Skip to content

WHAT IT CONTAINS

The Data Processing Agreement, clause by clause

A Data Processing Agreement attaches the processing relationship to an underlying service agreement and then records instructions, data categories, subprocessors, transfer safeguards, incident response, audit support and what happens to the data when the service ends.

This page describes a class of document in general terms. It is not legal advice, it is not about your situation, and it is not a substitute for the advice of an attorney. Reading it creates no attorney-client relationship.

01

The document in one view

Common Paper's current DPA separates the transaction-specific processing details from reusable Standard Terms. Its Cover Page identifies the parties, the underlying agreement, the processing details and the transfer annexes; its Standard Terms then supply the operating clauses.

The first structural question is the relationship. The form distinguishes a controller appointing a processor from a processor appointing a subprocessor. The role determines which transfer module and downstream obligations the form points to, while the actual data, people, purpose and duration remain transaction-specific fields.

The transaction-specific fields are therefore as important to the record as the reusable Standard Terms.


02

Clause order

  1. 1Parties, underlying agreement and processing roles.
  2. 2Subject matter, nature, purpose, duration, data categories and data-subject categories.
  3. 3Documented processing instructions and limits on use.
  4. 4Subprocessor approval, notice, objection and flow-down obligations.
  5. 5Restricted-transfer mechanism and the applicable SCC or UK Addendum module.
  6. 6Security-incident notice, information and containment steps.
  7. 7Audit information, reports and security due diligence.
  8. 8Coordination on third-party inquiries, data requests and impact assessments.
  9. 9Return or deletion after the processing relationship ends.
  10. 10Liability allocation, conflict order, term and definitions.

03

The fields that move in review

FieldWhat the form records
Processing detailsPurpose, duration, data categories, people and frequency
Approved subprocessorsIdentity, country and processing task
Change noticeAdvance notice and objection window for a new subprocessor
Security incidentNotice timing, known facts and containment cooperation
Audit routeReports, questionnaires, inspection boundary and cadence
Restricted transfersModule, governing member state and transfer annexes
DeletionReturn, deletion, certification and any continuing retention
LiabilityWhether the service-agreement cap applies or a separate DPA cap is stated
PrecedenceWhich transfer terms, DPA terms or service terms control a conflict

04

The mark set on the Cover Page

Customer signature
signature, printed name, title and date
Provider signature
signature, printed name, title and date
Processing role
one choice for each party
Underlying agreement
one reference field
Transfer module
one selection where a restricted transfer applies
Default routing
sequential after the processing annexes are settled
Reference-form field count
12

05

What makes this page distinct

A DPA is not a privacy notice and not the service agreement itself. The privacy notice explains a company's handling of personal data to people; the DPA records the processing instructions and operational commitments between the organisations behind one service relationship.

The varying datum is the processing annex: categories, people, purpose, duration, subprocessors, locations and transfer module. Replacing those fields with generic prose produces a document that no longer identifies the processing operation it is meant to describe.

Clause text quoted from Common Paper standard agreements, © Common Paper, licensed under CC BY 4.0.


SOURCES

Where each figure came from

  1. 1. Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

    Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30

  2. 2. After the DPA expires, Provider will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law.

    Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30

  3. 3. This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.

    Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30

NEXT

OctoDoc, the signing system of record

Nobody wants to read the contract. OctoDoc is being built so you do not have to: write a document from a prompt, ask plain-language questions about the one you were sent, and keep every one of them in a single place instead of four accounts and an inbox.

Unlimited human sends on the paid tier.