Establishing secure connection…Loading editor…Preparing document…

Data Protection Addendum Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA PROTECTION ADDENDUM

This Data Protection Addendum ("Addendum") is entered into as of Effective Date: by and between Controller Name: with principal address: ("Controller"), and Processor Name: with principal address: ("Processor"). Controller and Processor are each a "Party" and collectively the "Parties."

RECITALS

WHEREAS, Controller and Processor are parties to an existing agreement under which Processor processes Personal Data on behalf of Controller (the "Agreement");

WHEREAS, the Parties wish to set out their respective rights and obligations regarding the processing, protection, transfer and security of Personal Data in compliance with applicable data protection law;

WHEREAS, this Addendum supplements and forms part of the Agreement and governs Processing of Personal Data by Processor on behalf of Controller.

NOW, THEREFORE

In consideration of the foregoing and the mutual covenants contained herein, the Parties agree as follows.

1. DEFINITIONS

For purposes of this Addendum, the following capitalized terms have the meanings set forth below: "Personal Data" means any information relating to an identified or identifiable natural person processed under the Agreement; "Processing" has the meaning given in applicable data protection law; "Subprocessor" means any Processor engaged by Processor to carry out Processing activities on behalf of Controller.

2. SUBJECT MATTER, DURATION, NATURE AND PURPOSES OF PROCESSING

3. INSTRUCTIONS AND ROLE OF PARTIES

Processor shall process Personal Data only on documented instructions from Controller, unless required to do otherwise by applicable law. Controller instructs Processor to process Personal Data for the purposes described in Section 2. Processor shall notify Controller if, in Processor's opinion, an instruction infringes applicable data protection law.

4. SECURITY MEASURES

Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:






5. SUBPROCESSING

Controller hereby authorizes Processor to engage Subprocessors as necessary for performance of the Agreement, subject to the restrictions below. Processor shall: (a) enter into a written contract with each Subprocessor imposing obligations substantially similar to those in this Addendum; (b) remain fully liable to Controller for the performance of Subprocessors' obligations; and (c) provide Controller with prior written notice of any intended appointment or replacement of a Subprocessor and a reasonable opportunity to object on reasonable data protection grounds.

6. INTERNATIONAL TRANSFERS

Processor shall not transfer Personal Data outside the jurisdiction(s) where it is collected except as permitted by applicable law and only where there is an adequate level of protection or appropriate safeguards. The Parties agree that transfers shall be governed by one or more lawful transfer mechanisms selected below.




7. DATA SUBJECT RIGHTS

Processor shall, taking into account the nature of the Processing, assist Controller by implementing appropriate technical and organizational measures to the extent reasonably possible to enable Controller to respond to requests from data subjects to exercise their rights under applicable data protection law. Processor shall not respond to a data subject request except on documented instructions from Controller unless required by law to do so.

8. PERSONAL DATA BREACH

Processor shall notify Controller without undue delay and, where legally required, no later than 72 hours after becoming aware of a Personal Data breach affecting Controller's Personal Data. Notification shall include, to the extent possible, the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed and a contact point for further information.

9. AUDIT AND INSPECTION

Controller shall have the right to audit Processor's compliance with this Addendum, including inspection of facilities and records, subject to reasonable notice and confidentiality obligations. Such audits shall be conducted no more frequently than once annually unless required by law or upon a documented material breach.

10. RETURN OR DELETION OF PERSONAL DATA

Upon termination or expiration of the Agreement, Processor shall, at Controller's choice, return all Personal Data to Controller and delete existing copies, or securely destroy all Personal Data, unless retention is required by applicable law. Processor shall certify in writing to Controller that it has complied with this obligation within the timeframe set forth below.

11. LIABILITY AND INDEMNITY

Each Party shall be liable for damages it causes by any breach of its obligations under this Addendum arising from negligence, willful misconduct or breach of applicable data protection law. Processor shall indemnify Controller against losses arising from Processor's breach of this Addendum, including breaches by Subprocessors, except to the extent caused by Controller's instructions or breach.

12. TERM; SURVIVAL

This Addendum shall commence on the Effective Date and shall continue in effect for the term of the Agreement. Provisions that by their nature should survive termination, including but not limited to liability, return or deletion of Personal Data, audit obligations and confidentiality, shall survive termination or expiration of this Addendum.

