# Data Processing Agreement (DPA)

> **⚠️ Legal template — review by a qualified attorney is required before use.** Generic, jurisdiction-neutral starting point from SentinelPanda. **Not legal advice.** GDPR, UK GDPR, CCPA/CPRA, and other regimes impose specific requirements (and transfer mechanisms) that must be tailored by counsel. Do not sign or send without review.

This Data Processing Agreement ("DPA") forms part of the [Master Services Agreement / Subscription Agreement] (the "Principal Agreement") between **[Controller — legal name, address]** ("Controller") and **[Processor — legal name, address]** ("Processor").

## 1. Definitions
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in applicable data protection law ("Data Protection Laws").

## 2. Roles and scope
The Processor processes Personal Data only on behalf of, and on the documented instructions of, the Controller, for the purposes described in **Annex A**. The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.

## 3. Processor obligations
The Processor shall:
- Process Personal Data only per the Controller's documented instructions, including for transfers, unless required by law (in which case it notifies the Controller where lawful).
- Ensure persons authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see **Annex B**).
- Assist the Controller in responding to Data Subject requests and in meeting its security, breach-notification, and impact-assessment obligations.
- Notify the Controller without undue delay (and within [72 hours]) after becoming aware of a Personal Data Breach.
- At the Controller's choice, delete or return all Personal Data at the end of the services and delete existing copies unless retention is legally required.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits.

## 4. Subprocessors
The Controller authorizes the Processor to engage the subprocessors listed in **Annex C**. The Processor shall: impose data-protection obligations no less protective than this DPA on each subprocessor; give the Controller [notice / a mechanism to object] to changes; and remain liable for its subprocessors' acts and omissions.

## 5. International transfers
Where Personal Data is transferred to a country without an adequacy decision, the Parties shall rely on an approved transfer mechanism (e.g. Standard Contractual Clauses), incorporated by reference in **Annex D**.

## 6. Liability and term
Liability is governed by the Principal Agreement. This DPA continues for as long as the Processor processes Personal Data on the Controller's behalf.

---
### Annex A — Details of processing
Subject matter; duration; nature and purpose; types of Personal Data; categories of Data Subjects: _[complete]_.

### Annex B — Technical and organizational measures
_[List security controls — typically mirrors your ISO 27001 / SOC 2 controls: access control, encryption in transit and at rest, logging, backups, vulnerability management, personnel security, etc.]_

### Annex C — Approved subprocessors
| Subprocessor | Service | Location |
|---|---|---|
| [name] | [service] | [country] |

### Annex D — Transfer mechanism
_[SCCs module / other mechanism and any required details.]_
