Data Processing Addendum (DPA) — DRAFT
⚠️ TEMPLATE / DRAFT — NOT LEGAL ADVICE. A GDPR Art. 28 DPA is a binding contract with specific mandatory content and (for transfers) Standard Contractual Clauses. This draft must be reviewed and finalized by qualified data-protection counsel. Complete every
[BRACKET].
This DPA forms part of the Terms of Service between [Provider legal entity] ("Processor") and the customer ("Controller") and applies where the Processor processes personal data on the Controller's behalf under EU GDPR, UK GDPR, and/or equivalent laws.
1. Roles and scope
1.1 For Customer Data (documents, records, and associated metadata the Controller uploads to the Service), the Controller is the controller and the Processor is the processor. 1.2 The Processor processes such personal data only on the Controller's documented instructions (including as set out in the Terms and this DPA), unless required by law (in which case it will inform the Controller unless legally prohibited).
2. Subject-matter, duration, nature and purpose (Art. 28(3))
- Subject-matter / nature / purpose: hosting, storage, processing, and management of the Controller's controlled documents and records, and provision of the Service's features (versioning, workflow, e-signatures, audit trail, search, export).
- Duration: the term of the subscription plus the export/retention period in the Terms.
- Categories of data subjects: the Controller's personnel and any individuals named in the Controller's documents (determined by the Controller).
- Categories of personal data: as determined and uploaded by the Controller (e.g. names, roles, signatures, and any personal data within document content). The Controller must not upload special-category data unless [agreed in writing / appropriate safeguards].
3. Processor obligations (Art. 28(3)(a)–(h))
The Processor will: (a) process only on documented instructions; (b) ensure persons authorized to process are under confidentiality; (c) implement the security measures in Annex II; (d) respect the sub-processor terms in §4; (e) assist the Controller, by appropriate measures, to respond to data-subject rights requests; (f) assist the Controller with security, breach notification, and DPIAs (Arts. 32–36); (g) at the Controller's choice, delete or return personal data at end of provision, subject to legal retention and the append-only audit trail; (h) make available information necessary to demonstrate compliance and allow for and contribute to audits (§6).
4. Sub-processors
4.1 The Controller provides general authorization for the Processor to engage sub-processors. Current sub-processors: | Sub-processor | Purpose | Location | |---|---|---| | Amazon Web Services | hosting, database, document storage, email (SES) | [region] | | Stripe | subscription billing / payment processing | [region] | 4.2 The Processor will impose data-protection obligations on each sub-processor equivalent to those in this DPA (flow-down) and remains liable for their performance. 4.3 The Processor will notify the Controller before adding or replacing a sub-processor and give the Controller [30] days to object on reasonable data-protection grounds; if unresolved, the Controller may terminate the affected Service.
5. International transfers
Where processing involves transfer of personal data outside the EEA/UK to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses [module(s) — controller-to-processor] are incorporated by reference, with [details, docking, and any UK Addendum / Swiss amendments — COMPLETE].
6. Audits
The Processor will make available compliance information and allow audits by the Controller (or its auditor) [on reasonable notice, no more than once per year absent cause, subject to confidentiality]. The Processor may satisfy audit requests via third-party certifications/reports where available.
7. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information the Controller reasonably needs to meet its own notification duties.
8. Return and deletion
On termination, the Processor will, at the Controller's choice, return or delete Customer Data within [30] days, except (a) as required to be retained by law, and (b) the append-only audit-trail records where retention/regulation requires their preservation.
9. Liability
The parties' liability under this DPA is subject to the limitations in the Terms [confirm interaction with statutory data-protection liability — counsel].
Annex I — Details of processing
[Restate §2 specifics for the SCCs: parties, roles, data subjects, data categories, frequency, duration, purpose.]
Annex II — Technical and organizational security measures (Art. 32)
- Encryption of data in transit (TLS). [At-rest encryption via S3/RDS — confirm/enable.]
- Tenant isolation (per-tenant scoping; database Row-Level Security in production).
- Passwords stored as salted hashes (bcrypt); login brute-force rate-limiting.
- Append-only, hash-chained, tamper-evident audit trail (WORM mirror).
- Electronic-signature re-authentication bound to record content hashes.
- CSRF protection, security response headers (CSP, HSTS, nosniff, frame-options), and content sanitization.
- Role-based access control; least-privilege administrative access.
- Backups [RPO/RTO — COMPLETE]; access logging and monitoring [COMPLETE].
- Vendor management and sub-processor flow-down (§4).
(This annex describes current/target measures; confirm the production deployment state before representing them to a customer.)