Establishing secure connection…Loading editor…Preparing document…

GDPR Compliance Annex

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

GDPR COMPLIANCE ANNEX

This GDPR Compliance Annex (the "Annex") is entered into as of by and between Client Name: (the "Controller") and Service Provider Name: (the "Processor"). This Annex supplements and forms part of the agreement between the parties under which Processor will process personal data on behalf of Controller.

RECITALS

WHEREAS, Controller determines the purposes and means of the processing of Personal Data and engages Processor to process Personal Data in connection with the provision of services described in the underlying agreement; and

WHEREAS, the parties intend to ensure that the processing of Personal Data is performed in compliance with applicable data protection laws, including, where applicable, the EU General Data Protection Regulation; and

WHEREAS, this Annex sets out the parties' respective obligations with respect to such Personal Data and the security and confidentiality measures to be applied.

NOW THEREFORE, in consideration of the mutual covenants herein, the parties agree as follows:

1. DEFINITIONS

For purposes of this Annex, the following terms shall have the meanings set forth below: "Personal Data" means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller. "Processing" and related terms have the meanings set forth in applicable data protection law. Any capitalized term used but not defined in this Annex has the meaning given in the underlying agreement.

2. DETAILS OF PROCESSING

Subject matter of Processing:

Nature and purpose of Processing:

Duration of Processing:

3. OBLIGATIONS OF THE CONTROLLER

Controller shall determine the lawful basis for Processing, ensure data subject notices are provided as required, and provide Processor with documented instructions regarding Processing. Controller shall be responsible for responding to data subject requests where Controller is the data controller under applicable law.

4. OBLIGATIONS OF THE PROCESSOR

Processor shall only process Personal Data on documented instructions from Controller, including with regard to international transfers, unless required to do so by applicable law, in which case Processor will inform Controller of that legal requirement to the extent permitted.

Processor shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality and shall implement appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration or damage.

5. SUB-PROCESSING

Controller hereby grants Processor authorization to engage sub-processors to the extent listed or described below. Processor shall enter into a written contract with each sub-processor imposing obligations no less protective than those imposed on Processor under this Annex. Processor remains fully liable to Controller for performance of the sub-processor's obligations.

Allow onward transfer to sub-processors?

6. DATA SUBJECT RIGHTS

Processor shall, to the extent legally permitted, promptly notify Controller if it receives a request from a data subject under applicable data protection law. Processor shall assist Controller by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Controller's obligation to respond to such requests.

7. PERSONAL DATA BREACH

Processor shall notify Controller without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach, providing Controller with sufficient information to allow Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach. Processor shall cooperate with Controller in investigating and mitigating the breach.

8. RETURN OR DELETION OF PERSONAL DATA

Upon termination or expiry of the services, Processor shall, at Controller's choice, return all Personal Data to Controller and delete existing copies unless retention is required by applicable law. Where deletion is not possible, Processor shall ensure continued protection of Personal Data and limit further processing to those purposes required by law.

9. AUDIT AND INSPECTION

Controller (or an independent auditor mandated by Controller) may, upon reasonable notice and subject to confidentiality obligations, audit Processor's compliance with this Annex. Processor shall make available information necessary to demonstrate compliance and shall cooperate with audits and inspections. Any audits shall be scheduled to minimize disruption to Processor's operations.

10. INTERNATIONAL TRANSFERS

Transfers of Personal Data to jurisdictions outside the European Economic Area shall only occur where permitted by applicable law and where Controller has provided documented instructions. Such transfers shall be subject to appropriate safeguards agreed between the parties.

11. LIABILITY

Each party's liability for breaches of this Annex shall be determined in accordance with the underlying agreement, provided that Processor shall be liable for damages resulting from processing only to the extent caused by its breach of this Annex or negligence in performing its obligations hereunder.

12. TERM AND TERMINATION

This Annex shall remain in force for the duration that Processor processes Personal Data on behalf of Controller and shall survive termination of the underlying agreement to the extent required to give effect to the parties' obligations under this Annex.

13. NOTICES

14. GOVERNING LAW

This Annex shall be governed by and construed in accordance with the governing law specified in the underlying agreement. The parties agree that any dispute arising out of or in connection with this Annex shall be subject to the dispute resolution provisions of the underlying agreement.

15. ENTIRE AGREEMENT

This Annex, together with the underlying agreement, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior or contemporaneous understandings, agreements, or representations, whether written or oral, relating to such subject matter.

16. SEVERABILITY

If any provision of this Annex is held to be invalid, illegal or unenforceable, the remaining provisions shall continue in full force and effect and the parties shall endeavor to replace any invalid or unenforceable provision with a valid provision achieving, to the greatest extent possible, the economic, legal and commercial objectives of the invalid provision.

17. AMENDMENTS

No amendment to this Annex shall be effective unless in writing and signed by authorized representatives of both parties.

18. WAIVER

Failure by either party to exercise any right under this Annex shall not constitute a waiver of that right unless expressly acknowledged in writing by the party granting the waiver.

19. COUNTERPARTS

This Annex may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

Purpose and scope of a GDPR Compliance Annex

A GDPR Compliance Annex is a contractual addendum used when a U.S.-based organization processes or transfers personal data that is subject to the EU General Data Protection Regulation (GDPR). The annex clarifies roles (controller, processor), describes categories of personal data, lists permitted processing purposes, and documents technical and organizational measures to protect data. It also sets rules for subprocessors, cross-border transfers, breach notification, audit rights, and retention. For U.S. contracts that involve EU data subjects, the annex aligns operational controls with GDPR expectations while preserving governing law and dispute-resolution clauses appropriate to the parties.

Why include a GDPR Compliance Annex in vendor agreements

Including a GDPR Compliance Annex reduces legal ambiguity about data handling, clarifies each party’s obligations, supports compliance with cross-border transfer requirements, and documents security measures necessary to demonstrate accountability under GDPR.

Why include a GDPR Compliance Annex in vendor agreements

Who typically prepares or signs a GDPR Compliance Annex

Organizations, vendors, and legal teams that process or host EU personal data commonly use this annex to document obligations and technical controls before data flows begin.

  • Data protection officers and privacy teams who assess compliance and document controls for cross-border processing.
  • Procurement and vendor managers who need contractual assurances before onboarding cloud or SaaS providers.
  • Legal counsel who draft liability, audit, and data-transfer clauses aligned with governing law.

The annex is usually finalized and signed by authorized contract signatories and, where required, by the vendor’s privacy lead or security officer.

Core elements that a professional GDPR Compliance Annex should include

A practical annex is concise but complete: it names parties, describes data, limits processing, sets security standards, documents subprocessors, and addresses international transfers.

Parties

Clear identification of controller(s) and processor(s), including legal entity names and contact details for data protection representatives.

Data categories

Precise listing of categories of personal data and any special categories (sensitive data) to define processing scope and applicable safeguards.

Permitted purposes

Authorized processing activities and limitations, ensuring the processor acts only on documented instructions from the controller.

Security measures

Technical and organizational measures (encryption, access controls, logging, incident response) with measurable descriptions or references to security documentation.

Subprocessor rules

Requirements for prior notice or consent, vetting controls, and flow-down contractual language for any subprocessors engaged by the vendor.

Cross‑border transfers

Mechanisms used for transfers (standard contractual clauses, adequacy, EU-U.S. Data Privacy Framework) and any additional safeguards.

Required information fields in the annex

Controller name: Legal entity name
Processor name: Legal entity name
Data categories: Personal data types
Processing purposes: Authorized uses
Retention period: Storage duration
Contact person: Privacy or security lead

Step-by-step: completing a GDPR Compliance Annex

Follow a clear sequence to ensure the annex is accurate and enforceable: identify parties, define data, specify safeguards, confirm subprocessors, and obtain authorized signatures.

  • 01
    Identify parties: Record full legal names and addresses of controller and processor.
  • 02
    Describe data: List personal data categories and any sensitive data elements.
  • 03
    Specify measures: Reference concrete security measures and documentation.
  • 04
    Sign and retain: Obtain authorized signatures and keep a copy in records.

Configuring the annex for e-signature workflows

Set up an e-signature workflow that enforces signatory order, required authentication, and document retention to preserve auditability and legal validity.

Field Configuration
Upload annex template Use a locked PDF or DOCX with fillable fields.
Assign signers Add authorized signatory emails and roles.
Authentication level Select email link, SMS code, or stronger MFA.
Retention setting Enable archive and export of signed PDF + audit trail.

Where to send and store the signed annex

Define destinations and custodians for the executed annex to support evidence of consent and retention requirements.

  • Primary custodian: Legal or privacy team stores the executed annex in corporate contract repository.
  • Vendor copy: Processor retains a signed copy in its secure contract archive with restricted access.
  • Audit record: Export and store the audit trail (timestamps, IP, signer email) alongside the signed document.
  • Backup location: Retain immutable backups per retention schedule and disaster recovery policy.

Digital signing and eSubmission considerations

Choose an eSignature configuration that preserves intent, attribution, and retention required for legal validity under U.S. law and auditor expectations.

  • Supported formats: PDF, Word DOCX, and audit-ready exports
  • Integrations: Connect to contract repositories and cloud storage
  • Authentication: Email link, SMS code, or stronger MFA options

Ensure the platform you select records an immutable audit trail, preserves the signed file, and supports retention and export for compliance reviews.

Consequences of an incorrect or missing annex

Regulatory exposure: Potential GDPR enforcement actions
Contract risk: Ambiguous obligations may cause disputes
Data breach costs: Higher liability without documented controls
Operational delay: Onboarding may be suspended
Audit findings: Failed audits for incomplete records
Reputational harm: Loss of customer trust

Common mistakes when preparing a GDPR Compliance Annex

  • Using vague processing descriptions that leave room for differing interpretations during audits or incident response.
  • Failing to list subprocessors or using open-ended subcontracting clauses without notice or consent provisions.
  • Neglecting to reference specific technical measures (encryption, MFA) and providing only generic security language.
  • Omitting cross-border transfer mechanisms or relying on informal assurances instead of documented SCCs or adequacy solutions.

Authorized signers for the annex

Chief Privacy Officer

A senior privacy or data protection officer typically reviews and approves annex language, certifies operational controls, and provides contact details for compliance matters.

Authorized Contract Signatory

An officer or employee with delegated signing authority executes the annex on behalf of the legal entity and confirms corporate authorization for contractual commitments.

Typical timelines and processing expectations

Set clear deadlines in the annex for notification, onboarding, and response to data subject or regulatory requests to ensure timely compliance.

Annex execution:

Execute before any EU personal data is transferred or processing begins

Subprocessor notice:

Provide prior notice and the ability to object before new subprocessors are engaged

Breach notification:

Notify controller without undue delay and within contractual timeframes

Data subject requests:

Coordinate response timelines; GDPR generally expects action within one month

Security review:

Complete annual or event-driven security assessments as specified

Comparing eSignature providers for annex execution and retention

Platform selection affects authentication, audit trails, and retention. The table shows starter pricing and select features relevant to executing and storing GDPR Compliance Annexes.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

FAQs and troubleshooting for the GDPR Compliance Annex

Common questions focus on enforceability, signature methods, subprocessors, and retention. Answers below clarify practical concerns for U.S. organizations handling EU data.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users