Establishing secure connection…Loading editor…Preparing document…

Data Processing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA PROCESSING AGREEMENT

This Data Processing Agreement (the Agreement) is entered into as of Effective Date: by and between Client Name: with principal place of business at Client Address: (the "Controller"), and Processor Name: with principal place of business at Processor Address: (the "Processor").

RECITALS

WHEREAS, the Controller determines the purposes and means of Processing personal data in connection with the services described in Controller's agreement for Services; and

WHEREAS, the Processor will Process Personal Data on behalf of the Controller solely for the documented purposes and under the terms set forth herein; and

WHEREAS, the parties wish to set out the respective rights and obligations with respect to the Processing, security, and protection of Personal Data.

NOW THEREFORE, in consideration of the mutual covenants contained herein, the parties agree as follows:

1. DEFINITIONS

For purposes of this Agreement, the following terms have the meanings set forth below:

"Personal Data" means any information relating to an identified or identifiable natural person that is Processed by the Processor on behalf of the Controller pursuant to this Agreement.

"Processing" or "Process" means any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, erasure or destruction.

"Subprocessor" means any Processor engaged by the Processor to assist in fulfilling Processing activities on behalf of the Controller.

2. DETAILS OF PROCESSING

The subject matter, nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects are set out below and in any separate Statement of Work executed by the parties.

3. CONTROLLER INSTRUCTIONS

The Processor shall Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law. Where Processor is required to Process Personal Data by applicable law, Processor shall inform Controller of that legal requirement prior to Processing, unless that law prohibits such information on important grounds of public interest.

4. PROCESSOR OBLIGATIONS

The Processor warrants and undertakes that it shall:

  1. Implement and maintain technical and organisational measures appropriate to the risk to ensure the security and confidentiality of Personal Data;
  2. Ensure that persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. Assist the Controller in responding to Data Subject requests and in fulfilling the Controller's obligations under applicable data protection law where such assistance is reasonably available;
  4. Not engage any Subprocessor except as permitted in Section 5 of this Agreement;
  5. Maintain records of Processing activities relating to Personal Data under its responsibility and make such records available to the Controller as reasonable and necessary for compliance verification.

5. SUBPROCESSORS

The Processor may engage Subprocessors only with the prior written authorization of the Controller. Controller hereby grants general written authorization for the engagement of Subprocessors listed in the approved Subprocessor list field below, subject to the Processor entering into a written contract with each Subprocessor imposing obligations no less protective than those set forth in this Agreement.

Processor will provide Controller with prior notice of any intended changes concerning the addition or replacement of Subprocessors.

6. SECURITY MEASURES

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate, pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, and procedures for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.

7. BREACH NOTIFICATION

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Controller Personal Data. The Processor's notification shall include, to the extent reasonably available, a description of the nature of the breach, likely consequences, measures taken or proposed to be taken to address the breach and a contact point for further information.

8. AUDIT AND INSPECTION

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller. Such audits shall be subject to reasonable confidentiality restrictions and conducted during normal business hours on reasonable prior notice.

9. INTERNATIONAL TRANSFERS

Where the Processing involves the transfer of Personal Data to jurisdictions outside the jurisdiction of the Controller, the parties shall ensure that appropriate safeguards are in place and documented, and that the transfer complies with applicable data protection requirements.

10. RETURN OR DELETION OF PERSONAL DATA

Upon termination or expiry of the services giving rise to Processing, the Processor shall, at the election of the Controller, delete or return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data.

11. LIABILITY AND INDEMNITY

Each party shall be liable for losses arising from its breach of this Agreement or applicable data protection law. The Processor shall indemnify and hold the Controller harmless from third party claims arising from Processor's breach of this Agreement or Processor's negligent or wilful misconduct in relation to the Processing.

12. NOTICES

All notices required or permitted under this Agreement shall be given in writing and delivered to the contact details set forth below or to such other address as either party may designate by notice in accordance with this section.

13. GOVERNING LAW; SEVERABILITY; ENTIRE AGREEMENT

This Agreement shall be governed by and construed in accordance with the laws of . If any provision of this Agreement is held to be invalid or unenforceable, such provision shall be severed and the remaining provisions shall remain in full force and effect. This Agreement constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior or contemporaneous understandings.

