As a US-based B2B SaaS vendor, navigating the complex landscape of global data privacy regulations like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) is no longer optional—it's imperative. Your clients, whether in Europe or California, expect assurance that their data, and by extension their customers' data, is handled with the utmost care and in full compliance with applicable laws.
A robust Data Processing Addendum (DPA) is the cornerstone of this assurance. This guide and accompanying template will help you understand, draft, and implement a compliant DPA, protecting both your business and your clients.
A Data Processing Addendum (DPA) is a legally binding contract that outlines the terms under which a data processor (your SaaS company) processes personal data on behalf of a data controller (your client). It is an essential component of any B2B SaaS agreement where personal data is exchanged or handled, particularly when dealing with clients subject to GDPR or CCPA.
Understanding the core components of a DPA is crucial for effective implementation. Here’s a breakdown of essential clauses:
Clearly define terms like "Personal Data," "Data Subject," "Processing," "Controller," "Processor" (GDPR), and "Business," "Service Provider" (CCPA) according to the respective regulations. This ensures a shared understanding of the legal context.
Specify the subject matter, duration, nature, and purpose of the processing, as well as the types of personal data and categories of data subjects involved. This defines the boundaries of your processing activities.
The Controller/Business confirms that they have the lawful basis to transfer personal data to you for processing and that their instructions are lawful.
For transfers of personal data out of the European Economic Area (EEA) to countries not deemed to have adequate protection (like the US), the DPA must incorporate mechanisms such as the European Commission’s Standard Contractual Clauses (SCCs).
Standard contractual clauses that define how damages and legal costs will be handled in case of a breach or non-compliance.
Armed with this understanding, you can now utilize the following template as a strong starting point for your own DPA.
DATA PROCESSING ADDENDUM
This Data Processing Addendum ("
DPA") forms part of the main service agreement between the parties (the "
Principal Agreement") and is entered into by and between:
[Customer Name], a [Customer Entity Type] organized under the laws of [Customer Jurisdiction], with its principal place of business at [Customer Address] ("
Controller" or "
Business");
AND
[SaaS Vendor Name], a [SaaS Vendor Entity Type] organized under the laws of [SaaS Vendor Jurisdiction], with its principal place of business at [SaaS Vendor Address] ("
Processor" or "
Service Provider").
(Each a "
Party" and together the "
Parties")
WHEREAS, the Parties have entered into the Principal Agreement pursuant to which Processor provides certain services to Controller;
WHEREAS, in the course of providing such services, Processor may process Personal Data on behalf of Controller;
WHEREAS, the Parties wish to ensure compliance with the requirements of applicable data protection laws, including the General Data Protection Regulation (Regulation (EU) 2016/679) ("
GDPR") and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "
CCPA").
NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein, the Parties agree as follows:
1. DEFINITIONS
1.1. Unless otherwise defined herein, capitalized terms used in this DPA shall have the meanings set forth in the Principal Agreement.
1.2. The following terms shall have the meanings set forth below:
a. "
Applicable Data Protection Law" means the GDPR, the CCPA, and any other applicable data protection or privacy laws or regulations.
b. "
Controller" or "
Business" means the entity which determines the purposes and means of the Processing of Personal Data (i.e., [Customer Name]).
c. "
Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
d. "
Personal Data" means any information that (i) relates to an identified or identifiable natural person or household; and (ii) is Processed by Processor on behalf of Controller under the Principal Agreement.
e. "
Processor" or "
Service Provider" means the entity which Processes Personal Data on behalf of the Controller/Business (i.e., [SaaS Vendor Name]).
f. "
Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
g. "
Standard Contractual Clauses" or "
SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as adopted by the European Commission, currently Module Two (Controller-to-Processor), available at
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
h. "
Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.
2. DETAILS OF PROCESSING
2.1.
Subject Matter: The subject matter of the Processing is the Personal Data provided by Controller to Processor to enable Processor to perform the services under the Principal Agreement.
2.2.
Duration: Processing will be for the duration of the Principal Agreement, unless otherwise agreed in writing.
2.3.
Nature and Purpose: Processor will Process Personal Data as necessary to perform the services and fulfill its obligations under the Principal Agreement, and as further specified in this DPA.
2.4.
Types of Personal Data: [Specify types, e.g., names, email addresses, IP addresses, usage data, billing information, customer contact details, any special categories as applicable].
2.5.
Categories of Data Subjects: [Specify categories, e.g., Controller's end-users, employees, customers, prospects].
2.6.
Processor's Role: Processor acts as a "Processor" under GDPR and a "Service Provider" under CCPA with respect to the Personal Data.
3. OBLIGATIONS OF THE PROCESSOR (GDPR & CCPA)
3.1.
Lawful Processing: Processor shall Process Personal Data only on the documented instructions of the Controller/Business, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law to which the Processor is subject; in such a case, the Processor shall inform the Controller/Business of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
3.2.
Confidentiality: Processor shall ensure that persons authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3.
Security of Processing: Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. Such measures include, but are not limited to, those detailed in Schedule 1 (Security Measures).
