figma guide

Designing data processing agreements and subprocessor management UI in Figma: DPA workflows, change notices, and customer approvals

Design DPA and subprocessor management UI in Figma with agreement templates, customer acceptance flows, subprocessor registries, change notifications, and Legal review queues.

Published
Updated
Jul 31, 2026
Read time
9 min
Level
Intermediate

Quick answer

Data processing agreement (DPA) and subprocessor management UI is how B2B SaaS meets GDPR Article 28 obligations—publish current subprocessors, notify customers before changes, and track DPA acceptance without Legal living in email. Design a subprocessor registry with categories, data types, and residency; a change notification workflow with objection windows and audit trails; a customer DPA portal with versioned agreements and e-signature or click-wrap acceptance; and an admin Legal queue for template updates and enterprise redlines. Start from the Figma guides hub and pair with trust center, privacy settings, vendor risk, compliance exports, and Dev Mode handoff.


Who this is for

  • Product designers building privacy compliance modules, enterprise onboarding, or public trust pages with DPA workflows.
  • Design system teams aligning subprocessor tables, legal document cards, and acceptance modals with tables, forms, and badges.
  • Legal, privacy, and customer success teams managing subprocessors, DPA versions, and customer objection periods.

DPA hub (internal overview)

DPAHub — Acme SaaS · DPA v3.2 effective 2026-04-01 · Subprocessors: 47 active
├── Header: Pending customer acceptances 12 · Open change notices 2 · Legal review 1
├── Actions: [ Publish subprocessor update ] [ New DPA version ] [ Export acceptance log ]
├── Tabs: Subprocessors · Change notices · DPA versions · Customer acceptances · Templates · Settings
├── Alert: AWS Lambda added as subprocessor · Objection window ends 2026-08-14 · 3 enterprise holds
├── Banner: DPA v3.3 draft in Legal review · Target effective 2026-09-01
└── Link: [Trust center subprocessor page](/designing-trust-center-and-security-documentation-ui-in-figma/) · Vendor risk · Privacy settings
SectionPurpose
SubprocessorsMaster registry with purpose, data, residency
Change noticesAdd/remove/update with customer notification
DPA versionsTemplate history and effective dates
Customer acceptancesPer-tenant signed or click-wrap status
TemplatesStandard, HIPAA, EU SCC variants
SettingsObjection window length, notification channels

Verdict: DPA hub is Legal source of truth—public trust center subprocessors and customer-facing DPA links must sync from here, never from a static Notion page.


Subprocessor registry

SubprocessorRegistry — 47 active · Last published to trust center 2026-07-01
├── Stripe · Payments · PCI scope · US + EU · [Vendor risk: Low ]
│   ├── Data categories: Billing name, card token (via Stripe), email
│   ├── DPA: Stripe DPA 2024-01 · Link to signed copy
│   └── Status: Active · Added 2023-06-01 · No pending changes
├── AWS · Infrastructure · Hosting · US-East, EU-West, ap-southeast-1
│   ├── Data categories: All customer content at rest
│   ├── SCCs: Module 2 · Transfer mechanism documented
│   └── Status: Active · Review due 2026-12-01
├── New: Datadog · Observability · Logs may contain IPs · US only
│   ├── Status: Pending change notice · Effective if no objections 2026-08-14
│   └── Linked: [Change notice CN-2026-07-001]
└── Filter: [ Pending publish ] [ Review overdue ] [ Removed archived ]
Registry fieldUI detail
Vendor nameLegal entity; link to vendor risk record
PurposePlain-language processing purpose
Data categoriesPersonal data types processed
Location / residencyRegions; transfer mechanism if cross-border
StatusActive, pending notice, removed, archived
DPA referenceLink to vendor DPA or SCC module
Last reviewedAnnual review cadence for Legal

Use table patterns with sort by status and residency. Removed subprocessors stay in archive with removal date—customers may need historical DPA snapshots.

Every subprocessor row should link to vendor risk when your product has both modules—Legal and Security should see the same vendor identity.


Change notification workflow

ChangeNotice — CN-2026-07-001 · Add Datadog as subprocessor
├── Change type: Add · Effective date: 2026-08-14 (30-day objection window)
├── Summary: Application performance monitoring; logs may contain IP addresses
├── Comparison: Before 46 subprocessors → After 47
├── Customer notification: Email + in-app banner for admins · Sent 2026-07-15
├── Objection handling:
│   ├── No objection (default): Auto-accept after window
│   ├── Objection received: Flag account · CS + Legal thread · Termination path if required
│   └── Enterprise custom DPA: Manual review required before effective
├── Enterprise holds: 3 accounts require explicit re-acceptance · Block auto-effective
└── [ Publish to trust center ] [ Extend window ] [ Cancel change ] [ View audit log ]
Change typeNotification pattern
Add subprocessorFull notice with purpose, data, location
Remove subprocessorLighter notice; migration note if data deleted
Replace vendorOld → new mapping; data migration timeline
Location changeHighlight residency shift; SCC update if needed
Purpose expansionEmphasize new data categories

Design objection window countdown using badges—“12 days remaining” on admin dashboard and in-app inline alerts.

Enterprise accounts with custom DPAs must never auto-accept subprocessors—show blocked state until Legal marks reviewed.


