MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Having a Data Processing Agreement drafted for a software company by a specialized SME lawyer typically costs between €500 and €1,500 for a custom-made template, which you then reuse for all your clients. For a SaaS provider, this is often a sensible investment: you are the processor and bear the risk, and one good template covers your entire client portfolio. Below, you can read what the process entails, what information you need to provide, and when having it drafted pays off compared to doing it yourself.
The short answer
- Costs: €500 – €1,500 for a custom-made model from an SME lawyer.
- What you get: one reusable model that you close with every customer.
- Process: intake, mapping your technology and sub-processors, drafting, review, delivery.
- Lead time: usually one to two weeks.
- When useful: for special categories of data, many sub-processors, transfers outside the EEA, or customers imposing their own requirements.
Why have this drawn up as a software supplier?
Unlike a client who occasionally signs a data processing agreement, you, as a software company, enter into this agreement with virtually every business client. Therefore, a single good template has a wide reach: an error affects your entire portfolio, and a strong template saves disputes during every negotiation. This makes having one drafted more attractive than dealing with parties that rarely use the agreement.
Moreover, as the processor, you bear the risk. The client typically signs your model. If that model does not align with your hosting, sub-processors, or security, you are the one held accountable in the event of a data breach or audit. A legal expert who thinks from the processor's perspective ensures that the model is legally sound and executable.
What the process entails
Having a data processing agreement drawn up usually involves a few steps:
- Intake: the legal expert maps out what your software does, which personal data is processed by it, and for whom.
- Technology and sub-processors: you provide your hosting, cloud providers, email and backup services, and their locations.
- Security: you describe your actual measures (encryption, access control, backups) so that Article 32 is truthfully completed.
- Drafting: the legal expert writes the template with appendices (processing overview, security, sub-processors).
- Review and delivery: you discuss the concept, make adjustments, and receive a reusable final model.
What information you provide
The better your submission, the sharper the model. In any case, prepare:
- Data overview: which categories of personal data and data subjects your software affects, and whether any special categories of data are involved.
- Sub-processor list: all parties that process data on your behalf, including their establishment and data location.
- Data location: does everything run within the EU/EEA, or is something located outside (in which case a legal basis for data transfer is required)?
- Security measures: what you have actually implemented.
- Your general terms and conditions: so that liability aligns.
How much does it cost?
Prices vary with complexity:
- Standard model (ordinary data, common EU sub-processors): €500 – €1,000.
- Tailored solution with greater complexity (special categories of data, transfer outside the EEA, extended sub-processor chain): €1,000 – €1,500.
- Assessing a client model (when a large client imposes their own agreement on you): often on an hourly basis, a few hundred euros.
Weigh this against the reach: you use the same model for dozens or hundreds of customers. The costs per customer are then negligible, while the protection is extensive.
Do it yourself or have it drafted?
Having it drawn up pays off, especially in these situations:
- You process special personal data (healthcare, financial), which requires stricter security.
- You have sub-processors outside the EEA , and therefore transfer issues.
- Large clients impose their own models that you must evaluate or challenge.
- The liability and the connection to your terms and conditions are complex.
If you run a standard SaaS service with standard data and common EU sub-processors, you can often get by with a solid model that you have drafted or reviewed once, and then maintain yourself.
Practical example
A start-up with an accounting app grew rapidly and signed a data processing agreement for every customer using a template downloaded from the internet. When a major customer raised questions about the data location and sub-processors, it turned out the template did not align with the actual cloud setup. By having a custom template drafted just once—with an up-to-date list of sub-processors and a fair security appendix—the start-up was able to confidently present the same agreement to every customer from then on.
Honest recommendation
You do not always need to hire a lawyer. For a simple SaaS service involving ordinary personal data and known EU sub-processors, you can easily draft a data processing agreement yourself based on a reliable template, provided you complete the appendices honestly. Having one drafted is worth the investment as soon as you process special categories of data, use sub-processors outside the EEA, or have clients who set their own requirements. Because you reuse the template for all your clients, a one-time investment of a few hundred euros almost always pays for itself.
Want to know more? View the data processing agreement for a software company, read how to draft such an agreement and which pitfalls to avoid.
Frequently Asked Questions
Typically €500 – €1,500 for a custom-made, reusable template from a specialized SME lawyer. Standard templates are at the lower end; more complex situations involving special categories of data or transfers outside the EEA are at the higher end.
Usually one to two weeks, depending on how quickly you provide your data overview, sub-processor list, and security measures. A good submission significantly speeds up the process.
An overview of the personal data processed and data subjects, your list of sub-processors with data locations, whether everything operates within the EU/EEA, your actual security measures, and your general terms and conditions for the alignment of liability.
Yes, that is precisely the advantage. As a software supplier, you enter into a data processing agreement with virtually every business customer. One good model covers your entire portfolio; only the appendix regarding processed data may differ slightly per customer.
This applies especially to special categories of personal data, sub-processors outside the EEA, complex liability, or customers imposing their own model. For a simple SaaS service involving ordinary data and EU sub-processors, you can often manage on your own.
You then have them assessed on points that are risky for you as a processor: unrealistic deadlines, unlimited liability, or requirements that your technology cannot handle. This is usually done on an hourly basis and costs a few hundred euros.
Yes. If your hosting, sub-processors, or security changes, you must update the model. The list of sub-processors and the data location, in particular, must remain up-to-date, as an outdated list is a common source of problems during an audit.