Since 2018
Privacy-safe enterprise data
VOSB & SDVOSB
U.S. Veteran-Owned, Service-Disabled
SCC Transfers
EU/UK/CH per privacy policy
GDPR · CCPA · CPRA
Consent-first data sourcing
Template version: 2026-05. PDF: gsdsi-dpa-template-2026.pdf
An editable DOCX can be supplied by the compliance desk after diligence scoping: email compliance@gsdsi.com with your corporate template requirements.
How to accelerate review
- Download the PDF narrative and circulate with privacy + procurement.
- Diff your enterprise standard against ours: deltas cluster around subprocessors, SLA windows, and audit clauses.
- Send redlines to your GSDSI contact or compliance@gsdsi.com.
- GSDSI compliance typically responds inside five US business days with consolidated comments.
Key template modules
- Roles: customer as controller / GSDSI as processor within described scope
- EU SCCs Module 2 (controller-to-processor) as annex reference
- Sub-processor disclosures + notification cadence referenced to /trust/sub-processors
- Technical measures: TLS 1.2+, AES-256, MFA, RBAC, logging
- Security incident timelines aligned with the published breach SLA
- Assistance commitments for regulator and data-subject workflows
- Audit rights conditioned on SOC 2 or equivalent artefacts when available
- Returns / deletion instructions at termination
