Establishing secure connection…Loading editor…Preparing document…

Data Processing Agreement Privacy Policy

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Data Processing Agreement and Privacy Policy

This Data Processing Agreement and Privacy Policy (the "Agreement") is entered into as of between Controller: , with principal place of business at , and Processor: , with principal place of business at .

RECITALS

WHEREAS, Controller collects and determines the purposes and means of processing certain personal data in the course of its business operations; and

WHEREAS, Processor will process personal data on behalf of Controller in order to provide services pursuant to the parties' main agreement and must do so in compliance with applicable data protection laws and this Agreement; and

WHEREAS, the parties wish to set out their respective obligations regarding the processing, protection, transfer, and retention of personal data.

NOW THEREFORE

1. DEFINITIONS

1.1 "Personal Data" means any information relating to an identified or identifiable natural person that is provided to or collected by Processor on behalf of Controller in connection with the services.

1.2 "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure or destruction.

1.3 Other capitalized terms used in this Agreement shall have the meanings set forth in this section or as otherwise defined in the main agreement between the parties.

2. SUBJECT-MATTER, DURATION, NATURE AND PURPOSES OF PROCESSING

2.1 Subject-matter: The subject-matter of the Processing is the Personal Data provided or collected in connection with the services described in this Agreement and the main services agreement.

2.2 Duration: The Processor will process Personal Data for the duration necessary to perform the services and for any additional retention period required by applicable law or as specified by Controller:

3. PROCESSOR OBLIGATIONS

3.1 Processor shall only process Personal Data on documented instructions from Controller, including with respect to transfers of Personal Data to a third country or an international organization, unless required to do otherwise by applicable law. Where Processor is so required, Processor shall notify Controller of that legal requirement before processing, unless the law prohibits such notification.

3.2 Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. SUBPROCESSORS

4.1 Processor shall not engage any subprocessor without Controller's prior written authorization. Controller provides general authorization for the engagement of subprocessors identified in writing by Processor and for any future subprocessors subject to Controller's notice and objection rights as set out below.

4.2 Controller's consent to Processor's use of a subprocessor shall be deemed given unless Controller objects in writing within days after receipt of notice identifying the new subprocessor.

5. INTERNATIONAL TRANSFERS

5.1 Any transfer of Personal Data outside the country of initial collection shall be subject to appropriate safeguards, including binding contractual terms, approved standard contractual clauses, or other mechanisms permitted under applicable law, as required by Controller.

6. DATA SUBJECT RIGHTS

6.1 Processor shall, to the extent legally permitted, promptly notify Controller if it receives a request from a data subject to exercise any data subject rights. Processor shall not respond to such requests except on documented instructions from Controller or as required by applicable law.

7. SECURITY INCIDENTS AND BREACH NOTIFICATION

7.1 Processor shall notify Controller without undue delay and, where feasible, within hours of becoming aware of any personal data breach affecting Controller's Personal Data. The notification shall include, where possible, a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, and measures taken or proposed to be taken to address the breach.

8. AUDIT, COMPLIANCE AND RECORDS

8.1 Processor shall maintain written records of all categories of processing activities carried out on behalf of Controller. Controller, or an independent auditor mandated by Controller, shall have the right, upon reasonable notice and subject to confidentiality obligations, to audit Processor's compliance with this Agreement by on-site inspection or by providing audit evidence.

9. CONFIDENTIALITY

9.1 Each party shall keep confidential and not disclose to any third party any Confidential Information, including Personal Data, received under this Agreement except as required to perform its obligations under this Agreement or as required by law. Confidential Information shall be handled in accordance with the confidentiality terms set forth in the main agreement and, where applicable, with the requirements of data protection law.

10. RETURN OR DELETION OF DATA

10.1 Upon termination or expiration of the services, Processor shall, at Controller's choice, return all Personal Data to Controller and delete existing copies, or securely destroy all Personal Data and certify in writing that it has done so, except where retention is required by applicable law. If Processor cannot comply with Controller's instructions due to applicable law, Processor shall inform Controller of the relevant requirement and restrict further processing.

