What's your company name?
Use the legal name of your business. If you're signing as an individual, put your full name instead.
Generate a free GDPR-aligned DPA online. Set the controller and processor roles, record the required processing particulars, choose sub-processor and transfer terms, then preview your document and refine it with AI.
Use the legal name of your business. If you're signing as an individual, put your full name instead.
In most cases pick Corporation or LLC if you have a company. Choose Individual if you're signing as yourself.
Choose Yes if you'll sign in the editor yourself. Choose No if someone else on your side will sign.
This is how your name will appear as the signatory for your party.
A simple title like Founder or Owner is fine.
Usually your business address, or your home address if you're signing as an individual.
We'll use this when you send the document so they can complete their signature.
Use the legal name of their business. If they're an individual, put their full name instead.
In most cases this matches how they operate: Corporation, LLC, or Individual.
If you only know one contact, use that name for now. You can update it later.
In most cases this is CEO, Founder, General Counsel, or another authorized role.
Usually their principal business address. Approximate is okay if you don't have every detail yet.
We'll use this as the counterparty recipient when you send the DPA for signature.
That side is the controller. The other side is the processor, handling data only on the controller's instructions. A vendor is normally the processor.
A DPA sits under the commercial contract that governs the service. Name that agreement so the two documents line up.
Describe the nature and purpose of the processing in plain English. GDPR Article 28(3) requires this to be written down.
List the categories, separated by commas. Flag anything sensitive, such as health or financial data, so it can be handled correctly.
List the categories of people, separated by commas. Article 28(3) requires the categories of data subjects to be specified.
Most DPAs start today. Choose a custom date if you need a different effective date.
Pick the date the DPA should begin.
Things like sub-processors, international transfers, breach notification timing, audits, deletion at the end, US state privacy terms, or governing law.
Usually the state where your company is formed or where you do business. Delaware is common for US companies.
Name the country or region whose law should apply.
In most cases the processing runs for as long as the main agreement does.
Describe the period in your own words.
Article 28(2) allows either general written authorisation with advance notice, or case-by-case written approval. General authorisation is the norm for SaaS.
This is the window the controller has to raise an objection.
Chapter V of the GDPR requires a transfer mechanism. Standard Contractual Clauses are the usual answer for US vendors.
Name the mechanism the parties rely on.
The controller has 72 hours to notify its regulator, so processors are usually held to a shorter internal window.
Article 28(3)(g) requires the data to be deleted or returned when the services end.
Article 28(3)(h) requires audit rights. Once per year, plus after a breach, is the common commercial compromise.
Adds service provider language for the CCPA and similar state laws: no selling or sharing data, and no use outside the business purpose.
In most cases yes, so the two documents stay consistent. Choose No to pick a different jurisdiction.
Optional. Describe it in your own words. AI will draft the legal wording from what you write here.
This becomes the downloaded document name. You can change it later if needed.
Contract creator
Define how personal data is processed, secured, and shared between controllers and processors.
Modified from Common Paper standard terms. Common Paper standards