Establishing secure connection…Loading editor…Preparing document…

Customer Data Processing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

CUSTOMER DATA PROCESSING AGREEMENT

This Customer Data Processing Agreement ("Agreement") is entered into as of by and between Controller Name: with its principal place of business at ("Controller"), and Processor Name: with its principal place of business at ("Processor"). Controller and Processor are each a "Party" and together the "Parties."

RECITALS

WHEREAS, Controller determines the purposes and means of the processing of Personal Data and engages Processor to process Personal Data on Controller's behalf in connection with the provision of services described in the underlying services agreement between the Parties (the "Underlying Agreement"); and

WHEREAS, Processor will process Personal Data only on documented instructions from Controller and will implement technical and organizational measures to protect such Personal Data; and

WHEREAS, the Parties wish to set out their respective rights and obligations with respect to the Processing of Personal Data carried out under the Underlying Agreement.

NOW, THEREFORE, in consideration of the mutual covenants set forth herein, the Parties agree as follows:

1. DEFINITIONS

1.1 "Personal Data" means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller pursuant to this Agreement and the Underlying Agreement. Data Categories:

1.2 "Processing" or "process" has the meaning given in applicable data protection law and includes any operation or set of operations performed upon Personal Data, whether or not by automated means.

1.3 "Subprocessor" means any Processor engaged by Processor to process Personal Data on behalf of Controller.

2. SCOPE, PURPOSE AND DURATION

2.1 Processor shall process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by applicable law. Processing activities and purposes:

2.2 The term of Processing under this Agreement shall be coextensive with the Underlying Agreement and shall continue until the date specified in the Underlying Agreement or until the Parties agree that Processing has ceased.

3. CONTROLLER OBLIGATIONS

3.1 Controller shall ensure that its instructions for the Processing of Personal Data comply with applicable data protection laws and that Controller has a lawful basis for the processing of Personal Data as contemplated by this Agreement.

3.2 Controller shall provide Processor with documented instructions, contact details for data protection inquiries, and any required notifications to data subjects arising from Controller’s actions or omissions.

4. PROCESSOR OBLIGATIONS

4.1 Processor shall process Personal Data only on documented instructions from Controller and shall not disclose or use Personal Data for any purpose other than the performance of the Underlying Agreement and this Agreement.

4.2 Processor shall ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. SUBPROCESSORS

5.1 Controller authorizes Processor to engage Subprocessors to perform certain processing activities. Processor shall ensure that any Subprocessor is bound by written obligations substantially equivalent to those in this Agreement.

5.2 Controller consent to the use of Subprocessors (check as applicable):

6. SECURITY MEASURES

6.1 Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, pseudonymization and encryption, ability to ensure ongoing confidentiality, integrity, availability and resilience of Processing systems, and procedures for regular testing, assessment and evaluation of the measures.

7. DATA SUBJECT RIGHTS

7.1 Taking into account the nature of the processing, Processor shall assist Controller, by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Controller’s obligation to respond to requests to exercise data subject rights under applicable law.

8. BREACH NOTIFICATION

8.1 Processor shall notify Controller without undue delay upon becoming aware of a Personal Data Breach affecting Controller Personal Data and shall provide Controller with reasonable details to enable Controller to meet any obligations to report or inform data subjects under applicable law.

9. AUDIT AND RECORDS

9.1 Processor shall make available to Controller all information necessary to demonstrate compliance with obligations set out in this Agreement and allow for and contribute to audits, including inspections, by Controller or an auditor mandated by Controller, subject to reasonable notice and confidentiality obligations.

10. INTERNATIONAL TRANSFERS

10.1 Any transfer of Personal Data outside the country in which it was collected shall be subject to appropriate safeguards as required by applicable data protection law. The Parties shall document such transfers and the safeguards applied.

11. RETURN OR DELETION

11.1 Upon termination or expiration of the Underlying Agreement, Processor shall, at Controller’s choice, return all Personal Data to Controller and delete existing copies unless retention of Personal Data is required by applicable law. Retention period if required by law or agreed exception:

12. CONFIDENTIALITY

12.1 Each Party shall treat Personal Data as confidential and shall not disclose such Personal Data except as necessary to perform its obligations under the Underlying Agreement or as required by applicable law, subject to prior notice to the other Party where permitted.

