Establishing secure connection…Loading editor…Preparing document…

Data Sub-Processing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

DATA SUB-PROCESSING AGREEMENT

This Data Sub-Processing Agreement (the Agreement) is made and entered into as of Effective Date: by and between Processor Name: , a legal entity with principal place of business at (Processor), and Sub-Processor Name: , a legal entity with principal place of business at (Sub-Processor). Processor and Sub-Processor may be referred to individually as a Party and collectively as the Parties.

RECITALS

WHEREAS, Processor processes personal data on behalf of one or more controllers and requires certain processing activities to be performed by Sub-Processor; and

WHEREAS, Sub-Processor has represented that it possesses the technical and organizational measures required to protect personal data in accordance with applicable data protection laws and the terms of this Agreement; and

WHEREAS, the Parties wish to set out the terms and conditions under which Sub-Processor will process personal data on behalf of Processor.

NOW, THEREFORE, in consideration of the mutual covenants set forth below, the Parties agree as follows:

1. DEFINITIONS

For purposes of this Agreement: (a) "Processing" and "process" shall have the meanings given in applicable data protection laws; (b) "Personal Data" means any information relating to an identified or identifiable natural person that Processor supplies to Sub-Processor or that Sub-Processor collects, accesses or otherwise processes pursuant to this Agreement; (c) "Data Protection Laws" means all applicable laws and regulations relating to the protection of personal data; and (d) "Sub-Processing Services" means the specific processing activities and services described in Section 2 and in the Processing Details fields below.

2. APPOINTMENT AND SCOPE

2.1 Appointment. Processor hereby engages Sub-Processor to perform Sub-Processing Services on Processor's behalf, and Sub-Processor accepts such engagement, subject to the terms of this Agreement.

2.2 Processing Details. The categories of data subjects, categories of Personal Data, and processing operations authorized under this Agreement are described as follows:

3. SUB-PROCESSOR OBLIGATIONS

3.1 Compliance with Instructions. Sub-Processor shall process Personal Data only on documented instructions from Processor, unless required to do otherwise by applicable law. If Sub-Processor is compelled by law to process Personal Data otherwise than on Processor's documented instructions, Sub-Processor shall inform Processor promptly unless prohibited by law.

3.2 Confidentiality. Sub-Processor shall ensure that personnel authorized to process Personal Data are subject to obligations of confidentiality and have received appropriate training on data protection and security.

3.3 Security Measures. Sub-Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including measures to protect against unlawful or accidental destruction, loss, alteration, unauthorized disclosure or access.

4. SUB-SUBPROCESSING

4.1 Authorization. Sub-Processor shall not engage any additional sub-processors to carry out processing activities under this Agreement without Processor's prior written authorization. Where prior general authorization is provided, Sub-Processor shall notify Processor of any intended changes concerning the addition or replacement of sub-processors.

4.2 Contractual Flow-Down. Where Sub-Processor engages a sub-processor, Sub-Processor shall impose data protection obligations on that sub-processor no less protective than those in this Agreement and remain fully liable to Processor for the performance of that sub-processor's obligations.

5. AUDITS AND INSPECTIONS

5.1 Audit Rights. Processor shall have the right to audit Sub-Processor's compliance with the terms of this Agreement, either by itself or by an independent third party, upon reasonable prior notice, subject to any confidentiality obligations. Sub-Processor shall make available all information necessary to demonstrate compliance and shall permit and contribute to audits or inspections.

6. DATA SUBJECT RIGHTS AND ASSISTANCE

6.1 Assistance. Taking into account the nature of the processing and the information available to Sub-Processor, Sub-Processor shall assist Processor by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Processor's obligations to respond to requests for exercising data subject rights.

7. PERSONAL DATA BREACH

7.1 Notification. Sub-Processor shall notify Processor without undue delay and, in any event, within 48 hours after becoming aware of a Personal Data breach affecting Personal Data processed under this Agreement. The notification shall describe the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.

8. RETURN OR DELETION OF PERSONAL DATA

Upon expiration or termination of this Agreement, Sub-Processor shall, at Processor's choice, return all Personal Data to Processor and erase existing copies unless retention of the Personal Data is required by applicable law. Sub-Processor shall certify in writing to Processor that it has complied with this obligation.

9. INDEMNITY AND LIMITATION OF LIABILITY

9.1 Indemnity. Each Party shall indemnify, defend and hold harmless the other Party from and against any losses, liabilities, damages and costs arising from a breach of this Agreement by the indemnifying Party, subject to the indemnified Party's compliance with its obligations under this Agreement.

