diiirect
PlatformTalentDataPricingFuture of work
Sign inPost a role

Explore

  • Platform
  • Talent
  • Data
  • Pricing
  • Future of work
Sign in

Get started

Hire talentI'm looking for work

First shortlist in 5 days

diiirect

Hiring, but direct. A platform and talent marketplace where companies, recruiters, and skilled professionals work together to move from role brief to qualified shortlist faster.

Product

  • Platform
  • Intelligence
  • Categories
  • Talent
  • Pricing
  • Changelog
  • Roadmap

Who it's for

  • For talent
  • For companies
  • For recruiters
  • For non-profits
  • Compare all four

Company

  • Manifesto
  • Case studies
  • Contact
  • Book a demo
  • Press & Media
  • Investors
  • Partners

Resources

  • Templates
  • Assessments
  • Experts
  • Nominate an Expert
  • FAQ
  • Hackathons
  • Apply as talent
  • Start hiring
  • Blog

Tools

  • All tools
  • EOR calculator
  • Resume generator

Legal

  • Privacy
  • Terms
  • Data deletion

Categories

  • Software & Web
  • Data & AI/ML
  • DevOps & Cloud
  • Cybersecurity
  • Blockchain & Web3
  • All categories

By tool

  • HubSpot

Alternative to

  • Upwork
  • Toptal
  • Fiverr
  • Freelancer
  • Guru
Made withπŸ§‰inπŸ‡¦πŸ‡·πŸ‡ΊπŸ‡ΈbyDraidel
Template library

Templates for every step of hiring and working

Home/Templates/NDAs, confidentiality & IP/Data processing addendum (DPA)
Signable template

Data processing addendum (DPA)

An addendum setting a processor's obligations when handling personal data on a company's behalf: processing scope, confidentiality, security measures, sub-processors, breach notice, and deletion at the end of services.

  • Made forEmployers
  • Reading time~3 min
  • What's includedFillable fields, signature blocks, and e-signature delivery through Diiirect.
Use this templateSign in or create a free account to customize and send for e-signature.

The template

This data processing addendum governs how a service provider processes personal data on behalf of a company. It supplements the services agreement between the parties and applies whenever the provider processes personal data to deliver the services.

1. Parties and roles

This addendum is between Company name (the "Company", acting as controller) and Provider name (the "Provider", acting as processor). It takes effect on Effective date and forms part of the services agreement dated Services agreement date.

2. Scope of processing

  1. The Provider will process personal data only to provide the services, and only on the Company's documented instructions, including this addendum and the services agreement.
  2. The processing is described as follows β€” subject matter and duration: Processing subject matter and duration; categories of data subjects and personal data: Data subjects and data categories.
  3. If the Provider believes an instruction violates applicable data-protection law, it will inform the Company promptly before proceeding.

3. Confidentiality of processing

The Provider will ensure that every person it authorizes to process personal data is bound by a contractual or statutory duty of confidentiality, and processes the data only as needed for the services.

4. Security measures

  1. The Provider will implement and maintain appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
  2. These measures include, at minimum: access controls and least-privilege permissions; encryption of personal data in transit and, where feasible, at rest; logging and monitoring of access; secure development and change-management practices; and regular testing of the measures' effectiveness.
  3. The Provider will review the measures periodically and keep them aligned with the risk of the processing.

5. Sub-processors

  1. The Provider may engage sub-processors only with the Company's prior authorization. The current approved list is: Approved sub-processors.
  2. The Provider will give advance written notice of any intended change to sub-processors, allowing the Company a reasonable opportunity to object.
  3. The Provider will impose data-protection obligations on each sub-processor that are at least as protective as this addendum, and remains fully responsible for each sub-processor's performance.

6. Assistance to the company

  1. The Provider will promptly forward to the Company any request it receives from an individual about their personal data, and will not respond directly unless the Company instructs it to.
  2. Taking the nature of the processing into account, the Provider will assist the Company with appropriate measures to respond to individuals' requests, and with the Company's obligations regarding security, breach notification, and impact assessments.

7. Personal data breaches

  1. The Provider will notify the Company without undue delay after becoming aware of a personal data breach affecting the Company's data, and in any case within the window agreed here: Breach notification window.
  2. The notice will describe, to the extent known, the nature of the breach, the data and individuals affected, the likely consequences, and the measures taken or proposed.
  3. The Provider will cooperate with the Company's investigation and remediation, and will not notify authorities or individuals on the Company's behalf unless instructed or legally required.

8. International transfers

The Provider will not transfer personal data to a country or recipient outside the agreed processing locations without the Company's prior written authorization and a lawful transfer mechanism. Agreed processing locations: Processing locations.

9. Audits

The Provider will make available to the Company the information reasonably necessary to demonstrate compliance with this addendum, and will allow and contribute to audits or reviews conducted by the Company or an agreed independent auditor, on reasonable notice and no more than once per year unless a breach or regulator requires otherwise.

10. Return and deletion

When the services end, or earlier on request, the Provider will β€” at the Company's choice β€” return or securely delete all personal data and copies, and certify deletion in writing, except where law requires retention. Retained data remains protected under this addendum until deleted.

11. General

  1. If this addendum conflicts with the services agreement on personal data matters, this addendum controls.
  2. Liability for breaches of this addendum is governed by the services agreement unless the parties agree otherwise in writing.
  3. Amendments must be in writing and signed by both parties; an unenforceable provision does not affect the rest.

Signatures

For the Provider: ✍ Provider signature Date: Provider signature date

For the Company: ✍ Company signature Date: Company signature date

Highlighted fields are filled in when you customize and send this document on Diiirect.

Jurisdiction note

Data-protection laws differ by region on required contract clauses, cross-border transfer mechanisms, breach-notification timelines, and individual rights. Have local counsel confirm this addendum meets the requirements that apply to your data and locations.

Not legal advice

This template is provided for general informational purposes only and is not legal advice. Laws differ by jurisdiction and change over time β€” have a qualified professional review any document before you rely on it.

Related templates

Signable template

Confidential information acknowledgment

An onboarding acknowledgment confirming that a new team member has read and understood their confidentiality obligations, what counts as confidential, and how to handle and report incidents.

Employers
Signable template

Contractor confidentiality agreement

Confidentiality terms tailored to independent contractors, including rules for handling client materials, credentials, and devices during and after the engagement. Pairs with your independent contractor agreement.

Employers
Signable template

Employee invention assignment agreement

An employee-facing invention assignment covering inventions made during employment, a placeholder for statutory carve-outs, a duty to disclose, and cooperation on filings. Sign at or before the start date.

Employers
Signable template

Intellectual property assignment agreement

Assigns work-product intellectual property to the company, with definitions, a moral-rights waiver, a prior-inventions schedule, and further-assurances duties. Use it with employees or contractors creating work for the business.

Employers
Signable template

Interview candidate NDA

A short, candidate-friendly NDA for interviews and work trials where the candidate will see sensitive material such as roadmaps, code, or customer data. Scoped to the hiring process only.

Employers
Signable template

Mutual non-disclosure agreement

A two-way NDA for exploratory business conversations where both sides will share sensitive material. Covers what counts as confidential, standard exclusions, permitted disclosures, and how long the obligations last.

Employers