Your answers are saved on this device — never on our servers · Sign in

Fill in the details

0/62

0 of 62 completed

Type below - the document on the right updates as you go.

The clauses below are blurred in the preview. Fill in your details, then pay once to unlock the full document and download it as Word & PDF.

Proceed to payment

🔒 Secure & private · ⚡ Instant download after payment · One-time payment · no subscription

Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) - GDPR

DATA PROCESSING AGREEMENT (DPA) WITH STANDARD CONTRACTUAL CLAUSES

This Data Processing Agreement (this "DPA" or "Agreement") is entered into as of ________ (the "Effective Date")

BETWEEN:

________, a company incorporated under the laws of ________, having its registered office at ________, registered under company number ________ (the "Controller" or "data exporter"); and

________, a company incorporated under the laws of ________, having its registered office at ________, registered under company number ________ (the "Processor" or "data importer").

The Controller and the Processor are each a "Party" and together the "Parties".

RECITALS

  • (A) The Parties have entered into an underlying agreement dated ________ for the provision of the services described therein (the "Principal Agreement"), under which the Processor processes personal data on behalf of the Controller.
  • (B) This DPA sets out the terms on which the Processor processes personal data on behalf of the Controller and reflects the Parties' agreement with regard to the processing of personal data in accordance with the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR").
  • (C) Where the processing involves a restricted transfer of personal data, the Parties intend to rely on the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "SCCs"), as incorporated by reference into this DPA.
  • (D) This DPA is supplemental to, and forms part of, the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement, this DPA shall prevail with respect to the subject matter of the processing of personal data.

CLAUSE 1 — DEFINITIONS

1.1 The terms "personal data", "special categories of personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", "supervisory authority" and "third country" have the meaning given to them in the GDPR.

1.2 "Applicable Data Protection Law" means the GDPR and all other laws and regulations relating to the processing of personal data and privacy that apply to a Party, including, where applicable, the national data protection laws of ________.

1.3 "Restricted Transfer" means a transfer of personal data from the Controller to the Processor (or an onward transfer) to a country or territory outside the European Economic Area that is not the subject of an adequacy decision under Article 45 GDPR.

1.4 "Services" means the services provided by the Processor to the Controller under the Principal Agreement.

CLAUSE 2 — SUBJECT-MATTER, NATURE AND PURPOSE

2.1 The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1 to this DPA, in accordance with Article 28(3) GDPR.

2.2 The Processor shall process personal data only for the purposes described in Annex 1 and shall not process personal data for any other purpose unless required to do so by Union or Member State law to which the Processor is subject.

CLAUSE 3 — DURATION

3.1 This DPA shall take effect on the Effective Date and shall continue in force for the duration of the processing of personal data under the Principal Agreement, and in any event until the personal data is deleted or returned in accordance with Clause 12.

CLAUSE 4 — PROCESSING ON DOCUMENTED INSTRUCTIONS

4.2 This DPA and the Principal Agreement, together with the Controller's written use of the Services, constitute the Controller's complete and final documented instructions to the Processor.

4.3 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.

CLAUSE 5 — CONFIDENTIALITY

5.1 The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to personal data is limited to those persons who need access to perform the Processor's obligations under the Principal Agreement.

CLAUSE 6 — SECURITY OF PROCESSING (ARTICLE 32 GDPR)

6.2 In assessing the appropriate level of security, the Processor shall take account in particular of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

CLAUSE 7 — ASSISTANCE WITH DATA-SUBJECT RIGHTS (ARTICLES 12-23 GDPR)

7.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR (Articles 12 to 23).

7.2 The Processor shall promptly notify the Controller if it receives a request from a data subject in respect of personal data processed under this DPA, and shall not respond to that request except on the documented instructions of the Controller or as required by Applicable Data Protection Law.

CLAUSE 8 — ASSISTANCE WITH ARTICLES 32-36 GDPR

8.1 The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor, including in relation to security, personal data breach notification, data protection impact assessments and prior consultation with the supervisory authority.

CLAUSE 9 — PERSONAL DATA BREACH NOTIFICATION

9.1 The Processor shall notify the Controller without undue delay, and in any event within ________ hours, after becoming aware of a personal data breach affecting personal data processed under this DPA.

9.2 Such notification shall, at a minimum, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach, to the extent such information is available to the Processor.

CLAUSE 10 — SUB-PROCESSORS

10.1 The Controller grants the Processor ________ authorisation to engage sub-processors. The sub-processors authorised as at the Effective Date are listed in Annex 3.

10.2 Where the Processor engages a sub-processor, it shall do so by way of a written contract that imposes on the sub-processor the same data protection obligations as those set out in this DPA (in particular providing sufficient guarantees to implement appropriate technical and organisational measures), in accordance with Article 28(4) GDPR.

