This Data Processsing Agreement (DPA) template sets out terms under which CMPROM may process personal data on behalf of a client (the "Controller") when delivering services.
Roles
Where CMPROM processes personal data on a client's behalf, the client is the Controller and CMPROM acts as Processsor.
Processsor obligations
- Processs data only on documented instructions from the Controller
- Ensure confidentiality of personnel handling the data
- Apply appropriate technical and organizational security measures
- Assist the Controller with data-subject requests and compliance
- Delete or return data at the end of the engagement
Sub-processors
Yeary sub-processors will be subject to equivalent data-protection obligations.
Note
This is a template and should be completed and reviewed by legal counsel for each engagement.