On this pageStandard terms

Common Paper Data Processing Agreement

This is a fillable cover page for the Common Paper Data Processing Agreement. The binding terms are the external Standard Terms linked below — fill the fields here, then download the Word file to execute.

Standard terms

This cover page references the Standard Terms posted externally. View standard terms at https://commonpaper.com/standards/data-processing-agreement/1.1.

Parties

FieldDescriptionDefault
Company NameOfficial company name
Customer Contact NameCustomer contact name
Customer Contact TitleCustomer contact title
Customer AddressCustomer's physical address
Provider Contact NameProvider contact name
Provider Contact TitleProvider contact title
Provider AddressProvider's physical address
Physical AddressPhysical address for notifications
Contact AddressEmail and/or physical address

Service

FieldDescriptionDefault
Product NameName of product or service

Terms

FieldDescriptionDefault
Underlying AgreementName and date of the underlying agreement
Provider RoleProvider's role (Controller or Processor)
Custom OptionCustom option for selections
Custom OptionsMultiple custom options
UrlURL for references
Csa ReferenceCommon Paper CSA reference
Non Csa ReferenceNon-CSA agreement reference
Text BoxGeneral text box entry
FieldDescriptionDefault
Governing LawGoverning law state/province/country
Eu Member StateEU Member State for disputes
Uk Governing LawUK governing law selection
Dpa Covered Claims DetailSpecific scope of DPA Covered Claims (e.g., breach of DPA, gross negligence resulting in Security Incident)
Has Dpa Governing LawSet to true when DPA-specific governing law overrides the Agreement's governing law clause.
Has Ccpa TermsSet to true when California Consumer Privacy Act (CCPA) terms are included in the DPA.

Privacy

FieldDescriptionDefault
Subprocessor NameSubprocessor name
Countries ListList of all countries for data transfers
Security MeasuresDescription of security measures
Policy UrlURL of where to find policies
Has SubprocessorSet to true when a pre-approved subprocessor is specified.
Has Eea TransfersSet to true when EEA data transfer mechanisms are specified.
Has Uk TransfersSet to true when UK data transfer mechanisms are specified.
Data Subject End UsersSet to true when end users or customers are included as data subjects.
Data Subject EmployeesSet to true when employees are included as data subjects.
Data Subject CustomSet to true to include a custom data subject category. Specify in custom_option.
Pd NameSet to true when Name is a category of personal data processed.
Pd ContactSet to true when contact information (email, phone, address) is a category of personal data processed.
Pd EmploymentSet to true when employment information (employee ID, compensation) is a category of personal data processed.
Pd FinancialSet to true when financial information (bank account numbers) is a category of personal data processed.
Pd ProfessionalSet to true when professional or biographic information (resume, CV) is a category of personal data processed.
Pd TransactionalSet to true when transactional information (account info, purchases) is a category of personal data processed.
Pd User ActivitySet to true when user activity and analysis (device info, IP address) is a category of personal data processed.
Pd LocationSet to true when location information is a category of personal data processed.
Pd CustomSet to true to include a custom personal data category. Specify in custom_option.
Processing ContinuousSet to true when data processing is continuous.
Processing Frequency CustomSet to true to specify a custom processing frequency. Specify in custom_options.
Pa ReceivingSet to true when receiving data (collection, accessing, retrieval) is a processing activity.
Pa HoldingSet to true when holding data (storage, organization, structuring) is a processing activity.
Pa UsingSet to true when using data (analysis, consultation, testing) is a processing activity.
Pa UpdatingSet to true when updating data (correcting, adaptation, alteration) is a processing activity.
Pa ProtectingSet to true when protecting data (restricting, encrypting, testing) is a processing activity.
Pa SharingSet to true when sharing data (disclosure, dissemination) is a processing activity.
Pa ReturningSet to true when returning data to the data exporter or data subject is a processing activity.
Pa ErasingSet to true when erasing data (destruction, deletion) is a processing activity.
Pa CustomSet to true to include a custom processing activity. Specify in custom_options.

