Data Processing Agreement
This document is a versioned implementation template, not a production-ready agreement. It must be completed with the customer, processor, processing details, security measures, locations, deletion process and subprocessors, then approved by the parties before regulated customer data is processed.
Template version 2026-07-30-template-1
1. Parties and status
The customer identified in the completed order or registration record is the controller, and the legal entity identified as the production operator is the processor, except where either party acts in another role for a specific activity. This DPA applies only when the processor handles personal data on the controller’s behalf in connection with Optimus Invoicing.
2. Processing details
The subject matter, duration, nature and purpose of processing, categories of personal data, categories of data subjects, and the controller’s obligations and rights must be completed in Schedule 1 below. Processing is limited to what is necessary to provide, secure, support and terminate the contracted service and to the controller’s documented instructions, including the completed agreement and authorised use of product features. If UK law requires other processing, the processor must inform the controller before that processing unless the law prohibits the information on important grounds of public interest.
If the processor believes an instruction infringes applicable data-protection law, it will inform the controller unless the law prohibits that notice and may suspend the affected processing while the parties resolve it.
3. Confidentiality
The processor must ensure that people authorised to process personal data are bound by an appropriate duty of confidentiality and receive access only where needed for their responsibilities.
4. Security
The processor must implement measures appropriate to the risk as required by Article 32 UK GDPR. Schedule 2 must describe the measures actually operated in production, including identity and access management, encryption in transit, secret and key management, tenant isolation, secure development and patching, logging and monitoring, vulnerability handling, backups and restore tests, incident response, supplier assurance, continuity and deletion controls.
Application features alone are not a complete security programme. Schedule 2 must be verified against the deployed infrastructure before this DPA is adopted.
5. Subprocessors
The controller authorises only the subprocessors in the completed Subprocessor Schedule, under the authorisation model stated there. The processor must impose materially equivalent data-protection obligations on each subprocessor and remain responsible for its obligations under this DPA. The schedule must state how the controller will be informed of intended additions or replacements and how a reasonable objection can be raised.
6. Assistance to the controller
Taking account of the nature of processing and information available, the processor must provide reasonable assistance with data-subject requests and the controller’s obligations concerning security, personal-data breaches, data-protection impact assessments and prior consultation. The completed support schedule must identify the channels, responsibilities and any agreed charges; this template does not invent response-time commitments.
7. Personal-data breaches
The processor must notify the controller without undue delay after becoming aware of a personal-data breach affecting controller data and provide available information needed for the controller’s assessment and notifications. The production incident process and notification contacts must be completed before launch.
8. International transfers
Personal data must not be transferred outside the UK except on documented instructions or as needed to provide the agreed service and with a lawful transfer mechanism. The completed schedules must identify relevant locations, adequacy status, contractual safeguards and transfer-risk assessments. No transfer representation is made by this uncompleted template.
9. Return and deletion
At the controller’s choice following termination, the processor must return or delete personal data and delete existing copies unless applicable law requires retention. Schedule 1 must define the request/export route, active-system deletion process, backup treatment, verification and any legal exception. No fixed deletion period is promised until that schedule is completed.
10. Demonstrating compliance and audits
The processor must make available information reasonably necessary to demonstrate compliance with Article 28 and allow audits or inspections on proportionate notice, subject to appropriate confidentiality, security and disruption safeguards. The parties must complete the evidence and audit procedure before adoption.
11. Priority and liability
The final DPA should identify the order of precedence between it, the order form and the Business Terms. Liability and cost allocation must be agreed in the final contract; this template intentionally does not create a cap or indemnity.
Schedule 1 — processing instructions (completion required)
| Required field | Production entry |
|---|---|
| Controller legal name, address and contact | Not completed |
| Processor legal name, address and privacy contact | Not completed |
| Subject matter, nature and purpose | Not completed |
| Duration and termination event | Not completed |
| Categories of data subjects | Not completed |
| Categories of personal data | Not completed |
| Whether special-category or criminal-offence data is permitted | Not completed; it must not be assumed to be approved |
| Controller instructions and authorised features | Not completed |
| Controller obligations and rights | Not completed |
| Return, export, deletion and backup treatment | Not completed |
| Processing countries and transfer safeguards | Not completed |
Schedule 2 — technical and organisational measures (completion required)
The production operator must attach an accurate, deployment-specific control schedule and evidence owner. It must distinguish application controls from infrastructure and operational controls, identify material residual risks, and be reviewed whenever architecture or suppliers change.
Schedule 3 — contacts and signatures (completion required)
Complete the authorised representatives, privacy/security contacts, notice addresses, effective date and acceptance mechanism for both parties. Questions about completing this template can be sent to info@optimustech.co.uk.