Data Processing Agreement Template
Effective date: [Date]
Controller / Business: [Controller legal name]
Processor / Vendor: [Processor legal name]
Related agreement: [Service agreement / order form]
1. Purpose and Scope
This DPA applies where Processor processes Personal Data or Personal Information on behalf of Controller in connection with the services described in Annex 1. If this DPA conflicts with the related agreement, the more protective privacy term controls.
2. Roles and Instructions
Controller determines the purposes and means of processing. Processor processes data only on documented instructions from Controller, including the related agreement, order forms, product configuration, and this DPA.
3. Confidentiality and Access
Processor will ensure that authorized personnel are bound by confidentiality obligations and access covered data only on a need-to-know basis.
4. Security Measures
Processor will maintain appropriate technical and organizational measures, including access controls, encryption in transit, logging, vulnerability management, backup and recovery, personnel training, incident response, and secure deletion.
5. Subprocessors
Processor may engage subprocessors only with authorization, prior notice, reasonable objection rights, equivalent flow-down terms, and responsibility for subprocessor performance.
6. Assistance
Processor will reasonably assist Controller with individual rights requests, privacy impact assessments, prior consultation, regulator inquiries, compliance evidence, and records of processing.
7. Breach Notice
Processor will notify Controller without undue delay after becoming aware of a personal data breach or security incident, and in any event within [24 / 48 / 72] hours, with available facts and remediation steps.
8. Transfers
Transfers or remote access require a valid legal transfer mechanism and supplementary measures where required. Annex 4 identifies transfer countries and tools.
9. Return, Deletion, and Audit Evidence
At the end of services, Processor will return or delete covered data at Controller's choice unless retention is legally required. Processor will provide audit reports, certifications, security summaries, or a reasonable inspection process where reports are insufficient.
10. Jurisdiction Modules
- EU/UK: include GDPR / UK GDPR Article 28 processor terms, Article 32 security, audit evidence, DPIA assistance, breach assistance, SCCs/UK transfer terms where required.
- US: include service-provider, contractor, or processor restrictions: no sale/share, no cross-context behavioral advertising, no unrelated retention/use/disclosure, no unauthorized combining, rights assistance, and deletion/return.
- China: include PIPL entrusted-processing terms: agreed purpose, method, categories, retention, protection measures, no unauthorized sub-entrustment, rights assistance, return/deletion, and audit cooperation.
Annexes
| Annex | What to complete |
|---|---|
| Annex 1: Processing Details | Subject matter, duration, purpose, processing operations, data subjects, data categories, sensitive data, locations, retention. |
| Annex 2: Security Measures | Access control, encryption, logging, vulnerability management, backups, incident response, training, segregation, secure deletion. |
| Annex 3: Subprocessors | Name, purpose, location, transfer mechanism, notice method, and objection process. |
| Annex 4: Transfer Details | Exporter/importer, countries, transfer tool, TIA/PIPL route, supplementary measures. |
| Annex 5: Optional Terms | UK GDPR, Swiss FADP, US state law, China PIPL, sector-specific or AI/profiling terms only where applicable. |
数据处理协议(中国 PIPL 委托处理版)
本模板依据《中华人民共和国个人信息保护法》(PIPL)就委托处理个人信息而拟定。下方蓝色【…】为可填写项,可在上方生成器中填写后自动带入。本文仅为示范,正式使用前请由专业律师审核。
协议双方
本《数据处理协议》(以下简称"本协议")由以下双方签订:
数据提供方(个人信息处理者):【数据提供方公司名称】
地址:【数据提供方地址】(以下简称"数据提供方")
与
受托方(受委托处理者):【受托方公司名称】
地址:【受托方地址】(以下简称"受托方")
1. 定义
本协议中,"个人信息""敏感个人信息""处理""个人信息处理者""委托处理"等用语,含义与《个人信息保护法》一致。
2. 协议内容和期限
受托方按照数据提供方的指示,为以下目的处理个人信息:【请填写服务内容与处理目的】。
本协议有效期与双方主服务合同一致;主服务合同终止或解除的,本协议同时终止。
3. 技术和制度措施
受托方应采取必要的技术和管理措施,保障所处理个人信息的安全,防止未经授权的访问、泄露、篡改或丢失,具体措施见附件TOM。
4. 更正、删除和限制处理
个人请求更正、删除其个人信息,或要求限制处理的,受托方应按照数据提供方的指示及时配合处理,不得擅自处置。
5. 受托方的义务和职责
受托方仅可在数据提供方指示的范围内处理个人信息;不得超出约定的处理目的、方式;受托方人员负有保密义务。本协议终止后,受托方应按约定删除或返还个人信息。
6. 再委托
受托方未经数据提供方事先书面同意,不得将受托处理事项再委托给第三方。经同意再委托的,受托方应与再受托方约定不低于本协议的保护义务,并对再受托方的行为承担责任。
7. 受托方的配合义务与数据提供方的检查权
受托方应配合数据提供方履行法定义务,并提供证明其遵守本协议的必要信息。数据提供方有权对受托方的处理活动进行检查或委托第三方进行检查。
8. 侵权通知
发生或可能发生个人信息泄露、篡改、丢失等安全事件的,受托方应立即采取补救措施,并第一时间通知数据提供方,配合后续处置与上报。
9. 数据提供方的指示权
受托方应遵守数据提供方就个人信息处理作出的书面指示。受托方认为指示违反法律法规的,应及时告知数据提供方。
10. 数据删除与媒介返还
本协议终止后,受托方应按数据提供方指示删除全部个人信息及其副本,或返还存储介质,并出具书面说明;法律另有保存要求的除外。
11. 责任
因一方违反本协议给对方造成损失的,应依法承担赔偿责任。
12. 最终条款
本协议中文版本与英文版本如有不一致的,以中文版本为准。本协议适用中华人民共和国法律,争议由数据提供方住所地人民法院管辖。
签署
数据提供方:【数据提供方公司名称】
签署人(姓名 / 职务 / 日期):【请填写】
受托方:【受托方公司名称】
签署人(姓名 / 职务 / 日期):【请填写】
附件1 处理与传输
个人信息类别:【请填写,如:姓名、联系方式、账号信息等】
个人信息主体范围:【请填写,如:客户、员工、用户】
是否涉及敏感个人信息:【请填写】
跨境传输国家 / 地区:【请填写】
附件2 数据安全保障能力
受托方应具备与处理活动相适应的数据安全保障能力,包括组织管理、人员管理、访问控制、日志审计、应急响应等方面。
附件TOM 技术和组织措施
包括但不限于:访问权限最小化、传输与存储加密、操作日志留存、定期安全评估、数据备份与恢复、员工保密与安全培训等措施。