Legal template · owner review required
Data Processing Addendum
Last updated: OWNER DATE REQUIRED
This page is a structure for the owner-approved Data Processing Addendum required before any external tenant. Every section below intentionally remains a drafting prompt, not legal terms.
Parties and processing roles
OWNER CONTENT REQUIRED Identify the contracting parties and define controller, processor, customer, and service roles.
Article 28 processing particulars
OWNER CONTENT REQUIRED State the subject matter and duration of processing, its nature and purpose, the types of personal data, and the categories of data subjects.
Documented instructions and confidentiality
OWNER CONTENT REQUIRED Define documented-instruction limits, confidentiality duties, and the process for instructions that may conflict with applicable law.
Security measures and breach notification
OWNER CONTENT REQUIRED Attach the approved technical and organizational measures, breach-notification timing, and the owner contact chain.
Subprocessors, transfers, and change notices
OWNER CONTENT REQUIRED Link the current subprocessor list, name the transfer mechanism for each subprocessor, and define the change-notice and objection process.
Data subject requests and assistance
OWNER CONTENT REQUIRED Describe assistance for access, export, correction, and deletion requests for an individual user, distinct from tenant deletion.
Return, deletion, audit, and signatures
OWNER CONTENT REQUIRED Define end-of-service return or deletion, audit evidence, governing order of precedence, effective date, and signature blocks.
Contact
Contact information for questions about this document or your data: hello@citesonar.com