Processing Purpose
Clearly state permitted processing activities and business purposes; avoid open-ended or 'any purpose' language to limit exposure and clarify expectations.
A clear DPA addendum reduces legal and operational risk by documenting roles, limiting processing scope, and recording security and breach procedures in writing.
Typical stakeholders who draft, review, or sign DPAs and addenda.
Coordination across these groups ensures the addendum is accurate, actionable, and enforceable.
| Authentication Method | Use email + optional SMS code or stronger MFA depending on risk level. |
|---|---|
| Audit Trail | Enable complete logs: timestamps, IPs, and actions for each signer. |
| Document Versioning | Lock the executed PDF and retain prior draft versions for dispute resolution. |
| Subprocessor Approval | Add conditional fields to capture subprocessor lists and approval checkboxes. |
| Retention Settings | Configure automatic archival and access controls aligned with retention policy. |
Ensure the chosen eSignature platform supports industry-standard security, audit trails, and integrations needed for compliance.
Verify the platform can produce a tamper-evident PDF with a complete audit trail and customizable retention rules.
Align addendum effective date with the master contract start date.
HIPAA requires notification without unreasonable delay and no later than 60 days when applicable.
Specify advance notice period for onboarding new subprocessors (commonly 30 days).
Schedule annual reviews of security measures and subprocessor lists.
Retention obligations determine deletion timelines and backup preservation.
Initial addendum prepared and scoped by contract owner and privacy lead.
Negotiation and legal redlines resolved by both parties.
Authorized signatories sign and date the addendum; execution recorded.
Security measures, subprocessors, and retention actions are operationalized.
Clearly state permitted processing activities and business purposes; avoid open-ended or 'any purpose' language to limit exposure and clarify expectations.
List personal data categories and identify any special categories (health, SSNs). This helps determine applicable safeguards and supervisory obligations.
Specify technical and organizational controls required (encryption, access controls, logging) and reference standards or certifications where relevant.
Describe consent or notice processes for subprocessors, required contractual flow-down clauses, and audit rights for subcontracted services.
Set clear timelines, contact points, and remediation obligations for security incidents and breach notifications to affected parties and regulators.
Define data return or secure deletion obligations upon contract end, including timelines and proof of deletion or destruction.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial, no credit card required | Varies | Varies | Varies | Varies |
| Bulk Send | Yes (available) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |
Optica attached a DPA addendum to vendor agreements to standardize data handling across investments
A healthcare provider used a DPA addendum plus a BAA to document PHI handling