Establishing secure connection…Loading editor…Preparing document…

Data Processing Agreement Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA PROCESSING AGREEMENT

This Data Processing Agreement ("Agreement") is entered into as of Effective Date: by and between Controller Name: (the "Controller"), an entity organized as: with its principal place of business at: ; and Processor Name: (the "Processor"), an entity organized as: with its principal place of business at: .

RECITALS

WHEREAS, Controller determines the purposes and means of processing certain personal data in connection with the provision of services described in the Main Agreement between the parties; and

WHEREAS, Processor will process personal data on behalf of Controller and warrants that it has the technical and organizational measures necessary to protect such personal data; and

WHEREAS, the parties wish to record the terms under which Processor will process personal data on behalf of Controller.

NOW, THEREFORE, in consideration of the mutual covenants and obligations set forth herein, the parties agree as follows:

1. DEFINITIONS

1.1 "Personal Data" means any information relating to an identified or identifiable natural person that is provided to or accessed by Processor in connection with the Services described in this Agreement.

1.2 "Processing", "Controller", "Processor", and "Data Subject" shall have the meanings ascribed under applicable data protection laws. Additional terms used in this Agreement shall have the meaning set forth in the Main Agreement or as otherwise defined herein.

2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE OF PROCESSING

2.1 Subject Matter of Processing:

2.2 Duration of Processing:

2.3 Nature and Purpose of Processing:

3. TYPES OF PERSONAL DATA AND CATEGORIES OF DATA SUBJECTS

3.1 Types of Personal Data to be Processed:

3.2 Categories of Data Subjects:

4. PROCESSOR OBLIGATIONS

4.1 Processor shall process Personal Data only on documented instructions from Controller, unless required to do otherwise by applicable law. Processor will inform Controller of such legal requirement unless prohibited by applicable law from doing so.

4.2 Processor shall ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. SUB-PROCESSING

5.1 Controller hereby authorizes Processor to engage sub-processors to perform specific processing activities listed in Sub-processor Annex or otherwise notified to Controller. Processor will impose on each sub-processor substantially the same data protection obligations as set out in this Agreement by way of a written contract.

5.2 Controller consent to appointment of sub-processors: Consent given: Yes

5.3 If Processor intends to appoint a new sub-processor, Processor will provide Controller written notice at least prior to the engagement, permitting Controller to object on reasonable grounds.

6. TECHNICAL AND ORGANIZATIONAL MEASURES

6.1 Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as necessary: access control, encryption, pseudonymization where feasible, restoration of availability and resilience of processing systems, and regular testing and evaluation of measures.

6.2 Description of measures implemented by Processor:

7. DATA SUBJECT RIGHTS

7.1 Taking into account the nature of the processing, Processor shall assist Controller by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Controller's obligation to respond to requests for exercising the Data Subject's rights.

7.2 Processor will promptly notify Controller if it receives a Data Subject request relating to Personal Data processed on behalf of Controller and will not respond to such request except on Controller's documented instructions or as required by applicable law.

8. BREACH NOTIFICATION

8.1 Processor shall notify Controller without undue delay and, where feasible, within after becoming aware of a Personal Data Breach affecting Controller's Personal Data. Notification will describe the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed.

9. CROSS-BORDER TRANSFERS

9.1 Processor shall not transfer Personal Data to any jurisdiction outside the territory specified in the Main Agreement without Controller's prior written authorization. Where such transfers occur, Processor shall implement appropriate safeguards required by applicable data protection law.

10. RETURN OR DELETION OF PERSONAL DATA

10.1 Upon termination or expiry of the Main Agreement, Processor shall, at Controller's choice, return all Personal Data to Controller and delete existing copies, or securely destroy such Personal Data, within unless retention is required by applicable law.

11. AUDIT AND INSPECTION

11.1 Processor shall make available to Controller all information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits, including on-site inspections, subject to reasonable prior notice and confidentiality protections.

12. CONFIDENTIALITY

12.1 Processor shall treat Personal Data as confidential and shall not disclose Personal Data to any third party except as permitted by this Agreement or as required by law. Processor shall ensure that its personnel and sub-processors are bound by equivalent confidentiality obligations.

13. LIABILITY AND INDEMNITY

13.1 Each party's liability with respect to breaches of this Agreement shall be subject to the limitations and exclusions of liability set forth in the Main Agreement; provided, however, that nothing in this Agreement limits liability for willful misconduct or gross negligence.

