انتقل إلى المحتوى الرئيسي
DocumentMS

Glossary

Data processing addendum

Also called: DPA, data processing agreement

A data processing addendum is the contract between a controller and a processor governing how personal data is handled. GDPR Article 28 prescribes much of its content, and it is the document that turns a vendor's security claims into enforceable obligations.

Data processing addendum explained

What Article 28 requires

The subject matter and duration of processing, its nature and purpose, the types of personal data and categories of data subject, and the controller's obligations and rights. Then a set of processor commitments: process only on documented instructions, confidentiality of personnel, appropriate security measures, sub-processor controls, assistance with data subject rights, breach notification, deletion or return at the end, and information sufficient to demonstrate compliance.

The clauses that matter in an assessment

Sub-processor notice and objection. How much notice before a new sub-processor is engaged, and what happens if you object. Thirty days with a termination right is the common standard.

Breach notification timing. "Without undue delay" is the regulation's wording; a specific number of hours is what you want in the contract.

Audit rights. How compliance can be verified in practice — usually a report under NDA rather than a physical audit, which is reasonable, but it should be stated.

Deletion on termination. The retention window after the contract ends, and whether it can be shortened on request.

A practical signal

A vendor that publishes its standard addendum for review before contract is a vendor whose terms have been thought about. One that produces it only after a purchase order is one whose terms will surprise you.

FAQ

Data processing addendum: common questions

Will vendors accept our own DPA?

Larger vendors usually will not, because negotiating bespoke processor terms with every customer does not scale. Smaller vendors often will. Either way, read theirs before assuming.

Is a DPA needed if no personal data is involved?

Strictly no, but in a document system it almost always is — names, contact details and employment data appear in documents even when the system is not 'about' people.

جلسة من ثلاثين دقيقة مع مهندس حلول، على بنية مجلدات وسلسلة اعتماد تشبه ما لديك — لا بيئة عرض عامة.