14. AMENDMENTS; WAIVER; COUNTERPARTS

No amendment to this Agreement shall be effective unless made in writing and signed by authorised representatives of both parties. Failure by either party to enforce any provision of this Agreement shall not constitute a waiver of future enforcement of that or any other provision. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

15. MISCELLANEOUS

The parties acknowledge that the obligations and protections contained in this Agreement shall survive termination or expiry of the underlying services to the extent necessary to protect rights and liabilities arising in connection with the Processing of Personal Data.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What a Data Processing Agreement Is and when it applies

Data Processing Agreement (DPA) is a written contract that governs how a data controller and a data processor handle personal data. It defines roles and responsibilities, permitted processing purposes, security measures, data subject rights support, breach notification timelines, subprocessors, cross-border transfer rules, and retention limits. In the United States a DPA complements sectoral obligations such as HIPAA and FERPA and supports electronic execution under ESIGN and state electronic transaction laws when parties sign electronically. Use a DPA whenever one party processes personal data on behalf of another.

Why a clear DPA reduces legal and operational risk

A Data Processing Agreement clarifies legal responsibilities, reduces regulatory risk, and documents technical and organizational safeguards. It sets expectations for breach response, subprocessor use, and data retention. A clear DPA aids audits and demonstrates due diligence to partners and regulators.

Why a clear DPA reduces legal and operational risk

Who typically completes and signs a DPA

Use this DPA when parties exchange personal data or when a vendor processes personal data on your behalf.

  • In-house legal teams managing vendor contracts and privacy compliance programs.
  • Cloud service providers, SaaS vendors, and third-party data processors handling customer data.
  • Healthcare, education, finance, and other regulated industries with protected data.

Ensure authorized signers review technical safeguards and subprocessors before signing to avoid compliance gaps and document exceptions.

Who should sign on behalf of each party

Primary Signer: CEO

The authorized representative signing the DPA should have corporate authority to bind the organization. This is typically a C-level executive, general counsel, or VP of legal who understands data flows, risk allocation, and indemnity provisions and can commit to ongoing compliance obligations.

Vendor Signer

The vendor or processor signer must be an officer or authorized agent with operational responsibility for data handling. They should be able to document subprocessors, security controls, and incident response procedures and coordinate data subject access requests under applicable law.

Core clauses to include in a professional DPA

Core DPA clauses define processing scope, security obligations, subcontractor controls, breach response, data return or deletion, and audit rights between controller and processor.

Processing Scope

Specify categories of personal data, processing activities, purposes, and duration. Narrow, specific descriptions reduce interpretation risk and support lawful basis documentation, including examples and data flow diagrams where helpful.

Security Obligations

Detail technical and organizational measures such as encryption, access controls, logging, vulnerability management, penetration testing schedules, and incident response roles and timelines and subcontractor compliance validation.

Subprocessor Controls

Require a subprocessor list, prior notice or approval, and contract flow-down obligations ensuring equivalent security and breach reporting obligations for downstream vendors, including audit rights.

Breach Response

Set maximum notification timelines, information to provide to controller, obligations to mitigate, forensic cooperation requirements, and regulatory reporting assistance, including timelines and contact points for escalation.

Data Return/Deletion

Specify return or secure deletion methods, timelines after contract termination, verification steps, and exceptions for retained backups or legal hold obligations with certificate of destruction where applicable.

Audit Rights

Allow audits, on-site inspections, or independent third-party SOC reports; define frequency, notice period, confidentiality, and remediation timeframes for observed deficiencies, including corrective action plans and verification.

Step-by-step: prepare, negotiate, and execute a DPA

Follow these steps to prepare, negotiate, and sign a Data Processing Agreement with a third-party processor.

  • 01
    Prepare: Identify data types, legal basis, and processing purposes
  • 02
    Draft: Use standard clauses for security, subprocessors, and breach handling
  • 03
    Review: Legal and security teams approve obligations and limits
  • 04
    Sign: Obtain authorized signatures and record execution date

How to configure the online signing workflow

Typical online customization options when preparing a Data Processing Agreement for electronic completion and secure distribution.

