Parties & Scope
Identify controller, processor, and each named sub-processor; list processing activities and the categories of personal data covered by the sub-processing relationship, with narrow purpose limitations.
A clear Data Sub-Processing Agreement preserves contractual accountability, reduces compliance risk by documenting security and audit rights, and ensures transparency about where and how data is handled across vendor chains.
The agreement is a standard management tool for security, compliance, and contract teams overseeing third-party processing.
A privacy or compliance lead who reviews sub-processor commitments, verifies security controls, and enforces contractual audit and breach-notification rights across vendor relationships.
The processor or sub-processor signatory responsible for accepting obligations, documenting subprocessors, and coordinating evidence of technical and organizational safeguards when requested.
Identify controller, processor, and each named sub-processor; list processing activities and the categories of personal data covered by the sub-processing relationship, with narrow purpose limitations.
Define exactly which services the sub-processor may perform and prohibit any processing beyond the stated purposes without prior controller consent.
Specify technical and organizational measures (encryption, access controls, logging) and require the sub-processor to maintain and document those safeguards in line with applicable law.
Grant the controller (or an agreed auditor) rights to conduct security audits, request evidence, and require remediation within specified timelines for identified deficiencies.
Mandate immediate notification of incidents, defined timelines for reporting, cooperation obligations, and steps for containment and remediation aligned with breach-notification laws.
Allocate indemnities, limits of liability, and termination rights — including obligations to return or securely delete data upon contract end or controller direction.
| Field | Configuration |
|---|---|
| Authentication | Email + SMS OTP |
| Routing | Sequential signer order |
| Audit Trail | Enable timestamps and IP logging |
| Retention | Exportable signed PDF |
Ensure the platform you choose can produce a timestamped certificate of completion and supports secure long-term storage to meet retention obligations.
Enter as MM/DD/YYYY; marks the agreement start
Typically 10–30 days prior written notice
Immediate plus a written report within 72 hours
Allow 30–60 days notice for audits
Often 30–90 days depending on remedy clauses
| Document Type | Data Processing Agreement | Data Sub-Processing Agreement |
|---|---|---|
| Primary Parties | controller & processor | processor & sub-processor |
| Purpose Scope | broad processing duties | specific delegated tasks |
| Controller Rights | direct audit rights | indirect audit via processor |
| Signature Requirement | controller and processor | processor and sub-processor |