11. LIABILITY AND INDEMNIFICATION

11.1 Each party shall be liable for breaches of this Agreement and applicable data protection law to the extent provided by law. Processor shall indemnify and hold Controller harmless from liabilities, losses, damages, and costs arising out of Processor's breach of its obligations under this Agreement, except to the extent that such loss results from Controller's breach or instructions.

12. NOTICES

12.1 Any notice required or permitted under this Agreement shall be given in writing and delivered to the addresses set out below or to such other address as either party may designate by notice in accordance with this section.

13. AMENDMENTS, WAIVER AND COUNTERPARTS

13.1 Any amendment or modification of this Agreement shall be in writing and signed by authorized representatives of both parties. No failure or delay by either party in exercising any right under this Agreement shall operate as a waiver of such right. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument.

14. GOVERNING LAW; SEVERABILITY; ENTIRE AGREEMENT

14.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of , without regard to its conflict of law principles.

14.2 Severability: If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

14.3 Entire Agreement: This Agreement, together with any referenced exhibits and the main services agreement, constitutes the entire agreement between the parties with respect to the Processing of Personal Data and supersedes all prior written or oral agreements on the subject.

15. MISCELLANEOUS

15.1 Remedies: The rights and remedies provided in this Agreement are cumulative and are in addition to any other rights and remedies available at law or in equity.

15.2 Interpretation: Headings are for convenience only and shall not affect interpretation. References to laws include successor statutes and implementing regulations.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What the Data Processing Agreement Privacy Policy Is and Why It Matters

The Data Processing Agreement Privacy Policy combines a data processing agreement (DPA) with a privacy policy addendum to define how a processor handles personal data on behalf of a controller, and to document privacy practices for covered data. It clarifies roles (controller vs processor), categories of personal data processed, permitted processing purposes, security measures, subprocessors, cross-border transfer terms, breach notification obligations, and retention rules. In the United States this document supports compliance with sectoral laws (for example HIPAA and FERPA) and aligns with electronic-signature acceptance under ESIGN and state UETA statutes for contract execution.

Why a Combined DPA and Privacy Policy Protects Your Organization

A clear Data Processing Agreement Privacy Policy reduces regulatory risk, ensures contractual allocation of responsibilities, documents security controls, and creates an auditable record for regulators and customers. It also demonstrates the parties’ consent to electronic execution under ESIGN and applicable state UETA frameworks.

Why a Combined DPA and Privacy Policy Protects Your Organization

Who Typically Prepares or Signs This Document

Organizations of all sizes use DPAs and privacy policies to formalize personal data handling between controllers and processors.

  • Data controllers and legal teams: draft terms, set permitted purposes and compliance obligations.
  • Managed service providers and SaaS processors: define subprocessors, security controls, and incident response.
  • Compliance officers and procurement: review, negotiate, and approve contractual language before signing.

Depending on the organization, signatory roles often include the company legal officer, authorized contracting officer, or an operations executive with delegated authority.

Step-by-Step: How to Complete a Data Processing Agreement Privacy Policy

Follow these steps to prepare, review, and execute the combined DPA and privacy policy using an electronic workflow.

  • 01
    Gather inputs: Collect party names, data categories, processing purposes, and contact details.
  • 02
    Draft terms: Specify roles, security measures, subprocessors, cross-border rules, and retention.
  • 03
    Legal review: Have counsel verify regulatory clauses (HIPAA, FERPA, CCPA as applicable).
  • 04
    Execute: Route for signatures, capture audit trail, and store executed copy in records.

How to Configure an Online Signing Workflow for This Agreement

Set up the document routing, authentication, and retention options before sending to ensure compliance and a reliable audit trail.

Field Configuration
Authentication Email link, SMS code, or KBA as required
Routing Sequential order with approver and final signer
Conditional fields Show or hide subprocessor lists based on responses
Audit retention Retain signature audit trail for minimum required period

Where to Send, Store, and Share the Executed Agreement

After signing, route the executed DPA and privacy policy to the appropriate internal and external recipients to maintain compliance and operational readiness.

  • Counterparty: Send executed copy to the contracting party for their records.
  • Legal Repository: Store PDF in central contract management with full audit trail.
  • Data Protection Officer: Provide DPO or privacy lead a copy for oversight and monitoring.
  • Auditors and Regulators: Share upon lawful request or during compliance audits.

