AI Translation Vendor DPA Questions: A Buyer’s Checklist

Use this AI translation vendor DPA checklist to examine model training, subprocessors, retention, transfers, security, breach notice, and audit terms before you sign.

Also in: EN UK RU
AI Translation Vendor DPA Questions: A Buyer’s Checklist

An AI translation vendor can process more than the file you upload: extracted text, prompts, outputs, corrections, support attachments, and operational logs may all enter the service’s data flow. If your team handles personal or confidential material, a DPA that says only “provide translation services” leaves too many practical questions unanswered.

A data processing agreement, or DPA, sets the terms for a processor handling personal data on a controller’s behalf. Before signing, map the translation workflow, ask who handles each data type and where, then check that the contract matches the vendor’s real product and settings. The GDPR’s Article 28 requirements provide the baseline; AI-specific questions make that baseline usable for a translation service.

Start with the processing the contract actually describes

A processor DPA should describe the work in enough detail that both sides can tell what the vendor is allowed to do. Article 28(3) of the GDPR requires the contract to state the subject matter and duration of processing, its nature and purpose, the types of personal data, the categories of data subjects, and the controller’s rights and obligations.

For translation, a generic phrase such as “hosting and provision of the service” may not tell you whether the vendor receives an original document, extracts its text, sends that text to an AI inference provider, stores a translation, or allows a human reviewer to see the content. Ask the vendor to describe those operations in the DPA or a linked processing annex.

Start by writing down your own expected use. A team translating employment contracts has different data and confidentiality concerns from one translating public product descriptions. A document may contain names, contact details, financial information, health information, or information about children. The vendor needs a clear scope, and your team needs to know whether the service is permitted for that material.

Ask the vendor to answer these points in writing:

  1. What is the purpose of each processing step? Separate document intake, text extraction, translation, quality checks, customer support, and service analytics.
  2. Which data types can enter each step? Include files, extracted text, prompts, outputs, correction requests, feedback, account details, and logs.
  3. Who are the data subjects? Employees, customers, applicants, patients, or other groups may appear in the documents.
  4. How long does each processing activity last? The service term and the retention of stored content are related, but they are not identical.
  5. Which actions does the vendor take only on your instructions? Distinguish those from any separate processing the vendor performs as an independent controller, such as account administration or legal compliance.

A useful DPA annex should describe translation-specific processing, not merely repeat the name of the service. The contract should also make clear which document controls if the DPA, product terms, privacy notice, and in-product settings say different things. If a product setting changes whether submitted material is retained or used for an additional purpose, the contract should explain how that setting affects the vendor’s obligations.

The UK Information Commissioner’s Office describes the Article 28 contract terms as a minimum that controllers and processors can supplement. As the ICO puts it, “[t]hese are the minimum required, but the controller and processor may agree to supplement them with their own terms” in its contract guidance. Translation-specific clauses are a sensible supplement when generic terms do not answer what happens to prompts, corrections, or source files.

The practical test is simple: could a colleague read the annex and understand what happens to a document from upload through deletion? If not, ask for a workflow description before treating the DPA as complete.

Ask exactly what happens to content in model training

“Do you train on customer data?” sounds like a clear question, but a short “no” can leave important categories undefined. Ask about each type of material and each possible use. The vendor should state separately whether it uses source files, extracted text, prompts, translations, corrections, feedback, or metadata for model training, fine-tuning, evaluation, or service improvement.

The key distinction is between processing needed to provide the translation you requested and additional processing for the vendor’s own purposes. Under Article 28(3)(a), a processor acts on documented controller instructions unless applicable law requires otherwise. The GDPR text is the legal starting point; a vendor’s general privacy statement does not tell you whether a particular product setting or term permits a particular use.

Use questions that force a specific answer:

  • Does the service use uploaded originals to train or fine-tune a model?
  • Does the answer differ for extracted text, prompts, translations, or corrections?
  • Does the vendor use user feedback or ratings for evaluation or service improvement?
  • Does the answer change if a user switches a setting, joins a beta, or submits a support request?
  • Can the vendor identify the terms and settings that apply to the product your team will use?
  • Does a model provider receive customer content, and, if so, what limits apply to that provider?
  • Can the vendor confirm that content will not be used for an additional purpose unless you give a separate documented instruction?

