Legal
Data processing addendum.
The contract term that governs personal data we process on your behalf.
What the addendum will cover
- The parties, and which is controller and which is processor for each activity
- Subject matter, duration, nature and purpose of the processing
- Categories of data subject and categories of personal data
- The documented instructions the processor acts on, and the limits of them
- Confidentiality obligations on anyone with access
- Technical and organisational measures, referencing the security page
- Sub-processors: the authorisation model, the current list, and notice of change
- Assistance with data-subject rights requests, and the response window
- Personal data breach notification — trigger, timescale and content
- Audit and information rights, and what evidence satisfies them
- International transfers, and the safeguard relied on for each
- Deletion or return of data at the end of the contract, and the retention window
- Liability, and how it interacts with the main agreement
Why it is not written yet
A DPA names a legal entity, and the registered name, address and company registration are still pending. An addendum signed by an unnamed party is not worth the file it is in. It also has to list sub-processors accurately, and that list is not published either.
Both are being resolved. Until they are, this page says so rather than carrying a template downloaded from somewhere else with a name dropped into it — which is the common practice, and which fails the first time anyone reads it properly.
If you need one now
Procurement teams frequently need a DPA before a trial, not after. If that is your position, say so when you get in touch and it will be treated as a blocker rather than a formality.