Establishing secure connection…Loading editor…Preparing document…

Data Processing Agreement Template

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA PROCESSING AGREEMENT

This Data Processing Agreement (the Agreement) is entered into as of (Effective Date) by and between Controller Name: with address and Processor Name: with address .

RECITALS

WHEREAS, Controller determines the purposes and means of Processing of Personal Data in connection with Controller's provision of services and business operations; and

WHEREAS, Processor will process certain Personal Data on behalf of Controller pursuant to Controller's documented instructions and the terms of this Agreement; and

WHEREAS, the parties wish to set forth their respective responsibilities for the protection of Personal Data and to ensure that Processing by Processor complies with applicable data protection law.

NOW, THEREFORE, in consideration of the mutual covenants contained herein, the parties agree as follows:

1. DEFINITIONS

1.1. "Personal Data" means any information relating to an identified or identifiable natural person that Controller provides to Processor or that Processor otherwise processes on Controller's behalf pursuant to this Agreement.

1.2. "Processing" or "Process" means any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure or destruction.

1.3. "Sub-processor" means any Processor engaged by Processor to carry out specific Processing activities on behalf of Controller pursuant to this Agreement.

2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE OF PROCESSING

2.1. Subject matter: The subject matter of Processing under this Agreement is Controller's Personal Data processed by Processor in connection with the services described in the principal commercial agreement between the parties.

2.2. Duration: The Processing shall commence on the Effective Date and shall continue for the term of the underlying services agreement unless earlier terminated in accordance with this Agreement.

3. CONTROLLER INSTRUCTIONS

3.1. Processor shall process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do otherwise by applicable law. Where Processor is required by law to process Personal Data other than on documented instructions of Controller, Processor shall inform Controller of that legal requirement unless that law prohibits such information on important grounds of public interest.

4. PROCESSOR OBLIGATIONS

4.1. Confidentiality and personnel: Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2. Assistance to Controller: Processor shall, taking into account the nature of the processing and the information available to Processor, assist Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller’s obligation to respond to requests for exercising the data subject’s rights.

5. SECURITY INCIDENTS AND BREACH NOTIFICATION

5.1. In the event of a confirmed or reasonably suspected Personal Data breach, Processor shall notify Controller without undue delay and, where feasible, within hours of becoming aware of the breach and shall provide Controller with sufficient information to allow Controller to meet any regulatory obligations to notify authorities and data subjects.

6. SUB-PROCESSING

6.1. Controller authorizes Processor to engage Sub-processors where Processor provides Controller with prior written notice of such appointment and implements a contract with the Sub-processor imposing obligations no less protective than those set out in this Agreement. Controller may object in writing to the appointment of a Sub-processor within days of receipt of notice on reasonable grounds.

7. INTERNATIONAL TRANSFERS

7.1. Any transfer of Personal Data by Processor to a country or territory outside the country of Controller's establishment shall be subject to appropriate safeguards as required by applicable data protection law. Processor shall implement and maintain appropriate transfer mechanisms and shall provide Controller with documentation evidencing such safeguards upon request.

8. DATA SUBJECT RIGHTS

8.1. Processor shall, to the extent legally permitted, promptly notify Controller if Processor receives a request from a data subject to exercise their rights under applicable data protection law. Processor shall assist Controller, taking into account the nature of the Processing, in fulfilling Controller's obligations to respond to such requests.

9. AUDIT, RECORDS AND INSPECTION

9.1. Processor shall maintain records of Processing activities carried out on behalf of Controller and shall, upon reasonable prior notice and subject to any confidentiality obligations to third parties, make available to Controller all information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits, including inspections, by Controller or an authorized auditor.

10. RETURN OR DELETION OF PERSONAL DATA

10.1. Upon termination or expiration of the services, Processor shall, at Controller's option, return all Personal Data to Controller and delete existing copies, or securely destroy such Personal Data, unless retention of some or all of the Personal Data is required by applicable law. Processor shall certify in writing to Controller that it has complied with this obligation.

