Data Processing Agreement

Répondez à quelques questions et obtenez un accord de traitement des données que vous pouvez télécharger et modifier

100 % gratuit. Fonctionne entièrement dans votre navigateur : vos fichiers et données ne quittent jamais votre appareil et rien n'est envoyé à un serveur.

Modèle, pas un avis juridique. This is a template, not legal advice. It covers the clauses Article 28(3) requires, but the schedule is what an auditor reads, and only you know what is really in it. Where personal data leaves the UK or EEA you also need a transfer risk assessment alongside the clauses referred to here - that assessment is a separate piece of work this cannot do for you.

Partir d’un exemple

Remplit chaque réponse d’un exemple travaillé que vous pouvez modifier. Choisissez celui le plus proche de votre activité.

0 of 10 details filled
The parties
What the processing is for
The processing may only be done for this. Anything vague here becomes a wide permission.
The schedule

Article 28(3) requires this. It is also the part an auditor reads first, and the part generic templates leave blank.

Article 28(3) requires this list. A DPA without it fails an audit.
Sub-processors and transfers
Name, purpose and country. The country is what decides whether the transfer clause below applies.
Operational terms
The Controller has 72 hours to tell the regulator, so a processor notice period longer than 48 hours is not workable.

Data Processing Agreement

15 sections · 1335 words · updates as you type

Data Processing Agreement

Last updated: 19 September 2026

Parties

This Data Processing Agreement ("DPA") is made on 19 September 2026 between:

[Controller] of [Controller address] ("the Controller")

and

[Processor] of [Processor address] ("the Processor").

It forms part of, and is subject to, the main agreement between the Parties under which the Processor provides services to the Controller ("the Main Agreement"). Where this DPA conflicts with the Main Agreement on the processing of personal data, this DPA prevails.

Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU General Data Protection Regulation (EU) 2016/679, and any other law applicable to the processing under this DPA.

"Personal Data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Data Protection Law.

"Sub-processor" means any third party engaged by the Processor to process Personal Data under this DPA.

Roles of the parties

The Controller determines the purposes and means of the processing. The Processor processes Personal Data only on behalf of the Controller.

The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subject are set out in the Schedule at the end of this DPA.

The Controller is responsible for ensuring it has a lawful basis for the processing it instructs, and that any notice or consent required has been given. The Processor is entitled to rely on the Controller instructions in that respect.

Processing on documented instructions

The Processor shall process Personal Data only on the Controller documented instructions, including as to transfers to a third country, unless required to do otherwise by law - in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so.

The Main Agreement, this DPA and the use of the service in its ordinary way constitute the Controller initial documented instructions. Further instructions must be given in writing.

The Processor shall tell the Controller immediately if, in its opinion, an instruction infringes Data Protection Law. The Processor may suspend the affected processing until the instruction is confirmed, corrected or withdrawn.

Confidentiality of personnel

The Processor shall ensure that every person authorised to process Personal Data under this DPA is bound by an appropriate duty of confidentiality, whether by contract or by statute, and that the duty survives the end of their engagement.

Access is limited to those who need it to deliver the services, and is removed when they no longer do.

Security of processing

Taking account of the state of the art, the cost of implementation and the risk to data subjects, the Processor shall implement appropriate technical and organisational measures under Article 32, including as appropriate:

  • encryption of Personal Data in transit and at rest;
  • measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems;
  • the ability to restore availability and access to Personal Data promptly after an incident;
  • a process for regularly testing and evaluating the effectiveness of those measures;
  • role-based access control, with access granted on a need-to-know basis and reviewed periodically;
  • logging of access to and changes affecting Personal Data.

The Processor shall not materially reduce the level of protection these measures provide during the term of this DPA.

Sub-processors

The Controller gives general authorisation for the Processor to engage Sub-processors, and the Processor maintains a current list which it makes available to the Controller on request.

The Processor shall give the Controller at least 30 days notice before adding or replacing a Sub-processor. The Controller may object on reasonable data protection grounds within that period; if the Parties cannot resolve the objection, the Controller may terminate the affected part of the services without penalty.

The Processor shall impose on every Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-processor obligations.

Assisting with data subject rights

Taking account of the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, so far as possible, in responding to requests to exercise data subject rights - access, rectification, erasure, restriction, portability and objection.

Where the Processor receives such a request directly, it shall not respond to it itself, other than to confirm receipt and direct the person to the Controller, and shall pass the request to the Controller without undue delay.

Assisting with security, breaches and assessments

The Processor shall assist the Controller in complying with its obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to the Processor. That includes assistance with data protection impact assessments and with any prior consultation with a supervisory authority.

The Processor shall notify the Controller without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting Personal Data processed under this DPA. The notification shall describe, as far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, the Processor shall provide information in phases rather than delay the first notification.

The Processor shall not make any public statement about a breach affecting the Controller Personal Data without the Controller prior written agreement, unless required to by law.

