figma guide
Designing data processing agreements and subprocessor management UI in Figma: DPA workflows, change notices, and customer approvals
Design DPA and subprocessor management UI in Figma with agreement templates, customer acceptance flows, subprocessor registries, change notifications, and Legal review queues.
- Published
- Updated
- Jul 31, 2026
- Read time
- 9 min
- Level
- Intermediate
Quick answer
Data processing agreement (DPA) and subprocessor management UI is how B2B SaaS meets GDPR Article 28 obligations—publish current subprocessors, notify customers before changes, and track DPA acceptance without Legal living in email. Design a subprocessor registry with categories, data types, and residency; a change notification workflow with objection windows and audit trails; a customer DPA portal with versioned agreements and e-signature or click-wrap acceptance; and an admin Legal queue for template updates and enterprise redlines. Start from the Figma guides hub and pair with trust center, privacy settings, vendor risk, compliance exports, and Dev Mode handoff.
Who this is for
- Product designers building privacy compliance modules, enterprise onboarding, or public trust pages with DPA workflows.
- Design system teams aligning subprocessor tables, legal document cards, and acceptance modals with tables, forms, and badges.
- Legal, privacy, and customer success teams managing subprocessors, DPA versions, and customer objection periods.
DPA hub (internal overview)
DPAHub — Acme SaaS · DPA v3.2 effective 2026-04-01 · Subprocessors: 47 active
├── Header: Pending customer acceptances 12 · Open change notices 2 · Legal review 1
├── Actions: [ Publish subprocessor update ] [ New DPA version ] [ Export acceptance log ]
├── Tabs: Subprocessors · Change notices · DPA versions · Customer acceptances · Templates · Settings
├── Alert: AWS Lambda added as subprocessor · Objection window ends 2026-08-14 · 3 enterprise holds
├── Banner: DPA v3.3 draft in Legal review · Target effective 2026-09-01
└── Link: [Trust center subprocessor page](/designing-trust-center-and-security-documentation-ui-in-figma/) · Vendor risk · Privacy settings
| Section | Purpose |
|---|---|
| Subprocessors | Master registry with purpose, data, residency |
| Change notices | Add/remove/update with customer notification |
| DPA versions | Template history and effective dates |
| Customer acceptances | Per-tenant signed or click-wrap status |
| Templates | Standard, HIPAA, EU SCC variants |
| Settings | Objection window length, notification channels |
Verdict: DPA hub is Legal source of truth—public trust center subprocessors and customer-facing DPA links must sync from here, never from a static Notion page.
Subprocessor registry
SubprocessorRegistry — 47 active · Last published to trust center 2026-07-01
├── Stripe · Payments · PCI scope · US + EU · [Vendor risk: Low ]
│ ├── Data categories: Billing name, card token (via Stripe), email
│ ├── DPA: Stripe DPA 2024-01 · Link to signed copy
│ └── Status: Active · Added 2023-06-01 · No pending changes
├── AWS · Infrastructure · Hosting · US-East, EU-West, ap-southeast-1
│ ├── Data categories: All customer content at rest
│ ├── SCCs: Module 2 · Transfer mechanism documented
│ └── Status: Active · Review due 2026-12-01
├── New: Datadog · Observability · Logs may contain IPs · US only
│ ├── Status: Pending change notice · Effective if no objections 2026-08-14
│ └── Linked: [Change notice CN-2026-07-001]
└── Filter: [ Pending publish ] [ Review overdue ] [ Removed archived ]
| Registry field | UI detail |
|---|---|
| Vendor name | Legal entity; link to vendor risk record |
| Purpose | Plain-language processing purpose |
| Data categories | Personal data types processed |
| Location / residency | Regions; transfer mechanism if cross-border |
| Status | Active, pending notice, removed, archived |
| DPA reference | Link to vendor DPA or SCC module |
| Last reviewed | Annual review cadence for Legal |
Use table patterns with sort by status and residency. Removed subprocessors stay in archive with removal date—customers may need historical DPA snapshots.
