The recurring cost of the memo
Every new vendor arrives with a data processing agreement, and every DPA has to be checked against GDPR. Most in-house teams handle the pile the same way: send it to outside counsel, wait a couple of weeks, receive a memo. The work is careful and the bill reflects it - and the next DPA gets none of the benefit. The analysis is a snapshot; the cost repeats every time the portfolio moves.
There is another way to run the same review: as a playbook. You write your GDPR positions down once as a set of checks. Every agreement is reviewed against the same checks, and every verdict comes with the clause it was read from. The review becomes repeatable, and the money you spend on judgement stops being spent on reading.
The job that never really ends
If you run privacy in-house, the gap analysis is a standing obligation, not a project. Renewals arrive redlined. Supervisory guidance shifts. A sub-processor changes, a transfer mechanism stops holding up, and agreements you cleared last year need another look.
The questions are stable. Does the DPA list sub-processors and let you object to new ones? Does it commit to breach notification within a defined window? Does it cover international transfers with a real mechanism, and grant audit rights? The checklist is stable. The problem is running it, accurately and with sources, across a pile that keeps growing.
How PONS runs the analysis
Start with the playbook - your GDPR requirements written as one check per obligation, built from your own positions or adjusted from a template. Then point PONS at the documents. It reviews each DPA against the playbook and produces a gap table: the requirement in your words, what the agreement actually says - or that it says nothing - and what would close the gap.
Behind every finding is the source clause. When PONS says a DPA has no breach notification window, you open the exact language it read, or see that the section is absent. You are not taking the tool's word for it - you are checking its work.
Every row comes with the clause behind it, so deciding is fast.
The portfolio, not one contract at a time
The part that changes the job is running the whole set at once. The results read as a portfolio, which answers the questions leadership actually asks. Which vendors are missing breach notification terms? Where did we quietly give up audit rights? Sort by the gap instead of the document, and the ten agreements with the same missing clause line up together.
It also makes the recurring work manageable. A new vendor slots into the same table. When guidance shifts, adjust the playbook once and re-run the set. The analysis stops being a snapshot.
For the failures, PONS can suggest language to close each gap, with the legal basis attached - wording you can drop into the redline rather than draft from a blank page. You still edit it to fit the deal.
Where this leaves you
The outside-counsel memo described the work well: careful reading, mapped against a standard, written up with sources. PONS keeps that shape and changes who does the reading. You define the standard once, PONS runs it across the portfolio, and your time goes to the decisions that need a lawyer rather than to turning pages.