Data Processing Agreement by Common Paper

OLOpen Legal LibraryUpdated 24 Oct 2025

The Common Paper Data Processing Agreement (DPA) is a standard agreement that explains how personal data should be handled between controllers and processors and makes sure it follows GDPR, CCPA, and other privacy laws. It is part of Common Paper’s trusted library of open, lawyer-checked standard agreements.

Data Processing Agreement (DPA)

USING THIS DPA

This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1.1 posted at http://commonpaper.com/standards/data-processing-agreement/1.1/ ("DPA Standard Terms"), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be "none" or "not applicable" and the correlating clause, sentence, or section does not apply to this DPA. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. A copy of the DPA Standard Terms is attached for convenience only.

Key Terms

The key legal terms of the DPA are as follows:

Agreement

This DPA supplements the [underlying agreement].

Approved Subprocessors

Identify all subprocessors or link to a list of subprocessors available online.

[ ] List of Subprocessors available at [subprocessors url]

[ ] [subprocessor name]
Country of location: [List of all countries]
Anticipated Processing task: [text box]

Provider Security Contact

[provider security contact]

Security Policy

Select and customize those that apply and delete the rest.

[ ] As defined in the Agreement.

[ ] Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.

[ ] Security Policy available at [security policy url]

[ ] Provider will maintain annually updated reports or annual certifications of compliance with the following:

[ ] ISO 27001

[ ] SOC 2 Type I

[ ] SOC 2 Type II

[ ] HIPAA

[ ] Penetration testing

[ ] PCI Level 1

[ ] PCI Level 2

[ ] FedRAMP Authorized

[ ] Other: [fill in]

Changes to the Agreement

If this DPA does not include a separate indemnity, liability cap, or governing law from the Agreement, delete this entire section.

DPA Covered Claim

Select the box to include this language and customize the yellow-highlighted language to add indemnity obligations specific to the DPA. If you do not want to provide a separate indemnity with this DPA, delete this row entirely.

[ ] select if using Common Paper CSA:The Agreement includes an additional Provider Covered Claim for any action, proceeding, or claim arising out of or relating to

(1) Provider’s breach or alleged breach of the DPA

or

(2) Provider’s gross negligence or willful misconduct, in each case, that results in a Security Incident.

[ ] select if not using Common Paper CSA:Without limiting the indemnity obligations in the Agreement, if any, Provider will indemnify, defend, and hold harmless Customer from and against any action, proceeding, or claim made by someone other than Customer, Customer’s Affiliates, or Users, and all out-of-pocket damages, awards, settlements, costs, and expenses, including reasonable attorneys’ fees and other legal expenses, that arise from

(1) Provider’s breach or alleged breach of the DPA

or

(2) Provider’s gross negligence or willful misconduct, in each case, that results in a Security Incident.

DPA Liability Cap

Select the box to include this language and customize the yellow-bracketed amounts to add a separate super cap specific to DPA Covered Claims. If you do not want to provide a separate liability cap for DPA Covered Claims, delete this row entirely.

[ ] The Agreement includes an additional Increased Claim for DPA Covered Claims, with a separate Increased Cap Amount of the greater of $[dpa cap amount fixed] or [dpa cap multiplier] times the fees paid or payable by Customer to Provider in the 12 month period immediately before the claim.

[ ] The following is added to the end of Section 8.1 of the DPA Standard Terms:

However, Provider’s total cumulative liability arising out of or related to DPA Covered Claims will not be more than the greater of $[dpa cap amount fixed] or [dpa cap multiplier] times the fees paid or payable by Customer to Provider in the 12 month period immediately before the claim.

Governing Law and Chosen Courts

Select the box / include this language to modify the governing law and jurisdiction for this DPA (governing law for SCCs are handled in the Restricted Transfer section). If you do not want to modify the governing law and jurisdiction from the Agreement, delete this row entirely.

[ ] Notwithstanding the governing law or similar clauses of the Agreement, all interpretations and disputes about this DPA will be governed by the laws of the [governing state] without regard to its conflict of laws provisions. In addition, and notwithstanding the forum selection, jurisdiction, or similar clauses of the Agreement, the parties agree to bring any legal suit, action, or proceeding about this DPA in, and each party irrevocably submits to the exclusive jurisdiction of, the courts of the [governing state].