Return or deletion at the end

On the Controller written request, and in any event on the end of the provision of services, the Processor shall at the Controller choice delete or return all Personal Data and delete existing copies, unless the law requires it to keep them.

Unless the Controller instructs otherwise, deletion takes place 30 days after the end of the services, giving the Controller a window to export its data. Where Personal Data remains in routine backups that are not readily accessible, the Processor shall isolate it from further processing and delete it on the ordinary backup cycle, and this DPA continues to apply to it until then.

The Processor shall certify deletion in writing on request.

Information and audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

The Controller may audit the Processor on reasonable written notice of at least 30 days, no more than once in any 12-month period unless a personal data breach or a regulator requires otherwise. Audits take place during business hours, are subject to confidentiality, and must not unreasonably disrupt the Processor business. The Controller bears its own costs.

International transfers

The Processor shall not transfer Personal Data outside the United Kingdom or the European Economic Area without the Controller prior written consent.

Where the Controller consents to such a transfer, the Processor shall first put in place a transfer mechanism valid under Data Protection Law, and shall tell the Controller which mechanism it relies on.

Liability and term

This DPA takes effect on the date above and continues for as long as the Processor processes Personal Data on the Controller behalf. The obligations of confidentiality, deletion and assistance survive its end.

Liability under this DPA is subject to the limitations and exclusions in the Main Agreement, except where Data Protection Law does not permit that - in particular, nothing in this DPA limits either Party liability to a data subject or to a supervisory authority.

Schedule - details of the processing

Subject matter and purpose of the processing

[the services under the main agreement]

Nature of the processing

Collection, storage, organisation, retrieval, use, transmission and deletion of Personal Data, to the extent needed to provide the services.

Duration

For the term of the Main Agreement, plus the retention period of 30 days set out above.

Categories of data subject

  • [list the categories of individual whose data is processed]

Categories of personal data

  • [list the types of personal data processed]

Approved sub-processors

  • None at the date of this DPA.

Signed

For [Controller] (Controller)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

For [Processor] (Processor)

Signature: ______________________________

Name: __________________________________

Position: _______________________________

Date: ___________________________________

Généré à partir d’un modèle. Pas un avis juridique - lisez-le avant de le publier ou de le signer.

Autres documents que vous pouvez générer

La plupart des sites ont besoin de plus d’un. Une politique de confidentialité sans CGU, ou des CGU sans politique de remboursement, laisse le vide évident.

Privacy PolicyA privacy policy written from what your site actually does - GDPR and CCPA sections included only where they apply.Terms and ConditionsTerms of service built around what you actually sell - goods, subscription, downloads or services.Cookie PolicyA cookie policy with a real table - each cookie named, with its purpose and how long it lasts.Cookie Consent BannerGenerates a working consent banner - blocks tagged scripts until consent, Google Consent Mode v2, no dark patterns.Refund and Return PolicyA refund policy customers can follow and payment processors accept - windows, exclusions and statutory rights in plain words.Website DisclaimerA disclaimer that names the actual risk your site carries, plus affiliate and sponsorship disclosures.Accessibility StatementA WCAG accessibility statement that states what you actually meet, names known issues, and gives people a route to report problems.Non-Disclosure AgreementA mutual or one-way NDA with a real purpose clause, standard carve-outs and a defined term.Freelance ContractAn independent contractor agreement that pins down scope, revisions, IP ownership and what happens when payment is late.W-9 FormFills a substitute Form W-9 in your browser - your TIN is never uploaded, stored or sent anywhere.1099-NEC Contractor SummaryPrepares a 1099-NEC recipient statement and a payer summary - with a straight answer about what you can and cannot print yourself.Shipping PolicyA shipping policy Shopify and Amazon sellers can publish - origin, times, tracking, duties and who pays.DSAR Form GeneratorA data-delete and access request page you can host - GDPR and CCPA wording, no upload, no signup.

À propos de cet outil

Répondez à une poignée de questions et le document s'écrit tout seul. Il existe pour les éditeurs SaaS, les agences et les développeurs dont les clients entreprise ne signeront pas tant qu'un DPA n'existe pas, et pendant l'achat, car c'est généralement le document qui bloque le contrat est le moment où cela vaut vingt minutes. Un point qui sépare une version utilisable d'une copie : l'article 28(3) liste huit éléments qu'un contrat de sous-traitant doit contenir, et un DPA auquel il en manque un n'est pas un DPA - c'est un document qui échoue à un audit. Les huit sont inconditionnels ici ; ce que le questionnaire change, c'est l'annexe, qui est la partie que les auditeurs lisent vraiment et que les modèles génériques laissent vide. Rien d'inutile n'est inclus. Une clause qui ne vous concerne pas est omise, pas remplissage - un document décrivant quelque chose que vous ne faites pas est un problème en soi. Rien n'est téléversé. L'ensemble est assemblé localement, donc les détails confidentiels restent sur votre machine et il n'y a pas de compte à créer ou supprimer plus tard.

Comment utiliser cet outil

  1. Répondez aux questionsResponsable du traitement. Adresse du responsable. Sous-traitant. Rien de ce que vous tapez ne quitte le navigateur.
  2. Regardez-le se construireLes clauses apparaissent et disparaissent au fil de vos réponses, donc le document correspond à ce que vous faites vraiment plutôt qu'à un modèle générique.
  3. Copier ou téléchargerCopiez le texte, ou téléchargez en PDF, Word ou texte brut. La version Word est celle à modifier.

Pourquoi l’utiliser

  • S'exécute entièrement dans votre navigateur. Rien n'est téléversé, rien n'est stocké, pas de compte.
  • Gratuit, sans filigrane, sans barrière e-mail et sans limite par document.
  • Construit à partir de vos réponses, donc les clauses dont vous n'avez pas besoin sont omises plutôt qu'ajoutées pour faire du volume.
  • Téléchargeable en PDF, Word ou texte brut - le fichier Word est modifiable, sans protection.
  • Dit clairement ce qu'il est et n'est pas, au-dessus de l'aperçu plutôt que dans un pied de page.

Usages courants

  • Donner un brouillon à un avocat pour relecture plutôt que de le payer pour partir de zéro.
  • Remplacer un document copié qui décrit une autre activité.
  • Préparer ce qu'un client, une boutique d'applications ou un prestataire de paiement a demandé à voir.
  • Éditeurs SaaS, agences et développeurs dont les clients entreprise ne signeront pas tant qu'un DPA n'existe pas.
  • Mettre quelque chose en place pendant l'achat, car c'est généralement le document qui bloque le contrat.

Conseils pour de meilleurs résultats

  • Conservez une copie de chaque version avec sa date. Quand quelqu'un demande ce que disaient vos conditions en mars dernier, la réponse doit être un fichier, pas un souvenir.
  • Remplissez les champs de texte libre plutôt que de les sauter. Les listes nommées - sous-traitants, exclusions, livrables - sont ce qui le fait sonner comme le vôtre plutôt que copié.
  • Lisez-le avant de le publier. C'est un brouillon construit à partir de clauses types, et vous seul savez si chaque ligne est vraie pour vous.
  • Téléchargez la version Word si vous prévoyez de la modifier. Le PDF est pour publier ; le .docx pour changer.

Erreurs à éviter

  • Ne nommer aucun sous-traitant ultérieur. Un DPA dont la liste de sous-traitants est vide alors que le service tourne sur AWS et envoie du courrier via un tiers est la première chose qu'un auditeur sécurité attrape, et cela bloque l'affaire plutôt que de la conclure.
  • Laisser le texte de substitution. Tout ce qui est entre crochets est un champ que vous avez sauté, et les lecteurs le voient tout de suite.
  • Le publier et ne plus jamais le relire. Ces documents vieillissent - vous ajoutez un outil, changez de prestataire, commencez à vendre ailleurs, et le document décrit encore l'année dernière.
  • Le cacher. Un document que personne ne trouve ne fait pas son travail - il appartient au pied de page de chaque page.

Questions fréquentes

Répondez aux questions à gauche. Le document se construit au fur et à mesure, et vous pouvez le copier ou le télécharger en PDF, Word ou texte brut lorsqu'il convient.

Non. Il assemble un brouillon à partir de clauses types, et chaque page l'indique au-dessus de l'aperçu. Les DPA manquants ou faibles se découvrent pendant les revues de sécurité fournisseurs, ce qui est un problème commercial bien avant d'être réglementaire.

Oui - gratuit, sans inscription, sans e-mail requis et sans filigrane. Il s'exécute dans votre navigateur, c'est pourquoi il ne coûte rien à proposer.

De façon générale, les éditeurs SaaS, agences et développeurs dont les clients entreprise ne signeront pas tant qu'un DPA n'existe pas. Le meilleur moment pour le faire est pendant l'achat, car c'est généralement le document qui bloque le contrat.

Ne nommer aucun sous-traitant ultérieur. Un DPA dont la liste de sous-traitants est vide alors que le service tourne sur AWS et envoie du courrier via un tiers est la première chose qu'un auditeur sécurité attrape, et cela bloque l'affaire plutôt que de la conclure.

Non. Tout se passe sur votre appareil - rien n'est envoyé à un serveur, rien n'est stocké, et fermer l'onglet l'efface.

Oui. Téléchargez la version Word et modifiez ce que vous voulez - c'est un .docx normal, sans protection.

Les gens recherchent aussi

  • modèle d'accord de traitement des données gratuit
  • modèle d'accord de traitement des données usa
  • modèle d'accord de traitement des données uk
  • modèle d'accord de traitement des données pour petite entreprise
  • modèle d'accord de traitement des données
  • modèle d'accord de traitement des données sans inscription
  • modèle d'accord de traitement des données

Related guides