Review draft — not legal advice

Data processing terms prepared for counsel and customer review.

This page is a commercial-readiness outline, not an executed agreement. Final language must reflect the actual engagement, jurisdictions, providers, and legal advice.

Required schedules

The final DPA should make the processing boundary inspectable.

01

Roles and instructions

Identify controller and processor roles, the documented instructions, and the services covered by the agreement.

02

Data schedule

List data subjects, categories, purposes, processing activities, duration, and prohibited data.

03

Security measures

Describe environment isolation, access control, encryption in transit, artifact handling, incident notification, and deletion.

04

Subprocessors and transfers

Attach the approved provider list, change-notice mechanism, transfer basis, and objection process.

05

Rights and assistance

Define support for data-subject requests, audits, impact assessments, return, and deletion.