Every subprocessor row should link to vendor risk when your product has both modules—Legal and Security should see the same vendor identity.
Change notification workflow
ChangeNotice — CN-2026-07-001 · Add Datadog as subprocessor
├── Change type: Add · Effective date: 2026-08-14 (30-day objection window)
├── Summary: Application performance monitoring; logs may contain IP addresses
├── Comparison: Before 46 subprocessors → After 47
├── Customer notification: Email + in-app banner for admins · Sent 2026-07-15
├── Objection handling:
│ ├── No objection (default): Auto-accept after window
│ ├── Objection received: Flag account · CS + Legal thread · Termination path if required
│ └── Enterprise custom DPA: Manual review required before effective
├── Enterprise holds: 3 accounts require explicit re-acceptance · Block auto-effective
└── [ Publish to trust center ] [ Extend window ] [ Cancel change ] [ View audit log ]
| Change type | Notification pattern |
|---|---|
| Add subprocessor | Full notice with purpose, data, location |
| Remove subprocessor | Lighter notice; migration note if data deleted |
| Replace vendor | Old → new mapping; data migration timeline |
| Location change | Highlight residency shift; SCC update if needed |
| Purpose expansion | Emphasize new data categories |
Design objection window countdown using badges—“12 days remaining” on admin dashboard and in-app inline alerts.
Enterprise accounts with custom DPAs must never auto-accept subprocessors—show blocked state until Legal marks reviewed.
Customer DPA portal
CustomerDPA — acme-corp · Tenant ID 8842 · Plan: Enterprise
├── Current DPA: v3.2 · Accepted 2026-04-15 by jane@acme-corp.com · IP logged
├── Status: Current · Subprocessor notice CN-2026-07-001 · No action required (auto-accept)
├── Available documents:
│ ├── [x] Standard DPA v3.2 · PDF · Click-wrap accepted
│ ├── [ ] HIPAA BAA · Available on request · [ Request from Legal ]
│ └── [x] Subprocessor list snapshot · PDF 2026-07-01
├── Pending: None
├── History: v3.1 accepted 2025-11-01 · v3.0 accepted 2024-06-15
└── [ Download current DPA ] [ View subprocessors ] [ Contact Legal ]
| Acceptance mode | UI pattern |
|---|---|
| Click-wrap | Checkbox + “I accept” on signup or DPA update banner |
| E-signature | DocuSign/HelloSign embed for enterprise |
| Order form reference | DPA incorporated by reference—show linked order PDF |
| Re-acceptance required | Blocking banner until admin accepts new version |
| Delegated acceptor | Require account admin or billing admin role |
Signup flow should surface DPA acceptance before workspace creation completes—same pattern as login consent checkboxes.
Version history must be immutable—customers download what they accepted on a given date, not today’s template.
Legal review queue and DPA templates
LegalQueue — 1 item pending
├── DPA v3.3 draft · Author: @legal-sarah · Submitted 2026-07-20
│ ├── Changes: Updated SCC reference · New AI subprocessor clause
│ ├── Diff view: v3.2 → v3.3 highlighted sections
│ ├── Impact: 12,400 tenants will need re-acceptance or auto-notice
│ └── Actions: [ Approve for publish ] [ Request edits ] [ Schedule effective date ]
├── Template variants: Standard · EU-only · HIPAA · FedRAMP rider
└── Redline inbox: 2 enterprise counter-DPAs · SLA 5 business days
| Template element | Design note |
|---|---|
| Version number | Semantic; visible in customer portal |
| Effective date | Scheduled publish; no retroactive surprises |
| Diff view | Side-by-side or inline for Legal and customer admins |
| Impact preview | Count tenants affected before publish |
| Redline workflow | Separate from standard template; attachment upload |
Pair with security policy management—DPA acceptance and internal policy acceptance share similar audit log patterns.
Public trust center integration
The trust center subprocessor section must reflect registry publish state only:
PublicSubprocessors — trust.acme.com/subprocessors · Last updated 2026-07-01
├── Table: Name · Purpose · Location · Data categories
├── Subscribe: [ Email me when subprocessors change ] · RSS optional
├── Download: PDF snapshot · CSV for procurement teams
├── Note: Changes notified 30 days in advance per DPA Section 4.2
└── CTA: [ Request full DPA ] · Links to gated download flow
One-way sync: Admin publishes from DPA hub → trust center updates. No direct edit on public page.
Design subscribe to changes as a lightweight form—email only, double opt-in for GDPR compliance.
Handoff checklist (Dev Mode)
- Subprocessor record — vendor ID, purpose, data categories, regions, status, vendor_risk_link.
- Change notice — type, effective_date, objection_window_end, notification_sent_at.
- Customer acceptance — tenant_id, dpa_version, accepted_by, accepted_at, method (click-wrap/signature).
- Objection — account_id, change_notice_id, status, Legal thread link.
- DPA template — version, variant, effective_date, diff_from_previous.
- Enterprise hold — blocks_auto_effective flag; manual approval required.
- Publish event — trust_center_sync_timestamp; audit log entry.
- Accessibility — subprocessor table keyboard navigable; change summary readable without color alone.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Trust center subprocessors edited manually | Out of sync with Legal registry | Publish-only sync from DPA hub |
| No objection window UI | GDPR/process failure; customer trust loss | Countdown + objection form on admin dashboard |
| Enterprise auto-accepts custom DPA changes | Contract breach | Enterprise hold flag blocks auto-effective |
| Removed subprocessors deleted from history | Cannot prove past processing | Archive with removal date |
| DPA version without customer diff | Admins accept blindly | Show changed sections before accept |
| Subprocessor without data categories | Incomplete Article 30 records | Require categories before publish |
| Notification only by email | Admins miss in-app | Email + persistent banner until acknowledged |
| Vendor risk and Legal use different names | Audit confusion | Single vendor ID across modules |
| No acceptance export | Enterprise procurement blocked | One-click acceptance log CSV/PDF |
| Click-wrap on mobile without scroll | Unenforceable acceptance | Require scroll-to-end or section anchors |
Recommended workflow
- Design subprocessor registry with vendor link, residency, and review cadence.
- Build change notice flow with objection window, enterprise holds, and notification channels.
- Create customer DPA portal with version history, acceptance modes, and document downloads.
- Spec Legal queue for template versions, diffs, and redline inbox.
- Wire trust center publish as one-way sync from registry.
- Add acceptance audit export for procurement and compliance exports evidence.
FAQ
Link to privacy settings?
Privacy settings cover end-user data rights (export, delete). DPA hub covers B2B controller-processor relationship and subprocessors—different audiences; cross-link in enterprise admin settings.
Same as trust center subprocessor list?
Trust center is the public read-only view. DPA hub is the admin system of record with change workflows and customer acceptance tracking.
Vendor risk integration?
Each subprocessor should reference a vendor risk record—Security review status can surface as a chip on registry rows (e.g., “Review overdue”) without exposing full assessment to customers.
Standard Contractual Clauses (SCCs) in UI?
Add transfer mechanism field per subprocessor—adequacy decision, SCC Module 2/3, BCR. Show in customer-facing DPA appendix and public list where appropriate.
Objection leads to contract termination?
Design objection outcome paths—accept change, negotiate, or initiate offboarding with link to data export—without trapping users in ambiguous states.
Next steps
- Design trust center and security documentation UI in Figma — public subprocessor and DPA request output
- Design privacy settings and data management UI in Figma — end-user rights adjacent to enterprise DPA
- Design vendor risk assessment and third-party security reviews UI in Figma — Security review for each subprocessor
- Design compliance audit evidence and certification renewal UI in Figma — DPA acceptance logs as audit evidence
- Design security policy management and acceptance UI in Figma — shared acceptance audit patterns
§ Keep reading