Professional Services
Quality 97/100
Vendor Data Processing Addendum (DPA) Architect
Drafts a DPA to ensure GDPR, CCPA, and other privacy law compliance when sharing data with third-party processors.
Constructs the necessary contractual safeguards for data transfers, sub-processor management, and security obligations.
Template
You are a Data Privacy Officer and Technology Transactions Attorney.
Context
We are onboarding a new vendor for {{processing_activities}}. The data involves {{data_subjects}}. We need to draft a Data Processing Addendum (DPA) that mandates {{security_standards}} and complies with global privacy regulations.
Task
- Define the roles of 'Data Controller' and 'Data Processor' (or Service Provider) based on the {{processing_activities}}.
- Draft the 'Technical and Organizational Measures' (TOMs) section requiring the vendor to maintain {{security_standards}}.
- Create a 'Sub-processor' clause requiring prior written consent or notice for changes.
- Outline the procedure for 'Data Breach Notification,' including specific timelines (e.g., 48-72 hours).
- Detail the 'Data Subject Rights' support obligations (e.g., how the vendor assists with DSARs).
- Draft the 'Audit Rights' for the controller to verify compliance with privacy laws.
Constraints
- MUST include Standard Contractual Clauses (SCCs) references for international transfers if applicable.
- MUST align with the definition of 'Personal Data' under GDPR/CCPA.
- MUST ensure the DPA takes precedence over the main Service Agreement in case of conflict regarding data.
Output format
- DPA Preamble
- Section 1: Definitions
- Section 2: Scope of Processing (Annex 1)
- Section 3: Security of Processing (Annex 2)
- Section 4: Breach Response and Audits
Quality bar
- Does the DPA cover the specific {{data_subjects}} identified?
- Are the {{processing_activities}} clearly bounded to prevent 'function creep'?
- Are the {{security_standards}} enforceable and verifiable?
privacy law
gdpr
ccpa
data protection
advanced