DPA Draft
Draft from assets/template.docx. Preserve its structure and formatting while tailoring it to the actual processing relationship. Do not recreate the agreement from prose or substitute a public form.
Operating rules
- Treat the bundled template as the sole drafting base. Work on a copy and never overwrite it.
- Determine facts before selecting clauses. Do not assume that every SaaS vendor is a processor or that every international relationship requires SCCs.
- Use plain-language questions in small groups. Reuse facts already supplied; do not ask twice.
- Distinguish facts, recommended positions, and user-approved positions. Mark unresolved deal facts
[TBD]; never invent them.
- Verify current law and official transfer instruments when the answer turns on a changing legal requirement.
- Treat the current Common Paper DPA only as an issue-spotting comparator. Do not copy its language or replace the bundled template.
- Escalate unusual regulated data, uncertain role allocation, conflicting instructions, or a requested legal position that may not satisfy an applicable legal floor.
Intake
Collect enough information to complete every applicable body provision and schedule.
1. Parties and underlying agreement
Ask for:
- Company and customer legal names, addresses if needed, effective date, and signatories.
- The underlying MSA, SaaS agreement, order form, or other agreement and its defined terms.
- Whether the DPA should be incorporated into, attached to, or stand apart from that agreement.
- The governing law and order-of-precedence structure in the underlying agreement.
- Existing data-use, deidentification, analytics, service-improvement, or AI/ML permissions that the DPA must match.
If the underlying agreement is available, read the relevant privacy, security, confidentiality, data-use, incident, termination, indemnity, liability, and precedence provisions before drafting. If it is unavailable, identify every alignment item that remains conditional.
2. Factual roles and instructions
Identify roles from conduct, not labels:
- Controller to processor: Customer determines the purposes and essential means; Company processes on documented instructions.
- Processor to subprocessor: Customer processes for another controller and appoints Company in the processing chain.
- Independent or joint controller activity: Do not force controller activity into processor language. Define or separately document it.
Capture the permitted instructions, service purpose, any legally required processing outside instructions, and the escalation process for an instruction that appears unlawful. Confirm which party receives data-subject requests and regulator inquiries.
3. Processing description
Populate the processing schedule with:
- Subject matter, nature, purpose, and duration.
- Categories of data subjects.
- Categories of personal data and any sensitive, special-category, criminal, biometric, financial, health, precise-location, or children's data.
- Processing operations, systems, locations, transfer frequency, and access model.
- Retention period and deletion triggers.
- Controller rights and obligations.
Use a tailored description. “Providing the services” alone is insufficient when the actual processing can be described more precisely.
For AI- or ML-enabled services, also map:
- each product feature and processing channel, including portal, API, messaging,
integrations, batch processing, and human review;
- whether outputs support or make decisions, who validates them, and who handles
challenges or legally significant consequences;
- prompts and other Input, Output, source records, feedback, usage telemetry,
performance and evaluation metrics, embeddings, retrieval context, caches,
fine-tunes, and other derived data;
- retention and deletion by artifact rather than one undifferentiated period;
- model providers and other subprocessors, their locations, retention, and data-
use restrictions; and
- customer notices, consents, lawful-basis responsibilities, opt-outs, and other
instructions relevant to those uses.
Separate permission to provide the service, bounded operational monitoring,
customer-specific improvement, global product improvement, and model training.
Do not infer one permission from another. A no-training position should not
accidentally prohibit necessary inference or approved use of non-content
performance metrics, while “service improvement” or “usage data” language must
not silently authorize training on Input, Output, retrieval context, or personal
data.
4. Applicable regimes and transfer corridors
Determine the actual people, establishments, data locations, access locations, and transfer routes. Consider:
- EU GDPR and EEA transfers.
- UK GDPR and UK transfers.
- Swiss FADP and Swiss transfers.
- CCPA/CPRA and other applicable US state processor-contract requirements.
- Sectoral requirements such as HIPAA, GLBA, FERPA, COPPA, or another specialized regime.
Do not add jurisdictions merely because the template offers them. Do not treat a generic DPA as a substitute for a required BAA or other sector-specific addendum.