9.2 Limitation. Except for liability arising from willful misconduct, gross negligence, or a breach of confidentiality or data protection obligations, neither Party's aggregate liability under this Agreement shall exceed an amount equal to the fees paid under the associated services agreement during the twelve (12) months preceding the claim.

10. TERM AND TERMINATION

This Agreement shall commence on the Effective Date and shall continue for the duration of the provision of Sub-Processing Services unless earlier terminated by either Party for material breach which is not cured within thirty (30) days of written notice. Termination of this Agreement shall be without prejudice to accrued rights and liabilities.

11. NOTICES

All notices under this Agreement shall be in writing and delivered to the addresses specified below. Notices are deemed given upon delivery or, if mailed, three (3) business days after deposit in the mail.

12. AMENDMENTS, WAIVER AND COUNTERPARTS

12.1 Amendments. No amendment or modification of this Agreement shall be effective unless in writing and signed by authorized representatives of both Parties.

12.2 Waiver. No failure or delay by either Party to exercise any right under this Agreement shall operate as a waiver of that right.

12.3 Counterparts. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

13. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

13.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction specified below in the Governing Law field, without regard to its conflict of law principles.

13.2 Entire Agreement. This Agreement constitutes the entire agreement between the Parties with respect to the subject matter and supersedes all prior agreements and understandings relating to that subject matter.

13.3 Severability. If any provision of this Agreement is held invalid or unenforceable, that provision shall be limited or eliminated to the minimum extent necessary so that this Agreement shall otherwise remain in full force and effect.

14. MISCELLANEOUS

The Parties represent and warrant that they have the authority to enter into this Agreement and to perform their obligations hereunder. Any headings are for convenience only and do not affect interpretation.

Processor Printed Name:

By:

Date:

Sub-Processor Printed Name:

By:

Date:

Enter text✕

What a Data Sub-Processing Agreement Covers

A Data Sub-Processing Agreement is a legal addendum that defines obligations, scope and controls when a primary data processor engages a sub-processor to carry out processing on behalf of a data controller. It clarifies permitted processing purposes, categories of personal data, security measures, audit rights, liability allocation, and termination steps to ensure regulatory compliance and maintain the controller’s instructions.

Why a Dedicated Sub-Processor Addendum Matters

A clear Data Sub-Processing Agreement preserves contractual accountability, reduces compliance risk by documenting security and audit rights, and ensures transparency about where and how data is handled across vendor chains.

Why a Dedicated Sub-Processor Addendum Matters

Who Typically Completes This Agreement

The agreement is a standard management tool for security, compliance, and contract teams overseeing third-party processing.

  • Data controllers requesting assurance over where personal data flows and under what conditions
  • Primary processors engaging cloud, analytics, or managed-services sub-processors
  • Legal, compliance, or procurement teams reviewing vendor chains for regulatory risk

Primary Roles Involved

Data Protection Officer

A privacy or compliance lead who reviews sub-processor commitments, verifies security controls, and enforces contractual audit and breach-notification rights across vendor relationships.

Vendor Legal Representative

The processor or sub-processor signatory responsible for accepting obligations, documenting subprocessors, and coordinating evidence of technical and organizational safeguards when requested.

Core Clauses to Include in a DSA

A professional Data Sub-Processing Agreement contains specific, enforceable clauses that allocate responsibility, set security expectations, and preserve the controller’s oversight rights over any subcontracted processing.

Parties & Scope

Identify controller, processor, and each named sub-processor; list processing activities and the categories of personal data covered by the sub-processing relationship, with narrow purpose limitations.

Permitted Purposes

Define exactly which services the sub-processor may perform and prohibit any processing beyond the stated purposes without prior controller consent.

Security Requirements

Specify technical and organizational measures (encryption, access controls, logging) and require the sub-processor to maintain and document those safeguards in line with applicable law.

Audit & Inspection

Grant the controller (or an agreed auditor) rights to conduct security audits, request evidence, and require remediation within specified timelines for identified deficiencies.

Data Breach Procedures

Mandate immediate notification of incidents, defined timelines for reporting, cooperation obligations, and steps for containment and remediation aligned with breach-notification laws.

Liability & Termination

Allocate indemnities, limits of liability, and termination rights — including obligations to return or securely delete data upon contract end or controller direction.