10.3 The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller at least ________ days to object, thereby giving the Controller the opportunity to object to such changes.

10.4 The Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.

CLAUSE 11 — INTERNATIONAL TRANSFERS AND STANDARD CONTRACTUAL CLAUSES

11.1 The Processor shall not carry out a Restricted Transfer of personal data unless it has taken such measures as are necessary to ensure the transfer is in compliance with Applicable Data Protection Law.

11.2 Where a Restricted Transfer takes place, the Parties agree that the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/914 (the "SCCs") are hereby incorporated into and form part of this DPA by reference, and shall apply to that transfer.

11.3 The applicable Module of the SCCs is ________ (for example, Module Two: Controller-to-Processor). The Parties shall complete the SCCs as follows:

  • Clause 7 (Docking clause): ________ (applicable / not applicable).
  • Clause 9 (Use of sub-processors): Option ________ (General written authorisation with a minimum notice period of ________ days / Specific prior authorisation).
  • Clause 11 (Redress): the optional independent dispute-resolution body provision is ________ (included / not included).
  • Clause 17 (Governing law): the SCCs shall be governed by the law of ________.
  • Clause 18 (Choice of forum and jurisdiction): disputes shall be resolved before the courts of ________.

11.4 The Annexes to the SCCs shall be populated using the information set out in Annex 1 and Annex 2 to this DPA. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail with respect to the Restricted Transfer.

11.5 The competent supervisory authority for the purposes of the SCCs shall be ________.

CLAUSE 12 — DELETION OR RETURN OF PERSONAL DATA

12.1 At the choice of the Controller, the Processor shall ________ (delete / return) all the personal data to the Controller after the end of the provision of the Services relating to processing, and shall delete existing copies unless Union or Member State law requires storage of the personal data.

12.2 The Processor shall, on request, provide the Controller with written certification that it has complied with this Clause 12.

CLAUSE 13 — AUDITS AND INSPECTIONS

13.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

13.2 The Controller shall give the Processor reasonable prior written notice of not less than ________ days before any such audit, and audits shall be conducted no more than ________ per year unless required by a supervisory authority or following a personal data breach.

CLAUSE 14 — LIABILITY

14.1 Each Party's liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Principal Agreement, and any reference in the Principal Agreement to the liability of a Party means the aggregate liability of that Party under the Principal Agreement and this DPA together.

14.2 The aggregate liability of the Processor under this DPA shall not exceed ________, save to the extent such limitation is not permitted by Applicable Data Protection Law.

14.3 Nothing in this DPA limits the rights of data subjects under the GDPR or the SCCs.

CLAUSE 15 — TERM AND TERMINATION

15.1 This DPA shall remain in effect for so long as the Processor processes personal data on behalf of the Controller under the Principal Agreement.

15.2 Either Party may terminate this DPA on written notice with immediate effect if the other Party is in material breach of this DPA and fails to remedy that breach within ________ days of receiving written notice.

CLAUSE 16 — GOVERNING LAW AND JURISDICTION

16.1 This DPA shall be governed by and construed in accordance with the laws of ________, without prejudice to Clause 17 of the SCCs where the SCCs apply.

16.2 The courts of ________ shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to Clause 18 of the SCCs where the SCCs apply.

CLAUSE 17 — MISCELLANEOUS

17.1 This DPA, together with its Annexes and the Principal Agreement, constitutes the entire agreement between the Parties in relation to the processing of personal data and supersedes any prior arrangements on that subject.

17.2 If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

ANNEX 1 — DETAILS OF PROCESSING (ARTICLE 28(3) GDPR)

Subject-matter of the processing________
Duration of the processing________
Nature of the processing________
Purpose of the processing________
Types of personal data________
Special categories of personal data (if any)________
Categories of data subjects________
Frequency of the transfer (if applicable)________

ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES (ARTICLE 32 GDPR)

Pseudonymisation and encryption of personal data________
Measures to ensure ongoing confidentiality, integrity, availability and resilience of systems________
Measures to restore availability and access to personal data after an incident________
Process for regularly testing and evaluating the effectiveness of measures________
Access control and identity management________
Physical security of processing facilities________
Logging, monitoring and incident management________
Staff training and awareness________

ANNEX 3 — LIST OF AUTHORISED SUB-PROCESSORS

Sub-processor nameLocation / countryProcessing activity
________________________
________________________
________________________

SIGNATURES

For and on behalf of the Controller (data exporter):

Name: ________

Title: ________

Signature: ________

Date: ________

For and on behalf of the Processor (data importer):

Name: ________

Title: ________

Signature: ________

Date: ________

Fields you complete are inserted into the document live. This template is general guidance only - not legal advice.