Data-processing agreement - template
Draft — company details and operational annexes remain to be confirmed.
LEGAL-DRAFT-20261008-1 · B2B · EN
Parties and processing annex
Identify the controller, processor, any reseller and the relevant legal entities before signing. This template applies only to processing carried out on documented customer instructions. Complete the annex with the service, purposes, data subjects, categories of data, processing operations, duration and deletion/export instructions. A connectivity supplier or payment provider may be an independent controller for other operations.
Instructions, confidentiality and safeguards
The processor follows documented lawful instructions, limits access to authorised personnel under confidentiality obligations and maintains agreed technical and organisational safeguards. Instructions that conflict with applicable requirements are escalated. The security annex must specify controls actually implemented; untested network automation or planned RBAC is not a contractual assurance.
Subprocessors and transfers
Maintain an approved named subprocessor list, functions, locations and transfer safeguards. Specify the authorisation and change-notice process and apply appropriate onward obligations. Hosting, connectivity, payment, notifications and support must be assessed separately. No unspecified international transfer is authorised by this template.
Assistance and incidents
Agree channels and procedures for assistance with rights requests, security incidents, impact assessment and regulator enquiries. Escalate breaches promptly enough for the controller's obligations. Incident contacts, timelines, evidence, responsibility and costs must be specified in the final annex; none are invented here.
Audit, return and deletion
Agree proportionate audit/evidence access and remediation. On termination, return or delete customer data according to documented instructions and applicable retention obligations. Specify backup treatment, residual copies, retention exceptions and confirmation. The current platform does not yet provide a complete automated rights-request/deletion workflow.