Ask the vendor to turn its answer into contract language or identify the binding product terms that do so. A sales email or a general statement about privacy may not bind the processing flow for the service you are buying. Check that the DPA, service terms, and actual account settings agree.

A workable clause should name the relevant data categories and uses. For example, a clause might prohibit use of customer content for training, fine-tuning, evaluation, or service improvement unless the controller gives a separate documented instruction. The wording needs review against your contract and the vendor’s actual technical setup; the point is to avoid leaving “customer data” or “service improvement” undefined.

Also ask whether a human can review content. A vendor may use people for support, abuse investigation, quality review, or troubleshooting. Ask which roles can see submitted text, what confidentiality commitments apply, and whether the vendor records or limits that access. Article 28(3)(b) requires people authorized to process personal data to be bound by confidentiality or an appropriate statutory duty, as set out in the GDPR.

A typical snag appears when a procurement team approves “no model training,” while a product team later enables a feedback feature that sends corrections for evaluation. The contract and controls should make the boundary clear before use, rather than leaving staff to infer it from a toggle label.

Get the full subprocessor chain, not just the hosting company

An AI translation service can rely on multiple providers. A cloud host may store files, a model provider may handle inference, and a support platform may receive an attachment during troubleshooting. Ask the vendor to identify every provider and recipient that handles customer content, state each party’s role, and list where processing or access can occur.

Article 28(2) of the GDPR requires prior specific or general written authorization before a processor engages another processor. If the vendor relies on general authorization, the contract must describe how it will tell you about intended additions or replacements and give you an opportunity to object.

Request a subprocessor annex with enough detail to make that authorization meaningful:

What to request What a useful answer tells you
Provider name and role Whether the party hosts files, performs AI inference, provides support, or handles another defined task
Data categories received Whether the provider can receive originals, extracted text, prompts, outputs, or account data
Processing and access locations Where the provider stores, accesses, or receives the content
Change process How the vendor gives notice of a new or replacement provider
Objection process How you object, how much notice you receive, and what happens if the issue remains unresolved
Contractual flow-down Whether the provider must meet the relevant data-protection obligations

A vague promise to “use trusted service providers” does not identify recipients or locations. Ask for the list in the DPA or a referenced annex, and make sure the vendor will keep it current. The EDPB’s Opinion 22/2024 says a list of approved subprocessors should be included in the contract or annex and kept up to date when approved at signing.

The first processor remains accountable to the controller for its subprocessor’s performance under Article 28(4). The vendor should impose the same data-protection obligations on its subprocessors by contract. Ask for written confirmation of that flow-down, rather than assuming the model provider’s standard terms automatically match your DPA. The EDPB opinion discusses those obligations and the processor chain.

The objection mechanism deserves careful reading. “You may object” is incomplete if the agreement does not say how notice arrives, how long you have to respond, or what happens if the vendor cannot offer a reasonable alternative. Ask whether you can stop using the affected feature or terminate the relevant service without being forced to accept a new recipient.

The European Data Protection Board says controllers should be able to determine processing purposes and means effectively, and describes recipients, including processors, as an essential means. See EDPB Opinion 22/2024.

For a translation buyer, that makes a recipient list more than an administrative attachment. The list helps you assess whether a model provider, hosting location, or support channel fits your use case before documents enter the service.

Set retention and deletion terms by data type

“Deleted when the account closes” is not a retention schedule. Ask how long the vendor keeps every category of content and what event starts the clock. An original file, extracted text, translation, support attachment, and security log may follow different schedules.

