Establishing secure connection…Loading editor…Preparing document…

Privacy Disclosure Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PRIVACY DISCLOSURE AGREEMENT

This Privacy Disclosure Agreement ("Agreement") is made and entered into as of Effective Date: by and between Disclosing Party: , with principal place of business at , and Receiving Party: , with principal place of business at .

RECITALS

WHEREAS, Disclosing Party possesses Confidential Information and Personal Data (each as defined below) relating to its customers, employees, and business operations, which information Disclosing Party may disclose to Receiving Party for the Purpose described below; and

WHEREAS, the parties desire to set forth their respective rights and obligations with respect to receiving, processing, transferring, safeguarding, and returning or destroying such Confidential Information and Personal Data in order to comply with applicable privacy and data protection requirements; and

WHEREAS, Disclosing Party and Receiving Party intend that this Agreement establish legally binding obligations regarding confidentiality, security, data subject rights assistance, breach notification, and permitted disclosures.

NOW, THEREFORE, in consideration of the mutual covenants contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties agree as follows:

1. DEFINITIONS

1.1 "Confidential Information" means all non-public information disclosed by Disclosing Party to Receiving Party, whether disclosed orally, visually, in writing, or by electronic or other means, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. Confidential Information includes Personal Data.

1.2 "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to identifiers, contact details, financial information, government identifiers, health information, and other categories disclosed in the course of performance. Categories of Personal Data to be disclosed are described below.

2. PURPOSE

2.1 The parties agree that Disclosing Party will disclose Confidential Information and Personal Data to Receiving Party solely for the purpose of: (the "Purpose"). Receiving Party shall not use Confidential Information for any purpose other than the Purpose without the prior written consent of Disclosing Party.

3. DISCLOSURE AND USE RESTRICTIONS

3.1 Receiving Party shall: (a) process Confidential Information only on documented instructions from Disclosing Party and solely for the Purpose; (b) restrict access to Confidential Information to those of its employees, officers, contractors or agents who have a strict need to know and who are bound by confidentiality obligations at least as protective as those in this Agreement; and (c) not disclose, sell, transfer, assign or otherwise make available Confidential Information to any third party except as expressly permitted by this Agreement.

4. PERMITTED DISCLOSURES

4.1 Receiving Party may disclose Confidential Information only to: (a) its employees, directors, officers, and contractors who need such information to perform the Purpose; (b) affiliates and subcontractors who have executed written agreements imposing obligations at least as protective as this Agreement; and (c) the extent required by applicable law, regulation or court order, provided that Receiving Party gives Disclosing Party prompt written notice of any such demand to permit Disclosing Party to seek protective relief unless prohibited by law.

5. SECURITY AND BREACH NOTIFICATION

5.1 Receiving Party shall implement and maintain appropriate administrative, physical, and technical safeguards to protect Confidential Information against unauthorized access, disclosure, alteration, or destruction, consistent with industry standards and applicable law. Receiving Party shall document such safeguards and make them available to Disclosing Party upon reasonable request.

5.2 In the event of any actual or reasonably suspected security incident or unauthorized disclosure affecting Confidential Information ("Breach"), Receiving Party shall: (a) promptly take measures to contain and mitigate the Breach; (b) notify Disclosing Party without undue delay and, in any event, no later than days after discovery; and (c) cooperate with Disclosing Party in investigating the Breach and complying with any regulatory notification obligations.

6. DATA SUBJECT RIGHTS AND ASSISTANCE

6.1 Receiving Party shall promptly notify Disclosing Party if it receives any request or complaint from a data subject relating to Personal Data and shall not respond to such request without Disclosing Party's direction, except as required by law. Receiving Party shall provide reasonable assistance to Disclosing Party in responding to data subject access, correction, deletion, portability, objection and other privacy-related requests.

7. STORAGE, RETENTION, RETURN AND DESTRUCTION

7.1 Receiving Party shall retain Personal Data only for as long as necessary to fulfill the Purpose or as required by applicable law. Upon termination of this Agreement or upon Disclosing Party's written request, Receiving Party shall, at Disclosing Party's election, return all Confidential Information and Personal Data to Disclosing Party or securely destroy such information within days and certify destruction in writing.

8. SUBPROCESSORS AND THIRD PARTIES

8.1 Receiving Party shall not engage any subcontractor or third party to process Confidential Information or Personal Data without the prior written consent of Disclosing Party. Where consent is given, Receiving Party shall impose on such subprocessors obligations no less protective than those set forth in this Agreement and shall remain liable for the acts and omissions of such subprocessors.