For a restricted transfer, identify the available lawful mechanism before selecting contract language. If SCCs are used, select the module that matches the factual chain—commonly Module 2 for controller-to-processor or Module 3 for processor-to-processor—and complete all selections and annexes. Address the UK Addendum or other current UK mechanism and Swiss adaptations where applicable. Record whether adequacy or a verified Data Privacy Framework certification applies, and whether a transfer assessment or supplementary measures are required. Never claim or rely on a certification without verification.
5. Subprocessors
Ask for the current list or URL, processing locations, change-notice period, and operational approval model.
Provider-side baseline:
- General written authorization.
- Current list plus advance notice of intended additions or replacements.
- Objection limited to reasonable data-protection grounds.
- Good-faith resolution, with a practical termination or service-change path if unresolved.
- Written flow-down of materially equivalent data-protection duties.
- Company remains responsible for its subprocessors to the extent required by law and the negotiated agreement.
Use specific prior written approval only when required by the facts, regulation, or approved deal posture; confirm the business can operate it.
6. Security and incidents
Describe only controls the Company actually maintains. Use a complete security
schedule, incorporated exhibit, or stable security-document URL, addressing as
applicable access, encryption, monitoring, vulnerability and incident response,
physical/network security, resilience, data lifecycle, training, and vendor
oversight.
For SCC annexes, provide sufficiently specific technical and organizational measures; do not rely only on “appropriate security.” Reconcile every statement with actual practices, certifications, and the underlying agreement.
Set the incident clause by operational capability:
- Define the trigger precisely, distinguishing an attempted event from a confirmed personal-data breach where appropriate.
- Use “without undue delay” and any agreed outside period only if operations can meet it.
- Require known details, affected data and people, likely consequences, mitigation, contact information, rolling updates, evidence preservation, and reasonable cooperation.
- Allocate regulatory and data-subject notifications consistently with the parties' roles; do not let the processor notify externally without controller direction unless law requires it.
7. Assistance, audits, and cooperation
Cover reasonable assistance with data-subject requests, security inquiries, regulator consultations, DPIAs, transfer assessments, and breach response, taking account of the nature of processing and information available to the processor.
Provider-side audit baseline:
- Supply current independent reports or certifications first.
- Permit targeted written follow-up where those materials are insufficient.
- Limit routine audits by frequency, scope, notice, confidentiality, non-interference, and cost allocation.
- Preserve broader access when an authority requires it or a material incident or substantiated compliance concern warrants it.
- Do not promise customer-directed penetration testing against production systems.
State any fees for extraordinary assistance without charging for work the processor must perform to cure its own breach or noncompliance.
8. Return, deletion, and survival
Specify whether data is returned, deleted, or both at termination or instruction; the completion period; certification on request; and transition mechanics. Include narrow backups, logs, legal-hold, and mandatory-retention exceptions, with continued protection and no further use. Align the clause with actual retention architecture and the underlying agreement. Continue the DPA while Company processes covered personal data.
9. US state privacy terms
Where Company acts as a CCPA service provider or contractor, include the required business-purpose scope and restrictions applicable to the relationship, including restrictions on selling or sharing, use outside the specified purposes or direct business relationship, and combining data except as permitted. Include appropriate confidentiality, equivalent-level protection, audit or monitoring rights, remediation, and notice if Company can no longer comply. Address any applicable US state processor-contract requirements without assuming one California clause satisfies every state.
10. Liability, indemnity, and precedence
Choose intentionally among:
- DPA claims inside the underlying agreement's general cap.
- A defined, higher privacy or security super-cap.
- A separately negotiated fixed cap.
- An express carveout approved by the user.
State the relationship between caps and claim categories clearly; avoid double counting and accidental uncapped exposure. Align any DPA indemnity with the underlying agreement, or use a standalone indemnity only when necessary and approved. Confirm defense control, covered third-party claims, exclusions, notice, cooperation, and whether the indemnity is subject to the selected cap.
Provide that the DPA controls conflicts only to the extent concerning covered personal-data processing. Preserve any mandatory precedence of SCCs or other transfer instruments. Avoid broadly displacing unrelated commercial terms in the underlying agreement.