13. NOTICES

Any notice required or permitted under this Addendum shall be given in writing and delivered to the contact details of the relevant Party. Notices relating to data protection matters shall be sent to the data protection contacts specified below.

14. AMENDMENT; WAIVER; COUNTERPARTS

No amendment of this Addendum will be effective unless in writing and signed by authorized representatives of both Parties. No failure or delay by either Party to exercise any right under this Addendum shall constitute a waiver of that right. This Addendum may be executed in counterparts, each of which shall be deemed an original.

15. GOVERNING LAW; SEVERABILITY; ENTIRE AGREEMENT

This Addendum shall be governed by and construed in accordance with the law specified in the Agreement. If any provision of this Addendum is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. This Addendum, together with the Agreement, constitutes the entire agreement between the Parties in respect of its subject matter and supersedes all prior agreements and understandings relating to such subject matter.

16. MISCELLANEOUS

Each Party represents and warrants that it has the legal authority to enter into this Addendum and that signing this Addendum does not violate any other agreement. The Parties shall cooperate in good faith to implement any additional reasonable measures required to comply with applicable data protection laws.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What the Data Protection Addendum Form Is

A Data Protection Addendum Form is a contractual addendum that records how parties handle personal data when one party processes data on behalf of another. It identifies roles (controller, processor), data categories, processing purposes, security measures, subprocessors, breach notification timelines, retention rules, cross-border transfer mechanisms, audit rights, and signature blocks to create enforceable obligations under commercial contract law.

Why a DPA Matters for Compliance and Contractual Clarity

A Data Protection Addendum clarifies each party's data handling responsibilities, reduces regulatory risk, and documents breach response and audit rights. Properly executed, it supports contractual enforceability and helps satisfy U.S. requirements under ESIGN and applicable state privacy and breach-notification laws.

Why a DPA Matters for Compliance and Contractual Clarity

Who Prepares and Relies on the Data Protection Addendum Form

Organizations that process or control personal data, vendors, and in-house legal or compliance teams prepare and sign the Data Protection Addendum Form.

  • Enterprise legal and procurement teams negotiating third-party data processing agreements and vendor contracts.
  • SaaS vendors, cloud providers, and managed-service companies documenting responsibilities for customer data and subprocessors.
  • Healthcare providers and payers adding HIPAA-specific terms where protected health information is processed.

The executed addendum becomes part of the commercial agreement and is used by operations, security, and legal teams to manage obligations and audits.

Essential Sections to Include in a Professional DPA

A complete Data Protection Addendum Form breaks the agreement into clear sections covering parties, scope, security, subprocessors, breach response, audits, and termination procedures.

Parties

Identify controller(s) and processor(s) by full legal name, registered address, designated data protection contact, and a primary security contact for incident reporting and regulatory inquiries.

Scope

Describe categories of personal data, types of data subjects, processing purposes, and allowed processing activities so obligations and limitations are contractually clear.

Security Measures

Specify technical and organizational safeguards such as encryption, access controls, logging, vulnerability management, patching cadence, and regular security testing.

Subprocessors

List authorized subprocessors or define a subprocessors approval and notice process, plus flow-down contractual obligations to subprocessors.

Breach Response

Define incident notification timing, roles for investigation and remediation, regulatory reporting responsibilities, and assistance for affected data subjects under state breach laws.

Audit & Termination

Grant audit rights, define remote or on-site assessments, detail data return or secure deletion procedures on termination, and specify survival clauses for key obligations.

Required Data Elements and Fields

Controller Name: Full legal entity name and primary contact.
Processor Name: Full legal entity name and designated security contact.
Data Categories: Types of personal data processed (PHI, identifiers).
Processing Purpose: Explicit business purpose or service function.
Retention Period: Retention duration or deletion schedule.
Security Standard: Referenced controls or frameworks (e.g., encryption).

Step-by-Step: Complete and Execute the DPA

Follow these sequential steps to prepare, review, and finalize the Data Protection Addendum Form.

  • 01
    Gather Information: Collect party details, data types, and contacts.
  • 02
    Draft Provisions: Populate scope, security, subprocessors, and retention.
  • 03
    Legal Review: Have counsel review obligations and liability clauses.
  • 04
    Execute: Sign via authorized representative and retain executed copy.