13. LIABILITY AND INDEMNIFICATION

13.1 Each Party's liability arising out of or related to this Agreement shall be determined in accordance with the Underlying Agreement, provided that nothing in this Agreement shall limit either Party's liability for breach of applicable data protection laws or for personal injury or death resulting from gross negligence or willful misconduct.

13.2 Processor shall indemnify and hold Controller harmless from third-party claims arising from Processor's breach of its obligations under this Agreement, subject to the limitations and procedures in the Underlying Agreement.

14. NOTICES

14.1 All notices under this Agreement shall be given in writing and shall be delivered to the contact details below. Notice to Controller:

14.2 Notice to Processor:

15. AMENDMENT, WAIVER, COUNTERPARTS

15.1 This Agreement may be amended only by a written agreement executed by authorized representatives of both Parties. No failure or delay by either Party in exercising any right under this Agreement shall constitute a waiver of that right.

15.2 This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

16. GOVERNING LAW, ENTIRE AGREEMENT, SEVERABILITY

16.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of , without regard to conflict-of-law principles.

16.2 Entire Agreement: This Agreement, together with the Underlying Agreement, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings.

16.3 Severability: If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect and shall be construed so as to give effect to the intent of the Parties as nearly as possible.

SIGNATURES

The Parties have executed this Agreement by their duly authorized representatives on the dates set forth below.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What a Customer Data Processing Agreement Covers

A Customer Data Processing Agreement (DPA) is a binding contract that sets rules for how a service provider (processor) handles personal data on behalf of a customer (controller). The DPA defines roles, lawful purposes, categories of personal data, security measures, subprocessors, breach notification procedures, audit and access rights, data transfer restrictions, and retention or deletion requirements. In cross-border contexts the DPA also records legal bases for transfers and any supplementary safeguards. For regulated industries the DPA typically references HIPAA, sector-specific rules, and applicable contractual obligations.

Why a DPA Matters for Risk and Compliance

A DPA reduces legal and operational risk by documenting responsibilities for data security, incident response, and lawful processing.

Why a DPA Matters for Risk and Compliance

Who Typically Signs and Uses a DPA

Organizations that exchange or host customer personal data adopt DPAs to clarify responsibilities before processing begins.

  • Data controllers and customers responsible for regulatory compliance and data subject rights.
  • SaaS vendors and cloud service providers acting as data processors for business customers.
  • Third-party subprocessors, managed service providers, and consultants with access to customer data.

Use a DPA whenever a vendor will store, analyze, or transmit personal data that creates legal obligations for either party.

Core Clauses to Include in a Professional DPA

A robust DPA groups obligations clearly so reviewers can find security, transfer, and termination rules quickly; this reduces negotiation time and audit friction.

Scope

Define categories of personal data, data subjects, and permitted processing activities in precise terms to avoid ambiguity during audits.

Roles & Responsibilities

Specify controller vs processor duties, change management, and obligations to follow documented instructions from the controller.

Security Measures

List technical and organizational controls such as encryption, access controls, incident response, and regular vulnerability testing.

Subprocessors

Require notification or prior consent for subprocessors, and mandate flow-down of DPA obligations to each subprocessor.

Breach Notification

Set timelines and content for breach notices, including regulatory notification responsibilities and cooperation for investigations.

Audit & Rights

Grant audit rights, define frequency and format of assessments, and address remediation obligations following findings.

Essential Data Elements Required in the DPA

Controller Name: Legal entity name
Processor Name: Legal entity name
Data Categories: Personal data types processed
Processing Purpose: Business purpose description
Retention Period: Specified retention timeframe
Contact Details: Notice email or postal address

How to Prepare and Execute a DPA — Step by Step

Follow these practical steps to draft, review, sign, and operationalize a DPA so processing can begin with documented safeguards in place.

  • 01
    Map Data: Identify data types, flows, and storage locations across systems.
  • 02
    Draft Clauses: Insert scope, security, subprocessors, and termination language consistent with obligations.
  • 03
    Legal Review: Have counsel review for regulatory alignment and enforceability.
  • 04
    Execute & Record: Obtain authorized signatures and store final DPA in a secure records system.

Configuring an Online DPA Workflow

Configure e-signature and access settings to match the DPA's authentication and audit requirements before sending for signatures.

Field Configuration
Signature Method Email link or advanced auth (SMS code)
Authentication Email + SMS or KBA as required
Audit Trail Enable immutable logs and timestamps
Data Location Limit storage region to specified jurisdictions

Technical and Integration Considerations

Choose signing and storage platforms that meet the DPA's security and data residency requirements.

