Establishing secure connection…Loading editor…Preparing document…

Data Protection Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA PROTECTION AGREEMENT

This Data Protection Agreement ("Agreement") is entered into as of Effective Date: by and between Data Controller: with registered address and Data Processor: with registered address (each a "Party" and together the "Parties").

RECITALS

WHEREAS, the Data Controller determines the purposes and means of Processing of Personal Data in connection with the Controller's business operations; and

WHEREAS, the Data Processor processes Personal Data on behalf of the Controller in accordance with a separate services agreement between the Parties and, in doing so, will receive, store, and otherwise process Personal Data; and

WHEREAS, the Parties wish to record their respective obligations with respect to the Processing of Personal Data to ensure compliance with Applicable Data Protection Law.

NOW THEREFORE, in consideration of the mutual covenants set forth herein, the Parties agree as follows:

1. DEFINITIONS

For the purposes of this Agreement:

"Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller.

"Processing" or "Process" means any operation or set of operations performed upon Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, restriction, erasure, or destruction.

"Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under this Agreement.

"Sub-processor" means any Processor engaged by the Processor to carry out specific Processing activities on behalf of the Controller.

2. PURPOSE AND SCOPE OF PROCESSING

2.1 The Processor shall Process Personal Data only for the following documented purposes:

2.2 Categories of Personal Data to be Processed:

2.3 Categories of Data Subjects:

2.4 The duration of Processing shall be the term of the underlying services agreement or until the Controller instructs deletion, whichever occurs first. The specific retention period or criteria for deletion is:

3. INSTRUCTIONS AND ROLE OF THE PARTIES

3.1 The Controller instructs the Processor to Process Personal Data only in accordance with this Agreement and any documented instructions provided by the Controller. The Processor shall notify the Controller if, in the Processor's opinion, an instruction infringes Applicable Data Protection Law.

3.2 The Processor shall not Process Personal Data for any purpose other than to provide the services specified in this Agreement and the underlying services agreement.

4. TECHNICAL AND ORGANIZATIONAL MEASURES

4.1 The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate: pseudonymization and encryption of Personal Data; measures to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; a process for regularly testing, assessing and evaluating the effectiveness of measures; and procedures for ensuring the ability to restore availability and access to Personal Data in a timely manner after an incident.

4.2 Specific security measures applied by the Processor:

5. SUB-PROCESSORS

5.1 The Processor shall not engage any Sub-processor without prior written authorization from the Controller. Where prior general written authorization has been provided, the Processor shall provide the Controller with notice of any intended changes concerning the addition or replacement of Sub-processors, thereby giving the Controller the opportunity to object on reasonable grounds.

5.2 The Processor shall ensure that Sub-processors are subject to data protection obligations no less protective than those set out in this Agreement and shall remain fully liable for the acts and omissions of its Sub-processors.

6. DATA SUBJECT RIGHTS

6.1 The Processor shall, to the extent legally permitted, promptly notify the Controller of any request received from a Data Subject seeking to exercise rights under Applicable Data Protection Law. The Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, in responding to such requests within required legal timeframes.

7. SECURITY INCIDENTS AND BREACH NOTIFICATION

7.1 The Processor shall notify the Controller without undue delay and, in any event, no later than days after becoming aware of a confirmed Security Incident affecting Personal Data.

7.2 The notification shall include, where possible, the nature of the incident, the categories and approximate number of Data Subjects and records affected, likely consequences, measures taken or proposed to address the incident, and the contact details of a person who can provide more information.

8. AUDITS AND INSPECTIONS

8.1 The Processor shall provide the Controller with reasonable access to information necessary to demonstrate compliance with this Agreement and shall allow for and contribute to audits, including on-site inspections, subject to reasonable notice and confidentiality obligations.

9. INTERNATIONAL TRANSFERS

9.1 Where Personal Data is transferred to a jurisdiction that does not provide an adequate level of protection under Applicable Data Protection Law, the Parties shall implement appropriate safeguards to ensure lawfulness of the transfer. The Processor shall only transfer Personal Data outside the Controller's jurisdiction with the Controller's documented instructions or as permitted under this Agreement.

10. RETURN OR DELETION OF PERSONAL DATA

10.1 Upon termination or expiry of the underlying services agreement, the Processor shall, at the Controller's choice, return all Personal Data to the Controller and delete existing copies, or securely destroy such Personal Data, unless retention of some or all Personal Data is required by Applicable Data Protection Law. Where deletion is not possible, the Processor shall isolate and protect the retained Personal Data from further processing.