Complete-coverage gate
Before editing or delivering an edit plan, make a private coverage ledger for
every cover-page field, body section, subsection, schedule, annex, and option in
the template. Mark each item edit, retain, delete, not applicable, or
open, with its dependency and reason. Do not silently omit assistance, audit,
deletion, liability, precedence, or conflict provisions merely because the main
commercial changes sit elsewhere.
When an edit makes another provision inaccurate or inert, include every
conforming edit in the plan. In particular, deleting or disabling a transfer
schedule requires checking all definitions, precedence clauses, liability
carveouts, annex references, and survival provisions that point to it. Run the
same dependency check for changes to incident timing, subprocessors, deletion,
AI/ML permissions, and the underlying-agreement cross-references.
An unknown fact or required local-law approval does not justify an unusable
placeholder where the drafting choice is otherwise known. Provide complete
conditional language for each viable option, label the assumption and approval
gate, and recommend which option should become operative after confirmation.
Use a bare [TBD] only for a value that cannot responsibly be bounded or for
language that genuinely requires jurisdiction-specific advice. Never present
conditional local-law language as verified law without checking an official
source or obtaining the required local-law review.
Confirm the drafting plan
Before editing, summarize and obtain confirmation of roles; processing and
sensitive-data scope; applicable laws, transfers, and SCC module; subprocessors;
security and incident timing; audits and assistance; return/deletion; the AI/ML
data-use map above; US or sectoral terms; liability, indemnity, term, precedence;
and every unresolved fact or underlying-agreement assumption.
Build the DOCX deterministically
- Copy
assets/template.docx to a new working file.
- Read the entire copy, including cover-page tables, body text, schedules, headers, footers, comments, and existing revisions.
- Create an edit plan keyed to exact text and structural anchors. Include the complete replacement text, rationale, dependencies, and any required table-cell edit.
- Reconcile the edit plan against the complete-coverage ledger. Every template item must have a disposition, and every removed or changed mechanism must have all dependent references conformed.
- Resolve every mutually exclusive option. Remove unused options and all drafting instructions without deleting adjacent substantive text.
- Apply edits to the working copy only. If the editor uses block IDs, use current
IDs, one operation per block, complete replacement text, and strict
validation. Re-extract after any intervening change; never reuse stale IDs.
- If no deterministic DOCX editor is available, or the available editor cannot
safely modify required content, stop and provide the completed intake and edit
plan rather than flattening or omitting content. State that no DOCX was
modified and identify the unavailable capability.
- Produce a clean DOCX by default. Produce a tracked comparison only if requested.
Do not regenerate the document from Markdown, paste it into a new blank DOCX, or normalize styles globally.
Deliverables
Provide the clean DPA, a concise memo covering selected positions, assumptions,
unresolved facts, and approvals, plus a verification summary. If step 7
triggered, provide instead the completed intake, exact-anchor edit plan, and a
limitation note stating that the bundled template remains unmodified.
Final checks
Before delivery:
- Re-read the output and compare it with the source copy and confirmed drafting plan.
- Confirm correct party names, roles, effective date, defined terms, and underlying-agreement references.
- Confirm the processing schedule is complete and consistent with the operative clauses.
- Confirm every retained jurisdictional part applies and every required transfer annex is present and completed.
- Confirm the SCC module, parties, governing-law selections, annexes, UK/Swiss modifications, and TOMs align.
- Confirm subprocessor, security, incident, audit, assistance, deletion, risk
allocation, precedence, and the AI/ML data-use map are coherent with the
underlying agreement and operationally supportable.
- Search for drafting notes, option labels, bracketed guidance, duplicate alternatives, unresolved placeholders, client-specific residue, comments, and unintended tracked changes. Disclose any approved
[TBD]; otherwise remove all such artifacts.
- Validate and reopen the DOCX. When the host can render, inspect every page;
otherwise use text readback and disclose the unavailable visual check.
- Never describe the draft as final or execution-ready while material facts, transfer details, schedules, or required approvals remain unresolved.
