Data Processing Agreement
Effective date: [Date]
This Data Processing Agreement is entered into by and between [Controller legal name], [address and entity details] (“Controller”), and [Processor legal name], [address and entity details] (“Processor”), together the “Parties.”
1. Processing Relationship and Scope
[Controller, processor, service description, term, regions, and linked data-processing schedule.]
2. Documented Instructions
[Purpose, duration, nature, frequency, location, prohibited secondary use, and instruction-change process.]
3. Data Categories and Data Subjects
[Data subject groups, personal-data categories, special-category data, and volume or frequency.]
4. Security Measures
[Technical and organizational controls, encryption, resilience, restoration, testing, and certification evidence.]
5. Personnel Confidentiality and Access
[Confidentiality undertakings, least privilege, training, access review, and offboarding.]
6. Subprocessors and International Transfers
[Subprocessor list, notice and objection route, flow-down duties, transfer mechanism, and transfer impact assessment.]
7. Rights Requests and DPIA Assistance
[Assistance timeline, verification, correction/deletion, portability, DPIA, and regulator cooperation.]
8. Personal-Data Breach Response
[Breach definition, notification deadline, minimum content, containment, updates, and contact tree.]
9. Audits and Compliance Evidence
[Audit notice, remote evidence, on-site limits, cost allocation, remediation, and regulator access.]
10. Return, Deletion, and Retention
[Deletion certificate, backup exceptions, legal retention, export format, and end-of-service deadline.]
11. Liability, Order of Precedence, and Signatures
[Liability allocation, precedence over commercial terms, governing law, and authorized signatories.]
Signatures
Controller
Name: [Name]
Title: [Title or capacity]
Signature: ____________________
Date: [Date]
Processor
Name: [Name]
Title: [Title or capacity]
Signature: ____________________
Date: [Date]
Legal notice: This DPA must be mapped to the parties’ actual jurisdictions, transfer mechanism, security program, and sector requirements by privacy counsel.