DATA PROCESSING AGREEMENT (DPA) WITH STANDARD CONTRACTUAL CLAUSES
This Data Processing Agreement (this "DPA" or "Agreement") is entered into as of ________ (the "Effective Date")
BETWEEN:
________, a company incorporated under the laws of ________, having its registered office at ________, registered under company number ________ (the "Controller" or "data exporter"); and
________, a company incorporated under the laws of ________, having its registered office at ________, registered under company number ________ (the "Processor" or "data importer").
The Controller and the Processor are each a "Party" and together the "Parties".
RECITALS
- (A) The Parties have entered into an underlying agreement dated ________ for the provision of the services described therein (the "Principal Agreement"), under which the Processor processes personal data on behalf of the Controller.
- (B) This DPA sets out the terms on which the Processor processes personal data on behalf of the Controller and reflects the Parties' agreement with regard to the processing of personal data in accordance with the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR").
- (C) Where the processing involves a restricted transfer of personal data, the Parties intend to rely on the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "SCCs"), as incorporated by reference into this DPA.
- (D) This DPA is supplemental to, and forms part of, the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the subject matter of the processing of personal data.
CLAUSE 1 — DEFINITIONS
1.1 The terms "personal data", "special categories of personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", "supervisory authority" and "third country" have the meaning given to them in the GDPR.
1.2 "Applicable Data Protection Law" means the GDPR and all other laws and regulations relating to the processing of personal data and privacy that apply to a Party, including, where applicable, the national data protection laws of ________.
1.3 "Restricted Transfer" means a transfer of personal data from the Controller to the Processor (or an onward transfer) to a country or territory outside the European Economic Area that is not the subject of an adequacy decision under Article 45 GDPR.
1.4 "Services" means the services provided by the Processor to the Controller under the Principal Agreement.
CLAUSE 2 — SUBJECT-MATTER, NATURE AND PURPOSE
2.1 The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1 to this DPA, in accordance with Article 28(3) GDPR.
2.2 The Processor shall process personal data only for the purposes described in Annex 1 and shall not process personal data for any other purpose unless required to do so by Union or Member State law to which the Processor is subject.
CLAUSE 3 — DURATION
3.1 This DPA shall take effect on the Effective Date and shall continue in force for the duration of the processing of personal data under the Principal Agreement, and in any event until the personal data is deleted or returned in accordance with Clause 12.
CLAUSE 4 — PROCESSING ON DOCUMENTED INSTRUCTIONS
Lorem ipsum dolor sit amet consectetur adipiscing elit sed do eiusmod tempor incididunt ut labore et dolore magna aliqua ut enim ad minim veniam quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat duis aute irure dolor in reprehenderit voluptate velit esse cillum dolore eu fugiat nulla pariatur lorem ipsum dolor sit amet consectetur adipiscing elit sed do eiusmod tempor incididunt ut labore et dolore magna aliqua ut.
4.2 This DPA and the Principal Agreement, together with the Controller's written use of the Services, constitute the Controller's complete and final documented instructions to the Processor.
4.3 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
CLAUSE 5 — CONFIDENTIALITY
5.1 The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to personal data is limited to those persons who need access to perform the Processor's obligations under the Principal Agreement.
CLAUSE 6 — SECURITY OF PROCESSING (ARTICLE 32 GDPR)
Lorem ipsum dolor sit amet consectetur adipiscing elit sed do eiusmod tempor incididunt ut labore et dolore magna aliqua ut enim ad minim veniam quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat duis aute irure dolor in reprehenderit voluptate velit esse cillum dolore eu fugiat nulla pariatur lorem ipsum dolor sit amet consectetur adipiscing elit sed do eiusmod tempor incididunt ut.
6.2 In assessing the appropriate level of security, the Processor shall take account in particular of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
CLAUSE 7 — ASSISTANCE WITH DATA-SUBJECT RIGHTS (ARTICLES 12-23 GDPR)
7.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR (Articles 12 to 23).
7.2 The Processor shall promptly notify the Controller if it receives a request from a data subject in respect of personal data processed under this DPA, and shall not respond to that request except on the documented instructions of the Controller or as required by Applicable Data Protection Law.
CLAUSE 8 — ASSISTANCE WITH ARTICLES 32-36 GDPR
8.1 The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor, including in relation to security, personal data breach notification, data protection impact assessments and prior consultation with the supervisory authority.
CLAUSE 9 — PERSONAL DATA BREACH NOTIFICATION
9.1 The Processor shall notify the Controller without undue delay, and in any event within ________ hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.
9.2 Such notification shall, at a minimum, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach, to the extent such information is available to the Processor.
CLAUSE 10 — SUB-PROCESSORS
10.1 The Controller grants the Processor ________ authorisation to engage sub-processors. The sub-processors authorised as at the Effective Date are listed in Annex 3.
10.2 Where the Processor engages a sub-processor, it shall do so by way of a written contract that imposes on the sub-processor the same data protection obligations as those set out in this DPA (in particular providing sufficient guarantees to implement appropriate technical and organisational measures), in accordance with Article 28(4) GDPR.
10.3 The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller at least ________ days to object, thereby giving the Controller the opportunity to object to such changes.
10.4 The Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
CLAUSE 11 — INTERNATIONAL TRANSFERS AND STANDARD CONTRACTUAL CLAUSES
11.1 The Processor shall not carry out a Restricted Transfer of personal data unless it has taken such measures as are necessary to ensure the transfer is in compliance with Applicable Data Protection Law.
11.2 Where a Restricted Transfer takes place, the Parties agree that the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 (the "SCCs") are hereby incorporated into and form part of this DPA by reference, and shall apply to that transfer.
11.3 The applicable Module of the SCCs is ________ (for example, Module Two: Controller-to-Processor). The Parties shall complete the SCCs as follows:
- Clause 7 (Docking clause): ________ (applicable / not applicable).
- Clause 9 (Use of sub-processors): Option ________ (General written authorisation with a minimum notice period of ________ days / Specific prior authorisation).
- Clause 11 (Redress): the optional independent dispute-resolution body provision is ________ (included / not included).
- Clause 17 (Governing law): the SCCs shall be governed by the law of ________.
- Clause 18 (Choice of forum and jurisdiction): disputes shall be resolved before the courts of ________.
11.4 The Annexes to the SCCs shall be populated using the information set out in Annex 1 and Annex 2 to this DPA. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail with respect to the Restricted Transfer.
11.5 The competent supervisory authority for the purposes of the SCCs shall be ________.
CLAUSE 12 — DELETION OR RETURN OF PERSONAL DATA
12.1 At the choice of the Controller, the Processor shall ________ (delete / return) all the personal data to the Controller after the end of the provision of the Services relating to processing, and shall delete existing copies unless Union or Member State law requires storage of the personal data.
12.2 The Processor shall, on request, provide the Controller with written certification that it has complied with this Clause 12.
CLAUSE 13 — AUDITS AND INSPECTIONS
13.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
13.2 The Controller shall give the Processor reasonable prior written notice of not less than ________ days before any such audit, and audits shall be conducted no more than ________ per year unless required by a supervisory authority or following a personal data breach.
CLAUSE 14 — LIABILITY
14.1 Each Party's liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Principal Agreement, and any reference in the Principal Agreement to the liability of a Party means the aggregate liability of that Party under the Principal Agreement and this DPA together.
14.2 The aggregate liability of the Processor under this DPA shall not exceed ________, save to the extent such limitation is not permitted by Applicable Data Protection Law.
14.3 Nothing in this DPA limits the rights of data subjects under the GDPR or the SCCs.
CLAUSE 15 — TERM AND TERMINATION
15.1 This DPA shall remain in effect for so long as the Processor processes personal data on behalf of the Controller under the Principal Agreement.
15.2 Either Party may terminate this DPA on written notice with immediate effect if the other Party is in material breach of this DPA and fails to remedy that breach within ________ days of receiving written notice.
CLAUSE 16 — GOVERNING LAW AND JURISDICTION
16.1 This DPA shall be governed by and construed in accordance with the laws of ________, without prejudice to Clause 17 of the SCCs where the SCCs apply.
16.2 The courts of ________ shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to Clause 18 of the SCCs where the SCCs apply.
CLAUSE 17 — MISCELLANEOUS
17.1 This DPA, together with its Annexes and the Principal Agreement, constitutes the entire agreement between the Parties in relation to the processing of personal data and supersedes any prior arrangements on that subject.
17.2 If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
ANNEX 1 — DETAILS OF PROCESSING (ARTICLE 28(3) GDPR)
| Subject-matter of the processing | ________ |
| Duration of the processing | ________ |
| Nature of the processing | ________ |
| Purpose of the processing | ________ |
| Types of personal data | ________ |
| Special categories of personal data (if any) | ________ |
| Categories of data subjects | ________ |
| Frequency of the transfer (if applicable) | ________ |
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES (ARTICLE 32 GDPR)
| Pseudonymisation and encryption of personal data | ________ |
| Measures to ensure ongoing confidentiality, integrity, availability and resilience of systems | ________ |
| Measures to restore availability and access to personal data after an incident | ________ |
| Process for regularly testing and evaluating the effectiveness of measures | ________ |
| Access control and identity management | ________ |
| Physical security of processing facilities | ________ |
| Logging, monitoring and incident management | ________ |
| Staff training and awareness | ________ |
ANNEX 3 — LIST OF AUTHORISED SUB-PROCESSORS
| Sub-processor name | Location / country | Processing activity |
| ________ | ________ | ________ |
| ________ | ________ | ________ |
| ________ | ________ | ________ |
SIGNATURES
For and on behalf of the Controller (data exporter):
Name: ________
Title: ________
Signature: ________
Date: ________
For and on behalf of the Processor (data importer):
Name: ________
Title: ________
Signature: ________
Date: ________