9. AUDIT RIGHTS

9.1 Disclosing Party shall have the right, upon reasonable notice and during normal business hours, to audit Receiving Party's compliance with the terms of this Agreement, including physical and technical safeguards. Audits shall be conducted in a manner that minimizes disruption to Receiving Party's business and may be performed by Disclosing Party or by an independent third party engaged by Disclosing Party and bound by confidentiality obligations.

10. REMEDIES

10.1 Receiving Party acknowledges that any actual or threatened breach of this Agreement may cause irreparable harm to Disclosing Party for which monetary damages may be an inadequate remedy. Accordingly, Disclosing Party shall be entitled to seek injunctive relief and other equitable remedies in addition to any other remedies available at law or in equity.

11. LIMITATIONS OF LIABILITY

11.1 Except as expressly provided in this Agreement, neither party shall be liable for indirect, consequential, special or punitive damages. Nothing in this Agreement shall limit liability for gross negligence, willful misconduct, fraudulent misrepresentation, or liabilities arising under applicable data protection laws.

12. TERM, SURVIVAL AND TERMINATION

12.1 This Agreement commences on the Effective Date and shall continue in effect until the earlier of completion of the Purpose or termination by either party upon thirty (30) days' prior written notice. Notwithstanding termination, the obligations with respect to Confidential Information and Personal Data shall survive for a period of years from the date of termination, or for such longer period as required by applicable law.

13. NOTICES

13.1 All notices required or permitted under this Agreement shall be in writing and shall be deemed given when delivered personally, sent by nationally recognized overnight courier, or sent by certified mail, return receipt requested, to the addresses set forth below or to such other address as a party may designate in writing.

14. AMENDMENT AND WAIVER

14.1 No amendment, modification or waiver of any provision of this Agreement shall be effective unless in writing and signed by authorized representatives of both parties. Failure or delay by either party to exercise any right shall not constitute a waiver of that right.

15. GOVERNING LAW

15.1 This Agreement shall be governed by and construed in accordance with the laws of the State of , without regard to principles of conflicts of law.

16. ENTIRE AGREEMENT

16.1 This Agreement constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, understandings, negotiations and discussions, whether oral or written.

17. SEVERABILITY

17.1 If any provision of this Agreement is held to be invalid, illegal or unenforceable, the remaining provisions shall remain in full force and effect and shall be construed so as to effectuate the intent of the parties to the fullest extent permitted by law.

18. COUNTERPARTS

18.1 This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument. Signatures provided by electronic means shall be valid and binding.

MISCELLANEOUS

19.1 The parties acknowledge that Disclosing Party may incur damages as a result of Receiving Party's breach of its obligations under this Agreement and that Disclosing Party's remedies at law may be inadequate; accordingly, Disclosing Party shall be entitled to seek equitable relief in addition to any other remedies.

19.2 The obligations of confidentiality, data protection, breach notification, return or destruction, and remedies shall survive termination of this Agreement for the periods specified herein.

Disclosing Party - Printed Name:

By:

Date:

Receiving Party - Printed Name:

By:

Date:

Enter text✕

What a Privacy Disclosure Agreement Is and When It’s Used

A Privacy Disclosure Agreement is a written statement that describes how an organization collects, uses, shares, and retains personal information. It defines data categories, permissible uses, third-party recipients, retention periods, security measures and the parties’ responsibilities. In the United States this document supports consumer notices required by state privacy laws and industry rules such as HIPAA, and it documents consent and attribution when records are distributed or stored electronically under ESIGN and UETA standards. Properly drafted disclosures reduce regulatory risk and set operational expectations between controllers, processors and recipients.

Why a Clear Privacy Disclosure Agreement Matters

A clear agreement protects legal compliance and reduces ambiguity about permitted data uses, helping organizations meet state privacy laws, HIPAA obligations, and ESIGN/UETA electronic-consent requirements while establishing accountability for security and retention.

Why a Clear Privacy Disclosure Agreement Matters

Who Typically Prepares or Signs This Agreement

In smaller organizations these roles may be combined; in regulated sectors like healthcare and finance formal signatory authority typically rests with legal or senior management.

  • Privacy officer or counsel — Drafts policy language, ensures regulatory alignment and documents lawful basis for processing.
  • Business owner or operations lead — Confirms commercial purposes, data recipients, and retention terms for operational workflows.
  • Third-party vendor or processor — Reviews obligations, security controls, and any data transfer or subcontracting limitations.

Core Sections to Include in a Professional Privacy Disclosure Agreement

A complete agreement organizes obligations so stakeholders can find legal bases, permitted uses, security commitments and retention rules quickly.

Purpose

Explain each specific business purpose for data collection and processing, avoiding vague terms so parties understand permitted downstream uses and limits.