How to Configure an Online DPA Workflow

Set up a digital workflow that captures required fields, enforces authentication, and preserves an audit trail for the executed addendum.

Field Configuration
Signature Type eSignature or wet-ink option selectable
Authentication Email link, SMS code, or KBA where required
Retention Setting Archive signed PDF/A and metadata indefinitely
Audit Trail Capture IP, timestamp, and action log

Digital Execution and File Formats

Choose a platform that supports PDF and DOCX formats, rigorous audit trails, and common enterprise integrations.

  • File Formats: PDF, DOCX, and Excel supported
  • Integrations: Salesforce, NetSuite, Microsoft 365 compatibility
  • Authentication: Email, SMS, or advanced methods

How Digital Signing Typically Works for a DPA

A standard electronic signing workflow moves the draft DPA from sender to signer with authentication and preserves a signed record and audit trail.

  • Upload Document: Sender uploads final DPA to the platform
  • Assign Fields: Place signature, date, and name fields
  • Send to Signer: Deliver via email link or signing portal
  • Capture Evidence: Platform records IP, timestamp, and events

Common Deadlines and Timing Considerations

Track execution timing, operational start dates, and notification windows to ensure contractual and regulatory compliance.

Effective Date Entry:

Document the agreed MM/DD/YYYY effective date

Breach Notice Window:

Specify notification period (e.g., 72 hours) if agreed

Subprocessor Notice:

Define notice period before onboarding subprocessors

Retention Start:

State when retention clocks begin (creation or termination)

Review Cadence:

Set periodic review intervals for DPA terms

Key Milestones in the DPA Lifecycle

Map the agreement from negotiation through termination so stakeholders know when obligations start and end.

01

Negotiation

Draft and clarify scope and liabilities

02

Legal Approval

Counsel reviews risk allocation and terms

03

Execution

Authorized signatories sign the addendum

04

Operational Start

Processor begins processing per effective date

Common Mistakes to Avoid

  • Using broad or vague data descriptions that create ambiguous obligations and expose parties to unintended processing permissions.
  • Failing to list subprocessors or lacking a clear approval and notice mechanism for onboarding downstream vendors.
  • Omitting incident response timelines or failing to assign roles, which delays regulatory reporting and remediation.
  • Neglecting to align retention and deletion clauses with industry rules such as HIPAA or tax record retention requirements.

Penalties and Risks for an Incomplete or Incorrect DPA

Regulatory Fines: Potential enforcement penalties and corrective action
Contractual Damages: Indemnities, breach damages, and litigation costs
Operational Disruption: Delayed processing or suspension of services
Breach Notification Costs: Direct costs to notify and remediate affected subjects
Reputational Harm: Loss of customer trust and brand damage
Compliance Gaps: Failure to meet HIPAA or state requirements

Who Typically Signs the Data Protection Addendum

Chief Legal Officer

Senior legal officer or authorized signatory who can bind the organization and accept contractual liability on behalf of the company; often reviews indemnity and liability limits before signing.

Data Protection Officer

Operational privacy or security lead who certifies technical controls and incident response readiness; provides attestations about safeguards and assists with audit or compliance requests.

Practical Tips for Accurate and Efficient DPA Completion

Adopt consistent templates, validate signatory authority, and align technical controls with contractual promises to reduce risk and negotiation cycles.

Use a Minimal Template
Start with a concise template that includes required legal clauses and avoids extraneous obligations that prolong negotiation and increase legal exposure.
Align Technical and Contractual Controls
Ensure stated security measures in the DPA match operational practices and evidence, such as encryption, patching schedules, and vulnerability scanning.
Document Subprocessor Process
Define a clear subprocessors notice and objection process to maintain control over downstream vendors and meet customer expectations.
Version Control and Archiving
Track DPA versions, archive executed copies in immutable format (PDF/A), and preserve the audit trail for legal and regulatory review.

eSignature Pricing Comparison for Executing a Data Protection Addendum

Compare common plan attributes that matter when executing and archiving Data Protection Addendum Forms across vendors; signNow is listed first per comparison rules.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no card Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap Limits to 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

FAQs and Troubleshooting for the Data Protection Addendum Form

Answers to common questions about enforceability, e-signatures, notarization, updates, and audits for Data Protection Addendum Forms.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users