Data Processing Agreement by Common Paper

Open Legal LibraryUpdated 24 Oct 2025

The Common Paper Data Processing Agreement (DPA) is a standard agreement that explains how personal data should be handled between controllers and processors and makes sure it follows GDPR, CCPA, and other privacy laws. It is part of Common Paper’s trusted library of open, lawyer-checked standard agreements.

Data Processing Agreement (DPA)

USING THIS DPA

This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1.1 posted at http://commonpaper.com/standards/data-processing-agreement/1.1/ ("DPA Standard Terms"), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be "none" or "not applicable" and the correlating clause, sentence, or section does not apply to this DPA. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement. A copy of the DPA Standard Terms is attached for convenience only.

Key Terms

The key legal terms of the DPA are as follows:

Agreement

This DPA supplements the [underlying agreement].

Approved Subprocessors

Identify all subprocessors or link to a list of subprocessors available online.

[ ] List of Subprocessors available at [subprocessors url]

[ ] [subprocessor name]
Country of location: [List of all countries]
Anticipated Processing task: [text box]

Provider Security Contact

[provider security contact]

Security Policy

Select and customize those that apply and delete the rest.

[ ] As defined in the Agreement.

[ ] Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.

[ ] Security Policy available at [security policy url]

[ ] Provider will maintain annually updated reports or annual certifications of compliance with the following:

[ ] ISO 27001

[ ] SOC 2 Type I

[ ] SOC 2 Type II

[ ] HIPAA

[ ] Penetration testing

[ ] PCI Level 1

[ ] PCI Level 2

[ ] FedRAMP Authorized

[ ] Other: [fill in]

Changes to the Agreement

If this DPA does not include a separate indemnity, liability cap, or governing law from the Agreement, delete this entire section.

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu
Jurisdiction
General
Source
Data Processing Agreement by Common Paper
from Common Paper
Document info
HTML document. Document created on Fri Sep 12th, 2025. Last updated on Fri Oct 24th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
General
Data Protection Addendum (DPA)
The Data Protection Addendum (DPA) is a modular, lawyer-vetted addendum that supplements core SaaS or cloud service agreements to address data processing obligations, cross-border transfers, security, and privacy compliance. It is part of OLL’s widely trusted library of open, lawyer-vetted standard agreements.
Updated 10 Nov 2025
Data Sharing Agreement
This Data Sharing Agreement outlines the terms under which a Data Collector shares specific information, referred to as "the data" and a "Limited Dataset," with a Recipient. It details the information to be shared, payment terms, and strict restrictions on the Recipient's use, contact with participants, disclosure, and data protection measures. The agreement also includes provisions for notifying the Data Collector in case of security breaches or pertinent discoveries.
Updated 17 Oct 2025
Data Use Agreement
This Data Use Agreement outlines the terms under which a Data Provider will share specific data with a Data Collector. It details the scope of the data, including a limited dataset that excludes identifying factors, and establishes restrictions on how the Data Collector and any third-party recipients may use and protect this information. The agreement also includes provisions for notifying parties in case of security breaches or pertinent discoveries.
Updated 17 Oct 2025
England & Wales
Data Breach Notification Policy
This template sets out the organisation’s process for identifying, managing, recording, and reporting personal data breaches in compliance with the UK GDPR and the Data Protection Act 2018. It explains staff responsibilities, internal escalation, and when and how breaches must be notified to the ICO and affected individuals.
Updated 7 Feb 2026
US
Data Protection Policy by EasyLegalDocs
This Cybersecurity Policy outlines the company’s commitment to protecting the confidentiality, integrity, and availability of its information assets through measures such as access control, data protection, incident response, and vendor oversight. It establishes procedures for data handling, employee training, and compliance to ensure adherence to applicable U.S. laws and recognized cybersecurity frameworks.
Updated 11 Nov 2025
US
Business Associate Agreement by Common Paper
The Common Paper Business Associate Agreement (BAA) is designed to enable HIPAA covered entities to share protected health information with SaaS providers and other business associates. It is part of CommonPaper’s widely trusted library of open, lawyer-vetted standard agreements.
Updated 11 Aug 2026
US
Business Associate Agreement by Bonterms
The Bonterms Business Associate Agreement (BAA) is designed to enable HIPAA covered entities to exchange protected health information with SaaS providers and other business associates. It is part of Bonterms’ widely trusted library of open, lawyer-vetted standard agreements.
Updated 10 Nov 2025
US
Subprocessors - US & EU Subprocessors (Basecamp)
This “Subprocessors” policy outlines the company’s use of trusted third-party service providers to help operate its products—such as cloud hosting, analytics, or customer support tools. It explains that all subprocessors have GDPR-compliant agreements in place to ensure the same level of data protection as the company itself provides.
Updated 20 Oct 2025
European Union
Data Processing Agreement (DPA) - standard by Common Paper
This Data Processing Agreement (DPA) template is designed to supplement an underlying agreement between a Customer and a Provider, detailing their respective responsibilities for processing personal data. It includes provisions for subprocessors, security contacts, and compliance with various data protection laws such as GDPR, CCPA, and international data transfer mechanisms. The template outlines key terms and standard clauses for managing personal data processing activities.
Updated 17 Oct 2025

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.