Field Setting | Configuration
Authentication Method | Email link with optional SMS code
Signature Type Type | Click-to-sign, drawn, or PKI digital signature
Subprocessor Notice Policy | Prior notice and objection window
Audit Trail Retention | Stored with signed PDF and metadata

Typical electronic signing flow for a DPA

Typical e-execution workflow for a DPA includes upload, field placement, signer authentication, and audit trail capture.

  • Upload: PDF or DOCX version uploaded to platform
  • Fields: Place signature, date, and checkbox fields
  • Authenticate: Email link, SMS code, or advanced KBA
  • Store: Signed PDF with audit trail retained

Platform considerations for e-executing and storing DPAs

Platform and integration considerations for signing and storing DPAs electronically across common business systems securely.

  • Formats: PDF, DOCX, HTML support
  • Integrations: Salesforce, NetSuite, Google Workspace
  • Authentication: Email, SMS, KBA, SSO

Pricing and feature comparison for common e-signature vendors

Compare vendor pricing and key features relevant to Data Processing Agreements and e-signature needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Essential data and security items to record in the DPA

Parties: Controller and processor legal names
Contact Info: Authorized rep name, email, phone
Processing Purpose: Specific purposes and lawful basis
Categories of Data: Personal data categories processed
Subprocessors: List with approval and change process
Security Measures: Encryption, access controls, logging

Key penalties and risks from a deficient DPA

Regulatory Fines: State or federal penalties
Contract Liability: Indemnity and damages exposure
Breach Notification: Missed timelines increase fines
Termination Risk: Service interruption or loss
Data Subject Claims: Class actions, statutory damages
Tax and Reporting: Incorrect filing triggers penalties

Common pitfalls when preparing a DPA

  • Using broad, undefined processing purposes that permit unrelated uses and create compliance ambiguity with data subject rights and retention rules.
  • Failing to list subprocessors or to include a clear approval and notification process for adding new subprocessors.
  • Relying on informal email confirmations rather than signed agreements increases enforceability risk and complicates audit trails.
  • Neglecting to align retention schedules with IRS, HIPAA, or state requirements can expose organizations to fines or litigation.

Typical timelines and response expectations

Key deadlines and response expectations for DPA negotiation, execution, breach notification, and retention alignment with regulatory timelines.

Negotiation Period:

Allow two to four weeks for internal review and insurer approval

Execution Window:

Sign within 30 days of final agreement

Breach Notice:

Processor must notify controller within 72 hours of detection

Subprocessor Notice:

Prior notice and objection period of 10–14 days

Retention Review:

Annual review of retention schedules and legal holds

Milestones from draft to post-termination

Sequential milestones from DPA draft through post-termination obligations and records retention for lifecycle management and audits.

01

Drafting

Create initial DPA draft with mapped data flows

02

Review & Approval

Legal and security approval, revise clauses as needed

03

Execution

Obtain signatures and store signed copies with audit trail

04

Post-Termination

Return or delete data, certify destruction or retention

Standalone DPA vs embedded contract clauses

Quick comparison of standalone Data Processing Agreements versus embedded clauses in master service agreements for clarity and control.

Criteria Standalone DPA Embedded Clause
Scope narrow, specific often broader
Subprocessor Control explicit approvals vague notice terms
Audit Rights commonly included often limited
Enforceability clear obligations relies on msa

Examples showing DPAs in practice

Real-world examples showing how DPAs manage third-party data processing and compliance obligations across industries in practice.

Optica Ventures

Optica Ventures simplified vendor signatures for remote investors using an online execution flow that replaced paper and in-person signings.

  • This reduced turnaround time by several days.
  • The company reported faster execution and an easier experience for customers, noting that a straightforward interface helped close agreements more quickly while preserving a clear audit trail and digital records suitable for compliance and internal review.

Fertility Centers

A healthcare provider needed HIPAA-compliant remote signature workflows for patient consents and administrative documents to reduce in-person contact.

  • They adopted secure e-signatures with audit trails.
  • The organization praised responsive support and the platform's ability to integrate with existing systems, allowing staff to manage consents efficiently while maintaining encryption, access logs, and retention controls expected under healthcare privacy obligations.

Frequently asked questions about executing DPAs

Answers to common questions about executing, signing, and enforcing Data Processing Agreements in U.S. contexts, including electronic signature considerations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users