Data Processing Agreement Template
GDPR-aligned DPA between data controller and processor.
Use this free data processing agreement template to create, fill in and sign a data processing agreement online. Send to the other party for a legally binding signature — tamper-evident audit trail included.
Template preview
DATA PROCESSING AGREEMENT
This Data Processing Agreement ("DPA") forms part of the agreement between [controller name] ("Controller") and [processor name] ("Processor") dated [date]. It governs Processor’s processing of Personal Data on Controller’s behalf.
1. Subject Matter & Purpose
Processor will process Personal Data only to provide the services described in the underlying agreement, on Controller’s documented instructions, and for the purposes of: [processing purpose].
2. Categories of Data & Data Subjects
Categories of Personal Data: [data categories]. Categories of Data Subjects: [subject categories].
3. Processor Obligations
Processor will: (a) process Personal Data only on documented Controller instructions; (b) ensure persons authorized to process the data are under confidentiality obligations; (c) implement appropriate technical and organizational security measures; (d) assist Controller with data subject requests and DPIAs.
4. Sub-processors
Processor may engage sub-processors only with Controller’s prior written consent (general or specific). Processor remains liable for sub-processor compliance. Current sub-processors: [subprocessors].
5. International Transfers
Any transfer of Personal Data to a country outside the EEA requires an appropriate transfer mechanism (Standard Contractual Clauses, adequacy decision, or other lawful basis).
6. Security & Breach Notification
Processor will notify Controller of any Personal Data Breach without undue delay, and in any event within 72 hours of becoming aware. Notification includes nature, categories affected, likely consequences, and mitigation measures.
7. Return / Deletion
On termination of services, Processor will return or delete all Personal Data, at Controller’s choice, unless retention is required by law.