Data Processing Agreement (DPA) - standard by Common Paper
This Data Processing Agreement (DPA) template is designed to supplement an underlying agreement between a Customer and a Provider, detailing their respective responsibilities for processing personal data. It includes provisions for subprocessors, security contacts, and compliance with various data protection laws such as GDPR, CCPA, and international data transfer mechanisms. The template outlines key terms and standard clauses for managing personal data processing activities.
Using this DPA
This DPA has 2 parts:
The Key Terms on this Cover Page
The Common Paper DPA Standard Terms Version 1 posted at [commonpaper.com/standards/data-processing-agreement/1.0/](https://commonpaper.com/standards/data-processing-agreement/1.0/) (“DPA Standard Terms”) which is incorporated by reference.
If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be “none” or “not applicable” and the correlating clause, sentence, or section does not apply to this Agreement. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement.
Key Terms
The key legal terms of the DPA are as follows:
Agreement
This DPA supplements the [name & date of underlying agreement].
Approved Subprocessors
- [ x ] List of Subprocessors available at [insert URL]
- [ ] [Subprocessor name]
- Country of location: [list of all countries]
- Anticipated Processing task: [text box]
Provider Security Contact
[Email and/or physical address]
Security Policy
- [ x ] As defined in the Agreement.
- [ ] Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.
- [ ] Security Policy available at [insert URL of where to find]
- [ ] Provider will maintain annually updated reports or annual certifications of compliance with the following:
- [ ] ISO 27001
- [ ] Penetration testing
- [ ] SOC 2 Type I
- [ ] PCI Level 1
- [ ] SOC 2 Type II
- [ ] PCI Level 2
- [ ] HIPAA
- [ ] FedRAMP Authorized
- [ ] Other: [fill in]
Changes to the Agreement
DPA Covered Claim
- [ ] [Select if using Common Paper CSA:] The Agreement includes an additional Provider Covered Claim for any action, proceeding, or claim arising out of or relating to [(1) Provider’s breach or alleged breach of the DPA or (2) Provider’s gross negligence or willful misconduct in each case that results in a Security Incident.]
- [ ] [Select if not using Common Paper CSA:] Without limiting the indemnity obligations in the Agreement, if any, Provider will indemnify, defend, and hold harmless Customer from and against any action, proceeding, or claim made by someone other than Customer, Customer’s Affiliates, or Users, and all out-of-pocket damages, awards, settlements, costs, and expenses, including reasonable attorneys’ fees and other legal expenses that arise from [(1) Provider’s breach or alleged breach of the DPA or (2) Provider’s gross negligence or willful misconduct in each case that results in a Security Incident.]
DPA Liability Cap
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








England & Wales note
This version is drafted for England & Wales. Scotland and Northern Ireland differ on some points — for example notice periods and tribunal procedure. Tell GitLaw where you hire and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