Governing State means: [governing state]

Service Provider Relationship

Select the box / include this language to affirm a service provider relationship and that no sale of personal information (e.g., as regulated by CCPA) will occur.

[ ] To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

Restricted Transfers

Governing Member State

Select EEA for data transfers originating within the EEA; select UK for data transfers originating within the UK

[ ] EEA Transfers: [governing member state]

[ ] UK Transfers: [governing member state]

Annex I(A) List of Parties

Data Exporter

Name: Customer
Address: [customer physical address]
Contact Person:
Name: [customer contact name]
Position: [customer contact title]
Address: [customer contact address]
Activities relevant to transfer: See Annex 1(B)
Role: [data exporter role]

Data Importer

Name: Provider
Address: [provider physical address]
Contact Person:
Name: [provider contact name]
Position: [provider contact title]
Address: [provider contact address]
Activities relevant to transfer: See Annex 1(B)
Role: Processor

Annex I(B) Description of Transfer and Processing Activities

Service

[service name]

Categories of Data Subjects

Select all that apply, customize as needed, and delete the rest.

[ ] Customer’s end users or customers

[ ] Customer’s employees

[ ] [custom option(1)]

Categories of Personal Data

Select all that apply, customize as needed, and delete the rest.

[ ] Name

[ ] Contact information such as email, phone number, or address

[ ] Employment information such as employee ID or compensation

[ ] Financial information such as bank account numbers

[ ] Professional or biographic information such as resume or CV

[ ] Transactional information such as account information or purchases

[ ] User activity and analysis such as device information or IP address

[ ] Location information

[ ] [custom option (2)]

Special Category Data
Is special category data Processed?

Select one or the other

( ) Yes ( ) No

Special Category Data Restrictions or Safeguards

 If “Yes” is selected above, identify the safeguards in place to protect special category data by checking the applicable box, customizing as needed, and deleting the rest. If “No” is selected above, delete this entire row.

[ ] See Security Policy

[ ] [custom option (3)]

Frequency of Transfer

Select all that apply, customize as needed, and delete the rest.

[ ] Continuous

[ ] [custom options (1)]

Nature and Purpose of Processing

Provider will Process Customer Personal Data as instructed in Section 3.2 of the DPA Standard Terms. The nature of processing includes:

Select all that are applicable, customize as needed, and delete the rest.

[ ] Receiving data, including collection, accessing, retrieval, recording, and data entry

[ ] Holding data, including storage, organization, and structuring

[ ] Using data, including analysis, consultation, testing, automated decision making, and profiling

[ ] Updating data, including correcting, adaptation, alteration, alignment, and combination

[ ] Protecting data, including restricting, encrypting, and security testing

[ ] Sharing data, including disclosure, dissemination, allowing access, or otherwise making available

[ ] Returning data to the data exporter or data subject

[ ] Erasing data, including destruction and deletion

[ ] [custom options (2)]

Duration of Processing

Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.

Annex I(C)

Competent Supervisory Authority

The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.

Annex II

Technical and Organizational Security Measures

Select all that are applicable, customize as needed, and delete the rest.

[ x ] See Security Policy

[ ] Pseudonymization and encryption of personal data:
describe the measures

[ ] Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services:
describe the measures

[ ] Ability to restore the availability of and access to Customer Personal Data in a timely manner following a physical or technical incident:
describe the measures

[ ] Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure Processing:
describe the measures

[ ] User identification and authorization process and protection:
describe the measures

[ ] Protecting Customer Personal Data during transmission (in transit):
describe the measures

[ ] Protecting Customer Personal Data during storage (at rest):
describe the measures

[ ] Physical security where Customer Personal Data is processed:
describe the measures

[ ] Events logging:
describe the measures

[ ] Systems configuration, including default configuration:
describe the measures

[ ] Internal IT and IT security governance and management:
describe the measures

[ ] Certification or assurance of processes and products:
describe the measures

[ ] Ensuring data minimization:
describe the measures

[ ] Ensuring data quality:
describe the measures

[ ] Ensuring limited data retention:
describe the measures

[ ] Ensuring accountability:
describe the measures

[ ] Allowing data portability and ensuring erasure:
describe the measures

Provider and Customer have not changed the DPA Standard Terms except for the details on the Cover Page above. By signing this Cover Page, each party agrees to enter into this DPA as of the last date of signature below.

