Establishing secure connection…Loading editor…Preparing document…

GDPR Compliance Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

GDPR COMPLIANCE DOCUMENT

This Data Processing Addendum (the "Addendum") is entered into as of by and between Controller Name: , registered address (the "Controller"), and Processor Name: , registered address (the "Processor"). The Controller and Processor are referred to collectively as the "Parties."

RECITALS

WHEREAS, the Parties have entered into a separate agreement governing the provision of services (the "Principal Agreement"), dated , pursuant to which the Processor may Process Personal Data on behalf of the Controller;

WHEREAS, the Parties intend by this Addendum to set out their respective rights and obligations with respect to the Processing of Personal Data in order to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable; and

WHEREAS, the Parties agree that this Addendum supplements and forms part of the Principal Agreement and governs Processing of Personal Data exchanged or processed under or in connection with that Principal Agreement.

NOW THEREFORE, in consideration of the mutual covenants contained herein and for other good and valuable consideration, the Parties agree as follows:

1. DEFINITIONS

For the purposes of this Addendum, the following terms shall have the meanings set out below: "Personal Data" means any information relating to an identified or identifiable natural person; "Processing" means any operation or set of operations performed on Personal Data; "Sub-processor" means any Processor engaged by the Processor; "Data Subject" means the individual to whom the Personal Data relates.

2. DETAILS OF PROCESSING

The Parties agree that the subject matter, duration, nature, and purpose of the processing, the types of Personal Data and categories of Data Subjects are described as follows.

3. CONTROLLER INSTRUCTIONS AND SCOPE

3.1 The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law. If the Processor is required to process Personal Data by applicable law, it shall notify the Controller of that legal requirement unless the law prohibits such notification.

3.2 The Processor shall not process Personal Data for any purpose other than for the performance of the Principal Agreement, for the purposes set out in this Addendum, or as otherwise instructed in writing by the Controller.

4. PROCESSOR OBLIGATIONS

4.1 The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate, pseudonymisation and encryption of Personal Data, the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services, and a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.

4.2 The Processor shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. SUB-PROCESSORS

5.1 The Processor shall not engage any Sub-processor without prior specific or general written authorisation of the Controller. For general authorisations, the Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, thereby giving the Controller the opportunity to object on reasonable grounds.

Controller authorises the Processor to engage Sub-processors under the terms of this Addendum.

6. DATA SUBJECT RIGHTS

6.1 Taking into account the nature of the processing, the Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising Data Subject rights.

7. SECURITY BREACH NOTIFICATION

7.1 The Processor shall notify the Controller without undue delay and in any event within of becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller. The Processor's notification shall describe, to the extent possible, the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences and measures taken.

8. INTERNATIONAL TRANSFERS

8.1 The Processor shall not transfer Personal Data to a country outside the European Economic Area or a territory not subject to equivalent protection without implementing appropriate safeguards as required by applicable data protection law and without providing the Controller with written details of the transfer mechanism.

9. AUDIT AND INSPECTIONS

9.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this Addendum and allow for and contribute to audits, including on-site inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.

10. RETURN OR DELETION

10.1 Upon termination or expiry of the Principal Agreement, the Processor shall, at the choice of the Controller, return all Personal Data to the Controller and delete existing copies unless applicable law requires storage of the Personal Data. Costs reasonably incurred by the Processor for returning or deleting data shall be borne as set out in the Principal Agreement.

11. LIABILITY AND INDEMNIFICATION

11.1 Each Party's liability arising under or in connection with this Addendum shall be subject to any limitations of liability set forth in the Principal Agreement, provided that nothing in this Addendum shall exclude or limit liability for death or personal injury resulting from negligence, or for willful misconduct, or for any liability which cannot be limited under applicable law.

11.2 The Processor shall indemnify the Controller for any losses incurred by the Controller arising from the Processor's breach of this Addendum, including breaches of security obligations and unauthorised processing, to the extent caused by the Processor's acts or omissions.

12. TERM AND TERMINATION

12.1 This Addendum shall commence on the Effective Date and shall continue in force for the duration of the Principal Agreement or for such period as the Processor Processes Personal Data on behalf of the Controller.