Security

FieldDescriptionDefault
Other Security CertificationName of additional security certification (e.g. "ISO 27701 Privacy Information Management")
Dpa Security Reasonable EffortsSet to true when Provider will use commercially reasonable efforts to secure the Service from unauthorized access.
Has Dpa Security PolicySet to true when Provider has a Security Policy available at the specified policy_url.
Has Dpa Security CertificationsSet to true when Provider maintains annually updated security reports or certifications.
Cert Iso 27001Set to true when Provider holds ISO 27001 certification.
Cert Penetration TestingSet to true when Provider performs regular penetration testing.
Cert Soc2 Type1Set to true when Provider holds SOC 2 Type I certification.
Cert Pci Level1Set to true when Provider holds PCI Level 1 certification.
Cert Soc2 Type2Set to true when Provider holds SOC 2 Type II certification.
Cert Pci Level2Set to true when Provider holds PCI Level 2 certification.
Cert HipaaSet to true when Provider holds HIPAA certification.
Cert FedrampSet to true when Provider holds FedRAMP Authorization.
Cert OtherSet to true to include an additional security certification. Specify the certification in other_security_certification.
Security Measures See PolicySet to true when security measures reference the Security Policy.
Security Measures CustomSet to true to include custom security measures. Specify in custom_option.
Sm PseudonymizationSet to true when pseudonymization and encryption of personal data is a security measure.
Sm ConfidentialitySet to true when ensuring ongoing confidentiality, integrity, availability, and resilience is a security measure.
Sm RestoreSet to true when ability to restore availability and access after incidents is a security measure.
Sm TestingSet to true when regular testing and evaluation of security measures is a security measure.
Sm User AuthSet to true when user identification and authorization process protection is a security measure.
Sm TransitSet to true when protecting personal data during transmission (in transit) is a security measure.
Sm StorageSet to true when protecting personal data during storage (at rest) is a security measure.
Sm PhysicalSet to true when physical security of processing locations is a security measure.
Sm LoggingSet to true when events logging is a security measure.
Sm ConfigSet to true when systems configuration and default configuration is a security measure.
Sm GovernanceSet to true when internal IT and IT security governance and management is a security measure.
Sm CertificationSet to true when certification or assurance of processes and products is a security measure.
Sm MinimizationSet to true when data minimization is a security measure.
Sm QualitySet to true when ensuring data quality is a security measure.
Sm RetentionSet to true when ensuring limited data retention is a security measure.
Sm AccountabilitySet to true when ensuring accountability is a security measure.
Sm PortabilitySet to true when allowing data portability and ensuring erasure is a security measure.

Liability

FieldDescriptionDefault
Cap MultiplierLiability cap multiplier
Greater Of DollarDollar amount for the greater-of liability cap
Indemnification Csa ReferenceSet to true when using Common Paper CSA-style indemnification reference for DPA Covered Claims.
Indemnification Non Csa ReferenceSet to true when using non-CSA indemnification language for DPA Covered Claims.
Cap Csa ReferenceSet to true when using CSA-style Increased Claim cap for DPA Covered Claims.
Cap Non Csa ReferenceSet to true when using non-CSA liability cap language for DPA Covered Claims.

Signature Block

FieldDescriptionDefault
Provider Signatory TypeWhether the Provider signatory is an entity or individualentity
Provider Signatory NameFull legal name of the Provider's signatory
Provider Signatory TitleTitle/role of the Provider's signatory (entity only)
Provider Signatory CompanyCompany name for the Provider signatory (entity only)
Customer Signatory TypeWhether the Customer signatory is an entity or individualentity
Customer Signatory NameFull legal name of the Customer's signatory
Customer Signatory TitleTitle/role of the Customer's signatory (entity only)
Customer Signatory CompanyCompany name for the Customer signatory (entity only)

This template is a drafter's starting point. It does not constitute legal advice. Workflow support only. Not legal advice.

Based on the Common Paper Data Processing Agreement, available at https://commonpaper.com. Licensed under CC BY 4.0. Copyright Common Paper, Inc.