PROVIDER: [provider name]

CUSTOMER: [customer name]

Signature

Print Name

[provider signatory name]

[customer signatory name]

Title

[provider signatory title]

[customer signatory title]

Date

[provider signature date]

[customer signature date]

Standard Terms

Processor and Subprocessor Relationships

Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.

Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.

Processing

Processing Details. Annex I(B) on the Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.

Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer’s use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA. Provider will abide by these instructions unless prohibited from doing so by Applicable Laws. Provider will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.

Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or include new products, features, or functionality, Provider may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes.

Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer’s Processing of Customer Personal Data. Customer’s agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer’s agreement with its Controller.

Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws.

Subprocessors.

Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors includes the identities of the Subprocessors, their country of location, and their anticipated Processing tasks. Provider will inform Customer at least 10 business days in advance and in writing of any intended changes to the Approved Subprocessors whether by addition or replacement of a Subprocessor, which allows Customer to have enough time to object to the changes before the Provider begins using the new Subprocessor(s). Provider will give Customer the information necessary to allow Customer to exercise its right to object to the change to Approved Subprocessors. Customer has 30 days after notice of a change to the Approved Subprocessors to object, otherwise Customer will be deemed to accept the changes. If Customer objects to the change within 30 days of notice, Customer and Provider will cooperate in good faith to resolve Customer’s objection or concern.

When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of Agreement.

If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor, and (ii) Provider’s agreement with the Subprocessor will incorporate these obligations, including details about how Provider and its Subprocessor will coordinate to respond to inquiries or requests about the Processing of Customer Personal Data. In addition, Provider will share, at Customer’s request, a copy of its agreements (including any amendments) with its Subprocessors. To the extent necessary to protect business secrets or other confidential information, including personal data, Provider may redact the text of its agreement with its Subprocessor prior to sharing a copy.

Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Provider and the Subprocessor.

Restricted Transfers

Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards for the transfer of Customer Personal Data to that territory consistent with Applicable Data Protection Laws.

Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows:

Module Two (Controller to Processor) of the EEA SCCs apply when Customer is a Controller and Provider is Processing Customer Personal Data for Customer as a Processor.

Module Three (Processor to Sub-Processor) of the EEA SCCs apply when Customer is a Processor and Provider is Processing Customer Personal Data on behalf of Customer as a Subprocessor.

For each module, the following applies (when applicable):

The optional docking clause in Clause 7 does not apply;

In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 10 business days;

In Clause 11, the optional language does not apply;

All square brackets in Clause 13 are removed;

In Clause 17 (Option 1), the EEA SCCs will be governed by the laws of Governing Member State;

In Clause 18(b), disputes will be resolved in the courts of the Governing Member State; and

The Cover Page to this DPA contains the information required in Annex I, Annex II, and Annex III of the EEA SCCs.

Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows:

Section 3.2 of this DPA contains the information required in Table 2 of the UK Addendum.

Table 4 of the UK Addendum is modified as follows: Neither party may end the UK Addendum as set out in Section 19 of the UK Addendum; to the extent ICO issues a revised Approved Addendum under Section ‎18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly.

The Cover Page contains the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum.

Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.

Security Incident Response

Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) promptly take reasonable steps to contain and investigate the Security Incident. Provider’s notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.

Audit & Reports

Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits, including inspections by Customer, to assess Provider’s compliance with this DPA. However, Provider may restrict access to data or information if Customer’s access to the information would negatively impact Provider’s intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will only exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.

Security Reports. Customer acknowledges that Provider is regularly audited against the standards defined in the Security Policy by independent third-party auditors. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report so that Customer can verify Provider’s compliance with the standards defined in the Security Policy.

Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider’s compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to the Provider Security Contact and may only be made once a year.

Coordination & Cooperation

Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer’s prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Provider will follow Customer’s reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer’s giving of Customer Personal Data to Provider, Provider will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Provider will cooperate with and provide reasonable assistance to Customer, at Customer’s expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider’s Processing of Customer Personal Data under this DPA.

DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.

Deletion of Customer Personal Data

Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law.

Deletion at DPA Expiration.

After the DPA expires, Provider will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law. If return or destruction is impracticable or prohibited by Applicable Laws, Provider will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Provider to continue hosting or Processing Customer Personal Data.

If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs if Customer asks for one.

Limitation of Liability

Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party’s total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.

Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.

Exceptions. This DPA does not limit any liability to an individual about the individual’s data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.

Conflicts Between Documents

This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.

Term of Agreement

This DPA will start when Provider and Customer agree to a Cover Page for the DPA and sign or electronically accept the Agreement and will continue until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.

Definitions.

Applicable Laws” means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.

Applicable Data Protection Laws” means the Applicable Laws that govern how the Service may process or use an individual’s personal information, personal data, personally identifiable information, or other similar term.

Controller” will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.

Cover Page” means a document that is signed or electronically accepted by the parties that incorporates these DPA Standard Terms and identifies Provider, Customer, and the subject matter and details of the data processing.

Customer Personal Data” means Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.

DPA” means these DPA Standard Terms, the Cover Page between Provider and Customer, and the policies and documents referenced in or attached to the Cover Page.

EEA SCCs” means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.

European Economic Area” or “EEA” means the member states of the European Union, Norway, Iceland, and Liechtenstein.

GDPR” means European Union Regulation 2016/679 as implemented by local law in the relevant EEA member nation.

Personal Data” will have the meaning(s) given in the Applicable Data Protection Laws for personal information, personal data, or other similar term.

Processing” or “Process” will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.

Processor” will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.

Report” means audit reports prepared by another company according to the standards defined in the Security Policy on behalf of Provider.

Restricted Transfer” means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.

Security Incident” means a Personal Data Breach as defined in Article 4 of the GDPR.

Service” means the product and/or services described in the Agreement.

"Special Category Data” will have the meaning given in Article 9 of the GDPR.

Subprocessor” will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.

UK GDPR” means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom’s European Union (Withdrawal) Act of 2018 in the United Kingdom.

UK Addendum” means the international data transfer addendum to the EEA SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu
Jurisdiction
General
Source
CP
Data Processing Agreement by Common Paper
from Common Paper
Document info
HTML document. Document created on Fri Sep 12th, 2025. Last updated on Fri Oct 24th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
FeaturedGeneral
Term sheet by Common Paper
Outline the initial terms of a business deal with this non-binding term sheet. It sets a framework for negotiating a **Definitive Agreement** while including legally binding confidentiality protections for both parties.
Updated 13 Aug 2026
General
Landscaping Contract by EasyLegalDocs
This landscaping services agreement establishes the terms for garden maintenance, design, and installation work at a client's property. It covers recurring service schedules, payment terms, and technical requirements for project modifications.
Updated 13 Aug 2026
General
Statement of Counterclaim (Pleading) (ICC Rules) by OLL
This template provides a structured **Statement of Counterclaim** for international arbitration under the ICC Rules (2026). It serves as a secondary pleading to elaborate on claims first raised in the Respondent's Answer.
Updated 13 Aug 2026
Business Development Agreement
This agreement establishes a professional relationship where one party provides specialized **business development and tender advisory services** to another. It includes specific provisions for a success-based commission calculated as a percentage of contract value if a bid is awarded.
Updated 13 Aug 2026
Delaware (US)
Graphic Design Contract by EasyLegalDocs
This contract establishes the terms for a graphic design project between a client and a freelance designer. It specifies **ownership of deliverables**, payment schedules including a deposit and net 30 terms, and intellectual property rights under **Delaware law**.
Updated 13 Aug 2026
Lease Assignment Agreement by EasyLegalDocs
Transfer a tenant's rights and obligations under an existing lease to a new person or entity. This document requires the **Landlord's written consent** and includes representations that the original lease is currently in good standing. It effectively swaps the parties for the remainder of the term.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by thousands of businesses

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work, with practicing lawyers

Trained on 5.5K+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

Portrait headshots of the independent lawyers on the GitLaw standards committee

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Start free

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.