Business

Data Processing Agreement | 11 CCR 7051 & GDPR Art. 28

Vendor DPA drafted to 11 CCR 7051 service provider terms, GDPR Article 28 and Decision (EU) 2021/914 clauses. Covers CA, TX, VA, CO, CT. Word and PDF.
4.6/521 reviews50 000+ downloadsInstant download
Share

A data processing agreement controls what a vendor may and may not do with personal information you hand over to it. In US practice it rarely stands alone. It attaches to a master services agreement or a SaaS order form and does two jobs: it carries the CCPA service provider terms that keep a vendor disclosure from counting as a sale, and the GDPR Article 28 terms plus the EU Standard Contractual Clauses that European customers will not sign without. This vendor DPA template is drafted for US companies on either side of the table, and covers subprocessor control, breach notice, audit rights, and deletion at the end of the engagement.

Compliant

2026 Legislation

50,000+ clients

trust us

Affordable

From $4.90 / doc

Secure payment

Instant download

Data Processing Agreement | 11 CCR 7051 & GDPR Art. 28

Secure payment

Fill in the template

What is a data processing agreement?

A data processing agreement is a written contract between the party that decides why personal data is collected and the party that handles it on that party's behalf. European law calls them the controller and the processor. California uses a different vocabulary for the same relationship: a business discloses personal information to a service provider or a contractor for a business purpose. The paper is titled a DPA either way, so a good template defines both sets of terms and maps them to each other.

Three documents get confused with it. An NDA stops a vendor from telling anyone your secrets but says nothing about purpose limitation, deletion, or subprocessors, so it satisfies no privacy statute. A privacy policy is a public disclosure to consumers, not a contract between two companies. A HIPAA business associate agreement under 45 CFR 164.504(e) reaches protected health information only, and a healthcare vendor usually needs both. The DPA sits underneath your commercial terms rather than replacing them, so attach it to the master services agreement that governs the engagement and inherit the term, governing law, and liability cap by reference.

2

When do you need this document?

The ordinary trigger is procurement. You are about to route customer records, payroll files, or support tickets through an outside platform, and the vendor's terms say nothing about deletion or subprocessors. The mirror image is just as common: an enterprise buyer sends you a fifteen page DPA drafted by its own counsel and you need a position of your own. Offering your house paper first beats any redline you will write later.

Human resources work is the quiet trap. Payroll bureaus, benefits brokers, background check firms, and applicant tracking systems all process personal information, and California reaches employee records where most state statutes exempt them, so an employment documents package built for US employers that omits vendor privacy terms leaves a real gap. Two edge cases deserve flagging. A vendor that wants your customer data to train its own models is processing for its own purpose, which breaks service provider status and needs an express carve out or a flat prohibition. The other is the US only company that lands its first Irish customer. GDPR follows the data, not the incorporation certificate.

3

Key clauses included in our template

  • The scope and instruction clause records the subject matter, duration, nature and purpose of processing, the categories of personal data, and the categories of data subjects. Article 28(3) GDPR and Texas Business and Commerce Code section 541.104(b) both demand this specificity, and vagueness here is the usual reason a DPA fails audit.
  • The purpose limitation and no sale clause bars use or disclosure outside the direct business relationship, blocks combination with outside data, and confirms that no valuable consideration is exchanged. This language preserves service provider status under 11 CCR section 7051.
  • The subprocessor clause sets general or specific authorization, gives you notice and a right to object before a new subprocessor is engaged, flows equivalent terms down in writing, and keeps the vendor liable for its subcontractors.
  • The security clause commits the vendor to defined technical and organizational measures rather than a promise of reasonableness: encryption in transit and at rest, access control, logging, and confidentiality duties surviving termination.
  • The incident notification clause fixes a deadline shorter than the regulatory one, requires the vendor to supply the facts you need for your own state breach notifications, and bars unilateral public statements.
  • The assistance, audit, and deletion clause covers consumer and data subject requests, data protection assessments, an annual audit or an independent assessor report in the alternative, and return or deletion of every copy with certification. Read it against the SaaS and software license agreement template, which allocates the same risks from the opposite direction.
4

State-specific considerations

California is the outlier and the drafting anchor. 11 CCR section 7051 is the most prescriptive processor contract rule in the country, the CCPA alone reaches employee and job applicant data, and Civil Code section 1798.150 gives consumers a private right of action for breaches of unencrypted personal information caused by unreasonable security. That statutory damages exposure is why California vendors negotiate hardest over the security schedule. Draft to California first and the rest of the country generally follows.

Texas applies the Texas Data Privacy and Security Act with no revenue threshold, so small companies fall in unless they qualify under section 541.107. Section 541.104(b) mandates the contract terms and 541.104(c) lets a vendor substitute a qualified independent assessor's report for a customer audit. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended section 541.104 to reach personal data processed by an artificial intelligence system, so AI vendors selling into Texas must say so in the processing description.

Virginia is the model most other states copied. Virginia Code section 59.1-579 requires processing instructions, confidentiality duties, deletion or return at the customer's election, and cooperation with assessments. It exempts employee and business to business data, so a Virginia only analysis understates your California obligations.

Colorado adds detail through the Attorney General's rules at 4 CCR 904-3, read with section 6-1-1305(5) of the Colorado Privacy Act, and says plainly that a processor becomes a controller once it decides purposes and means on its own. Connecticut tracks the same structure at section 42-520, and its cure period has now sunset, so the Attorney General can act on a first violation without giving you a window to fix it. Related paperwork sits in the US business contracts and incorporation documents catalog.

5

How to fill out this data processing agreement

You begin by identifying which side of the relationship you are on, because the template branches from there. Customer produces a controller favorable draft with tighter subprocessor control and a short notification window; vendor relaxes the audit mechanics and adds the independent assessor alternative that Texas and Virginia permit. Next you describe the processing itself. The form asks for the categories of personal data, the categories of individuals, the business purposes, and the retention period, then writes them into the schedule regulators read first.

You then select your governing statutes. California adds the service provider language, the combination prohibition, and the contractor certification. Any European exposure attaches the Article 28 terms and prompts you to pick the transfer module, with the annexes pre-populated from answers you already gave. Last, you list your subprocessors, set the notification deadline in hours, and choose between deletion and return at termination. The agreement downloads in editable Word and signature ready PDF, with schedules kept as separate exhibits.

6

Common mistakes to avoid

The costliest mistake is treating the DPA as boilerplate and leaving the processing description generic. Regulators read the schedule before the clauses, and a line saying only that the vendor provides services supports neither service provider status nor an Article 28 defense. Close behind is granting a broad right to use aggregated, anonymized, or derived data for product improvement. That language is standard in supplier paper and it is where model training gets smuggled in. Data that can be re-identified is still personal information, and a right to use it for the vendor's own purposes destroys service provider status.

Notification timing is the third recurring failure. Vendors offer to notify without undue delay because that is the statutory phrase, but the controller carries the seventy two hour clock and cannot start it until the vendor calls. Fix a number of hours instead. The fourth is a stale subprocessor annex listing three cloud providers when the vendor now uses eleven, breaching the flow down obligation every state statute imposes. Last, companies pick the wrong transfer module, using controller to processor clauses when their vendor is itself a processor passing data onward. Get that wrong and the transfer has no legal basis.

Key takeaways

California rules

A DPA keeps disclosures from becoming sales

Under California Civil Code 1798.100(d) and 11 CCR 7051(a), you need a written contract before disclosing personal information to a service provider. The DPA has to spell out specific business purposes and lock down use, combining, subcontracting, and monitoring. If the contract is not compliant, the recipient may not qualify as a service provider and the disclosure can be treated as a sale or share, triggering opt-out rights and enforcement risk.

EU transfers

GDPR Article 28 plus SCCs are nonnegotiable

For EU personal data, the DPA must include the GDPR Article 28(3) processor terms and control subprocessing under Article 28(2), with breach escalation under Article 33(2) without undue delay. If data leaves the EEA, you typically add the EU Standard Contractual Clauses under Decision (EU) 2021/914, using the right module for the flow. Clauses like 14 and 15 drive transfer assessments and handling government access demands.

Operations

Attach the DPA to the deal terms

A DPA usually does not stand alone; it rides under your master services agreement or SaaS order form. That structure matters because the DPA is about processing rules (subprocessors, audits, deletion at end of engagement), while the MSA supplies the commercial backbone like term, governing law, and liability cap. Do not confuse it with an NDA or a privacy policy, and remember it does not shift your responsibility away from you as the controller.

Frequently Asked Questions

Yes. Once both parties sign, a DPA is an enforceable commercial contract, and electronic signatures are valid under the ESIGN Act and the Uniform Electronic Transactions Act. It is drafted to the mandatory terms in 11 CCR section 7051, Article 28(3) GDPR, and the state processor statutes. What no template can do is verify your vendor's actual security practices. If you handle health records or biometrics at scale, have counsel review the security schedule.

They cover different regimes and are not interchangeable. A business associate agreement is a HIPAA instrument required by 45 CFR 164.504(e), reaching protected health information held by covered entities and their business associates. A data processing agreement covers personal information generally under state privacy statutes and the GDPR. A medical billing platform serving a US clinic with European patients needs both, since the HIPAA carve out in state privacy laws removes health information but leaves everything else.

Both formats come with every document. The Word file is fully editable, which matters more here than with most contracts because DPA negotiations reliably produce redlines on the audit clause, the notification window, and the subprocessor list. The PDF is formatted for signature and archiving. Schedules stay separate, so an updated annex can be reissued by notice without amending the agreement. More privacy and commercial paperwork sits in the complete US legal template library.

The statutes are vaguer than most buyers expect. Article 33(2) GDPR says a processor must notify the controller without undue delay, and state privacy laws use similar language, which pushes the real answer into the contract. The controller then has seventy two hours from becoming aware to reach its lead supervisory authority under Article 33(1), with state breach deadlines on top. Negotiate a fixed number of hours, usually twenty four to forty eight, and make the vendor name the categories of data affected in that first message.

In most cases, yes. California requires the contract before you disclose personal information to any service provider, with no European element involved, and Virginia, Colorado, Connecticut, Texas, and the newer state laws all impose written processor terms. The GDPR portion simply stays unused. The test is whether you meet any state's applicability threshold and send personal data to outside vendors. If both are true, the paperwork is required wherever your customers live.

The template makes the vendor delete or return every copy at your election within a defined period after termination, then certify in writing that it has done so. Article 28(3)(g) GDPR mandates that choice, and the state statutes require deletion or return on request. Backups are the sticking point, since few vendors can surgically remove records from immutable storage. The compromise is that backups stay covered by the agreement and are overwritten on the normal retention cycle, with that cycle written into the contract.

4.6/5

21 verified reviews · 50 000+ downloads

Data Processing Agreement | 11 CCR 7051 & GDPR Art. 28
  • Immediate access to the document
  • PDF + Word download
  • Compliant with 2026 legislation
  • Reviewed by lawyers
Fill in the template
Secure payment
Updated on September 3, 2026

You might also like

Master Services Agreement Template
Partnership Agreement Template