Data Processing Agreement
Customized Agreements
Data Processing Agreement
Record customer/controller/business and provider/processor/service-provider/contractor responsibilities for specifically described personal-data processing under selected regimes, with an activity-level role map, documented instructions, purpose limits, actual safeguards, subprocessor authorization, rights and investigation assistance, supplied transfer mechanisms, and a complete return, retention, and deletion lifecycle across seven schedules.
Also called: dpa contract, controller processor agreement, service provider data processing addendum.

What you walk away with
A clean multi-page PDF and DOCX after you finish — not a web-form dump. Preview the document before you pay.
- PDF export
- DOCX export
- E-sign included
- No subscription
Privacy roles, required contract language, consumer or data-subject rights, sensitive-data treatment, incident timing, government access, international-transfer mechanisms, audit duties, liability, retention, and deletion vary by applicable regime and current law. Official sources and selected text should be rechecked when used.
Jurisdiction details
See how this document starts in your state
Choose the state where the document will be used. The state page shows the maintained coverage level, local-rule limits, and a builder link with the canonical state code already selected.
When this fits
Use this document when…
- A SaaS or cloud provider processing customer personal data under documented instructions
- A California business engaging a service provider or contractor for specific stated business purposes
- A processor appointing a subprocessor while preserving upstream instructions and duties
- A service relationship needing documented subprocessors, security measures, rights assistance, international transfers, and deletion
Before you start
Information you will need
- Customer, provider, Main Agreement, processing services, roles by activity, jurisdictions, selected privacy regimes, and document precedence
- Processing subject, duration, purposes, operations, people, data categories, sensitive data, volume, sources, recipients, systems, locations, and documented instructions
- Purpose, use and disclosure limits, personnel confidentiality, access, accuracy, active retention, return, export, deletion, backups, legal holds, and retained-copy exceptions
- Actual technical and organizational security measures, incidents, assessments, records, audit evidence, rights requests, impact assessments, investigations, and government requests
- Subprocessor identity and authorization, transfers and supplied mechanisms, liability relationship, termination, notices, official source records, and signatures
What you receive
- One customized Data Processing Agreement
- Schedule A processing details
- Schedule B data use, access, retention, return, and deletion lifecycle
- Schedule C technical and organizational security measures
- Schedule D authorized subprocessors
- Schedule E request, assessment, investigation, and cooperation assistance
- Schedule F international transfers and supplied mechanisms
- Schedule G termination, return, retained-copy exceptions, and deletion
- PDF and DOCX export with electronic signature capability
Document questions
Questions about this document
What is a Data Processing Agreement?
Record customer/controller/business and provider/processor/service-provider/contractor responsibilities for specifically described personal-data processing under selected regimes, with an activity-level role map, documented instructions, purpose limits, actual safeguards, subprocessor authorization, rights and investigation assistance, supplied transfer mechanisms, and a complete return, retention, and deletion lifecycle across seven schedules.
How do I create a Data Processing Agreement?
A SaaS or cloud provider processing customer personal data under documented instructions; A California business engaging a service provider or contractor for specific stated business purposes; A processor appointing a subprocessor while preserving upstream instructions and duties
What should a Data Processing Agreement include?
Customer, provider, Main Agreement, processing services, roles by activity, jurisdictions, selected privacy regimes, and document precedence; Processing subject, duration, purposes, operations, people, data categories, sensitive data, volume, sources, recipients, systems, locations, and documented instructions; Purpose, use and disclosure limits, personnel confidentiality, access, accuracy, active retention, return, export, deletion, backups, legal holds, and retained-copy exceptions; Actual technical and organizational security measures, incidents, assessments, records, audit evidence, rights requests, impact assessments, investigations, and government requests; Subprocessor identity and authorization, transfers and supplied mechanisms, liability relationship, termination, notices, official source records, and signatures
Special situations
- EU GDPR, UK GDPR, and California CCPA paths apply only when selected facts and roles support them; the product does not promise universal privacy-law compliance.
- Sensitive processing requires identified categories, people, systems, purposes, access, safeguards, locations, retention, incident treatment, and customer duties.
- Specific or general subprocessor authorization is coordinated with notice, objection, alternatives, flow-downs, transfer terms, and continuing responsibility.
- International transfers require the complete current official mechanism and completed annexes supplied by the parties; the product does not invent or paraphrase mandatory clauses.
Frequently asked questions
Does selecting a role make it correct?
No. The questionnaire maps roles to actual purposes, decisions, and processing activities and detects incompatible selections.
Does this guarantee GDPR or CCPA compliance?
No. It records selected regime-specific terms and facts without claiming that generic language satisfies every privacy law.
Can it cover subprocessors?
Yes. It supports specific approval or general authorization with notice, objections, alternatives, flow-down duties, transfer treatment, and continuing responsibility.
Does it reproduce international transfer clauses?
No. It records the selected mechanism and annex facts, while requiring the complete current official text to be supplied and attached.
How are deletion and legal retention reconciled?
The lifecycle and exit schedules assign every active, replicated, cached, logged, backed-up, held, returned, deidentified, and deleted copy one outcome.
Related documents
Not legal advice
Locke Direct helps structure documents and workflows. It does not replace a qualified lawyer for complex, unusual, or high-risk situations.
Last reviewed August 2, 2026.