1---2name: dpa-draft3description: Draft a provider-side Data Processing Agreement from the bundled DOCX template after structured intake covering party roles, processing details, security, subprocessors, incidents, audits, deletion, international transfers, US privacy terms, and risk allocation. Use when a service provider or vendor asks to draft, prepare, create, or customize its DPA or privacy addendum. Do not use to draft customer-side paper, review counterparty paper, or negotiate an existing DPA.4license: MIT5---67# DPA Draft89Draft from `assets/template.docx`. Preserve its structure and formatting while tailoring it to the actual processing relationship. Do not recreate the agreement from prose or substitute a public form.1011## Operating rules1213- Treat the bundled template as the sole drafting base. Work on a copy and never overwrite it.14- Determine facts before selecting clauses. Do not assume that every SaaS vendor is a processor or that every international relationship requires SCCs.15- Use plain-language questions in small groups. Reuse facts already supplied; do not ask twice.16- Distinguish facts, recommended positions, and user-approved positions. Mark unresolved deal facts `[TBD]`; never invent them.17- Verify current law and official transfer instruments when the answer turns on a changing legal requirement.18- Treat the current Common Paper DPA only as an issue-spotting comparator. Do not copy its language or replace the bundled template.19- Escalate unusual regulated data, uncertain role allocation, conflicting instructions, or a requested legal position that may not satisfy an applicable legal floor.2021## Intake2223Collect enough information to complete every applicable body provision and schedule.2425### 1. Parties and underlying agreement2627Ask for:2829- Company and customer legal names, addresses if needed, effective date, and signatories.30- The underlying MSA, SaaS agreement, order form, or other agreement and its defined terms.31- Whether the DPA should be incorporated into, attached to, or stand apart from that agreement.32- The governing law and order-of-precedence structure in the underlying agreement.33- Existing data-use, deidentification, analytics, service-improvement, or AI/ML permissions that the DPA must match.3435If the underlying agreement is available, read the relevant privacy, security, confidentiality, data-use, incident, termination, indemnity, liability, and precedence provisions before drafting. If it is unavailable, identify every alignment item that remains conditional.3637### 2. Factual roles and instructions3839Identify roles from conduct, not labels:4041- **Controller to processor:** Customer determines the purposes and essential means; Company processes on documented instructions.42- **Processor to subprocessor:** Customer processes for another controller and appoints Company in the processing chain.43- **Independent or joint controller activity:** Do not force controller activity into processor language. Define or separately document it.4445Capture the permitted instructions, service purpose, any legally required processing outside instructions, and the escalation process for an instruction that appears unlawful. Confirm which party receives data-subject requests and regulator inquiries.4647### 3. Processing description4849Populate the processing schedule with:5051- Subject matter, nature, purpose, and duration.52- Categories of data subjects.53- Categories of personal data and any sensitive, special-category, criminal, biometric, financial, health, precise-location, or children's data.54- Processing operations, systems, locations, transfer frequency, and access model.55- Retention period and deletion triggers.56- Controller rights and obligations.5758Use a tailored description. “Providing the services” alone is insufficient when the actual processing can be described more precisely.5960For AI- or ML-enabled services, also map:6162- each product feature and processing channel, including portal, API, messaging,63 integrations, batch processing, and human review;64- whether outputs support or make decisions, who validates them, and who handles65 challenges or legally significant consequences;66- prompts and other Input, Output, source records, feedback, usage telemetry,67 performance and evaluation metrics, embeddings, retrieval context, caches,68 fine-tunes, and other derived data;69- retention and deletion by artifact rather than one undifferentiated period;70- model providers and other subprocessors, their locations, retention, and data-71 use restrictions; and72- customer notices, consents, lawful-basis responsibilities, opt-outs, and other73 instructions relevant to those uses.7475Separate permission to provide the service, bounded operational monitoring,76customer-specific improvement, global product improvement, and model training.77Do not infer one permission from another. A no-training position should not78accidentally prohibit necessary inference or approved use of non-content79performance metrics, while “service improvement” or “usage data” language must80not silently authorize training on Input, Output, retrieval context, or personal81data.8283### 4. Applicable regimes and transfer corridors8485Determine the actual people, establishments, data locations, access locations, and transfer routes. Consider:8687- EU GDPR and EEA transfers.88- UK GDPR and UK transfers.89- Swiss FADP and Swiss transfers.90- CCPA/CPRA and other applicable