  • Integrations: Support for Salesforce, NetSuite, Microsoft 365
  • File Formats: Accept PDF, DOCX, and HTML
  • Authentication: Email, SMS, and SSO options

Confirm the selected platform can produce an audit trail, export original signed documents, and apply required retention controls.

Typical Routing and Submission Flow

A standard online DPA workflow uses upload, field placement, signer assignment, secure delivery, and completion with audit logs captured.

  • Upload Document: Place the DPA PDF or DOCX into the signing platform.
  • Add Fields: Insert signature, date, and contact fields as needed.
  • Send to Signers: Email or secure link routes the DPA to authorized signatories.
  • Capture Audit: System records IP, timestamp, and authentication events.

Timing and Deadlines to Track for a DPA

Certain actions tied to the DPA are time-sensitive; track execution, review cycles, and incident response commitments.

Execution Before Processing:

DPA should be signed before any processor begins controlled data processing.

Periodic Review:

Review DPA terms annually or after material service changes.

Breach Notification:

Notify controller per contract; HIPAA requires entity notice timelines (see HIPAA rule).

Subprocessor Notice:

Provide any required advance notice when adding subprocessors as contractually defined.

Record Retention:

Retain executed DPAs alongside transactional records for the applicable retention period.

Key Milestones in DPA Lifecycle

Track the DPA from initial draft through execution and ongoing monitoring to ensure obligations are met over time.

01

Drafting

Define scope, data categories, and security controls with stakeholders.

02

Approval

Legal and security teams review and approve terms.

03

Execution

Authorized signatories sign and the executed copy is stored securely.

04

Monitoring

Periodic audits and reviews verify compliance and subprocessors.

Common Pitfalls to Avoid When Preparing a DPA

  • Leaving processing purposes vague, which can create disagreement about permitted activities and lead to audit findings.
  • Failing to list or control subprocessors and their locations, resulting in unapproved data transfers and compliance gaps.
  • Omitting specific security controls and measurements, making it difficult to enforce required safeguards during assessments.
  • Not defining breach notification content and timing, which delays response and may trigger regulatory consequences.

Risks and Potential Consequences of an Inadequate DPA

Regulatory Fines: Monetary penalties from authorities
Contract Liability: Indemnities and breach damages
Data Breach Costs: Remediation, notification, and forensics
Reputational Harm: Loss of customer trust
Operational Disruption: Service interruptions and remediation
Injunctions: Court orders limiting processing

eSignature Pricing and Feature Comparison

Comparison of starting price and selected feature availability across common e-signature vendors; signNow is listed first per vendor ordering rules.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no card required Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes (Business Premium) Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA available) Yes (BAA available) Yes (BAA available) No No

Real-World Examples of Signing and Compliance

Below are customer experiences that illustrate secure, compliant execution of agreements using integrated e-signature and recordkeeping tools.

Martin Properties — Tim Martin

Tim Martin used online signing to complete property agreements remotely, improving turnaround time by removing in-person steps.

  • The platform supported mobile and offline signing when needed.
  • He reported consistent compliance and secure storage, enabling his team to close transactions faster without sacrificing auditability or chain-of-custody for records.

Fertility Centers — John Butler

John Butler needed secure, auditable signature workflows for patient forms and consent documents.

  • Integration with existing systems preserved records and access controls.
  • The result was streamlined patient onboarding, enforceable consent documentation, and documented audit trails that met regulatory review expectations.

Practical Tips for Accurate and Efficient DPA Completion

Adopt these practices to reduce negotiation time, limit amendments, and maintain operational compliance after execution.

Define Processing Narrowly
Limit permitted processing to specific activities and data categories so obligations and limitations are enforceable and reduce ambiguity in audits.
Maintain a Subprocessor Register
Keep a current list of subprocessors available to customers with procedures for notification and objection to maintain transparency.
Specify Measurable Controls
Use concrete security metrics (encryption algorithms, access control standards, testing frequency) rather than vague security promises.
Document Incident Playbooks
Align breach notification timing, content, and escalation paths with contractual and regulatory obligations to speed response.

Frequently Asked Questions About Customer Data Processing Agreements

Answers to common questions about DPA enforceability, signatures, breach response, and recordkeeping to help legal and operations teams manage compliance.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users