11. CONFIDENTIALITY

11.1 The Processor shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

12. LIABILITY AND INDEMNIFICATION

12.1 Each Party shall be liable for and shall indemnify the other Party for losses arising from its breach of this Agreement or its failure to comply with Applicable Data Protection Law, subject to any limitations of liability agreed in the underlying services agreement.

13. NOTICES

Controller Notices Contact

Processor Notices Contact

14. AMENDMENTS, WAIVER, COUNTERPARTS

14.1 No amendment to this Agreement will be effective unless in writing and signed by authorized representatives of both Parties. A waiver of any right or remedy under this Agreement must be in writing.

14.2 This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument.

15. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

15.1 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified by the Controller:

15.2 Entire Agreement: This Agreement, together with the underlying services agreement, constitutes the entire agreement between the Parties with respect to the Processing of Personal Data and supersedes all prior written or oral agreements and representations relating to its subject matter.

15.3 Severability: If any provision of this Agreement is held to be invalid or unenforceable by a court of competent jurisdiction, such provision shall be severed and the remainder of this Agreement shall remain in full force and effect.

SIGNATURES

Data Controller:

By:

Date:

Data Processor:

By:

Date:

Enter text✕

What a Data Protection Agreement Is and When it Applies

A Data Protection Agreement (DPA) is a written contract that sets terms between a data controller and a data processor describing how personal data is processed, protected, and shared. It clarifies roles and responsibilities, security measures, permitted subprocessors, data subject request handling, breach notification obligations, and retention limitations. In the United States a DPA helps organizations meet statutory privacy obligations (for example under state privacy laws and sectoral rules such as HIPAA) and documents operational controls used to limit legal and regulatory risk when personal data is transferred or processed.

Why a DPA Matters for Compliance and Risk Management

A clear, executed DPA documents legal responsibilities, reduces regulatory exposure, and sets measurable security and notification requirements. It protects both parties by allocating liability, specifying data-handling limits, and creating an operational framework for responding to incidents and data subject requests.

Why a DPA Matters for Compliance and Risk Management

Who Typically Signs or Manages a DPA

Organizations completing DPAs range from small vendors to large enterprises; different roles are involved in negotiation, approval, and execution.

  • Real Estate: Property managers and title companies use DPAs when sharing tenant or purchaser personal information with third-party services.
  • Healthcare: Covered entities and business associates include DPAs to meet HIPAA obligations and define permitted PHI processing.
  • Financial Services: Banks and payment processors require DPAs for vendors handling account, transaction, or identity data.

Signatory coordination usually involves legal, privacy, security, and business owners to ensure operational and legal requirements align before execution.

Who Has Signing Authority

Data Controller

Chief Privacy Officer or General Counsel typically signs for the controller. That person must be authorized to bind the organization to compliance obligations and financial liabilities described in the agreement.

Data Processor

An authorized business officer or delegated contractual signatory signs for the processor. This signer must accept technical, organizational, and subcontractor obligations included in the DPA.

Core Elements to Include in a Professional Data Protection Agreement

A strong DPA is specific about scope, security, subprocessors, audit rights, breach response, and termination procedures. Each element should be measurable and aligned with applicable privacy rules and industry standards.

Scope of Processing

Define categories of personal data, processing purpose, and duration to avoid vague or open-ended authority.

Security Measures

Specify technical and organizational safeguards such as encryption, access controls, logging, and vulnerability management.

Subprocessor Rules

Require processor notification and controller approval for subprocessors and include flow-down obligations.

Breach Notification

Set maximum notification timelines, required content, and cooperation expectations for incident response.

Audit and Inspection

Allow audits or attestations (SOC 2, ISO 27001) with frequency, notice, and confidentiality protections.

Termination & Data Return

Detail data return or secure deletion methods, timelines, and certification of destruction on contract end.

Required DPA Data Elements (Quick Reference)

Parties: Controller and processor legal names
Contact Details: Authorized contact for notices
Data Types: Categories of personal data processed
Processing Purpose: Permitted uses and limitations
Security: Baseline safeguards and standards
Subprocessors: Allowed subprocessors and approval process

Key Risks When a DPA Is Incomplete or Incorrect

Regulatory Fines: Civil penalties and enforcement actions
Contract Liability: Indemnity and breach damages exposure
Operational Disruption: Service interruption and remediation costs
Litigation Risk: Class actions or individual claims
Reputational Harm: Loss of customer trust and market value
Noncompliance Costs: Remediation and audit expenses

Common Mistakes to Avoid When Preparing a DPA

  • Using overly broad processing descriptions that leave signers unable to verify compliance or enforce restrictions.
  • Failing to specify subprocessors or allowing unlimited subcontracting without a notification and approval process.
  • Omitting clear breach notification timelines and required content, which delays incident response and regulatory reporting.
  • Neglecting retention and deletion obligations, producing legal uncertainty about post-termination data handling and potential exposure.

Step-by-Step: How to Complete a Data Protection Agreement

Follow these practical steps to draft, review, and execute a DPA so it reflects operational reality and complies with applicable privacy rules.

  • 01
    Prepare Draft: List parties, data categories, and purposes of processing.
  • 02
    Define Controls: Document encryption, access, and incident response measures.
  • 03
    Legal Review: Have privacy counsel and security review obligations and liability clauses.
  • 04
    Execute: Obtain authorized signatures from controller and processor.

How to Configure an Online DPA Workflow

Set up a reproducible signing and approval workflow that enforces required fields, authentication, and auditability.

Field Configuration
Authentication Email link or SMS code; consider stronger auth for sensitive data
Signature Type Electronic signature with audit trail; PKI optional for higher assurance
Conditional Fields Lock or reveal clauses based on role or answers
Integrations Connect to document storage, CRM, or ticketing for recordkeeping

Where to Send and How Routing Typically Works

Use defined routing to ensure each stakeholder reviews and signs in the correct order and receives a retained copy.

  • Legal Review: Send to counsel for liability and clause validation
  • Security Review: Send to security team to confirm technical controls
  • Business Owner: Obtain sign-off on scope and operational feasibility
  • Final Execution: Obtain signatures from authorized controller and processor signatories

Technical Requirements for eSigning and Storing DPAs

Choose a platform that provides secure storage, a tamper-evident audit trail, and integration with existing systems.

  • File Formats: PDF, DOCX, HTML, Excel
  • Integrations: Salesforce, NetSuite, Google Workspace
  • Security: AES-256 at rest, TLS 1.2/1.3

Ensure the platform supports role-based access, archival exports, and the ability to produce a certificate of completion to demonstrate intent and attribution.

eSignature Vendor Comparison for Executing a DPA

Compare common vendor pricing and capabilities when selecting an eSignature provider for DPAs; signNow is listed first per comparison conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Key Timelines and Deadlines to Track in a DPA Lifecycle

Track negotiation, execution, renewal, and incident response deadlines to avoid lapses in coverage or missed obligations.

Negotiation Window:

Allow 2–4 weeks for legal and security review

Execution Deadline:

Sign before processing begins to ensure lawful basis

Renewal Notice:

Provide 30–90 days advance notice for renewals

Data Subject Requests:

Respond within 45 days where CCPA/CPRA applies

Breach Notification:

Notify controller and authorities per contract timelines

Milestones from Draft to Operational Processing

These sequential milestones show the typical flow from initial drafting through enforcement and record retention.

01

Drafting

Prepare initial DPA containing scope and controls

02

Internal Review

Legal, privacy, and security teams review and revise

03

Execution

Authorized signatories sign and record the agreement

04

Implementation

Operationalize controls and notify subprocessors as required

Two Practical Use Cases for a Data Protection Agreement

These examples show how DPAs are applied in real workflows and what practical outcomes they secure.

Healthcare Vendor Onboarding

A hospital onboarding a cloud provider

  • Required BAA and encryption controls were mandated
  • The DPA documented PHI handling, incident timelines, and subprocessors, enabling compliance with HIPAA and reducing audit friction while clarifying liability.

SaaS Customer Integration

A SaaS vendor processing customer contact data

  • Customer required narrow processing purposes
  • The DPA limited data uses, required SOC 2 evidence, and required subprocessors to adopt the same safeguards, simplifying customer due diligence.

Practical Tips for Accurate and Efficient DPA Completion

Adopt consistent templates and clear operational references to reduce negotiation time and ensure enforceability.

Use a Standard Template
Maintain a vetted, template DPA that reflects your risk tolerance; update it for new legal requirements and reuse it to speed negotiations.
Link Operational Controls
Reference specific security policies and attestations (SOC 2, ISO 27001) rather than vague commitments to improve auditability and trust.
Limit Subprocessor Rights
Require written notice and approval for new subprocessors and include contractual flow-down obligations to preserve enforcement against subcontractors.
Document Changes
Track amendments and maintain a versioned archive to demonstrate which terms applied during specific processing activities or incidents.

Frequently Asked Questions About Data Protection Agreements

Answers to common practical and legal questions about DPAs, eSigning, and operational implementation.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users