WHAT IT CONTAINS
The Data Processing Agreement, clause by clause
A Data Processing Agreement attaches the processing relationship to an underlying service agreement and then records instructions, data categories, subprocessors, transfer safeguards, incident response, audit support and what happens to the data when the service ends.
This page describes a class of document in general terms. It is not legal advice, it is not about your situation, and it is not a substitute for the advice of an attorney. Reading it creates no attorney-client relationship.
01
The document in one view
Common Paper's current DPA separates the transaction-specific processing details from reusable Standard Terms. Its Cover Page identifies the parties, the underlying agreement, the processing details and the transfer annexes; its Standard Terms then supply the operating clauses.
The first structural question is the relationship. The form distinguishes a controller appointing a processor from a processor appointing a subprocessor. The role determines which transfer module and downstream obligations the form points to, while the actual data, people, purpose and duration remain transaction-specific fields.
The transaction-specific fields are therefore as important to the record as the reusable Standard Terms.
02
Clause order
- 1Parties, underlying agreement and processing roles.
- 2Subject matter, nature, purpose, duration, data categories and data-subject categories.
- 3Documented processing instructions and limits on use.
- 4Subprocessor approval, notice, objection and flow-down obligations.
- 5Restricted-transfer mechanism and the applicable SCC or UK Addendum module.
- 6Security-incident notice, information and containment steps.
- 7Audit information, reports and security due diligence.
- 8Coordination on third-party inquiries, data requests and impact assessments.
- 9Return or deletion after the processing relationship ends.
- 10Liability allocation, conflict order, term and definitions.
03
The fields that move in review
| Field | What the form records |
|---|---|
| Processing details | Purpose, duration, data categories, people and frequency |
| Approved subprocessors | Identity, country and processing task |
| Change notice | Advance notice and objection window for a new subprocessor |
| Security incident | Notice timing, known facts and containment cooperation |
| Audit route | Reports, questionnaires, inspection boundary and cadence |
| Restricted transfers | Module, governing member state and transfer annexes |
| Deletion | Return, deletion, certification and any continuing retention |
| Liability | Whether the service-agreement cap applies or a separate DPA cap is stated |
| Precedence | Which transfer terms, DPA terms or service terms control a conflict |
04
The mark set on the Cover Page
- Customer signature
- signature, printed name, title and date
- Provider signature
- signature, printed name, title and date
- Processing role
- one choice for each party
- Underlying agreement
- one reference field
- Transfer module
- one selection where a restricted transfer applies
- Default routing
- sequential after the processing annexes are settled
- Reference-form field count
- 12
05
What makes this page distinct
A DPA is not a privacy notice and not the service agreement itself. The privacy notice explains a company's handling of personal data to people; the DPA records the processing instructions and operational commitments between the organisations behind one service relationship.
The varying datum is the processing annex: categories, people, purpose, duration, subprocessors, locations and transfer module. Replacing those fields with generic prose produces a document that no longer identifies the processing operation it is meant to describe.
Clause text quoted from Common Paper standard agreements, © Common Paper, licensed under CC BY 4.0.
SOURCES
Where each figure came from
1. “Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.”
Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30
2. “After the DPA expires, Provider will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law.”
Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30
3. “This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.”
Common Paper · https://commonpaper.com/standards/data-processing-agreement/1.1/ · checked 2026-07-30
NEXT
OctoDoc, the signing system of record
Nobody wants to read the contract. OctoDoc is being built so you do not have to: write a document from a prompt, ask plain-language questions about the one you were sent, and keep every one of them in a single place instead of four accounts and an inbox.
Unlimited human sends on the paid tier.