Request a table that covers at least these categories:

Data type Questions to put to the vendor
Uploaded originals When does the vendor remove the file, and can an authorized user delete it earlier?
Extracted text Is the extracted text stored separately after translation finishes?
Prompts and context Does the vendor retain instructions, glossary terms, or other context submitted with a job?
Translations and corrections Can outputs or edited text remain in a job history, and how can they be removed?
Feedback and support attachments Are attachments retained in a separate support system, and who can access them?
Operational and security logs Which content or identifiers do logs contain, and what is their separate schedule?
Caches and backups How does deletion reach replicas, caches, and backups, and when does the next destruction cycle run?

Article 28(3)(g) requires the processor, at the controller’s choice, to return or delete personal data at the end of processing and delete existing copies unless applicable law requires storage. The ICO explains this obligation in its contract guidance. Ask for the deletion method, completion timeline, usable export format, and confirmation you can retain for your records.

Backups need a clear answer of their own. Immediate removal from every backup or archive may not be practical, but the vendor should explain the cycle and how it prevents restored data from returning to active use. ICO guidance describes safeguards such as putting data beyond use and deleting it as soon as possible on the next destruction cycle. Ask the vendor to state whether that approach applies and how it handles a restore.

A contract should also separate ordinary retention from a legal hold. If a law requires the vendor to keep particular records, ask which data is affected, why it must remain, who can access it, and when the legal restriction ends. Avoid wording that lets a general “business needs” exception swallow the deletion promise.

Before signature, run through one ordinary job and one offboarding scenario. For a normal job, ask when the original, extracted text, prompt, and output are removed. For offboarding, ask whether your team chooses return or deletion, how it gets the export, what happens to derived copies, and what proof of deletion the vendor supplies. A schedule that cannot answer those questions needs more detail.

Map transfers and access across every location

A statement that a vendor’s main data center is in the EEA does not tell you where every operation takes place. Ask which countries host, access, or receive content, including model inference, support access, troubleshooting, and subcontractor operations. Documented instructions under Article 28 need to cover transfers to third countries, so the DPA should reflect the real flow, not just the primary hosting region. See the GDPR.

For each recipient outside the EU or EEA, ask the vendor to identify the transfer mechanism and provide the completed transfer details. The European Commission explains that its modernized transfer Standard Contractual Clauses, or SCCs, apply to transfers from EU or EEA controllers or processors subject to the GDPR to recipients outside the EU or EEA that are not themselves subject to the GDPR. The Commission’s SCC page describes the mechanism.

Do not accept “we use SCCs” as the whole answer. Ask which recipient receives the data, which SCC module applies to the relationship, which data and transfer are covered, and whether the completed annexes identify the actual parties and processing. The transfer terms should match the specific recipient and service path.

A separate document can create a separate legal job. Commission Implementing Decision 2021/915 contains controller-processor clauses under GDPR Article 28. Those clauses are not the same thing as the Chapter V transfer SCCs. The Commission decision says the Article 28 clauses cannot be used as Chapter V transfer SCCs; check the decision text rather than treating the acronym as proof that a transfer is covered.

Ask whether the vendor has assessed the destination country and whether supplementary measures are needed. The EDPB Recommendations 01/2020 tell exporters to check whether safeguards work effectively in practice and discuss supplementary measures or suspension in specified risk circumstances. Request the relevant assessment or a clear explanation of how the vendor handles it.

A practical transfer table can expose gaps quickly:

Data path Recipient Location or access country Mechanism Evidence to request
File storage Hosting provider Vendor must specify Vendor must identify Subprocessor entry and transfer details
AI inference Model provider Vendor must specify Vendor must identify Provider role, terms, and transfer assessment
Support Support provider or staff Vendor must specify Vendor must identify Access controls and location details
Security operations Monitoring provider Vendor must specify Vendor must identify Data fields in logs and applicable safeguards

If the vendor cannot map a path because its provider can route requests dynamically, ask how it limits that routing and how it will notify you when the set of recipients or locations changes. A location answer should cover access as well as storage.

Check security, confidentiality, and incident response

A DPA needs a security commitment tied to the service’s risks, not just a link to a security page. Article 28(3)(c) requires contractual security measures meeting Article 32. The ICO states that “the contract must oblige the processor to take all security measures necessary to meet the requirements of Article 32 on the security of processing” in its guidance.

