Processing Scope
Define categories of personal data, processing purposes, and the duration of processing so the processor acts only on documented instructions.
A DPA apportions legal responsibility, records security controls, and sets incident-response obligations so both parties meet regulatory and contractual expectations; it demonstrates due diligence for audits and helps limit liability after a breach.
Use a DPA template as a starting point for negotiation, then adjust scope, subprocessors, and security annexes to reflect the specific processing activities and applicable law.
Primary negotiator for contract language and risk allocation; reviews indemnity, limitation of liability, and governing law clauses to ensure corporate exposure aligns with policy.
Responsible for advising on privacy obligations, assessing data flows, and ensuring technical and organizational measures in the DPA meet regulatory standards such as HIPAA or sectoral controls.
Define categories of personal data, processing purposes, and the duration of processing so the processor acts only on documented instructions.
Specify technical and organizational controls (encryption, access controls, incident monitoring) and reference standards or baselines the processor must meet.
Require prior notice and approval or a predefined list of subprocessors and include the obligation that subprocessors flow down equivalent contractual obligations.
Set maximum notification timelines, required content for notifications, and coordination procedures for regulatory reports or affected data subjects.
Allow for audits, either on-site or through third-party reports (SOC 2 Type II), and define frequency and data access limitations.
Obligate timely return or secure deletion of personal data at contract end and require a certificate of destruction or exportable data format.
| Field | Configuration |
|---|---|
| Party Names | Required text fields; exact-match validation |
| Effective Date | MM/DD/YYYY format with default today option |
| Subprocessor List | Repeatable table field for names and locations |
| Signature Order | Sequential routing: legal → security → exec |
Verify the chosen provider supports required compliance frameworks and produces an exportable, tamper-evident signed record for retention and audits.
Set maximum timeline (e.g., 72 hours) for initial notification or as negotiated
Require advance notice (commonly 10–30 days) before on-boarding subprocessors
Specify annual or biennial audits or SOC 2 reports as agreed
Require return or secure deletion within 30–90 days of termination
Schedule periodic reviews aligned with statute-driven retention obligations
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no card required | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |