Bracketed details and operational commitments require completion and legal review.
1. Parties and scope
Identify the controller, processor and any subprocessor relationship: [to complete]. Describe the subject matter, duration, purpose and nature of processing, categories of personal data and categories of individuals in an attached schedule.
2. Documented instructions
The processor should process personal data only on documented lawful instructions, including approved integrations and configured platform actions, subject to applicable legal obligations.
3. Confidentiality and security
Authorised personnel must be subject to confidentiality obligations. Attach a verified schedule of technical and organisational measures; design principles and pending assurance are not a substitute for that schedule.
4. Subprocessors and transfers
List approved subprocessors, authorisation and change-notice procedures, flow-down obligations, processing locations and applicable transfer safeguards. All details require confirmation.
5. Assistance and incidents
Specify procedures for rights requests, impact assessments, regulatory enquiries and personal data breaches. Agree notification responsibilities, contacts and timing consistent with applicable law.
6. Return, deletion and assurance
Agree the return or deletion process on termination, backup handling, audit rights and the evidence available to demonstrate compliance. Complete the operational periods and any audit conditions before signature.
7. Required schedules
Schedule 1: processing details. Schedule 2: verified security controls. Schedule 3: subprocessors and locations. Schedule 4: international transfers. Schedule 5: contacts and incident procedures. These schedules remain to be completed.