A DPA template is a ready-made data processing agreement that sets the rules for how a vendor handles personal data on your behalf, helping you meet the processor contract terms in GDPR Article 28. It covers roles, processing details, security and breaches.
It is the contract you sign with any vendor that will store, access or otherwise process personal data for you. Your business is the controller, deciding why the data is used; the vendor is the processor, acting only on your instructions.
Buyers use a data processing agreement template when onboarding software, payroll, marketing or support vendors that touch customer or employee data. Many vendors send their own DPA, so the template also works as a benchmark for checking theirs clause by clause.
This page is a template for your own vendor contracts. It is separate from Spendflo's own DPA, which covers the data Spendflo processes for its customers.
Who is the controller deciding the purpose and means of processing, and who is the processor carrying it out.
The subject matter, duration, nature and purpose of the processing, plus the types of personal data and people involved.
Act only on documented instructions, keep staff bound by confidentiality and help you answer data subject requests.
The technical and organisational safeguards, such as encryption and access controls, the vendor commits to.
When the vendor may bring in other providers, how you are told and how you can object.
How quickly and with what detail the vendor tells you about a personal data breach.
Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.
List what personal data the vendor will see, whose it is and why the vendor needs it.
Use your template, or compare the vendor's DPA against it clause by clause.
Fill in processing details, security measures and the current sub-processor list.
Agree breach timing, audit rights and sub-processor notice, then sign with the main contract.
File it with the contract and recheck it at renewal or when the service changes.
The shortest workable DPA still needs parties, processing details, instructions, confidentiality, security, sub-processors, breach notice and deletion at the end. Add audits and transfers when data leaves your region.
Attach the DPA to the main service agreement and say which document wins if they conflict. Fill in every bracket, and delete options that do not apply rather than leaving both.
Names of the controller and processor, and the service agreement this DPA supports.
Personal data, processing, data subject, sub-processor and personal data breach.
Points to Annex 1 for subject matter, duration, nature, purpose and data types.
The processor acts only on documented instructions and flags any it believes are unlawful.
Confidentiality of staff, record keeping and no use of the data for the vendor's own purposes.
Points to Annex 2 and commits the vendor to keep the measures up to date.
Authorisation, advance notice of changes, a right to object and flow-down of the same terms.
How the vendor helps you answer access, correction and deletion requests, and how fast.
The notice window, what the notice must contain and the vendor's duty to help contain it.
Help with data protection impact assessments and regulator enquiries.
Your right to evidence of compliance, such as audit reports, and to audit on reasonable notice.
Where data may be stored or accessed, and the transfer mechanism used if it leaves your region.
What happens to the data when the service ends, and the written confirmation you receive.
How liability links to the main agreement, and which document wins in a conflict.
5. Processor obligations 5.1 The Processor shall process Personal Data only on the documented instructions of the Controller set out in this Agreement and Annex 1, unless the law requires otherwise, in which case it shall tell the Controller first unless the law forbids it. 5.2 The Processor shall ensure every person authorised to process Personal Data is bound by a duty of confidentiality. 5.3 The Processor shall help the Controller respond to requests from Data Subjects to exercise their rights within [5] business days of a request. 7. Sub-processors 7.1 The Processor may engage the Sub-processors listed in Annex 3. It shall give the Controller at least [30] days' written notice before adding or replacing a Sub-processor. 7.2 The Controller may object on reasonable data protection grounds within [14] days of notice, and the parties shall discuss the objection in good faith. 7.3 The Processor shall bind each Sub-processor to terms no less protective than this Agreement and remains responsible for its performance. 9. Personal data breach 9.1 The Processor shall notify the Controller without undue delay, and in any event within [48] hours, after becoming aware of a Personal Data Breach. 9.2 The notice shall describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences and the steps taken or proposed.
This annex is the part most often left vague, yet it defines what the vendor is allowed to do. If a use is not listed here, the vendor has no instruction to carry it out.
| Field | What to enter | Example |
|---|---|---|
| Subject matter | The service the vendor provides | Customer email analytics for Lumen Retail |
| Duration | How long processing lasts | Term of the service agreement plus 30 days for deletion |
| Nature of processing | What the vendor does with the data | Collection, storage, analysis and deletion |
| Purpose | Why the vendor processes it | Measuring open and click rates for marketing emails |
| Types of personal data | Each category of data | Name, email address, purchase history, email engagement |
| Data subjects | Whose data it is | Lumen Retail customers who opted in to marketing |
| Special category data | Any sensitive data, or none | None |
Illustrative entries for a fictional retailer and analytics vendor.
Write measures as commitments the vendor can be held to. Your security team usually reviews this annex, so share it with them alongside the vendor's questionnaire answers. Spendflo's third-party risk management runs that review as part of vendor onboarding.
| Area | What the vendor commits to | Evidence to ask for |
|---|---|---|
| Encryption | Personal data encrypted in transit and at rest | Security whitepaper or audit report |
| Access control | Role-based access, multi-factor log-in, quarterly access reviews | Access policy summary |
| Staff | Background checks where lawful and annual privacy training | Training records summary |
| Resilience | Backups, tested recovery and a stated recovery time | Business continuity plan summary |
| Testing | Regular vulnerability scans and annual penetration tests | Latest test summary |
| Logging | Admin and data access logged and kept for a set period | Logging policy |
Sub-processors are the secondary vendors your vendor relies on, such as its cloud host or support desk tool. Ask for the list before signing and decide whether you need specific approval for each change or general approval with notice.
| Sub-processor | Service | Location | Data accessed |
|---|---|---|---|
| Cloud hosting provider | Infrastructure | EU (Ireland) | All service data |
| Email delivery service | Sending emails | EU (Germany) | Name, email address |
| Support desk tool | Customer support tickets | United States | Contact details in tickets |
Illustrative Annex 3 for the sample analytics vendor.
Subject: Notice of new sub-processor under our data processing agreement Dear [Controller contact], Under clause 7.1 of our data processing agreement dated [date], we are giving [30] days' notice that we intend to appoint [Sub-processor name] to provide [service] from [date]. Location of processing: [country] Personal data involved: [categories] Transfer mechanism, if outside [region]: [mechanism] You may object on reasonable data protection grounds by [date, 14 days from this notice]. [Name] [Role], [Vendor]
Under GDPR the controller usually has 72 hours to tell the regulator about a notifiable breach, so a slow vendor eats into your time. Most buyers ask for 24 to 72 hours from the vendor; the template uses 48 as a placeholder.
| Stage | Timing | What the vendor sends |
|---|---|---|
| First alert | Within [48] hours of awareness | What happened, when, and a named contact |
| Detail update | As facts are confirmed | Data types, people and records affected, likely consequences |
| Containment | Ongoing | Steps taken to stop the breach and limit harm |
| Final report | Within [30] days | Root cause, full impact and changes made to prevent a repeat |
Most vendors send their own DPA, and many are reasonable. The checklist helps procurement spot the gaps quickly, so legal review focuses on the points that matter. Pair it with a general contract review checklist for the main agreement.
Spendflo's Contracts Agent stores each DPA with its main contract and tracks the renewal date.
See the Contracts AgentThe business that decides why and how personal data is processed, usually the buyer.
The vendor that processes personal data on the controller's behalf and instructions.
A provider the processor engages to help deliver the service, such as a cloud host.
The person the personal data is about, such as a customer or employee.
A security incident leading to loss, change, disclosure of or access to personal data.
The legal basis for moving data to another country, such as standard contractual clauses.
You cannot complete Annex 1 until you know what data the vendor will see.
Check the vendor's DPA against your template before accepting it.
Write breach, notice and deletion periods as numbers, not as reasonable time.
Have your security team approve Annex 2 alongside the questionnaire.
Keep the DPA with the main agreement so both are found at renewal.
An annex listing every product the vendor sells authorises far too much.
You are approving providers you have never seen.
Without a deletion deadline, your data can stay with the vendor indefinitely.
A new module or data type may need an updated Annex 1.
Ask the requester what personal data the vendor will see and why.
Complete Annex 1, attach the vendor's security measures and sub-processor list.
Choose notice, breach and deletion periods that fit the risk of the data.
Send the DPA with the service agreement, then route both to counsel.
Lumen Retail buys email analytics from Orbit Analytics. Orbit's own DPA offers breach notice within 7 days and no sub-processor notice. Lumen's review checklist flags both. Orbit agrees to 48 hours and 30 days' notice, and attaches its three sub-processors as Annex 3. Counsel signs off in a week. Illustrative example.
Every part on this page, in Word, Google Docs and PDF, with the examples filled in.
Use the template as written, and add a transfer mechanism if the vendor or its sub-processors process data outside your region.
Some states, such as California, set their own terms for service provider contracts. Ask counsel to add those clauses.
Health information covered by HIPAA usually needs a business associate agreement as well as, or instead of, a DPA.
Best for negotiating with a vendor.
Best for drafting with legal and security.
The review checklist, ready to print.
Spendflo has handled 15,000+ agreements, at 30% average savings on software spend.
See your savingsA good DPA names the data, the purpose, the safeguards and the deadlines, so both sides know what is allowed. Keep it with the main contract and revisit it whenever the service or the data changes.
Fourteen clauses in order, with sample wording for the hardest three.
Open the template →2Subject matter, purpose and data types written for this vendor only.
Open Annex 1 →3Ten checks before a vendor's DPA goes to counsel.
Open the checklist →Quick answers to what people ask most about the dpa template (data processing agreement).
A DPA, or data processing agreement, is a contract between a business and a vendor that processes personal data for it, setting out instructions, security, sub-processors and breach duties. Download the template on this page to see every clause in order.
Start by mapping the personal data the vendor will handle, then fill in the parties, processing details, security measures, sub-processors and breach notice. Have counsel review the draft before signing. Download the template to begin with every clause already in place.
A data sharing agreement is a different document, used when two businesses each decide how they use shared data, whereas a DPA covers a vendor acting on your instructions. You can download this DPA template and adapt the parties and purpose clauses with counsel, but it is not a data sharing agreement as written.
The seven data protection principles in UK and EU GDPR are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. A DPA with a vendor puts several of them into contract terms. Download the template to see how.
You can download it free from this page in Word, Google Docs or PDF. It includes the full data processing agreement, Annexes 1 to 3, a sub-processor notice and a ten-point review checklist.
Contracts
Purchase orders
Vendor management
Sourcing and RFx
Budgets and business cases
Procurement
Accounts payable
Purchasing
Software buying
Supply chain
Spendflo runs intake, approvals and third-party risk reviews before a vendor sees your data, and its Contracts Agent keeps each DPA with the main agreement through renewal.
Enter your work email and we'll unlock every format.
Didn't start, or need another format? Pick one below.
Google Docs: upload the file to Google Drive, then open it with Google Docs.