US state processor-contract requirements.91- Sectoral requirements such as HIPAA, GLBA, FERPA, COPPA, or another specialized regime.9293Do not add jurisdictions merely because the template offers them. Do not treat a generic DPA as a substitute for a required BAA or other sector-specific addendum.9495For a restricted transfer, identify the available lawful mechanism before selecting contract language. If SCCs are used, select the module that matches the factual chain—commonly Module 2 for controller-to-processor or Module 3 for processor-to-processor—and complete all selections and annexes. Address the UK Addendum or other current UK mechanism and Swiss adaptations where applicable. Record whether adequacy or a verified Data Privacy Framework certification applies, and whether a transfer assessment or supplementary measures are required. Never claim or rely on a certification without verification.9697### 5. Subprocessors9899Ask for the current list or URL, processing locations, change-notice period, and operational approval model.100101Provider-side baseline:102103- General written authorization.104- Current list plus advance notice of intended additions or replacements.105- Objection limited to reasonable data-protection grounds.106- Good-faith resolution, with a practical termination or service-change path if unresolved.107- Written flow-down of materially equivalent data-protection duties.108- Company remains responsible for its subprocessors to the extent required by law and the negotiated agreement.109110Use specific prior written approval only when required by the facts, regulation, or approved deal posture; confirm the business can operate it.111112### 6. Security and incidents113114Describe only controls the Company actually maintains. Use a complete security115schedule, incorporated exhibit, or stable security-document URL, addressing as116applicable access, encryption, monitoring, vulnerability and incident response,117physical/network security, resilience, data lifecycle, training, and vendor118oversight.119120For SCC annexes, provide sufficiently specific technical and organizational measures; do not rely only on “appropriate security.” Reconcile every statement with actual practices, certifications, and the underlying agreement.121122Set the incident clause by operational capability:123124- Define the trigger precisely, distinguishing an attempted event from a confirmed personal-data breach where appropriate.125- Use “without undue delay” and any agreed outside period only if operations can meet it.126- Require known details, affected data and people, likely consequences, mitigation, contact information, rolling updates, evidence preservation, and reasonable cooperation.127- Allocate regulatory and data-subject notifications consistently with the parties' roles; do not let the processor notify externally without controller direction unless law requires it.128129### 7. Assistance, audits, and cooperation130131Cover reasonable assistance with data-subject requests, security inquiries, regulator consultations, DPIAs, transfer assessments, and breach response, taking account of the nature of processing and information available to the processor.132133Provider-side audit baseline:134135- Supply current independent reports or certifications first.136- Permit targeted written follow-up where those materials are insufficient.137- Limit routine audits by frequency, scope, notice, confidentiality, non-interference, and cost allocation.138- Preserve broader access when an authority requires it or a material incident or substantiated compliance concern warrants it.139- Do not promise customer-directed penetration testing against production systems.140141State any fees for extraordinary assistance without charging for work the processor must perform to cure its own breach or noncompliance.142143### 8. Return, deletion, and survival144145Specify whether data is returned, deleted, or both at termination or instruction; the completion period; certification on request; and transition mechanics. Include narrow backups, logs, legal-hold, and mandatory-retention exceptions, with continued protection and no further use. Align the clause with actual retention architecture and the underlying agreement. Continue the DPA while Company processes covered personal data.146147### 9. US state privacy terms148149Where Company acts as a CCPA service provider or contractor, include the required business-purpose scope and restrictions applicable to the relationship, including restrictions on selling or sharing, use outside the specified purposes or direct business relationship, and combining data except as permitted. Include appropriate confidentiality, equivalent-level protection, audit or monitoring rights, remediation, and notice if Company can no longer comply. Address any applicable US state processor-contract requirements without assuming one California clause satisfies every state.150151### 10. Liability, indemnity, and precedence152153Choose intentionally among:154155- DPA claims inside the underlying agreement's general cap.156- A defined, higher privacy or security super-cap.157- A separately negotiated fixed cap.158- An express carveout approved by the user.159160State the relationship between caps and claim categories clearly; avoid double counting and accidental uncapped exposure. Align any DPA indemnity with the underlying agreement, or use a standalone indemnity only when necessary and approved. Confirm