Data Categories

Define the types of personal information covered (identifiers, financial, health, biometric) so obligations map precisely to regulated categories.

Permitted Recipients

List internal teams and external vendors permitted to receive data and describe conditions for onward transfers or subcontracting.

Retention

Specify retention periods or criteria for deletion and archival, including triggers for early disposal or legal holds.

Security Measures

Describe technical and administrative safeguards (encryption, access controls, incident response) and reference applicable standards.

Signatures and Consent

Provide signature blocks, effective date, and any consumer disclosure language required under federal or state laws for electronic consent.

Essential Fields and Security Items to Capture

Signatory Name: Full legal name
Contact Information: Street address or business address
Data Categories: List types collected
Recipients: Named third parties
Retention Period: Specific time frame
Security Standards: Encryption, access controls

Step-by-Step: Completing a Privacy Disclosure Agreement

Follow this order to reduce rework and ensure the document aligns with operations and compliance obligations.

  • 01
    1. Identify parties: Enter legal names and roles for each party.
  • 02
    2. Describe processing: List purposes, categories, and lawful bases.
  • 03
    3. Add safeguards: Specify encryption, access control, incident response.
  • 04
    4. Sign and date: Obtain signatures, effective date, and retention terms.

How Electronic Execution and Distribution Typically Works

A consistent workflow ensures consent, attribution and an audit trail when using electronic platforms for privacy agreements.

  • Upload document: Prepare PDF or DOCX version for signing.
  • Place fields: Insert signature, date and checkbox fields.
  • Authenticate signer: Use email link, SMS code, or stronger methods.
  • Capture audit trail: Record timestamps, IP addresses and actions.

Typical Online Configuration Settings for eSigning

Configure authentication, consent disclosures and retention to meet legal and operational needs before sending.

Field Configuration
Signature method Electronic signature overlay or PKI
Authentication Email link, SMS code, or KBA
Consent disclosure Consumer notice required for electronic consent
Audit retention Retain completion record and PDF

Digital Signing and Distribution: Platform Considerations

Ensure the provider offers encryption in transit and at rest, HIPAA BAA where needed, and exportable audit trails for legal and regulatory review.

  • Integrations: Salesforce, NetSuite, Google Workspace
  • Supported formats: PDF, DOCX, HTML, Excel
  • Authentication options: Email, SMS, KBA, SSO

Timing, Consumer Requests and Response Expectations

Privacy disclosure agreements themselves rarely have filing deadlines, but related consumer-request timelines and retention obligations are time sensitive.

Provide disclosure on collection:

At or before the time of collection

CCPA access response:

45 days to respond to consumer requests

Consent withdrawal:

Acknowledge revocation promptly per policy

Record retention start:

Begins on effective date of agreement

Audit trail retention:

Keep signing records per retention policy

Common Mistakes to Avoid When Preparing This Agreement

  • Using broad or undefined purposes that permit unexpected downstream sharing and increase compliance risk.
  • Failing to list categories of personal data covered, leaving ambiguity about whether sensitive categories like health data are included.
  • Omitting consumer-facing disclosures and ESIGN consumer consent steps when electronic records are used for consumer transactions.
  • Not aligning retention language with legal holds, which can result in premature deletion or inconsistent preservation.

Key Penalties and Risks from Incomplete or Incorrect Agreements

Regulatory fines: State privacy and consumer-protection fines
Contract liability: Breach of contract damages
Operational disruption: Forced cessation of processing
Reputational harm: Loss of customer trust
Civil litigation: Class actions or statutory claims
Data breach costs: Investigation and remediation expenses

Real-World Examples of Privacy Disclosure Use

These examples show how organizations streamline consent and recordkeeping with online disclosures and eSignatures.

Optica Ventures LLC

Optica adopted online disclosures to simplify customer interactions.

  • The interface is simple and easy-to-use for team and customers.
  • The result improved turnaround on signed disclosures and reduced manual reconciliation, making compliance documentation consistent across clients.

Fertility Centers of Illinois

The center digitized patient privacy notices and consent forms.

  • airSlate SignNow provided flexibility and integration options.
  • Digitization preserved audit trails and ensured HIPAA-aligned record retention while supporting mobile signing for patients.

Frequently Asked Questions About Privacy Disclosure Agreements

Answers to common legal and technical questions about drafting, signing and storing privacy disclosure agreements.


Need help? Contact support

eSignature Pricing and Capabilities: signNow and Common Competitors

Compare typical starting prices and feature availability for common eSignature providers to inform platform selection for privacy disclosure workflows.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
be ready to get more
Join over 28 million airSlate SignNow users