Step-by-Step: Completing the Agreement

Follow these steps to draft, review, and finalize a Data Sub-Processing Agreement with an incoming sub-processor.

  • 01
    Draft core terms: Populate parties, scope, and data categories first.
  • 02
    Specify controls: Add technical and organizational security measures required.
  • 03
    Review with privacy: Have legal or DPO validate compliance and audit rights.
  • 04
    Execute and record: Collect signatures and store final signed agreement securely.

Typical Digital Workflow Settings

Configure your e-sign and exchange workflow to support secure execution, proof capture, and long-term retention of the signed agreement.

Field Configuration
Authentication Email + SMS OTP
Routing Sequential signer order
Audit Trail Enable timestamps and IP logging
Retention Exportable signed PDF

How Electronic Execution Typically Works

Electronic signature workflows capture consent, identity evidence, and an immutable audit trail to support enforceability under U.S. law.

  • Upload Document: Place signature and data fields where required.
  • Add Signers: Enter parties’ names and emails in signer order.
  • Signer Authentication: Authenticate via email link or SMS code.
  • Completion Record: Signed PDF plus audit certificate is generated.

Technical Considerations for eSubmission and Storage

Ensure the platform you choose can produce a timestamped certificate of completion and supports secure long-term storage to meet retention obligations.

  • File Formats: PDF, DOCX and export to PDF/A for archival
  • Integrations: CRM, cloud storage and SSO integrations
  • Authentication Options: Email, SMS OTP, or stronger multi-factor methods

Required Security and Compliance Elements

Encryption: AES-256 at rest; TLS 1.2/1.3 in transit
Access Controls: Role-based access and MFA
Audit Logs: Immutable action and timestamp records
BAA Availability: Business Associate Agreement where HIPAA applies
Data Minimization: Limit processing to necessary categories
Sub-processor List: Maintain and share an up-to-date roster

Common Legal and Operational Risks

Regulatory Fines: Significant fines for data breaches
Contract Liability: Indemnity for controller damages
Breach Notification: Mandatory rapid reporting obligations
Service Disruption: Operational interruptions from incidents
Termination Costs: Transition and data return expenses
Reputational Harm: Customer trust and brand damage

Frequent Drafting Pitfalls to Avoid

  • Overbroad scope language that permits unspecified processing is common and undermines the controller’s control over personal data.
  • Failing to name specific sub-processors or to require timely notice of new subprocessors creates blind spots in the vendor chain.
  • Vague security obligations without measurable controls or certification references make compliance verification difficult during audits.
  • Omitting clear breach-notification timelines and cooperation obligations delays response and increases regulatory exposure.

Key Dates and Notice Periods to Set

Establish explicit deadlines for effectiveness, notice periods for new sub-processors, audit scheduling, and breach reporting to avoid ambiguity.

Effective Date:

Enter as MM/DD/YYYY; marks the agreement start

Sub-processor Notice:

Typically 10–30 days prior written notice

Breach Notification:

Immediate plus a written report within 72 hours

Audit Scheduling:

Allow 30–60 days notice for audits

Termination Notice:

Often 30–90 days depending on remedy clauses

How a Sub-Processing Agreement Differs from Related Documents

Compare the DSA to a primary Data Processing Agreement (DPA) to confirm complementary roles, obligations, and signing parties.

Document Type Data Processing Agreement Data Sub-Processing Agreement
Primary Parties controller & processor processor & sub-processor
Purpose Scope broad processing duties specific delegated tasks
Controller Rights direct audit rights indirect audit via processor
Signature Requirement controller and processor processor and sub-processor

Practical Tips for Accurate and Efficient Completion

Follow these best practices to reduce negotiation cycles and strengthen compliance with minimal overhead.

Standardize a Template
Keep a single vetted Data Sub-Processing Agreement template to streamline onboarding and ensure consistent allocation of risk and obligations.
Maintain a Sub-Processor Registry
Track all active sub-processors, their roles, locations, and certifications to support audits and rapid incident response.
Limit Data Access
Grant sub-processors access only to data necessary to perform their tasks and document retention and deletion requirements explicitly.
Schedule Periodic Reviews
Reassess sub-processor controls and update DSAs on a fixed cadence or after material changes to services or personnel.

Frequently Asked Questions About Data Sub-Processing Agreements

Answers to common questions about scope, enforceability, signatures, breach handling, and operational implementation.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users