LatestContext is everything in the age of legal AIRead the article
Use case · 3 min read

GDPR gap analysis in hours, not weeks

Reviewing data processing agreements against GDPR used to be a two-week job for outside counsel. Here is how an in-house team can run it in an afternoon - every verdict sourced.

Sebastian Melbye · 2 June 2026

The recurring cost of the memo

Every new vendor arrives with a data processing agreement, and every DPA has to be checked against GDPR. Most in-house teams handle the pile the same way: send it to outside counsel, wait a couple of weeks, receive a memo. The work is careful and the bill reflects it - and the next DPA gets none of the benefit. The analysis is a snapshot; the cost repeats every time the portfolio moves.

There is another way to run the same review: as a playbook. You write your GDPR positions down once as a set of checks. Every agreement is reviewed against the same checks, and every verdict comes with the clause it was read from. The review becomes repeatable, and the money you spend on judgement stops being spent on reading.

The job that never really ends

If you run privacy in-house, the gap analysis is a standing obligation, not a project. Renewals arrive redlined. Supervisory guidance shifts. A sub-processor changes, a transfer mechanism stops holding up, and agreements you cleared last year need another look.

The questions are stable. Does the DPA list sub-processors and let you object to new ones? Does it commit to breach notification within a defined window? Does it cover international transfers with a real mechanism, and grant audit rights? The checklist is stable. The problem is running it, accurately and with sources, across a pile that keeps growing.

Every document, every requirement Your agreementsYour rules, appliedGaps, ranked

How PONS runs the analysis

Start with the playbook - your GDPR requirements written as one check per obligation, built from your own positions or adjusted from a template. Then point PONS at the documents. It reviews each DPA against the playbook and produces a gap table: the requirement in your words, what the agreement actually says - or that it says nothing - and what would close the gap.

Behind every finding is the source clause. When PONS says a DPA has no breach notification window, you open the exact language it read, or see that the section is absent. You are not taking the tool's word for it - you are checking its work.

Every row comes with the clause behind it, so deciding is fast.

The portfolio, not one contract at a time

The part that changes the job is running the whole set at once. The results read as a portfolio, which answers the questions leadership actually asks. Which vendors are missing breach notification terms? Where did we quietly give up audit rights? Sort by the gap instead of the document, and the ten agreements with the same missing clause line up together.

It also makes the recurring work manageable. A new vendor slots into the same table. When guidance shifts, adjust the playbook once and re-run the set. The analysis stops being a snapshot.

For the failures, PONS can suggest language to close each gap, with the legal basis attached - wording you can drop into the redline rather than draft from a blank page. You still edit it to fit the deal.

Where this leaves you

The outside-counsel memo described the work well: careful reading, mapped against a standard, written up with sources. PONS keeps that shape and changes who does the reading. You define the standard once, PONS runs it across the portfolio, and your time goes to the decisions that need a lawyer rather than to turning pages.

See it on your own documents

Legal work,delivered with PONS.