Data Processing Agreement
This is a plain-English draft DPA for orientation, not an executed agreement. It has not been reviewed by counsel and may not reflect your jurisdiction, your data flows, or the final commercial terms. Have a qualified lawyer review and tailor it, and execute it alongside your main contract. Nothing here is legal advice.
Overview
This Data Processing Agreement (“DPA”) forms part of the Engagement Agreement between XProgrammers (“Processor”) and the client (“Controller”) and applies whenever we process personal data on your behalf. Where this DPA conflicts with the main agreement on data protection, this DPA controls.
Definitions
Terms used here have the meaning given in applicable data protection law (including the GDPR). In short:
Roles of the parties
You are the Controller and we are the Processor. You determine the purposes and means of processing; we process personal data only on your documented instructions, including those set out in the Engagement Agreement and this DPA. If we believe an instruction breaks data protection law, we'll tell you.
Scope & purpose of processing
We process personal data only as needed to deliver the engaged services. The specifics for a given engagement — the subject matter, duration, nature and purpose, the types of personal data, and the categories of data subjects — are described in the Engagement Agreement or an annex to it.
Subprocessors
You give us general authorisation to engage subprocessors to deliver the services, on the following conditions:
- We bind each subprocessor by contract to data protection obligations no less protective than this DPA.
- We remain responsible to you for a subprocessor's performance.
- We maintain a current list of subprocessors and notify you before adding or replacing one that processes your data.
- You may reasonably object to a new subprocessor; if we can't resolve your concern, you may terminate the affected services.
Security measures
We implement appropriate technical and organisational measures to protect personal data, taking into account the risk. These include encryption in transit and at rest, least-privilege access control, network and secret management, secure development, and incident response. Our current controls are described on the Security page and may be updated as long as protection isn't reduced.
Data subject rights
Taking into account the nature of the processing, we'll assist you with appropriate technical and organisational measures to respond to data subject requests — access, rectification, erasure, restriction, portability, and objection. If a data subject contacts us directly, we'll refer them to you rather than respond ourselves, unless you instruct otherwise.
Personal data breach
We'll notify you without undue delay after becoming aware of a personal data breach affecting your data — and in any case in time to support your own notification duties, which under the GDPR run to 72 hours. Our notice will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. We'll cooperate with your investigation and remediation.
International transfers
Where processing involves transferring personal data outside the EEA (or your applicable region), we ensure an appropriate transfer mechanism is in place — typically the EU Standard Contractual Clauses — together with any supplementary measures needed to maintain an equivalent level of protection.
Audits
We'll make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits — including inspections — conducted by you or an auditor you mandate. To minimise disruption, audits happen on reasonable notice, no more than once a year unless required by a regulator or following an incident, and subject to confidentiality.
Return & deletion
On termination of the services, or earlier on your request, we'll return or delete personal data we process on your behalf and delete existing copies, unless the law requires us to keep them. On request, we'll confirm in writing that we've done so. Our access is revoked as part of hand-off.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Engagement Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable data protection law.