3.4.
Sub-processing:
a. Processor shall not engage any Sub-processor without the prior specific or general written authorization of the Controller/Business. In the case of general written authorization, Processor shall inform the Controller/Business of any intended changes concerning the addition or replacement of other Sub-processors, thereby giving the Controller/Business the opportunity to object to such changes.
b. Where Processor engages a Sub-processor for carrying out specific Processing activities on behalf of the Controller/Business, the same data protection obligations as set out in this DPA shall be imposed on that Sub-processor by way of a contract or other legal act under EU or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of Applicable Data Protection Law.
c. Processor shall remain fully liable to the Controller/Business for the performance of that Sub-processor’s obligations.
3.5.
Data Subject Rights: Taking into account the nature of the Processing, Processor shall assist the Controller/Business by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller/Business's obligation to respond to requests for exercising the Data Subject's rights under Applicable Data Protection Law. Processor shall promptly notify Controller/Business if it receives a request from a Data Subject concerning their Personal Data. Processor shall not respond directly to the Data Subject’s request without the Controller/Business's prior written authorization, unless legally required to do so.
3.6.
Assistance to Controller/Business: Taking into account the nature of Processing and the information available to the Processor, Processor shall assist the Controller/Business in ensuring compliance with the Controller/Business’s obligations under GDPR Articles 32 to 36 concerning:
a. Security of Processing (Art. 32);
b. Notification of a Personal Data breach to the supervisory authority (Art. 33);
c. Communication of a Personal Data breach to the Data Subject (Art. 34);
d. Data Protection Impact Assessment (Art. 35); and
e. Prior consultation (Art. 36).
3.7.
Personal Data Breach Notification: Processor shall notify the Controller/Business without undue delay upon becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Controller/Business. Such notification shall include, at a minimum, the information required by Applicable Data Protection Law.
3.8.
Deletion or Return of Personal Data: At the choice of the Controller/Business, Processor shall delete or return all Personal Data to the Controller/Business after the end of the provision of services relating to Processing, and delete existing copies unless applicable law requires storage of the Personal Data.
3.9.
Audits and Inspections: Processor shall make available to the Controller/Business all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller/Business or another auditor mandated by the Controller/Business, provided that Controller/Business provides reasonable advance notice, conducts the audit during Processor’s regular business hours, and takes reasonable steps to minimize disruption to Processor’s business.
3.10.
CCPA Specific Obligations (Service Provider):
a. Processor shall not Sell or Share Personal Data (as such terms are defined in the CCPA).
b. Processor shall not retain, use, or disclose Personal Data for any purpose other than for the business purposes specified in the Principal Agreement, or as otherwise permitted by the CCPA for Service Providers.
c. Processor shall not retain, use, or disclose Personal Data outside of the direct business relationship between Controller/Business and Processor.
d. Processor shall not combine the Personal Data received from, or on behalf of, Controller/Business with Personal Data that Processor receives from or on behalf of another person or collects from its own interaction with the consumer, except as permitted by the CCPA.
e. Processor certifies that it understands the restrictions and obligations set forth in this Section 3.10 and will comply with them.
4. OBLIGATIONS OF THE CONTROLLER (GDPR & CCPA)
4.1. Controller/Business warrants that it has all necessary rights, consents, and legal bases to provide the Personal Data to Processor for Processing in accordance with the Principal Agreement and this DPA.
4.2. Controller/Business shall ensure that its instructions to Processor comply with Applicable Data Protection Law.
4.3. Controller/Business is responsible for establishing a lawful basis for Processing the Personal Data and for providing appropriate privacy notices to Data Subjects.
5. INTERNATIONAL DATA TRANSFERS (GDPR)
5.1. The Parties acknowledge that Personal Data originating from the European Economic Area ("EEA") may be transferred to the United States (or other countries outside the EEA). Such transfers shall be subject to a valid transfer mechanism.
5.2. To the extent that the Processing of Personal Data involves a transfer from the EEA to a country outside the EEA not deemed by the European Commission to provide an adequate level of protection for Personal Data, the Parties agree to incorporate the Standard Contractual Clauses, which are hereby incorporated by reference and deemed executed by both Parties upon execution of this DPA.
5.3. For the purposes of the SCCs, Controller is the "Data Exporter" and Processor is the "Data Importer." The information required for Annex I and Annex II of the SCCs is set out in Sections 2.4, 2.5, and Schedule 1 of this DPA.
6. LIABILITY AND INDEMNIFICATION
6.1. The liability of each Party under this DPA shall be subject to the limitations of liability set forth in the Principal Agreement.
6.2. Controller/Business shall indemnify and hold Processor harmless from and against all claims, liabilities, costs, expenses, and damages arising out of Controller/Business's failure to comply with its obligations under this DPA or Applicable Data Protection Law.
7. TERM AND TERMINATION
7.1. This DPA shall become effective on the Effective Date and shall terminate automatically upon the termination or expiration of the Principal Agreement.
