Skip to content
Trust

Data Processing Agreement Template

Controller-processor scaffolding aligned to Standard Contractual Clauses, GDPR Art. 28, and CCPA service-provider expectations. Negotiate deltas with your GSDSI contact or compliance inbox.

Draft: counsel review required

The downloadable PDF is watermarked as a draft negotiating template and is not executable until mutually signed by both parties. Route final language through GSDSI legal if you diverge materially from published obligations.

Since 2018

Privacy-safe enterprise data

VOSB & SDVOSB

U.S. Veteran-Owned, Service-Disabled

SCC Transfers

EU/UK/CH per privacy policy

GDPR · CCPA · CPRA

Consent-first data sourcing

Template version: 2026-05. PDF: gsdsi-dpa-template-2026.pdf

An editable DOCX can be supplied by the compliance desk after diligence scoping: email compliance@gsdsi.com with your corporate template requirements.

How to accelerate review

  1. Download the PDF narrative and circulate with privacy + procurement.
  2. Diff your enterprise standard against ours: deltas cluster around subprocessors, SLA windows, and audit clauses.
  3. Send redlines to your GSDSI contact or compliance@gsdsi.com.
  4. GSDSI compliance typically responds inside five US business days with consolidated comments.

Key template modules

  • Roles: customer as controller / GSDSI as processor within described scope
  • EU SCCs Module 2 (controller-to-processor) as annex reference
  • Sub-processor disclosures + notification cadence referenced to /trust/sub-processors
  • Technical measures: TLS 1.2+, AES-256, MFA, RBAC, logging
  • Security incident timelines aligned with the published breach SLA
  • Assistance commitments for regulator and data-subject workflows
  • Audit rights conditioned on SOC 2 or equivalent artefacts when available
  • Returns / deletion instructions at termination

Frequently asked questions about the DPA template

Is the downloadable PDF a binding agreement?

No. It is a watermarked drafting template for negotiating teams. Executable obligations emerge only after both parties countersign an order referencing the final DPA or equivalent data processing exhibit.

Which transfer mechanisms does the template reference?

The scaffold references SCC Module 2 (controller-to-processor) where GDPR/UK GDPR transfers apply and aligns supplementary measures with TLS 1.2+, AES-256 storage, MFA, RBAC, and subprocessors enumerated on /trust/sub-processors.

Where can procurement review subprocessors?

The live disclosure table lives at /trust/sub-processors: updated quarterly or sooner when materially new processors join production workflows; enterprise notices follow contract terms.

What incident timelines appear in diligence?

Tiered breach notifications start with GDPR-class 72-hour notice for confirmed unauthorized access to identified customer payloads, escalate preliminary notices inside five US business days for suspected incidents, and document non-customer-impact events according to contractual reporting cadences. See /trust/security-program for verbatim SLA language.

✓ Opt-Out Request Honored via Global Privacy Control