Data processing agreement — working template
Client-specific agreement template. Complete the annexes and execute the applicable agreement before relying on its terms.
Not an executed agreement
This is a negotiation template, not a binding DPA, SCC or transfer agreement. It must be completed with the correct parties and signed or otherwise validly adopted before relevant processing begins. HQL may be a processor for some instructed client activities and a controller for its own sourcing or decisions. A label in a contract cannot override the actual facts. Joint control, independent disclosure or US service-provider status may require a different arrangement.
Service-specific processing scope
Lead generation: CRM storage and delivery of contact lists or qualified leads to clients. Website enquiries: Tally and Zoho, up to five years from collection. CRM projects: development and/or hosting at the client’s choice; HQL’s team currently has no live-data access. Medical billing: US clients, patient and insurance data, Morocco and India staff access, and included or separately signed BAA terms. Record the actual vendors, locations and controls in the annexes; the BAA must separately address the applicable HIPAA obligations. Do not apply website or lead-data retention automatically to patient records.
Annex A — processing particulars
Complete: parties and contacts; controller/processor roles; subject matter; nature and purpose; duration; categories of individuals; categories of personal data; sensitive data exclusions; countries of processing and access; client instructions; permitted recipients; delivery method; retention and deletion/return dates. Record restrictions on secondary use, training or enrichment of unrelated datasets. No blank annex should be treated as approval to process anything.
Instructions, confidentiality and security
Proposed processor obligations: process only documented lawful instructions, including transfers; promptly flag instructions believed unlawful; bind authorised personnel to confidentiality; apply agreed appropriate safeguards; restrict access; and maintain evidence of compliance. Annex B must set out actual controls, including account security, access approval, encryption where implemented, backups, testing, training and incident response. Do not substitute vague security promises for a completed annex.
Subprocessors and assistance
Annex C must identify approved subprocessors, functions, locations and change-notice/objection arrangements. Flow down equivalent applicable duties and allocate responsibility. The proposed processor should assist with rights requests, security, breaches, DPIAs and regulator consultation as required, notify the controller of a breach without undue delay, and cooperate with proportionate audit/information requests. Commercial response targets and assistance costs require agreement; this template does not invent a fixed breach deadline.
Return, deletion and restricted uses
On termination, return or delete personal data at the controller’s choice unless law requires retention, covering copies and backup treatment under the agreed schedule. The agreement must define any permitted residual legal/suppression records, access restrictions and expiry. Any CCPA service-provider/contractor language must address the relevant restrictions and statutory obligations if that role is appropriate; independent selling/sharing cannot be concealed by calling HQL a service provider.
Annex D — international transfers
List each exporter/importer, location and role. Determine an applicable lawful transfer mechanism. Where required, complete the correct EU SCC module and annexes; for UK restricted transfers, assess the IDTA or UK Addendum and the required risk assessment. Check onward transfers and supplementary measures. Do not claim participation in an adequacy or certification scheme without verification. This page does not reproduce or execute mandatory clauses.
Open commercial and legal items
Complete governing law, jurisdiction, order of precedence, liability allocation, fees, term, signatures and mandatory local terms. Mandatory regulatory obligations must not be overridden by the service agreement. Obtain jurisdiction-specific review before execution.
Official references
- EU GDPR official text
- EDPB — individual rights
- EDPB — controller and processor roles
- ICO — business-to-business marketing
- ICO — cookies and privacy notices
- ICO — international transfer safeguards
- Canada OPC — business information and privacy
- Canada OPC — provincial private-sector laws
- CRTC — CASL implied consent
- FTC — CAN-SPAM business guide
- California DOJ — CCPA
- Texas — Chapter 541
Legal policy centre