7.2. Sections 3.8 and 3.9 shall survive the termination or expiration of this DPA.
8. GOVERNING LAW AND JURISDICTION
8.1. This DPA shall be governed by and construed in accordance with the governing law clause in the Principal Agreement.
8.2. The courts specified in the Principal Agreement shall have exclusive jurisdiction over any disputes arising out of or relating to this DPA. If no such law or jurisdiction is specified in the Principal Agreement, this DPA shall be governed by and construed in accordance with the laws of the State of [Jurisdiction], USA, without regard to its conflict of laws principles, and the parties agree to the exclusive jurisdiction of the state and federal courts located in [County], [State].
9. MISCELLANEOUS
9.1. This DPA may be executed in counterparts, each of which shall be deemed an original, but all of which together shall constitute one and the same instrument.
9.2. In the event of any conflict or inconsistency between the provisions of this DPA and the Principal Agreement, the provisions of this DPA shall prevail regarding data processing obligations.
IN WITNESS WHEREOF, the Parties have caused this Data Processing Addendum to be executed by their duly authorized representatives as of the Effective Date.
EFFECTIVE DATE: [Effective Date]
CONTROLLER/BUSINESS: PROCESSOR/SERVICE PROVIDER:
[Customer Name] [SaaS Vendor Name]
By: _______________________________ By: _______________________________
Name: [Customer Signatory Name] Name: [SaaS Vendor Signatory Name]
Title: [Customer Signatory Title] Title: [SaaS Vendor Signatory Title]
Date: _______________________________ Date: _______________________________
---
SCHEDULE 1: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
This Schedule describes the technical and organizational measures implemented by Processor to ensure a level of security appropriate to the risk of processing Personal Data, in accordance with Article 32 of the GDPR and CCPA requirements.
1. Measures of user identification and authorization:
a. Access control mechanisms to prevent unauthorized users from accessing data processing systems.
b. Strong password policies, multi-factor authentication (MFA) where appropriate.
c. Role-based access controls (RBAC) to limit access to Personal Data to only authorized personnel based on job function.
d. Regular review of access rights.
2. Measures for protection of data during transmission and storage:
a. Encryption of Personal Data in transit (e.g., HTTPS/TLS) and at rest (e.g., AES-256 for databases and storage).
b. Secure configuration of infrastructure (firewalls, network segmentation).
c. Data backup and recovery procedures to ensure availability and resilience.
3. Measures for ensuring physical security of sites where Personal Data are Processed:
a. Controlled access to data centers and server rooms (e.g., badges, biometrics, surveillance).
b. Monitoring of physical access.
c. Environmental controls (e.g., temperature, humidity, fire suppression).
4. Measures for ensuring system and data resilience, availability, and recoverability:
a. Redundant systems and infrastructure to prevent single points of failure.
b. Regular backups and documented disaster recovery plan.
c. Regular testing of recovery procedures.
5. Measures for regular testing, assessing, and evaluating the effectiveness of security measures:
a. Regular security assessments, vulnerability scans, and penetration testing.
b. Internal and external audits of security controls.
c. Incident response plan and procedures for managing security breaches.
6. Measures concerning personnel management:
a. Employee background checks where permitted by law.
b. Mandatory data protection and security awareness training for all employees.
c. Confidentiality agreements signed by all employees and contractors.
7. Measures concerning Sub-processors:
a. Due diligence process for vetting Sub-processors.
b. Contractual obligations requiring Sub-processors to meet equivalent security standards.
c. Regular monitoring of Sub-processor compliance.
Processor reserves the right to update or modify these security measures from time to time, provided that such updates or modifications do not materially degrade the overall security of the services.
In today's digital-first business environment, executing legal documents like DPAs via electronic signature platforms is standard practice. Tools like DocuSign and Adobe Sign offer efficiency, security, and legal enforceability.
While both regulate data processing, GDPR's DPA focuses on the "Controller-Processor" relationship, emphasizing strict instructions, specific security measures (Art. 32), and international transfer mechanisms (SCCs). The CCPA's DPA (often embedded in service agreements) focuses on the "Business-Service Provider" relationship, primarily restricting the Service Provider from selling/sharing personal information, retaining/using it outside the direct business relationship, or combining it with other data, as well as mandating a certification of compliance with these restrictions.
A standardized DPA like the template provided is generally sufficient as an addendum to your main SaaS agreement. However, you must ensure that its schedules (e.g., data types, security measures) are accurate and reflect the specific services provided to each client. While the core legal clauses remain consistent, the factual details of the processing might vary, requiring slight customization or clear definition through the main agreement's description of services.
Yes, absolutely. The GDPR applies extraterritorially. If your US client (acting as a Controller) processes personal data of individuals located in the EU/EEA, and your SaaS service involves processing that data on their behalf, then your client is subject to GDPR. Consequently, as their Processor, you must enter into a GDPR-compliant DPA, including potentially Standard Contractual Clauses for transfers of data to your US-based systems, to ensure their compliance and yours.
Comments
Post a Comment