11. LIABILITY AND INDEMNITY

11.1. Each party's liability for breaches of obligations arising under this Agreement shall be governed by the liability provisions set out in the underlying services agreement between the parties. Without prejudice to any other rights, Processor shall be liable for damages caused by Processing where Processor has not complied with obligations of this Agreement or acted outside or contrary to Controller's lawful instructions.

11.2. To the extent permitted by applicable law, the parties shall indemnify each other for losses arising from their respective breaches of this Agreement, subject to any limits or exclusions of liability agreed in the principal agreement.

12. CONFIDENTIALITY

12.1. Each party shall maintain as confidential all information obtained from the other party in connection with this Agreement and shall not disclose such information except as required by law or as necessary to perform obligations under this Agreement and the underlying services agreement.

13. NOTICES

13.1. All notices and other communications required or permitted under this Agreement shall be in writing and shall be delivered to the addresses set out below or to such other address as may be notified in writing in accordance with this section.

14. AMENDMENT, WAIVER AND COUNTERPARTS

14.1. No amendment to this Agreement shall be effective unless it is in writing and signed by authorized representatives of both parties. No failure or delay by either party in exercising any right under this Agreement shall operate as a waiver of that right.

14.2. This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument.

15. GOVERNING LAW, ENTIRE AGREEMENT AND SEVERABILITY

15.1. Governing law: This Agreement shall be governed by and construed in accordance with the laws of without regard to conflict of law principles.

15.2. Entire Agreement: This Agreement constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior agreements and understandings relating to the Processing of Personal Data.

15.3. Severability: If any provision of this Agreement is held to be invalid or unenforceable, such provision shall be severed and the remainder of this Agreement shall remain in full force and effect.

16. MISCELLANEOUS

16.1. The obligations under this Agreement shall survive termination or expiration of the underlying services agreement to the extent necessary to allow the parties to fulfil their respective obligations to return or delete Personal Data and to comply with applicable legal requirements.

Controller

Printed Name:

By:

Date:

Processor

Printed Name:

By:

Date:

Enter text✕

What a Data Processing Agreement Template Is and When to Use It

A Data Processing Agreement Template (DPA) is a standardized contract that sets out how a data controller and a data processor handle personal data, including permitted purposes, security measures, subprocessors, breach notification, international transfers, and deletion or return at termination. In the United States, DPAs are used to document obligations driven by contractual commitments, sectoral rules (for example HIPAA for healthcare), and privacy laws that affect processing operations. A well-drafted DPA clarifies responsibilities, reduces compliance gaps, and supports auditability without replacing a full negotiated agreement when needed.

Why a Clear DPA Matters for Compliance and Risk Management

A DPA apportions legal responsibility, records security controls, and sets incident-response obligations so both parties meet regulatory and contractual expectations; it demonstrates due diligence for audits and helps limit liability after a breach.

Why a Clear DPA Matters for Compliance and Risk Management

Who Typically Uses a Data Processing Agreement Template

Use a DPA template as a starting point for negotiation, then adjust scope, subprocessors, and security annexes to reflect the specific processing activities and applicable law.

  • In-house legal teams and contract managers who need consistent, auditable processing clauses across vendors and cloud services.
  • IT and security teams who require documented technical and organizational measures before enabling integrations or data transfers.
  • SMBs and procurement teams reviewing vendor onboarding where standard terms reduce negotiation time and clarify breach notification timelines.

Typical Signatories and Their Roles

Legal Counsel

Primary negotiator for contract language and risk allocation; reviews indemnity, limitation of liability, and governing law clauses to ensure corporate exposure aligns with policy.

Data Protection Officer

Responsible for advising on privacy obligations, assessing data flows, and ensuring technical and organizational measures in the DPA meet regulatory standards such as HIPAA or sectoral controls.

Core Sections Every Professional DPA Should Include

A professional DPA organizes responsibilities and demonstrates compliance. Include clear clauses for processing scope, security measures, subprocessors, breach handling, audits, and termination to make obligations enforceable and auditable.