Customer DPA portal

CustomerDPA — acme-corp · Tenant ID 8842 · Plan: Enterprise
├── Current DPA: v3.2 · Accepted 2026-04-15 by jane@acme-corp.com · IP logged
├── Status: Current · Subprocessor notice CN-2026-07-001 · No action required (auto-accept)
├── Available documents:
│   ├── [x] Standard DPA v3.2 · PDF · Click-wrap accepted
│   ├── [ ] HIPAA BAA · Available on request · [ Request from Legal ]
│   └── [x] Subprocessor list snapshot · PDF 2026-07-01
├── Pending: None
├── History: v3.1 accepted 2025-11-01 · v3.0 accepted 2024-06-15
└── [ Download current DPA ] [ View subprocessors ] [ Contact Legal ]
Acceptance modeUI pattern
Click-wrapCheckbox + “I accept” on signup or DPA update banner
E-signatureDocuSign/HelloSign embed for enterprise
Order form referenceDPA incorporated by reference—show linked order PDF
Re-acceptance requiredBlocking banner until admin accepts new version
Delegated acceptorRequire account admin or billing admin role

Signup flow should surface DPA acceptance before workspace creation completes—same pattern as login consent checkboxes.

Version history must be immutable—customers download what they accepted on a given date, not today’s template.


LegalQueue — 1 item pending
├── DPA v3.3 draft · Author: @legal-sarah · Submitted 2026-07-20
│   ├── Changes: Updated SCC reference · New AI subprocessor clause
│   ├── Diff view: v3.2 → v3.3 highlighted sections
│   ├── Impact: 12,400 tenants will need re-acceptance or auto-notice
│   └── Actions: [ Approve for publish ] [ Request edits ] [ Schedule effective date ]
├── Template variants: Standard · EU-only · HIPAA · FedRAMP rider
└── Redline inbox: 2 enterprise counter-DPAs · SLA 5 business days
Template elementDesign note
Version numberSemantic; visible in customer portal
Effective dateScheduled publish; no retroactive surprises
Diff viewSide-by-side or inline for Legal and customer admins
Impact previewCount tenants affected before publish
Redline workflowSeparate from standard template; attachment upload

Pair with security policy management—DPA acceptance and internal policy acceptance share similar audit log patterns.


Public trust center integration

The trust center subprocessor section must reflect registry publish state only:

PublicSubprocessors — trust.acme.com/subprocessors · Last updated 2026-07-01
├── Table: Name · Purpose · Location · Data categories
├── Subscribe: [ Email me when subprocessors change ] · RSS optional
├── Download: PDF snapshot · CSV for procurement teams
├── Note: Changes notified 30 days in advance per DPA Section 4.2
└── CTA: [ Request full DPA ] · Links to gated download flow

One-way sync: Admin publishes from DPA hub → trust center updates. No direct edit on public page.

Design subscribe to changes as a lightweight form—email only, double opt-in for GDPR compliance.


Handoff checklist (Dev Mode)

  • Subprocessor record — vendor ID, purpose, data categories, regions, status, vendor_risk_link.
  • Change notice — type, effective_date, objection_window_end, notification_sent_at.
  • Customer acceptance — tenant_id, dpa_version, accepted_by, accepted_at, method (click-wrap/signature).
  • Objection — account_id, change_notice_id, status, Legal thread link.
  • DPA template — version, variant, effective_date, diff_from_previous.
  • Enterprise hold — blocks_auto_effective flag; manual approval required.
  • Publish event — trust_center_sync_timestamp; audit log entry.
  • Accessibility — subprocessor table keyboard navigable; change summary readable without color alone.

Common mistakes

MistakeWhy it hurtsFix
Trust center subprocessors edited manuallyOut of sync with Legal registryPublish-only sync from DPA hub
No objection window UIGDPR/process failure; customer trust lossCountdown + objection form on admin dashboard
Enterprise auto-accepts custom DPA changesContract breachEnterprise hold flag blocks auto-effective
Removed subprocessors deleted from historyCannot prove past processingArchive with removal date
DPA version without customer diffAdmins accept blindlyShow changed sections before accept
Subprocessor without data categoriesIncomplete Article 30 recordsRequire categories before publish
Notification only by emailAdmins miss in-appEmail + persistent banner until acknowledged
Vendor risk and Legal use different namesAudit confusionSingle vendor ID across modules
No acceptance exportEnterprise procurement blockedOne-click acceptance log CSV/PDF
Click-wrap on mobile without scrollUnenforceable acceptanceRequire scroll-to-end or section anchors

  1. Design subprocessor registry with vendor link, residency, and review cadence.
  2. Build change notice flow with objection window, enterprise holds, and notification channels.
  3. Create customer DPA portal with version history, acceptance modes, and document downloads.
  4. Spec Legal queue for template versions, diffs, and redline inbox.
  5. Wire trust center publish as one-way sync from registry.
  6. Add acceptance audit export for procurement and compliance exports evidence.

FAQ

Privacy settings cover end-user data rights (export, delete). DPA hub covers B2B controller-processor relationship and subprocessors—different audiences; cross-link in enterprise admin settings.

Same as trust center subprocessor list?

Trust center is the public read-only view. DPA hub is the admin system of record with change workflows and customer acceptance tracking.

Vendor risk integration?

Each subprocessor should reference a vendor risk record—Security review status can surface as a chip on registry rows (e.g., “Review overdue”) without exposing full assessment to customers.

Standard Contractual Clauses (SCCs) in UI?

Add transfer mechanism field per subprocessor—adequacy decision, SCC Module 2/3, BCR. Show in customer-facing DPA appendix and public list where appropriate.

Objection leads to contract termination?

Design objection outcome paths—accept change, negotiate, or initiate offboarding with link to data export—without trapping users in ambiguous states.


Next steps

Share on X

§ Keep reading

Related guides.