GDPR and NDA Review: What EU Founders Should Check
Processing personal data under NDAs triggers GDPR considerations — controller roles, subprocessors, transfers, and retention in EU NDA review.
An NDA is not a Data Processing Agreement. When personal data flows under a commercial relationship, GDPR applies separately.
Controller vs processor
Identify who determines purposes and means of processing employee or customer data shared under the NDA.
When you need a DPA
If you process personal data on behalf of a counterparty (or they process yours), a DPA is required — the NDA alone is insufficient.
International transfers
US counterparty + EU data may need SCCs or adequacy analysis. Jurisdiction clauses do not replace transfer tools.
Retention and return
GDPR storage limitation should align with NDA survival — not contradict it.
Subprocessors
List approved subprocessors in the DPA exhibit, not buried in a 40-page security schedule.
AI review tools
Verify where document text is processed and retention period. NDAShield deletes uploads after text extraction for analysis.
Checklist
- Is personal data in scope?
- Is there a DPA?
- Are transfers lawful?
- Does survival match GDPR retention?
Upload NDAs for clause flags; consult DPO or counsel for regulatory interpretation.