DPA Template + Generator

Generate a data processing agreement for EU, US, China, or combined cross-border use.为欧盟、美国、中国或跨境合用,快速生成一份数据处理协议。

Start with a neutral controller/processor DPA, then add the right jurisdiction module: GDPR Article 28, US service-provider/processor terms, China PIPL entrusted-processing terms, or all three.先用一份通用的"控制者 / 处理者"协议起步,再按需要加上对应地区的条款:欧盟 GDPR 第28条、美国服务商 / 处理者条款、中国《个人信息保护法》委托处理条款,或三者合一。

DPO Assessment数据保护负责人评估

Is a vendor-style DPA a good template as-is? Usually no. Vendor DPAs often contain company names, product-specific support portals, affiliate terms, service limits, and external security-policy links. A public template should be neutral, fillable, and balanced.

What should this DPA cover? Roles, documented instructions, confidentiality, security, subprocessors, data-subject assistance, breach notice, transfers, audit evidence, return/deletion, sensitive data, and jurisdiction-specific terms.

Drafting point: do not publish or sign a company-specific DPA without removing vendor names, product references, affiliate-only mechanics, and one-sided operational limits.

Recommended Checkpoints建议的检查要点

Roles are clearIdentify controller/business, processor/service provider/vendor, and any independent-controller activity.
Annex 1 is completeDescribe subject matter, duration, purpose, data categories, data subjects, locations, and retention.
Security is specificAttach actual technical and organizational measures rather than only linking to a changeable policy page.
Subprocessors are controlledUse notice, objection rights, onward flow-down terms, and processor responsibility.
Breach timing protects deadlinesUse “without undue delay” plus a practical outside deadline such as 24, 48, or 72 hours.
Transfers are not vagueChoose SCCs, UK Addendum/IDTA, China PIPL transfer route, TIA, and supplementary measures where needed.
Audit rights are balancedAllow reports/certifications first where reasonable, but preserve inspection rights for serious risk or regulator demand.
Deletion is provableRequire return/deletion, backup deletion schedule, and certification on request.

DPA Generator Structure数据处理协议生成器

Choose the jurisdiction path and adjust the facts. The draft keeps one core DPA structure and adds jurisdiction modules only where they apply.

Role check first. Import a saved Data Relationship Mapper result to confirm whether a processor DPA is the right document.
Open mapper

Risk triggers

Data Processing Agreement Template

Effective date: [Date]

Controller / Business: [Controller legal name]

Processor / Vendor: [Processor legal name]

Related agreement: [Service agreement / order form]

1. Purpose and Scope

This DPA applies where Processor processes Personal Data or Personal Information on behalf of Controller in connection with the services described in Annex 1. If this DPA conflicts with the related agreement, the more protective privacy term controls.

2. Roles and Instructions

Controller determines the purposes and means of processing. Processor processes data only on documented instructions from Controller, including the related agreement, order forms, product configuration, and this DPA.

3. Confidentiality and Access

Processor will ensure that authorized personnel are bound by confidentiality obligations and access covered data only on a need-to-know basis.

4. Security Measures

Processor will maintain appropriate technical and organizational measures, including access controls, encryption in transit, logging, vulnerability management, backup and recovery, personnel training, incident response, and secure deletion.

5. Subprocessors

Processor may engage subprocessors only with authorization, prior notice, reasonable objection rights, equivalent flow-down terms, and responsibility for subprocessor performance.

6. Assistance

Processor will reasonably assist Controller with individual rights requests, privacy impact assessments, prior consultation, regulator inquiries, compliance evidence, and records of processing.

7. Breach Notice

Processor will notify Controller without undue delay after becoming aware of a personal data breach or security incident, and in any event within [24 / 48 / 72] hours, with available facts and remediation steps.

8. Transfers

Transfers or remote access require a valid legal transfer mechanism and supplementary measures where required. Annex 4 identifies transfer countries and tools.

9. Return, Deletion, and Audit Evidence

At the end of services, Processor will return or delete covered data at Controller's choice unless retention is legally required. Processor will provide audit reports, certifications, security summaries, or a reasonable inspection process where reports are insufficient.

10. Jurisdiction Modules

  • EU/UK: include GDPR / UK GDPR Article 28 processor terms, Article 32 security, audit evidence, DPIA assistance, breach assistance, SCCs/UK transfer terms where required.
  • US: include service-provider, contractor, or processor restrictions: no sale/share, no cross-context behavioral advertising, no unrelated retention/use/disclosure, no unauthorized combining, rights assistance, and deletion/return.
  • China: include PIPL entrusted-processing terms: agreed purpose, method, categories, retention, protection measures, no unauthorized sub-entrustment, rights assistance, return/deletion, and audit cooperation.

Annexes

AnnexWhat to complete
Annex 1: Processing DetailsSubject matter, duration, purpose, processing operations, data subjects, data categories, sensitive data, locations, retention.
Annex 2: Security MeasuresAccess control, encryption, logging, vulnerability management, backups, incident response, training, segregation, secure deletion.
Annex 3: SubprocessorsName, purpose, location, transfer mechanism, notice method, and objection process.
Annex 4: Transfer DetailsExporter/importer, countries, transfer tool, TIA/PIPL route, supplementary measures.
Annex 5: Optional TermsUK GDPR, Swiss FADP, US state law, China PIPL, sector-specific or AI/profiling terms only where applicable.

数据处理协议(中国 PIPL 委托处理版)

本模板依据《中华人民共和国个人信息保护法》(PIPL)就委托处理个人信息而拟定。下方蓝色【…】为可填写项,可在上方生成器中填写后自动带入。本文仅为示范,正式使用前请由专业律师审核。

协议双方

本《数据处理协议》(以下简称"本协议")由以下双方签订:

数据提供方(个人信息处理者):【数据提供方公司名称】
地址:【数据提供方地址】(以下简称"数据提供方")

受托方(受委托处理者):【受托方公司名称】
地址:【受托方地址】(以下简称"受托方")

1. 定义

本协议中,"个人信息""敏感个人信息""处理""个人信息处理者""委托处理"等用语,含义与《个人信息保护法》一致。

2. 协议内容和期限

受托方按照数据提供方的指示,为以下目的处理个人信息:【请填写服务内容与处理目的】

本协议有效期与双方主服务合同一致;主服务合同终止或解除的,本协议同时终止。

3. 技术和制度措施

受托方应采取必要的技术和管理措施,保障所处理个人信息的安全,防止未经授权的访问、泄露、篡改或丢失,具体措施见附件TOM。

4. 更正、删除和限制处理

个人请求更正、删除其个人信息,或要求限制处理的,受托方应按照数据提供方的指示及时配合处理,不得擅自处置。

5. 受托方的义务和职责

受托方仅可在数据提供方指示的范围内处理个人信息;不得超出约定的处理目的、方式;受托方人员负有保密义务。本协议终止后,受托方应按约定删除或返还个人信息。

6. 再委托

受托方未经数据提供方事先书面同意,不得将受托处理事项再委托给第三方。经同意再委托的,受托方应与再受托方约定不低于本协议的保护义务,并对再受托方的行为承担责任。

7. 受托方的配合义务与数据提供方的检查权

受托方应配合数据提供方履行法定义务,并提供证明其遵守本协议的必要信息。数据提供方有权对受托方的处理活动进行检查或委托第三方进行检查。

8. 侵权通知

发生或可能发生个人信息泄露、篡改、丢失等安全事件的,受托方应立即采取补救措施,并第一时间通知数据提供方,配合后续处置与上报。

9. 数据提供方的指示权

受托方应遵守数据提供方就个人信息处理作出的书面指示。受托方认为指示违反法律法规的,应及时告知数据提供方。

10. 数据删除与媒介返还

本协议终止后,受托方应按数据提供方指示删除全部个人信息及其副本,或返还存储介质,并出具书面说明;法律另有保存要求的除外。

11. 责任

因一方违反本协议给对方造成损失的,应依法承担赔偿责任。

12. 最终条款

本协议中文版本与英文版本如有不一致的,以中文版本为准。本协议适用中华人民共和国法律,争议由数据提供方住所地人民法院管辖。

签署

数据提供方:【数据提供方公司名称】
签署人(姓名 / 职务 / 日期):【请填写】

受托方:【受托方公司名称】
签署人(姓名 / 职务 / 日期):【请填写】

附件1 处理与传输

个人信息类别:【请填写,如:姓名、联系方式、账号信息等】

个人信息主体范围:【请填写,如:客户、员工、用户】

是否涉及敏感个人信息:【请填写】

跨境传输国家 / 地区:【请填写】

附件2 数据安全保障能力

受托方应具备与处理活动相适应的数据安全保障能力,包括组织管理、人员管理、访问控制、日志审计、应急响应等方面。

附件TOM 技术和组织措施

包括但不限于:访问权限最小化、传输与存储加密、操作日志留存、定期安全评估、数据备份与恢复、员工保密与安全培训等措施。