An addendum setting a processor's obligations when handling personal data on a company's behalf: processing scope, confidentiality, security measures, sub-processors, breach notice, and deletion at the end of services.
This data processing addendum governs how a service provider processes personal data on behalf of a company. It supplements the services agreement between the parties and applies whenever the provider processes personal data to deliver the services.
This addendum is between Company name (the "Company", acting as controller) and Provider name (the "Provider", acting as processor). It takes effect on Effective date and forms part of the services agreement dated Services agreement date.
The Provider will ensure that every person it authorizes to process personal data is bound by a contractual or statutory duty of confidentiality, and processes the data only as needed for the services.
The Provider will not transfer personal data to a country or recipient outside the agreed processing locations without the Company's prior written authorization and a lawful transfer mechanism. Agreed processing locations: Processing locations.
The Provider will make available to the Company the information reasonably necessary to demonstrate compliance with this addendum, and will allow and contribute to audits or reviews conducted by the Company or an agreed independent auditor, on reasonable notice and no more than once per year unless a breach or regulator requires otherwise.
When the services end, or earlier on request, the Provider will β at the Company's choice β return or securely delete all personal data and copies, and certify deletion in writing, except where law requires retention. Retained data remains protected under this addendum until deleted.
For the Provider: β Provider signature Date: Provider signature date
For the Company: β Company signature Date: Company signature date
Highlighted fields are filled in when you customize and send this document on Diiirect.
Jurisdiction note
Data-protection laws differ by region on required contract clauses, cross-border transfer mechanisms, breach-notification timelines, and individual rights. Have local counsel confirm this addendum meets the requirements that apply to your data and locations.
Not legal advice
This template is provided for general informational purposes only and is not legal advice. Laws differ by jurisdiction and change over time β have a qualified professional review any document before you rely on it.
An onboarding acknowledgment confirming that a new team member has read and understood their confidentiality obligations, what counts as confidential, and how to handle and report incidents.
Confidentiality terms tailored to independent contractors, including rules for handling client materials, credentials, and devices during and after the engagement. Pairs with your independent contractor agreement.
An employee-facing invention assignment covering inventions made during employment, a placeholder for statutory carve-outs, a duty to disclose, and cooperation on filings. Sign at or before the start date.
Assigns work-product intellectual property to the company, with definitions, a moral-rights waiver, a prior-inventions schedule, and further-assurances duties. Use it with employees or contractors creating work for the business.
A short, candidate-friendly NDA for interviews and work trials where the candidate will see sensitive material such as roadmaps, code, or customer data. Scoped to the hiring process only.
A two-way NDA for exploratory business conversations where both sides will share sensitive material. Covers what counts as confidential, standard exclusions, permitted disclosures, and how long the obligations last.