Data processing agreement (DPA) template
Added to a service contract: instructions, security, sub-processors, breach notice, audits and deletion of data. A sample contract you can read in full, edit in QuoteBill and sign online with a secure link.
Sample — review with a lawyer · Simple electronic signature with an audit trail

Who it is for
For a business that has another company handle personal data for it, or a service provider that does so, and wants both sides’ duties written down alongside the service contract.
A sample only. Data protection law differs by country, so check what yours requires and add any terms it demands. Use it alongside a service contract, not on its own.
What it covers
15 clauses, in this order. Each one is in the sample text below, and you can edit, remove or add clauses before you send.
1. Purpose and relationship to the service contract
This agreement is added to a service contract named in a blank and covers the personal data the Processor handles for the Controller. On personal data it prevails; on all else the service contract applies.
2. Terms used
Plain definitions of personal data, processing, controller, processor, sub-processor and personal data breach. Other terms mean what the law that applies to the Controller says.
3. The processing
Blanks for the purpose, nature of the processing, types of data and groups of people, plus the duration and a line for especially sensitive data. The Processor uses the data only for this.
4. Instructions
The Processor acts only on the Controller’s documented instructions and never for its own purposes. It warns the Controller if an instruction seems unlawful and may pause it until confirmed.
5. Confidentiality of personnel
Only people who need the data for the services may reach it, and they are bound by confidentiality that continues after their work for the Processor ends.
6. Security measures
Appropriate technical and organisational measures, described in a blank or an attached description, reviewed regularly and never weakened. The data is kept apart from other customers’ data where possible.
7. Sub-processors
A general authorisation with a blank listing those in use. New or replaced ones are announced a set number of days ahead and the Controller may object. Each is bound to equal duties and the Processor answers for it.
8. Rights of the people concerned and other help
The Processor helps the Controller answer people who use their rights and passes direct requests on. It also gives the information the Controller needs for its own duties; extra help may be charged.
9. Personal data breaches
The Processor reports a breach without undue delay and within a set number of hours, says what is known, limits the harm and helps with notices. The Controller decides whom to notify.
10. Transfers to other countries
A blank for where the data is stored and accessed. Moving it to another country needs the Controller’s instruction and the law’s permission, with safeguards first where that law requires them.
11. Audits and information
The Processor supplies the information needed to check compliance. If that is not enough, an audit is possible with notice, in business hours and at set intervals; each side bears its costs unless a serious breach is found.
12. Return and deletion
At the end the Processor returns or deletes all personal data, as the Controller chooses, within a set number of days, copies at sub-processors included, unless the law requires it to keep some. It confirms deletion on request.
13. Data protection law that applies
Data protection law differs by country. A blank names the law that applies. Each party checks what that law requires of such an agreement, extra terms are added in writing, and nothing here gives less protection.
14. Liability, term and changes
Liability follows the liability clause of the service contract, without limiting what the law does not allow to be limited. The agreement lasts while data is processed; changes need both parties’ agreement.
15. Governing law and disputes
The law you name applies. The sides first try to settle a dispute in good faith, and otherwise the courts you name decide.
There is no price schedule: this agreement involves no payment.
The sample text
The whole sample, as QuoteBill starts it. Text in double square brackets, like [[10]], is a blank to fill in or check. A figure or time such as [[10]] that you leave as it is is used as shown when you send; a blank that needs your own words must be filled first. The clause text is written in English, Korean, Japanese and German; in other languages a contract starts in English for you to translate.
Read the sample text
Data Processing Agreement
Parties: Controller · Processor
1. Purpose and relationship to the service contract
This agreement sets out how the Processor handles personal data on behalf of the Controller. It is added to the following contract between the parties (the service contract) and applies to the processing of personal data that the Processor carries out for the Controller in providing the services under it. Service contract: [[Name and date of the service contract]]
If this agreement and the service contract conflict as far as personal data is concerned, this agreement prevails. In all other respects the service contract applies unchanged.
2. Terms used
Personal data means information about an identified or identifiable person. Processing means any operation on personal data, such as collecting, storing, using, sending or deleting it. The Controller is the party that decides why and how the personal data is processed; the Processor is the party that processes it on the Controller’s behalf. The people concerned are the people the personal data is about.
A sub-processor is a third party that the Processor engages to carry out part of the processing. A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss or alteration of, or disclosure of or access to, the personal data. Other terms that this agreement uses and that the law applying to the Controller defines have the meaning that law gives them.
3. The processing
The Processor processes the personal data only for the following purpose and in the following way:
Subject and purpose: [[What the processing is for, e.g. hosting the Controller’s customer database]]
Nature of the processing: [[e.g. storage, backup, access for support]]
Types of personal data: [[e.g. names, email addresses, order history]]
Groups of people the data is about: [[e.g. customers, employees]]
Duration: as long as the service contract runs, and afterwards as the clause on return and deletion says.
If the data includes information that the law treats as especially sensitive, the Controller has told the Processor: [[none / the kinds of sensitive data]]
4. Instructions
The Processor processes personal data only on the documented instructions of the Controller. Documented instructions are this agreement, the service contract and the Controller’s later instructions in writing or in electronic form within the scope of the services. The Processor does not process the data for its own purposes.
The Processor tells the Controller without undue delay if it believes an instruction breaches the law that applies, and may pause carrying it out until the Controller confirms or changes it. If the law requires the Processor to process the data in another way, it tells the Controller beforehand unless the law forbids that.
5. Confidentiality of personnel
The Processor allows only people who need the personal data for the services to access it, and makes sure that they are bound by a duty of confidentiality, by contract or by law. This duty continues after their work for the Processor ends.
6. Security measures
The Processor takes appropriate technical and organisational measures to protect the personal data against accidental or unlawful destruction, loss, alteration, disclosure and access, taking into account the risks, the state of the art and the cost. The measures include at least: [[Description of the measures, e.g. access control, encryption, backups, logging, staff training, or a reference to an attached security description]]
The Processor reviews the measures regularly and may change them as long as the level of protection does not fall. It keeps the Controller’s personal data separate from other customers’ data as far as the services allow.
7. Sub-processors
The Controller gives the Processor a general authorisation to engage sub-processors. The sub-processors in use at the effective date are: [[Names, locations and tasks of the sub-processors, or none]]
The Processor tells the Controller in writing or in electronic form at least [[30]] days before it adds or replaces a sub-processor. Within that time the Controller may object on reasonable grounds related to data protection; the parties then look for a solution in good faith, and if none is found the Controller may end the affected services.
The Processor binds each sub-processor to data protection duties that protect no less than this agreement and remains responsible to the Controller for what the sub-processor does.
8. Rights of the people concerned and other help
Taking into account the nature of the processing, the Processor helps the Controller, by suitable technical and organisational measures, to answer requests from people who use the rights the law gives them over their data, such as access, correction or deletion. If the Processor receives such a request directly, it passes it to the Controller without undue delay and does not answer it itself unless the Controller instructs it to.
The Processor also gives the Controller the information and help it reasonably needs for its own duties under the law that applies, such as security, notifying breaches, assessing risks to the people concerned and consulting an authority. For help that goes beyond what is reasonable for the services, the Processor may charge at the rates of the service contract or at rates agreed in advance: [[included / charged at the rates of the service contract]]
9. Personal data breaches
The Processor tells the Controller without undue delay, and in any case within [[48]] hours, after it becomes aware of a personal data breach affecting the Controller’s personal data. The notice states, as far as known, what happened, the kinds and approximate number of people and records concerned, the likely consequences, and what the Processor has done and will do. If not everything is known yet, the Processor gives the rest in stages.
The Processor takes reasonable steps to contain the breach and limit harm, and helps the Controller with any notification the law requires. The Controller decides whether and how to notify authorities and the people concerned, unless the law requires otherwise.
10. Transfers to other countries
The Processor processes the personal data only in the following places: [[Countries or regions where the data is stored and accessed]]
It transfers the data to another country, or allows access from there, only on the Controller’s instructions or with its approval, and only where the law that applies to the Controller allows it. Where that law requires safeguards for such a transfer, the parties put them in place and record them in writing or in electronic form before the transfer takes place.
