Scope of Services
Precise description of DSP tasks, data categories processed, and permitted processing activities to limit unexpected uses and downstream sharing.
A Legal DSP Agreement documents party responsibilities, reduces regulatory exposure, and creates contractual remedies for breaches. It supports enforceability for electronic execution under ESIGN (15 U.S.C. ch. 96) and state UETA laws, and it clarifies audit, data retention, and breach-notification duties to limit liability and regulatory risk.
The Legal DSP Agreement involves legal, privacy, procurement, and IT stakeholders; signers and administrators will differ by organization size and industry.
Implementation and ongoing monitoring are normally handled by procurement or vendor management with periodic audits and renewals coordinated by legal or privacy teams.
Precise description of DSP tasks, data categories processed, and permitted processing activities to limit unexpected uses and downstream sharing.
Technical and organizational measures required (encryption, access controls, logging, vulnerability management) with testing and audit schedules.
Rules for subcontractor approval, notification timing, flow-down obligations, and a right to audit or object to critical subprocessors.
Notification timelines, required content, investigation responsibilities, remediation steps, and cooperation with regulators and affected parties.
Limits on damages, indemnification triggers, and carve-outs for willful misconduct or gross negligence; include insurance requirements.
Obligations for returning or securely deleting data at termination and proof of destruction or certified deletion processes.
| Field | Configuration |
|---|---|
| Signature Type | Audit-trail e-signature with timestamp and IP capture |
| Authentication | Email plus SMS code or two-factor for controllers/critical signers |
| Access Controls | Role-based access to edit vs. view-only for template users |
| Retention Setting | Automate archive to secure storage with version history |
Ensure the eSignature platform supports required security, evidence capture, and integrations before use.
Choose a platform that captures an auditable certificate of completion, stores tamper-evident copies, and supports necessary compliance addenda.
Define start date and initial term length (e.g., 12–36 months)
Typically 30–90 days' written notice before term end
Commonly 30–60 days' advance notice
Often 15–30 days to remedy breaches unless immediate action required
Specify timeline (e.g., 30–90 days post-termination) and proof of destruction
| Document Type | DSP Agreement | DPA Addendum |
|---|---|---|
| Purpose | comprehensive services | processing-specific |
| Scope | full commercial terms | limited to data handling |
| Signature Required | often appended to main contract | |
| Regulatory Focus | broad compliance | privacy/security focus |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes (Business Premium) | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA available) | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |