Scope of Processing
Defines data categories, processing activities, and who is controller versus processor; restricts uses to agreed purposes and products.
A PDPA clarifies roles, limits liability, and documents safeguards required by privacy laws and sector rules. It reduces ambiguity about permitted uses, supports vendor audits, and is evidence of reasonable care in the event of regulatory review or incident response.
Organizations that collect or outsource processing of personal data commonly use a PDPA to set expectations and meet regulatory or contractual obligations.
Small vendors and large enterprises alike use PDPAs when third parties process customer, employee, or patient data; the document is often required before services commence.
Defines data categories, processing activities, and who is controller versus processor; restricts uses to agreed purposes and products.
Specifies technical and organizational safeguards such as encryption, access controls, incident response, and vulnerability management responsibilities.
Requires prior notice or approval for subprocessors and maps approval, flow-down terms, and liability allocation for their actions.
Sets timelines for notification, information required, and coordination for regulatory reporting and mitigation steps.
Allocates responsibility for handling access, correction, deletion, portability requests, and who bears costs for responses.
Specifies return or secure deletion of data on termination, verification steps, and retention exceptions for legal holds.
| Field | Configuration |
|---|---|
| Authentication | Email link, SMS code, or advanced signer verification |
| Field Types | Signature, initial, date, checkbox, conditional text fields |
| Conditional Logic | Show clauses or annexes only when specific options are selected |
| Notifications | Automatic reminders and completion receipts to stakeholders |
Confirm that your e-sign platform supports required authentication, compliance, and integrations before digital execution.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | Yes, 7-day free trial | Yes, trial available | Yes, trial available | Yes, trial available | Yes, trial available |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
Optica deployed standardized PDPAs across its vendor base to shorten onboarding and centralize controls.
A healthcare client paired PDPAs with HIPAA BAAs and secure eSignature workflows to collect patient authorizations.
Specify number of days to notify controller after discovery (commonly 72–90 hours or as contractually agreed)
Allocate response timeframe (controller typically requires processor assistance within 30–45 days)
Allow reasonable notice (30 days typical) for on-site or remote audits
Reassess security controls and subprocessors at least once per year
Define retention end dates and legal hold procedures tied to termination or litigation
Controller and processor align on scope, data categories, and core safeguards.
Counsel confirms indemnities, liability caps, and choice-of-law provisions.
Authorized signatories execute and date the PDPA; record retention begins.
Scheduled audits, security testing, and subprocessors checks are performed.
Chief Privacy Officer or General Counsel typically signs on behalf of the controller with authority to bind the organization and accept liability allocations; they must confirm the PDPA aligns with internal policies and legal requirements.
An executive with contracting authority such as VP of Legal or Head of Compliance signs for the processor; signatory confirms operational ability to meet security obligations and subprocessors commitments.