11. Audits and information
The Processor gives the Controller the information it reasonably needs to check that this agreement is kept, for example answers to written questions and relevant security reports or certificates it holds.
If that is not enough, the Controller, or an auditor it appoints who is bound to confidentiality, may carry out an audit, no more than once in [[12]] months unless a breach has occurred or the law requires more, after at least [[30]] days’ notice, during business hours and without unreasonably disturbing the Processor or putting other customers’ data at risk. Each party bears its own costs of an audit; if the audit shows a material breach by the Processor, the Processor also bears the reasonable cost of the audit.
12. Return and deletion
When the services end, or earlier on the Controller’s request in writing or in electronic form, the Processor, at the Controller’s choice, returns all personal data in a commonly used format or deletes it, within [[30]] days, and deletes existing copies, including those held by its sub-processors, unless the law that applies requires it to keep some of the data. Data that must be kept stays protected under this agreement and is used only for the purpose the law requires. On request the Processor confirms the deletion in writing or in electronic form.
13. Data protection law that applies
Data protection law differs by country. Each party complies with the data protection law that applies to it in connection with the services. The law that applies to the Controller’s processing is: [[Data protection law or laws that apply, e.g. the law of the country of the Controller]]
Each party is responsible for checking what the data protection law that applies to it requires of an agreement like this one. If that law requires terms that this agreement does not contain, or terms that differ from it, the parties add or change them in writing or in electronic form, and this agreement then applies together with them. Nothing in this agreement is meant to give less protection than that law requires.
14. Liability, term and changes
Each party’s liability under this agreement is governed by the liability clause of the service contract. This does not limit liability that the law does not allow to be limited, and it does not affect rights that the people concerned have under the law that applies.
This agreement lasts as long as the Processor processes personal data for the Controller under the service contract, and its duties continue as long as the Processor holds personal data. Changes to this agreement are valid only if both parties agree to them in writing or in electronic form.
15. Governing law and disputes
This agreement is governed by the law stated under Governing law. The parties will first try to settle any dispute in good faith. Otherwise the courts stated under Jurisdiction decide, unless mandatory law provides otherwise.
Governing law
[[Country or state whose law applies]]
Jurisdiction
[[Courts that decide disputes, e.g. the courts of your city]]
How to use it
Choose the template
Press the button to use this template. If you are not signed in, you first sign in or sign up for free and then come straight back to it.
Start a draft
The new-contract page opens with this template marked. Press its card to create a draft. Your company details fill in Party A, and you fill in the blanks, the other party and, where the template has one, the price schedule.
Send it for signature
You sign first, then send each signer a secure link and, by another route, an access code. Signers need no account.
Next steps
Your client opens the link on any device and needs no account. See what the signing looks like on the E-Contracts page, and read which kind of electronic signature is enough for which document.
What it is, and what it is not
QuoteBill creates a simple electronic signature with an audit trail. In the EU, the UK, the US and Korea a signature is not denied legal effect only because it is electronic, and in Japan most contracts need no particular form at all. What a simple electronic signature proves in a dispute depends on the evidence behind it, and some documents need another form.
It is not a qualified or advanced electronic signature, and QuoteBill does not verify who the signers are. It records the use of the link and access code you delivered, so anyone who has both can sign. The signature certificate lists every link issued and, for each action by the sender or a signer, its IP address and browser where they could be read.
Some documents need another form. Wills, many real-estate transfers, guarantees and some employment documents must, in some countries, be handwritten, notarised or signed with a qualified signature. The templates are samples, not legal advice: review them with a lawyer.
Other contract templates
Software development agreement
Specification, milestones, acceptance testing, defects, source code and payment by milestone.
Maintenance and support agreement
Covered systems, support hours and response targets, exclusions, updates, a monthly fee and extra work.
Software subscription agreement (SaaS)
Business-to-business terms for a software subscription: service, renewal, fees, customer data and availability.
Licence agreement
A licence to use a work, software, content or brand: scope, fees or royalties, ownership and termination.