12.2 Termination of the Principal Agreement shall automatically terminate this Addendum unless otherwise expressly agreed in writing.

GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

Governing Law: This Addendum shall be governed by and construed in accordance with the laws specified in the Principal Agreement. In the absence of such specification, the Parties agree that the laws of the jurisdiction of the Controller's principal place of business shall govern.

Entire Agreement: This Addendum, together with the Principal Agreement, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes any prior written or oral agreements.

Severability: If any provision of this Addendum is held to be invalid, illegal or unenforceable in any respect, the validity, legality and enforceability of the remaining provisions shall not be affected or impaired.

NOTICES

AMENDMENTS; WAIVER; COUNTERPARTS

Amendments: This Addendum may only be amended by a written instrument executed by authorised representatives of both Parties. Waiver: Failure or delay by either Party to exercise any right shall not operate as a waiver. Counterparts: This Addendum may be executed in counterparts, each of which shall be deemed an original.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What the GDPR Compliance Document Is and When It Applies

A GDPR Compliance Document records an organization’s policies, processes, and controls for handling European Union personal data. For U.S. entities that collect, store, or process data of EU residents, this document describes lawful bases, data subject rights handling, technical and organizational measures, retention schedules, and roles such as Data Controller and Data Protection Officer.

Why a Clear GDPR Compliance Document Matters

Maintaining a written GDPR Compliance Document reduces legal uncertainty, documents accountability, and supports cross-border data transfer decisions. It also helps demonstrate compliance to regulators and business partners while aligning privacy controls with contractual obligations and incident response plans.

Why a Clear GDPR Compliance Document Matters

Who Prepares and Relies on This Document

Teams and roles that commonly create or use the GDPR Compliance Document are cross-functional: privacy, legal, IT, and business units collaborate to define practices.

  • Data Protection Officers and privacy teams responsible for policy, oversight, and supervisory authority interactions.
  • In-house counsel and compliance officers who draft legal language, vendor clauses, and contractual safeguards.
  • IT, security, and operations teams that implement technical measures, logging, backups, and access controls.

Representative Signatories and Reviewers

Data Protection Officer

The DPO typically reviews and certifies the document for accuracy and sufficiency. This person advises on lawful basis selection, assists with data subject request procedures, and coordinates supervisory authority communication.

Chief Legal Officer

Legal leadership verifies contract language, vendor clauses, and cross-border transfer mechanisms. They confirm the document aligns with corporate policy and provides the organizational sign-off required for enforcement and contractual reliance.

Essential Components to Include

A professional GDPR Compliance Document groups key elements for clarity, evidence, and operational use. Include scope, roles, data inventories, legal bases, safeguards, and monitoring to meet accountability requirements and to support audits or regulatory inquiries.

Scope

Describe which entities, systems, and processing activities are covered, including geographic boundaries and types of personal data processed for transparency and auditability.

Roles & Responsibilities

Name the Data Controller, Data Processor relationships, the DPO (if appointed), and business owners accountable for specific processing steps and escalation channels.

Data Inventory

List data categories, processing purposes, data flows, and storage locations so legal bases and security measures can be matched to each processing activity.

Legal Basis

Document the lawful basis for each processing activity (consent, contract, legal obligation, vital interests, public task, legitimate interests) and justify any legitimate-interest assessments.

Technical Controls

Summarize encryption, access controls, logging, retention, and pseudonymization measures to show how privacy is integrated into operations and system design.

Monitoring & Review

Define audit frequency, metrics, incident response steps, and review cadences so the document remains accurate and demonstrates continuous compliance.

Core Data Elements to Record

Controller Name: Legal entity name
Processor Name: Third-party vendor names
DPO Contact: Email and phone
Processing Types: Collection, storage, transfer
Data Categories: Identifiers, financial data
Retention Period: Retention policy summary

Step-by-Step: Create and Finalize Your GDPR Compliance Document

Follow these numbered steps to prepare, review, and sign the document so it functions as a reliable compliance record and operational reference.

  • 01
    Gather Details: Collect system inventories, vendor lists, and data maps before drafting.
  • 02
    Map Processing: Link each processing activity to data categories and storage locations.
  • 03
    Document Legal Basis: Record lawful bases and perform legitimate-interest assessments where needed.
  • 04
    Review and Sign: Have legal and security review, then obtain authorized signatures and retention metadata.

