Free templateWord · Google Docs · PDF

DPA Template (Data Processing Agreement)

A DPA template is a ready-made data processing agreement that sets the rules for how a vendor handles personal data on your behalf, helping you meet the processor contract terms in GDPR Article 28. It covers roles, processing details, security and breaches.

  • Fourteen clauses in order, with sample wording
  • Annexes for processing details and security
  • Sub-processor notice and a review checklist
Book a demo
Updated 7 Oct 20266 partsReviewed by the Spendflo procurement team
Definition

What is a DPA template?

It is the contract you sign with any vendor that will store, access or otherwise process personal data for you. Your business is the controller, deciding why the data is used; the vendor is the processor, acting only on your instructions.

Buyers use a data processing agreement template when onboarding software, payroll, marketing or support vendors that touch customer or employee data. Many vendors send their own DPA, so the template also works as a benchmark for checking theirs clause by clause.

This page is a template for your own vendor contracts. It is separate from Spendflo's own DPA, which covers the data Spendflo processes for its customers.

Key components

Parties

Who is the controller deciding the purpose and means of processing, and who is the processor carrying it out.

Processing details

The subject matter, duration, nature and purpose of the processing, plus the types of personal data and people involved.

Processor obligations

Act only on documented instructions, keep staff bound by confidentiality and help you answer data subject requests.

Security measures

The technical and organisational safeguards, such as encryption and access controls, the vendor commits to.

Sub-processors

When the vendor may bring in other providers, how you are told and how you can object.

Breach notification

How quickly and with what detail the vendor tells you about a personal data breach.

Get the dpa template (data processing agreement) free

Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.

For beginners

How a DPA fits into a vendor contract

A DPA sits alongside the main service agreement and governs only the personal data side of the deal. It moves through five stages from scoping to renewal.
  1. 1
    Map the data

    List what personal data the vendor will see, whose it is and why the vendor needs it.

  2. 2
    Pick the paper

    Use your template, or compare the vendor's DPA against it clause by clause.

  3. 3
    Complete the annexes

    Fill in processing details, security measures and the current sub-processor list.

  4. 4
    Negotiate and sign

    Agree breach timing, audit rights and sub-processor notice, then sign with the main contract.

  5. 5
    Store and revisit

    File it with the contract and recheck it at renewal or when the service changes.

Need something simpler?

The shortest workable DPA still needs parties, processing details, instructions, confidentiality, security, sub-processors, breach notice and deletion at the end. Add audits and transfers when data leaves your region.

Part 1 · DPA template

The data processing agreement template

The agreement runs through fourteen clauses, from parties and definitions to deletion at the end. The sample wording below covers the three clauses vendors push back on most.

Attach the DPA to the main service agreement and say which document wins if they conflict. Fill in every bracket, and delete options that do not apply rather than leaving both.

  1. 01Parties and roles

    Names of the controller and processor, and the service agreement this DPA supports.

  2. 02Definitions

    Personal data, processing, data subject, sub-processor and personal data breach.

  3. 03Scope and details of processing

    Points to Annex 1 for subject matter, duration, nature, purpose and data types.

  4. 04Controller instructions

    The processor acts only on documented instructions and flags any it believes are unlawful.

  5. 05Processor obligations

    Confidentiality of staff, record keeping and no use of the data for the vendor's own purposes.

  6. 06Security measures

    Points to Annex 2 and commits the vendor to keep the measures up to date.

  7. 07Sub-processors

    Authorisation, advance notice of changes, a right to object and flow-down of the same terms.

  8. 08Data subject rights

    How the vendor helps you answer access, correction and deletion requests, and how fast.

  9. 09Personal data breach

    The notice window, what the notice must contain and the vendor's duty to help contain it.

  10. 10Assistance with assessments

    Help with data protection impact assessments and regulator enquiries.

  11. 11Audits and information

    Your right to evidence of compliance, such as audit reports, and to audit on reasonable notice.

  12. 12International transfers

    Where data may be stored or accessed, and the transfer mechanism used if it leaves your region.

  13. 13Return or deletion

    What happens to the data when the service ends, and the written confirmation you receive.

  14. 14Liability and precedence

    How liability links to the main agreement, and which document wins in a conflict.

Sample clauses: processor obligations, sub-processors, breach
5. Processor obligations
5.1 The Processor shall process Personal Data only on the documented instructions of the Controller set out in this Agreement and Annex 1, unless the law requires otherwise, in which case it shall tell the Controller first unless the law forbids it.
5.2 The Processor shall ensure every person authorised to process Personal Data is bound by a duty of confidentiality.
5.3 The Processor shall help the Controller respond to requests from Data Subjects to exercise their rights within [5] business days of a request.

7. Sub-processors
7.1 The Processor may engage the Sub-processors listed in Annex 3. It shall give the Controller at least [30] days' written notice before adding or replacing a Sub-processor.
7.2 The Controller may object on reasonable data protection grounds within [14] days of notice, and the parties shall discuss the objection in good faith.
7.3 The Processor shall bind each Sub-processor to terms no less protective than this Agreement and remains responsible for its performance.

9. Personal data breach
9.1 The Processor shall notify the Controller without undue delay, and in any event within [48] hours, after becoming aware of a Personal Data Breach.
9.2 The notice shall describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences and the steps taken or proposed.
This template is a starting point, not legal advice. Have your counsel review it before you sign.
Part 2 · Processing details

Annex 1: details of the processing

Annex 1 describes exactly what the vendor does with personal data and for how long. Write it for this vendor and this service, never as a copy of the vendor's whole product list.

This annex is the part most often left vague, yet it defines what the vendor is allowed to do. If a use is not listed here, the vendor has no instruction to carry it out.

FieldWhat to enterExample
Subject matterThe service the vendor providesCustomer email analytics for Lumen Retail
DurationHow long processing lastsTerm of the service agreement plus 30 days for deletion
Nature of processingWhat the vendor does with the dataCollection, storage, analysis and deletion
PurposeWhy the vendor processes itMeasuring open and click rates for marketing emails
Types of personal dataEach category of dataName, email address, purchase history, email engagement
Data subjectsWhose data it isLumen Retail customers who opted in to marketing
Special category dataAny sensitive data, or noneNone

Illustrative entries for a fictional retailer and analytics vendor.

Part 3 · Security measures

Annex 2: technical and organisational security measures

Annex 2 lists the specific safeguards the vendor commits to, not a promise of industry standard security. Ask for evidence of each measure before you sign.

Write measures as commitments the vendor can be held to. Your security team usually reviews this annex, so share it with them alongside the vendor's questionnaire answers. Spendflo's third-party risk management runs that review as part of vendor onboarding.

AreaWhat the vendor commits toEvidence to ask for
EncryptionPersonal data encrypted in transit and at restSecurity whitepaper or audit report
Access controlRole-based access, multi-factor log-in, quarterly access reviewsAccess policy summary
StaffBackground checks where lawful and annual privacy trainingTraining records summary
ResilienceBackups, tested recovery and a stated recovery timeBusiness continuity plan summary
TestingRegular vulnerability scans and annual penetration testsLatest test summary
LoggingAdmin and data access logged and kept for a set periodLogging policy
Part 4 · Sub-processors

Sub-processor list and change notice

Annex 3 names every sub-processor, what it does and where it processes data. Any change after signing must come with advance notice and a chance to object.

Sub-processors are the secondary vendors your vendor relies on, such as its cloud host or support desk tool. Ask for the list before signing and decide whether you need specific approval for each change or general approval with notice.

Sub-processorServiceLocationData accessed
Cloud hosting providerInfrastructureEU (Ireland)All service data
Email delivery serviceSending emailsEU (Germany)Name, email address
Support desk toolCustomer support ticketsUnited StatesContact details in tickets

Illustrative Annex 3 for the sample analytics vendor.

Sample sub-processor change notice
Subject: Notice of new sub-processor under our data processing agreement

Dear [Controller contact],

Under clause 7.1 of our data processing agreement dated [date], we are giving [30] days' notice that we intend to appoint [Sub-processor name] to provide [service] from [date].

Location of processing: [country]
Personal data involved: [categories]
Transfer mechanism, if outside [region]: [mechanism]

You may object on reasonable data protection grounds by [date, 14 days from this notice].

[Name]
[Role], [Vendor]
Part 5 · Breach notice

Breach notification timeline

The vendor alerts you without undue delay and within the agreed window, then sends fuller detail as it learns more. A fixed window in hours is easier to enforce than a vague promise.

Under GDPR the controller usually has 72 hours to tell the regulator about a notifiable breach, so a slow vendor eats into your time. Most buyers ask for 24 to 72 hours from the vendor; the template uses 48 as a placeholder.

StageTimingWhat the vendor sends
First alertWithin [48] hours of awarenessWhat happened, when, and a named contact
Detail updateAs facts are confirmedData types, people and records affected, likely consequences
ContainmentOngoingSteps taken to stop the breach and limit harm
Final reportWithin [30] daysRoot cause, full impact and changes made to prevent a repeat
Part 6 · Review checklist

DPA review checklist for vendor contracts

Ten checks cover the clauses where vendor DPAs most often fall short. Run them on every vendor's paper before it goes to counsel.

Most vendors send their own DPA, and many are reasonable. The checklist helps procurement spot the gaps quickly, so legal review focuses on the points that matter. Pair it with a general contract review checklist for the main agreement.

0 of 10 done

Scope

Security

Sub-processors

Breach

Exit

Spendflo's Contracts Agent stores each DPA with its main contract and tracks the renewal date.

See the Contracts Agent
Glossary

DPA terms, explained

These terms appear in every data processing agreement. Getting them right decides who is responsible for what.
Controller

The business that decides why and how personal data is processed, usually the buyer.

Processor

The vendor that processes personal data on the controller's behalf and instructions.

Sub-processor

A provider the processor engages to help deliver the service, such as a cloud host.

Data subject

The person the personal data is about, such as a customer or employee.

Personal data breach

A security incident leading to loss, change, disclosure of or access to personal data.

Transfer mechanism

The legal basis for moving data to another country, such as standard contractual clauses.

Best practices

Do this, avoid that

Be specific in the annexes, fix the breach window in hours and keep control of sub-processor changes. Most weak DPAs are vague on exactly those points.

Do

  • ✓
    Map data before drafting

    You cannot complete Annex 1 until you know what data the vendor will see.

  • ✓
    Compare the vendor's paper

    Check the vendor's DPA against your template before accepting it.

  • ✓
    Fix timings

    Write breach, notice and deletion periods as numbers, not as reasonable time.

  • ✓
    Involve security

    Have your security team approve Annex 2 alongside the questionnaire.

  • ✓
    Store it with the contract

    Keep the DPA with the main agreement so both are found at renewal.

Avoid

  • ×
    Copying annexes

    An annex listing every product the vendor sells authorises far too much.

  • ×
    Signing without the sub-processor list

    You are approving providers you have never seen.

  • ×
    Open-ended retention

    Without a deletion deadline, your data can stay with the vendor indefinitely.

  • ×
    Forgetting changes

    A new module or data type may need an updated Annex 1.

How to use it

Complete it in four steps

Map the data, fill in the annexes, set the timings in the brackets and send it with the main contract. Counsel then reviews the finished draft.
  1. Step 1

    Map the data

    Ask the requester what personal data the vendor will see and why.

  2. Step 2

    Fill in the annexes

    Complete Annex 1, attach the vendor's security measures and sub-processor list.

  3. Step 3

    Set the brackets

    Choose notice, breach and deletion periods that fit the risk of the data.

  4. Step 4

    Send with the contract

    Send the DPA with the service agreement, then route both to counsel.

Example

One DPA, start to finish

Comparing the vendor's DPA with the template showed two gaps. Both were fixed before signing, without slowing the purchase.

Lumen Retail buys email analytics from Orbit Analytics. Orbit's own DPA offers breach notice within 7 days and no sub-processor notice. Lumen's review checklist flags both. Orbit agrees to 48 hours and 30 days' notice, and attaches its three sub-processors as Annex 3. Counsel signs off in a week. Illustrative example.

Ready to use it? Download the dpa template (data processing agreement)

Every part on this page, in Word, Google Docs and PDF, with the examples filled in.

Variants

Fit it to your data

The core clauses work for most vendors, but the data and the region change what you add. Ask counsel which additions apply before you send it.
EU and UK personal data

GDPR processing

Use the template as written, and add a transfer mechanism if the vendor or its sub-processors process data outside your region.

US personal data

US state privacy laws

Some states, such as California, set their own terms for service provider contracts. Ask counsel to add those clauses.

US health data

Add a BAA

Health information covered by HIPAA usually needs a business associate agreement as well as, or instead of, a DPA.

Spendflo has handled 15,000+ agreements, at 30% average savings on software spend.

See your savings
Bottom line

A DPA protects data only if it is specific

A good DPA names the data, the purpose, the safeguards and the deadlines, so both sides know what is allowed. Keep it with the main contract and revisit it whenever the service or the data changes.

FAQ

Frequently asked questions

Quick answers to what people ask most about the dpa template (data processing agreement).

What is a DPA document?

A DPA, or data processing agreement, is a contract between a business and a vendor that processes personal data for it, setting out instructions, security, sub-processors and breach duties. Download the template on this page to see every clause in order.

How to write a DPA?

Start by mapping the personal data the vendor will handle, then fill in the parties, processing details, security measures, sub-processors and breach notice. Have counsel review the draft before signing. Download the template to begin with every clause already in place.

Can you provide a template for a data sharing agreement?

A data sharing agreement is a different document, used when two businesses each decide how they use shared data, whereas a DPA covers a vendor acting on your instructions. You can download this DPA template and adapt the parties and purpose clauses with counsel, but it is not a data sharing agreement as written.

What are the 7 DPA principles?

The seven data protection principles in UK and EU GDPR are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. A DPA with a vendor puts several of them into contract terms. Download the template to see how.

Where can I download a free DPA template?

You can download it free from this page in Word, Google Docs or PDF. It includes the full data processing agreement, Annexes 1 to 3, a sub-processor notice and a ten-point review checklist.

Template library

Browse all procurement templates

See all 60 templates →

Every vendor contract, with its DPA attached.

Spendflo runs intake, approvals and third-party risk reviews before a vendor sees your data, and its Contracts Agent keeps each DPA with the main agreement through renewal.

Book a demo
  • 14-clause DPA template
  • 3 annexes ready to fill
  • 4-stage breach timeline
  • 10-point review checklist