Ask what the vendor does to protect the actual translation workflow:

  • How does the service restrict staff and contractor access to files?
  • What confidentiality commitments apply to support personnel and human reviewers?
  • How does the vendor protect data in transit and at rest?
  • How does it separate customer workspaces or accounts?
  • What controls apply to model-provider connections and support attachments?
  • How does the vendor test the security measures and address findings?
  • What continuity and restoration arrangements apply if the service is disrupted?

Request evidence that fits your risk, such as a relevant independent report or a description of controls and remediation processes. A certification logo alone does not show whether prompts, files, or support access fall within the scope you care about. Ask what the evidence covers, when it was assessed, and whether relevant subprocessors are included.

Confidentiality deserves its own clause. Article 28(3)(b) requires authorized people to be under a confidentiality commitment or an appropriate statutory duty. Confirm that the obligation covers employees, contractors, support staff, and any human reviewers who may see submitted text. Also ask whether access is limited to a defined reason, recorded, and removed when no longer needed.

Breach reporting must give your team time and information to respond. The processor should notify the controller without undue delay, and the DPA should name an operational notification target and a contact route. The contract should also say what the first notice includes, how updates arrive, and how the vendor supports investigation and remediation. See Articles 33(1) and 33(2) of the GDPR.

Keep the deadlines distinct: the GDPR’s 72-hour period concerns the controller’s notice to a supervisory authority where feasible after becoming aware of a personal-data breach. That is not the processor’s notification period. A vendor clause that simply repeats “within 72 hours” can leave a controller waiting for information needed to assess its own duties.

A useful incident clause should cover at least the initial notification, known facts, affected data and systems, likely consequences where known, mitigation, investigation updates, and a contact who can answer follow-up questions. The vendor may not know every detail at first notice; the contract can require updates as facts become available.

Confirm assistance, audits, and exit rights

A processor DPA is also an operating agreement for requests and audits. Article 28(3) requires assistance with data-subject rights and with the controller’s compliance obligations, including security, breach response, impact assessments, and prior consultation where required. The ICO summarizes these requirements in its contract guidance.

Ask how the vendor will search for content linked to a person, export it, correct it, restrict processing, or delete it. A translation workflow may not index a person’s name in the same way as a customer database. Ask whether the vendor can search job history, stored files, support tickets, and relevant logs, and what response times it commits to. The contract should say how the vendor helps you answer a rights request without making the controller guess which system holds the relevant copy.

The audit clause should let you obtain information needed to demonstrate compliance and allow or contribute to audits, including inspections. Article 28(3)(h) sets that baseline. Ask about notice, scope, frequency, confidentiality, cost allocation, independent reports, remediation plans, and access to relevant subprocessor evidence. The ICO guidance explains the processor’s information and audit obligations.

A vendor may offer independent reports as the first step before an on-site inspection. That can be a workable process if the contract still allows a meaningful audit when the report does not answer a material question, a serious incident occurs, or a regulator requires further evidence. Read exceptions carefully. A clause that limits every review to a vendor-selected report may not give you the access the contract promises.

At contract end, the controller must be able to choose return or deletion, subject to legal retention requirements. Confirm that the export is in a usable format, that it includes the content you need, and that the vendor will delete remaining copies and provide confirmation. Article 28(3)(g) and the ICO’s contract guidance are the reference points.

For teams that need a review workflow as well as translation, the ChatsControl document tool includes optional auto-delete and retention settings. That can help address how long uploaded documents remain in the product, but it does not replace your organization’s DPA review: check the applicable terms, settings, subprocessors, and transfer details before uploading sensitive material. The service is cloud-based, so it is not a fit for an organization that requires an offline or on-premise translation tool.

A pre-signature checklist for procurement and privacy teams

Use this checklist in the vendor meeting, then attach the vendor’s written answers to your contract review. A “yes” without a named document, setting, or contractual clause is a prompt for follow-up, not a finished answer.