defense control, covered third-party claims, exclusions, notice, cooperation, and whether the indemnity is subject to the selected cap.161162Provide that the DPA controls conflicts only to the extent concerning covered personal-data processing. Preserve any mandatory precedence of SCCs or other transfer instruments. Avoid broadly displacing unrelated commercial terms in the underlying agreement.163164## Complete-coverage gate165166Before editing or delivering an edit plan, make a private coverage ledger for167every cover-page field, body section, subsection, schedule, annex, and option in168the template. Mark each item `edit`, `retain`, `delete`, `not applicable`, or169`open`, with its dependency and reason. Do not silently omit assistance, audit,170deletion, liability, precedence, or conflict provisions merely because the main171commercial changes sit elsewhere.172173When an edit makes another provision inaccurate or inert, include every174conforming edit in the plan. In particular, deleting or disabling a transfer175schedule requires checking all definitions, precedence clauses, liability176carveouts, annex references, and survival provisions that point to it. Run the177same dependency check for changes to incident timing, subprocessors, deletion,178AI/ML permissions, and the underlying-agreement cross-references.179180An unknown fact or required local-law approval does not justify an unusable181placeholder where the drafting choice is otherwise known. Provide complete182conditional language for each viable option, label the assumption and approval183gate, and recommend which option should become operative after confirmation.184Use a bare `[TBD]` only for a value that cannot responsibly be bounded or for185language that genuinely requires jurisdiction-specific advice. Never present186conditional local-law language as verified law without checking an official187source or obtaining the required local-law review.188189## Confirm the drafting plan190191Before editing, summarize and obtain confirmation of roles; processing and192sensitive-data scope; applicable laws, transfers, and SCC module; subprocessors;193security and incident timing; audits and assistance; return/deletion; the AI/ML194data-use map above; US or sectoral terms; liability, indemnity, term, precedence;195and every unresolved fact or underlying-agreement assumption.196197## Build the DOCX deterministically1981991. Copy `assets/template.docx` to a new working file.2002. Read the entire copy, including cover-page tables, body text, schedules, headers, footers, comments, and existing revisions.2013. Create an edit plan keyed to exact text and structural anchors. Include the complete replacement text, rationale, dependencies, and any required table-cell edit.2024. Reconcile the edit plan against the complete-coverage ledger. Every template item must have a disposition, and every removed or changed mechanism must have all dependent references conformed.2035. Resolve every mutually exclusive option. Remove unused options and all drafting instructions without deleting adjacent substantive text.2046. Apply edits to the working copy only. If the editor uses block IDs, use current205 IDs, one operation per block, complete replacement text, and strict206 validation. Re-extract after any intervening change; never reuse stale IDs.2077. If no deterministic DOCX editor is available, or the available editor cannot208 safely modify required content, stop and provide the completed intake and edit209 plan rather than flattening or omitting content. State that no DOCX was210 modified and identify the unavailable capability.2118. Produce a clean DOCX by default. Produce a tracked comparison only if requested.212213Do not regenerate the document from Markdown, paste it into a new blank DOCX, or normalize styles globally.214215## Deliverables216217Provide the clean DPA, a concise memo covering selected positions, assumptions,218unresolved facts, and approvals, plus a verification summary. If step 7219triggered, provide instead the completed intake, exact-anchor edit plan, and a220limitation note stating that the bundled template remains unmodified.221222## Final checks223224Before delivery:225226- Re-read the output and compare it with the source copy and confirmed drafting plan.227- Confirm correct party names, roles, effective date, defined terms, and underlying-agreement references.228- Confirm the processing schedule is complete and consistent with the operative clauses.229- Confirm every retained jurisdictional part applies and every required transfer annex is present and completed.230- Confirm the SCC module, parties, governing-law selections, annexes, UK/Swiss modifications, and TOMs align.231- Confirm subprocessor, security, incident, audit, assistance, deletion, risk232 allocation, precedence, and the AI/ML data-use map are coherent with the233 underlying agreement and operationally supportable.234- Search for drafting notes, option labels, bracketed guidance, duplicate alternatives, unresolved placeholders, client-specific residue, comments, and unintended tracked changes. Disclose any approved `[TBD]`; otherwise remove all such artifacts.235- Validate and reopen the DOCX. When the host can render, inspect every page;236 otherwise use text readback and disclose the unavailable visual check.237- Never describe the draft as final or execution-ready while material facts, transfer details, schedules, or required approvals remain unresolved.