Processing Scope

Define categories of personal data, processing purposes, and the duration of processing so the processor acts only on documented instructions.

Security Measures

Specify technical and organizational controls (encryption, access controls, incident monitoring) and reference standards or baselines the processor must meet.

Subprocessors

Require prior notice and approval or a predefined list of subprocessors and include the obligation that subprocessors flow down equivalent contractual obligations.

Breach Notification

Set maximum notification timelines, required content for notifications, and coordination procedures for regulatory reports or affected data subjects.

Audit and Inspection

Allow for audits, either on-site or through third-party reports (SOC 2 Type II), and define frequency and data access limitations.

Termination and Data Return

Obligate timely return or secure deletion of personal data at contract end and require a certificate of destruction or exportable data format.

Essential Information to Include in the Template

Parties: Controller name
Processor: Processor legal name
Data Types: Categories of personal data
Processing Purpose: Purpose summary
Security Controls: Encryption, access model
Retention: Retention and deletion policy

Common Risks When a DPA Is Incomplete

Unclear Liability: May lead to disputed indemnity exposure
Undefined Breach Process: Delays in notification and regulatory fines
Missing Subprocessor Controls: Unauthorized data transfers and compliance gaps
Insufficient Security Specs: Higher risk of data loss and reputational harm
No Data Return Clause: Complicated exit and data portability issues
Inconsistent Jurisdiction: Competing laws and enforcement ambiguities

Step-by-Step: How to Complete the Data Processing Agreement Template

Follow a structured sequence to complete and validate a DPA: identify parties and data flows, map processing activities, define security controls, list subprocessors, set breach procedures, and finalize signatures with appropriate authority.

  • 01
    Identify Parties: Enter full legal names and contact for notifications
  • 02
    Map Data Flows: List data categories and cross-border transfers
  • 03
    Set Controls: Specify encryption, access, and logging requirements
  • 04
    Approve Signatories: Confirm authorized signers and dates

How a DPA Works in Practice with Vendor Onboarding

A DPA integrates into vendor onboarding by documenting expected processing activities, security commitments, and response obligations; this enables risk review and operational alignment before access to production data.

  • Upload Template: Use the template as the basis for vendor-specific edits
  • Complete Fields: Populate parties, scope, and technical annex
  • Review Controls: Security team verifies measures and testing
  • Sign and Retain: Document sign-off and store auditable copies

Digital Customization Checklist for Online Completion

When completing a DPA online, configure fields and routing so legal, security, and operational stakeholders can review, approve, and sign in sequence.

Field Configuration
Party Names Required text fields; exact-match validation
Effective Date MM/DD/YYYY format with default today option
Subprocessor List Repeatable table field for names and locations
Signature Order Sequential routing: legal → security → exec

Considerations for eSigning and Secure Exchange

Verify the chosen provider supports required compliance frameworks and produces an exportable, tamper-evident signed record for retention and audits.

  • Authentication: Email, SMS code, or stronger KBA/SSO
  • Audit Trail: Timestamp, IP, and action log included
  • Document Formats: PDF, DOCX, and archival PDF/A supported

Timeframes and Deadlines to Keep in Mind

DPAs impose operational deadlines (for example notification windows and audit timelines) and interact with regulatory reporting periods; track both contractual and statutory timelines.

Breach Notification Window:

Set maximum timeline (e.g., 72 hours) for initial notification or as negotiated

Subprocessor Notice:

Require advance notice (commonly 10–30 days) before on-boarding subprocessors

Audit Frequency:

Specify annual or biennial audits or SOC 2 reports as agreed

Data Return:

Require return or secure deletion within 30–90 days of termination

Retention Review:

Schedule periodic reviews aligned with statute-driven retention obligations

Comparison: Common eSignature Providers for Executing DPAs

Select an eSignature provider based on price, compliance needs, and volume. The table below compares starting prices and key features across vendors; signNow is listed first per comparison format.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no card required Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently Asked Questions About the Data Processing Agreement Template

Answers to common questions about using, customizing, and validating a DPA including signatures, enforcement, and recordkeeping obligations.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users