13.2 Processor shall indemnify Controller for losses arising from Processor's unauthorized processing or breach of its obligations under this Agreement, to the extent such losses are caused by Processor's breach.

14. TERM AND TERMINATION

14.1 This Agreement shall commence on the Effective Date and shall continue for the term of the Main Agreement or until all Personal Data is returned or securely destroyed as required herein.

15. NOTICES

16. AMENDMENT, WAIVER, COUNTERPARTS

16.1 Any amendment to this Agreement shall be in writing and signed by duly authorized representatives of both parties. A waiver of any provision shall be effective only if in writing and signed by the waiving party. This Agreement may be executed in counterparts, each of which shall be deemed an original.

17. GOVERNING LAW, ENTIRE AGREEMENT, SEVERABILITY

17.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified in the Main Agreement. Parties submit to the exclusive jurisdiction of the competent courts of that jurisdiction for disputes arising under this Agreement.

17.2 Entire Agreement: This Agreement constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes prior agreements and understandings relating to the processing of Personal Data.

17.3 Severability: If any provision of this Agreement is held invalid or unenforceable, the remainder of this Agreement shall remain in full force and effect.

18. MISCELLANEOUS

18.1 Assignment: Neither party may assign its rights or obligations under this Agreement without the prior written consent of the other party, except to an affiliate or successor in connection with a merger or sale of substantially all assets.

18.2 Survival: The parties' rights and obligations under Sections concerning confidentiality, return or deletion of Personal Data, liability, and any other provisions intended to survive termination shall survive termination or expiration of this Agreement.

Controller

Printed Name:

By:

Date:

Processor

Printed Name:

By:

Date:

Enter text✕

What a Data Processing Agreement Document Is and When it Applies

A Data Processing Agreement Document (DPA) is a contract that sets out the responsibilities and obligations between a data controller and a data processor when personal data is processed on behalf of the controller. It defines scope, permitted processing activities, security measures, subprocessors, breach notification procedures, data return or deletion terms, and liability allocation. In the U.S. context a DPA supports regulatory obligations (for example HIPAA for covered entities and business associates) and demonstrates contractual safeguards needed for third-party data handling and cross-border transfers.

Why a DPA Matters for Risk Management and Compliance

A DPA clarifies roles, limits processing to agreed purposes, and documents security and breach-notification commitments to meet regulatory obligations such as HIPAA and contractual requirements from partners or vendors.

Why a DPA Matters for Risk Management and Compliance

Typical parties that create or sign a Data Processing Agreement

The DPA facilitates cross-functional review and creates an auditable record of responsibilities between contracting parties.

  • Controllers and processors: Legal and compliance teams who set processing limits and approve vendor safeguards.
  • IT and security teams: Review technical and administrative controls, incident response, encryption, and access rules.
  • Procurement and vendor managers: Negotiate subprocessors, liability caps, and termination conditions.

Core clauses to include in a professional Data Processing Agreement

A well-drafted DPA covers minimum necessary legal and technical points so both parties understand obligations, risks, and remedies.

Processing Scope

Describe categories of personal data, processing purposes, duration, and processing activities in clear, specific language to limit permitted uses and reduce compliance risk.

Security Measures

List technical and organizational safeguards (encryption, access controls, vulnerability management, logging) and reference standards or certifications where applicable, e.g., SOC 2 or ISO 27001.

Subprocessors

Define subprocessors approval process, notice requirements for new subprocessors, and the processor's obligation to flow down equivalent obligations to subcontractors.

Incident Response

Specify breach notification timelines, content requirements, cooperation obligations, and support for investigations and regulatory reporting.

Data Return and Deletion

State the procedures, formats, and timing for returning or securely deleting personal data at contract termination and for periodic data exports.

Liability and Indemnity

Allocate financial responsibility for breaches and noncompliance, set caps where appropriate, and include indemnities for third-party claims tied to processor actions.

Step-by-step: drafting and finalizing a Data Processing Agreement

Follow a staged approach to reduce legal and operational gaps when creating or approving a DPA.

  • 01
    Identify Roles: Confirm which party is controller and which is processor before drafting.
  • 02
    Define Scope: List data categories, purposes, and processing activities in a dedicated section.
  • 03
    Specify Controls: Document security measures, certifications, and breach procedures with measurable commitments.
  • 04
    Approve and Sign: Complete internal reviews (legal, security, procurement) and obtain authorized signatures from both parties.

Configuring an online DPA workflow for review and signature

Design the digital workflow to mirror internal review steps, collect approvals, and ensure an auditable record of each action.

Document Template Use a centralized DPA template with locked clauses and fillable variables to ensure consistency across vendors.
Reviewer Steps Assign sequential reviewers: legal, security, procurement. Require conditional approval before signature routing.
Signature Order Configure signer order to capture controller signature last, or as required by internal policy, to ensure acceptance of final terms.
Authentication Select signer authentication level (email link, SMS code, or advanced methods) appropriate to data sensitivity.
Audit Trail Enable capture of timestamps, IP, and actions to create an evidentiary record for compliance audits.

Where to send and how agreements move through your organization

Routing should reflect internal accountability and preserve evidence of review, approval, and signature for compliance and audit purposes.

  • Upload to Repository: Store the DPA in a document management system with access controls for legal and security teams.
  • Assign Reviewers: Route to legal and security sequentially; require documented approvals before signature.
  • Send to Vendor: Transmit the finalized DPA to the processor with a secure signing link or signed copy request.
  • Archive Final: Save the executed DPA and certificate of completion in a retention-classified archive for later retrieval.

Delivery options and technical formats for DPAs

Document format, storage, and integration choices affect retrievability for audits and the strength of evidentiary records.

  • File formats: PDF/A and DOCX are standard; signed PDFs preserve signatures and produce tamper-evident artifacts.
  • Delivery channels: Signed agreements can be sent via secure email or accessed through a protected signing link; consider enterprise SSO access.
  • Integrations: Integrate with systems such as Salesforce, NetSuite, Google Workspace, and Box to link agreements to vendor records and workflows.

Typical timelines and deadlines when negotiating or executing a DPA

Set internal deadlines to align negotiation, security review, and execution so data processing can proceed without regulatory gaps.

Negotiation Window:

Allow 1–4 weeks depending on complexity and subprocessors.

Security Assessment:

Schedule 2–3 weeks for security questionnaire review and remediation planning.

Signature Period:

Target 3–7 business days for external vendor signature once final terms are agreed.

Breach Notification:

Processor must notify controller promptly; specify maximum timeline (often 72 hours for sensitive breaches).

Annual Review:

Plan yearly reviews for changes in processing, subprocessors, or applicable law.

Common pitfalls when preparing a Data Processing Agreement

  • Vague processing scope that allows purposes beyond the controller’s intent.
  • No subprocessors clause or inadequate flow-down obligations to subcontractors.
  • Missing or unclear breach notification timelines and required content.
  • Failure to align data return, deletion, and portability procedures with operational capability.

Key legal and operational risks from an incorrect or missing DPA

Regulatory Fines: Monetary penalties for data violations under laws like HIPAA.
Contractual Liability: Indemnity and damages claims from partners or customers.
Operational Disruption: Inability to access or transfer data after termination.
Reputational Harm: Public trust loss after data incidents.
Litigation Costs: Attorney fees and defense costs for breach-related suits.
Data Access Risk: Unauthorized third-party processing due to missing flow-down obligations.

Comparing eSignature vendor pricing and capabilities for executing DPAs

Basic vendor comparisons focus on starting price, trial availability, bulk send, audit trail presence, HIPAA compliance, and envelope or session limits.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

How organizations use DPAs in real settings

Short examples show typical DPA scenarios across organizational roles and vendor relationships.

Optica Ventures

The venture firm standardized a DPA for portfolio providers to reduce legal review time.

  • Standardization reduced review iterations.
  • The result was faster onboarding and a single, auditable contract model across investments that clarified responsibilities and reduced vendor risk.

Fertility Centers of Illinois

A healthcare provider attached a HIPAA BAA to its DPA with cloud vendors.

  • BAA required specific encryption and breach reporting.
  • This approach ensured vendor contractual commitments aligned with 45 CFR requirements and simplified compliance audits.

FAQs and troubleshooting for Data Processing Agreement Documents

Answers to frequent questions on enforceability, signature methods, and implementation challenges when using DPAs.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users