welcom

Data-processing agreement - template

Draft — company details and operational annexes remain to be confirmed.

LEGAL-DRAFT-20261008-1 · B2B · EN

Service terms Privacy Cookie policy Data-processing agreement Acceptable use

Parties and processing annex

Identify the controller, processor, any reseller and the relevant legal entities before signing. This template applies only to processing carried out on documented customer instructions. Complete the annex with the service, purposes, data subjects, categories of data, processing operations, duration and deletion/export instructions. A connectivity supplier or payment provider may be an independent controller for other operations.

Instructions, confidentiality and safeguards

The processor follows documented lawful instructions, limits access to authorised personnel under confidentiality obligations and maintains agreed technical and organisational safeguards. Instructions that conflict with applicable requirements are escalated. The security annex must specify controls actually implemented; untested network automation or planned RBAC is not a contractual assurance.

Subprocessors and transfers

Maintain an approved named subprocessor list, functions, locations and transfer safeguards. Specify the authorisation and change-notice process and apply appropriate onward obligations. Hosting, connectivity, payment, notifications and support must be assessed separately. No unspecified international transfer is authorised by this template.

Assistance and incidents

Agree channels and procedures for assistance with rights requests, security incidents, impact assessment and regulator enquiries. Escalate breaches promptly enough for the controller's obligations. Incident contacts, timelines, evidence, responsibility and costs must be specified in the final annex; none are invented here.

Audit, return and deletion

Agree proportionate audit/evidence access and remediation. On termination, return or delete customer data according to documented instructions and applicable retention obligations. Specify backup treatment, residual copies, retention exceptions and confirmation. The current platform does not yet provide a complete automated rights-request/deletion workflow.

Reference sources

  • https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
Service termsPrivacyData-processing agreementAcceptable use
Cookie settings

Necessary cookies support login, security and your preferences. Optional tracking is disabled by default. Cookie policy