation. The sub-processor list is published with purpose, location and safeguards on its own page, the processing activities are described under data processing and the technical measures under security.
On question 5: the speech recognition runs on our own infrastructure in data centres in Germany. No third party processes audio or transcripts, and customer data is not used for model training. Both are in the contract, not only on this page.
On deletion: without a Pro subscription, transcriptions are deleted automatically after the default retention period, audio file included; the period is configurable in the account and stated as a number in the trust centre. With Pro they are kept, because the purpose is then a different one: a searchable archive that AI agents can query too.
None of that is an argument against doing your own assessment. It is a statement that the ten questions above are answerable here without anyone having to ask.