Technical Requirements for E-Signing and eSubmission

Choose a platform that supports secure signing, robust audit trails, and document format compatibility for legal enforceability.

  • Supported formats: PDF and DOCX formats with preserved audit metadata
  • Integrations: Connect to storage, CRM, and contract lifecycle tools
  • Authentication: Multi-factor options and traceable signer attribution

Preserve signed documents in an access-controlled repository, retain audit logs for the required retention period, and ensure exports include the certificate of completion for evidentiary value.

Key Clauses to Include in a Professional Data Processing Agreement Privacy Policy

A robust document balances legal clarity with operational detail so both parties understand obligations and remedies.

Scope and Definitions

Define controller/processor roles, data categories, and processing activities to prevent ambiguity and narrow contractual scope.

Security Standards

Specify technical and organizational measures such as encryption, access control, logging, and vulnerability management with measurable expectations.

Subprocessors

Require notice and approval processes for subcontractors; define onboarding, security checks, and termination rights for subprocessors.

Cross-Border Transfers

Describe permitted transfers, transfer mechanisms, and contractual safeguards for international data movements.

Breach Notification

Set timing and content for notifications, remediation responsibilities, and cooperation with investigations.

Audit and Inspection

Allow for audits or attestations (reports or onsite audits) and require remediation plans following findings.

Essential Information Fields to Capture in the Document

Controller Name: Legal entity name
Processor Name: Legal entity name
Contact Point: DPO or privacy contact
Data Categories: Types of personal data
Processing Purpose: Permitted uses
Retention Period: How long data is kept

Practical Tips for Accurate and Efficient Completion

Implement pragmatic controls and review steps to streamline drafting, negotiation, and execution while preserving legal certainty.

Use clear definitions
Keep definitions consistent across the agreement and related policies; ambiguous terms create enforcement gaps during audits or disputes.
Align retention with law
Match retention clauses to applicable statutes such as tax, employment, and health records requirements to avoid unintended deletions.
Document subprocessors
Maintain a current subprocessors list and a defined approval process; frequent changes should be governed by contract amendment rules.
Keep an audit trail
Record changes, approvals, and executed copies with timestamps and signer attribution to support compliance reviews and incident investigations.

Key Deadlines and Timing Expectations to Note

Track execution and notification deadlines to ensure contractual and regulatory obligations are met without delay.

Effective Date:

Date when processing obligations start

Execution Deadline:

Complete signatures before processing begins

Annual Review:

Reassess terms and subprocessors at least annually

Breach Notification:

HIPAA requires notification without unreasonable delay and no later than 60 days after discovery

Record Retention:

Keep executed agreement for the full statutory retention period

Common Risks and Penalties for Incomplete or Incorrect Agreements

Regulatory fines: Enforcement under HIPAA, CCPA, or sector rules
Contractual liability: Indemnities and damage awards for breaches
Operational disruption: Interrupted processing or access suspension
Data breach costs: Notification, mitigation, and remediation expenses
Reputational harm: Loss of customer trust and business
Litigation exposure: Class actions or individual claims

Typical eSignature Pricing and Feature Comparison for DPA Execution

Compare typical starting prices and key features when selecting an eSignature provider to execute and manage Data Processing Agreement Privacy Policy workflows.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Real-World Examples of How Organizations Use DPAs and Privacy Policies

These short examples show how teams apply the agreement to operations and compliance.

BIS — Supply Chain Compliance

Company needed SOC 2-level assurances for vendor data processing

  • Implemented a DPA with explicit security measures and audit rights
  • The agreement streamlined audits and supported vendor onboarding while preserving contractual liability limits and remediation steps.

Fertility Centers of Illinois — Patient Data

Healthcare provider required HIPAA protections and subprocessors control

  • Added BAA language and encryption requirements
  • The combined privacy policy and DPA clarified permitted uses and produced an auditable trail for privacy reviews and patient inquiries.

Frequently Asked Questions About the Data Processing Agreement Privacy Policy

Answers to common questions about legal enforceability, signatures, breach response, and storage of the executed agreement.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users