This document is a starting template prepared for review. Have it checked by qualified legal counsel before relying on it.
1. Scope
This Data Processing Agreement applies where we process personal data on behalf of a client in the course of providing our services. It supplements the main service agreement between the parties.
2. Roles of the Parties
The client acts as the data controller and determines the purposes and means of processing. We act as the data processor and process personal data only on the client's documented instructions.
3. Nature and Purpose of Processing
Processing is limited to the activities necessary to deliver the agreed services, including the categories of data and data subjects specified in the service agreement.
4. Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
5. Security Measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including measures relating to access control, encryption in transit, and resilience of processing systems.
6. Sub-processors
We engage sub-processors only where necessary, impose data protection obligations equivalent to those in this agreement, and remain responsible for their performance.
7. Assistance to the Controller
We provide reasonable assistance to the controller in responding to data subject requests, in carrying out data protection impact assessments, and in meeting breach notification obligations.
8. Deletion and Return of Data
On termination of the services, we delete or return personal data at the controller's election, except where retention is required by law.
9. Audit
We make available information necessary to demonstrate compliance with this agreement and allow for reasonable audits on prior written notice.
Questions about this document? Contact us.