Parties
Identify controller(s) and processor(s) by full legal name, registered address, designated data protection contact, and a primary security contact for incident reporting and regulatory inquiries.
A Data Protection Addendum clarifies each party's data handling responsibilities, reduces regulatory risk, and documents breach response and audit rights. Properly executed, it supports contractual enforceability and helps satisfy U.S. requirements under ESIGN and applicable state privacy and breach-notification laws.
Organizations that process or control personal data, vendors, and in-house legal or compliance teams prepare and sign the Data Protection Addendum Form.
The executed addendum becomes part of the commercial agreement and is used by operations, security, and legal teams to manage obligations and audits.
Identify controller(s) and processor(s) by full legal name, registered address, designated data protection contact, and a primary security contact for incident reporting and regulatory inquiries.
Describe categories of personal data, types of data subjects, processing purposes, and allowed processing activities so obligations and limitations are contractually clear.
Specify technical and organizational safeguards such as encryption, access controls, logging, vulnerability management, patching cadence, and regular security testing.
List authorized subprocessors or define a subprocessors approval and notice process, plus flow-down contractual obligations to subprocessors.
Define incident notification timing, roles for investigation and remediation, regulatory reporting responsibilities, and assistance for affected data subjects under state breach laws.
Grant audit rights, define remote or on-site assessments, detail data return or secure deletion procedures on termination, and specify survival clauses for key obligations.
| Field | Configuration |
|---|---|
| Signature Type | eSignature or wet-ink option selectable |
| Authentication | Email link, SMS code, or KBA where required |
| Retention Setting | Archive signed PDF/A and metadata indefinitely |
| Audit Trail | Capture IP, timestamp, and action log |
Choose a platform that supports PDF and DOCX formats, rigorous audit trails, and common enterprise integrations.
Document the agreed MM/DD/YYYY effective date
Specify notification period (e.g., 72 hours) if agreed
Define notice period before onboarding subprocessors
State when retention clocks begin (creation or termination)
Set periodic review intervals for DPA terms
Draft and clarify scope and liabilities
Counsel reviews risk allocation and terms
Authorized signatories sign the addendum
Processor begins processing per effective date
Senior legal officer or authorized signatory who can bind the organization and accept contractual liability on behalf of the company; often reviews indemnity and liability limits before signing.
Operational privacy or security lead who certifies technical controls and incident response readiness; provides attestations about safeguards and assists with audit or compliance requests.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no card | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | Limits to 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |