01

Template status and completion

Before this template can be used, it must identify the legal parties, addresses, effective date, governing arrangement and authorised signatories. The completed document should receive jurisdiction-specific legal review.

  • 01No contracting party inserted
  • 02No signature or effective date
  • 03Legal review required before execution
02

Proposed roles and instructions

The intended model treats the customer as controller for workspace content and the service operator as processor. Final language must limit processing to documented, lawful instructions needed to provide, secure and support the service.

  • 01Customer determines purpose
  • 02Processor follows documented instructions
  • 03Unlawful instructions must be rejected
03

Processing schedule

A completed schedule must specify data subjects, data categories, purposes, processing activities, duration and retention. Likely categories include account, membership, task, contact, time, finance, support and service-log data.

  • 01Data subjects and categories
  • 02Purpose and processing activity
  • 03Duration, retention and deletion
04

Security and confidentiality schedule

The final schedule must describe technical and organisational measures that accurately reflect the service at signing. Public security information is context, not a certification or substitute for the completed schedule.

  • 01Need-to-know access
  • 02Confidentiality obligations
  • 03Verified technical and organisational measures
05

Subprocessors and transfers

Before execution, the template must list the actual providers used for hosting, database, email, payment or support, together with purpose, processing region, contractual safeguards and the change-notification process.

  • 01Current provider list
  • 02Purpose and processing region
  • 03Transfer and change safeguards
06

Rights, incidents and end of service

The completed DPA must define assistance with data-subject requests, incident notification, deletion or return, compliance evidence and proportionate audit conditions without exposing other customers or system security.

  • 01Request and incident cooperation
  • 02Deletion or return terms
  • 03Controlled verification rights

CLEAR TERMS / DIRECT CONTACT

Need a precise answer? Ask us directly.

Ask about the DPA templateReturn home