# Data Processing Agreement (DPA)

> Skeleton only – the GDPR Art.28-required contract between controller
> and processor. Structural format, not legal advice – counsel review
> required before signing.

## Parties

| Field | Controller | Processor |
|-------|------------|-----------|
| Legal name | [entity] | [entity] |
| Address | | |
| DPO / contact | | |

**Effective date**: YYYY-MM-DD
**Underlying agreement**: [main contract ref]

## 1. Subject matter & duration

Processing of personal data for [service description], for the
duration of the underlying agreement.

## 2. Processing details

| Item | Detail |
|------|--------|
| Nature / purpose | [what processing and why] |
| Duration | [term] |
| Data categories | [names, emails, usage, ...] |
| Data subjects | [customers, employees, ...] |
| Special categories | [none / list with Art.9 basis] |

## 3. Processor obligations

- Process only on documented instructions (Art.28(3)(a))
- Confidentiality undertakings for personnel
- Security measures per Annex [N] (TOMs)
- Sub-processors: [prior authorization / list + change notice]
- Assist with data-subject rights requests
- Assist with DPIAs and regulator consultations
- Delete or return data at end of service
- Allow and contribute to audits
- Notify personal data breaches without undue delay (<= NN h)

## 4. Sub-processors

Current list: [annex link]. Changes notified N days in advance;
controller may object on reasonable grounds.

## 5. International transfers

- Locations: [countries]
- Safeguards: [SCCs / adequacy / BCRs]

## 6. Liability & term

[Liability cap / allocation; survives termination for data held.]

## Signatures

| Controller | Processor |
|------------|-----------|
| @name, [title] | @name, [title] |
| Date: YYYY-MM-DD | Date: YYYY-MM-DD |

## Annex: Technical & Organizational Measures (TOMs)

- [access control / encryption / backup / availability measures]
- [incident response / personnel training / physical security]