Review area Ask before signature Evidence or contract result
Processing scope Does the annex describe upload, extraction, translation, review, support, and service operations? Translation-specific processing description
Model use Are originals, text, prompts, outputs, corrections, feedback, and metadata used for training or improvement? Explicit allowed and prohibited uses
Instructions Which actions follow documented controller instructions, and which are separate controller activities? Clear role and purpose descriptions
Subprocessors Which providers handle content, and what does each provider do? Current named list and role descriptions
Changes How will new or replacement providers be announced, and how can you object? Notice, objection, and unresolved-objection process
Locations Where are content stored, accessed, and sent for inference or support? Data-flow and location details
Transfers Which transfer mechanism covers each recipient outside the EU or EEA? Completed transfer information and assessment
Retention How long are originals, text, prompts, outputs, feedback, logs, caches, and backups held? Schedule by data type and deletion event
Security What access, confidentiality, resilience, restoration, and testing measures apply? Contract commitment and risk-appropriate evidence
Incidents How will the vendor notify you and support investigation? Contact route, operational target, and update process
Rights requests How will the vendor locate, export, correct, restrict, or delete relevant content? Assistance process and committed response times
Audit What information and access can you obtain, including subprocessor evidence? Audit terms, report process, and remediation duties
Exit Can you choose return or deletion and obtain usable exports and confirmation? End-of-contract steps and backup treatment

Keep a record of open issues and assign each one to the person who can resolve it. Legal may review the transfer terms, security may examine control evidence, and the product owner may need to confirm which settings the team will use. Do not treat an answer from one group as proof that another part of the service follows the same rule.

One frequent contract trap is a DPA that describes the vendor as a processor while the service terms permit broad use of content for “improving services.” Another is a detailed hosting answer that omits model inference or support access. A third is a deletion promise that covers active files but says nothing about logs, backups, or derived copies. Compare the DPA, product terms, privacy notice, and settings against the same workflow so that mismatches surface before a real document enters the service.

An AI Act compliance statement does not close those gaps. The European Commission describes the AI Act as a risk-based framework for AI developers and deployers. GDPR processor-contract requirements remain separately relevant when personal data is processed on your behalf. Ask for the DPA and assess its terms on their own.

FAQ

What should an AI translation vendor DPA include?

A DPA should describe the translation processing and cover documented instructions, confidentiality, security, subprocessors, assistance, end-of-contract handling, and audits under GDPR Article 28. Add clear terms for model use, retention, transfers, and service-specific data flows.

Can an AI translation vendor use uploaded documents to train its models?

The answer depends on the vendor’s actual terms and settings. Ask separately about originals, extracted text, prompts, translations, corrections, feedback, and metadata, then put the agreed limits in the DPA or binding product terms.

What should I ask about AI translation vendor subprocessors and model providers?

Ask for each provider that handles customer content, its role, processing and access locations, and whether it is a subprocessor. Confirm written authorization, notice and objection terms for changes, and contractual data-protection obligations throughout the chain.

How long can a translation vendor retain source files, prompts, and outputs?

There is no single period that applies to every vendor or data type. Request a schedule for originals, extracted text, prompts, outputs, feedback, logs, caches, and backups, plus the deletion cycle, end-of-contract choice, and deletion confirmation.

What transfer safeguards should an AI translation vendor provide for data sent outside the EEA?

Ask which recipients receive or access content, which transfer tool covers each recipient, and whether a transfer assessment or supplementary measures are needed. A primary data center in the EEA does not answer where model inference or support access occurs.

Does an AI Act statement replace a GDPR DPA?

No. The AI Act and GDPR address different issues. If a vendor processes personal data on your behalf, review its processor terms under GDPR Article 28 separately.

What breach-notification period should an AI translation vendor promise?

The processor should notify the controller without undue delay, with a practical contact route, operational target, and incident details in the contract. The GDPR’s 72-hour supervisory-authority deadline applies to the controller where feasible; it is not the processor’s notification period.

Try ChatsControl

AI platform for professional translators

Try for free →