How to Configure an Online Workflow for the Document

Design a reproducible electronic workflow that covers access, authentication, retention, auditing, and notifications for sign-offs and updates.

Field Configuration
Access Control Role-based access, least privilege
Authentication Email link plus optional SMS or KBA
Retention Settings Automated archival and delete policies
Audit Trail Capture timestamps, IP, and actions

Where to Route Completed Documents

Decide in advance who receives the signed document and how it will be stored to ensure discoverability and regulatory readiness.

  • Internal Records: Store final version in a secure compliance repository with restricted access.
  • Legal Counsel: Deliver a copy to legal for contract management and audit history.
  • Vendor Folder: Attach related DPAs and vendor approvals to vendor records.
  • Regulatory Response: Keep an export-ready file to provide to authorities if legally required.

Digital Signing and File Format Requirements

For reliable e-signing and long-term evidentiary value, use formats and authentication methods that preserve audit trails and metadata.

  • Supported Formats: PDF, PDF/A, DOCX
  • Integrations: Salesforce, Microsoft 365, NetSuite, Google Workspace
  • Authentication Options: Email link, SMS code, two-factor

Key Timelines and Response Expectations

Track statutory and operational timeframes so responsibilities and notification obligations are met within required windows.

Data Subject Requests:

Respond within 30 days where GDPR applies.

Breach Notification:

Report to authorities within 72 hours of becoming aware when applicable.

Document Review:

Conduct annual reviews or when processing changes occur.

Vendor Reassessment:

Re-evaluate processors at least every 12–24 months.

Signature Validity:

Record date signed (MM/DD/YYYY) and retain proof of consent.

Common Preparation Errors to Avoid

  • Failing to tie each processing activity to a legal basis, leaving assessments incomplete or undocumented.
  • Omitting contact details or escalation paths for the DPO or privacy lead, which delays incident response.
  • Using vague retention terms such as 'reasonable period' instead of precise dates or measurable durations.
  • Not capturing an audit trail or failing to export metadata that proves signer identity and timestamp.

Consequences of an Incomplete or Incorrect Document

Regulatory Fines: Potential EU fines up to 4% global turnover
Contract Exposure: Breach of contractual DPAs and indemnities
Reputational Harm: Loss of customer trust and business
Legal Claims: Data subject lawsuits and statutory remedies
Operational Impact: Suspensions, audits, or remediation costs
Cross-Border Risk: Transfers halted pending adequacy or safeguards

Supporting Documents and Export Options to Include

Attach complementary records and choose durable file formats to preserve evidentiary value for audits and regulatory requests.

Export Formats

Provide signed exports as PDF/PDF-A with embedded audit trail to preserve metadata and proof of signing.

Supporting Docs

Include DPAs, privacy impact assessments, consent logs, and vendor security attestations as appendices to the primary document.

Versioning

Maintain a change log with effective dates and approver names for each revision to demonstrate governance.

Audit Evidence

Store timestamps, IP addresses, signer authentication method, and certificate of completion with each signed file.

Real-World Examples of Signed Compliance Records

These concise examples show how organizations document and sign GDPR compliance records in practice.

Optica Ventures LLC

Optica centralized its processing inventory and DPA records into a single compliance document for clarity and audits.

  • They reduced routing time by consolidating approvals.
  • After legal and privacy review, they maintain versioned signed records accessible to auditors and partners for contractual verification and regulatory readiness.

Tech Data

Tech Data integrated vendor DPAs into a master compliance record tied to supplier profiles.

  • Integration automated evidence collection.
  • The document provides a single source of truth for vendor compliance obligations, reducing review cycles and enabling consistent sign-off by legal, procurement, and privacy owners.

Typical eSignature Vendor Comparison for Document Execution

Compare common plan features and starting prices across leading eSignature vendors when selecting a platform to execute and retain compliance records.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Yes Yes Yes Yes
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/yr Varies by plan Varies by plan Varies by plan

Common Questions and Practical Answers

Answers to frequent questions about legal effect, signing, retention, and updating your GDPR Compliance Document.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users