Create a data processing agreement

Generate a free GDPR-aligned DPA online. Set the controller and processor roles, record the required processing particulars, choose sub-processor and transfer terms, then preview your document and refine it with AI.

You

What's your company name?

Use the legal name of your business. If you're signing as an individual, put your full name instead.

What type of party are you?

In most cases pick Corporation or LLC if you have a company. Choose Individual if you're signing as yourself.

Will you be signing this DPA?

Choose Yes if you'll sign in the editor yourself. Choose No if someone else on your side will sign.

What's your full name for the signature block?

This is how your name will appear as the signatory for your party.

What's your title?

A simple title like Founder or Owner is fine.

What's your address?

Usually your business address, or your home address if you're signing as an individual.

What's the email for your party's signer?

We'll use this when you send the document so they can complete their signature.

Them

What's their company name?

Use the legal name of their business. If they're an individual, put their full name instead.

What type of party are they?

In most cases this matches how they operate: Corporation, LLC, or Individual.

Who will sign for them?

If you only know one contact, use that name for now. You can update it later.

What's their title?

In most cases this is CEO, Founder, General Counsel, or another authorized role.

What's their address?

Usually their principal business address. Approximate is okay if you don't have every detail yet.

What's their email address?

We'll use this as the counterparty recipient when you send the DPA for signature.

Agreement

Which side decides how the personal data is used?

That side is the controller. The other side is the processor, handling data only on the controller's instructions. A vendor is normally the processor.

What agreement does this DPA attach to?

A DPA sits under the commercial contract that governs the service. Name that agreement so the two documents line up.

What is the personal data processed for?

Describe the nature and purpose of the processing in plain English. GDPR Article 28(3) requires this to be written down.

What types of personal data are processed?

List the categories, separated by commas. Flag anything sensitive, such as health or financial data, so it can be handled correctly.

Whose personal data is processed?

List the categories of people, separated by commas. Article 28(3) requires the categories of data subjects to be specified.

When should the agreement take effect?

Most DPAs start today. Choose a custom date if you need a different effective date.

What is the effective date?

Pick the date the DPA should begin.

Do you require any advanced terms?

Things like sub-processors, international transfers, breach notification timing, audits, deletion at the end, US state privacy terms, or governing law.

Which state's law should govern?

Usually the state where your company is formed or where you do business. Delaware is common for US companies.

Which jurisdiction?

Name the country or region whose law should apply.

Advanced

How long will the processing last?

In most cases the processing runs for as long as the main agreement does.

How long should the processing last?

Describe the period in your own words.

How should sub-processors be approved?

Article 28(2) allows either general written authorisation with advance notice, or case-by-case written approval. General authorisation is the norm for SaaS.

How much notice before a new sub-processor is added?

This is the window the controller has to raise an objection.

Will personal data be transferred outside the EEA or UK?

Chapter V of the GDPR requires a transfer mechanism. Standard Contractual Clauses are the usual answer for US vendors.

Which transfer safeguard applies?

Name the mechanism the parties rely on.

How quickly must a personal data breach be reported?

The controller has 72 hours to notify its regulator, so processors are usually held to a shorter internal window.

What happens to the personal data at the end?

Article 28(3)(g) requires the data to be deleted or returned when the services end.

How often can the controller audit?

Article 28(3)(h) requires audit rights. Once per year, plus after a breach, is the common commercial compromise.

Add US state privacy terms?

Adds service provider language for the CCPA and similar state laws: no selling or sharing data, and no use outside the business purpose.

Should this DPA follow the main agreement's governing law?

In most cases yes, so the two documents stay consistent. Choose No to pick a different jurisdiction.

Anything else to include?

Optional. Describe it in your own words. AI will draft the legal wording from what you write here.

Preview

What would you like to name the file?

This becomes the downloaded document name. You can change it later if needed.

Contract creator

Data Processing Agreement

Define how personal data is processed, secured, and shared between controllers and processors.

press Enter

Modified from Common Paper standard terms. Common Paper standards