Skip to content

Free U.S. Data Processing Addendum (DPA) Template

A processor‑friendly Data Processing Addendum for handling personal data within the United States, defining clear processing limits, required security measures, incident‑response obligations, and state‑privacy‑law compliance.

Category
Data & Privacy
License
CC0 1.0
Source files
GitHub

What is a U.S. Data Processing Addendum?

A U.S. Data Processing Addendum (DPA) supplements a primary services agreement and establishes contractual rules for how one party processes personal data on behalf of another.

This template uses “Customer” for the party engaging the service provider and “Provider” for the party processing personal data in connection with the contracted services.

Depending on the parties’ roles and the U.S. state privacy laws that apply, a DPA may be used to document processing instructions, security responsibilities, subprocessor requirements, assistance with consumer requests, incident-response procedures, and data return or deletion.

This template also addresses restrictions on unauthorized data use, AI and machine-learning use, automated decision-making, and other provisions that may be relevant when a service provider handles personal data for a business.

When do you need a DPA?

A business may need a DPA when a vendor, SaaS provider, or other service provider processes personal data on its behalf and applicable privacy law or the parties’ commercial requirements call for specific data-processing terms.

A DPA may be particularly relevant when a provider will access, store, transmit, analyze, or otherwise process personal data while delivering services.

Depending on the relationship and applicable law, the agreement may need to address:

  • How and why the Provider may process personal data
  • Required security measures
  • Security-incident notification and cooperation
  • Use and oversight of subprocessors
  • Assistance with consumer or data-subject requests
  • Restrictions on selling, sharing, combining, or independently using personal data
  • Data retention, return, and deletion
  • AI training, product improvement, and automated decision-making

Whether this U.S. DPA template is appropriate depends on the parties’ roles, the services provided, the types of personal data involved, the individuals and states affected, and the privacy laws that apply.

Why use this U.S. DPA template?

This U.S. Data Processing Addendum template provides a structured starting point for documenting how personal data may be processed in a U.S.-focused commercial relationship.

It is designed to be processor-friendly while addressing provisions that customers commonly expect when a service provider processes personal data on their behalf.

The template covers core areas including processing instructions, security obligations, incident response, subprocessor controls, audit and information rights, data return and deletion, state privacy-law requirements, and restrictions on unauthorized data use.

It also includes provisions addressing AI and machine-learning use and automated decision-making, helping businesses account for data-use questions that may arise in modern technology and SaaS relationships.

The template should be tailored to the specific services, data practices, operational capabilities, applicable privacy requirements, and terms of the main services agreement before use.

What does the U.S. DPA template cover?

Processing scope and restrictions

  • Processing limited to the Customer’s documented instructions
  • Restrictions on selling, sharing, combining, or independently using personal data
  • AI and machine-learning use restrictions
  • Automated decision-making transparency requirements

Security and incident response

  • Required security measures
  • Security-incident notification and response obligations
  • Customer responsibilities relating to sensitive data

Subprocessors and oversight

  • Subprocessor authorization, notice, and objection procedures
  • Audit and information rights
  • Acceptance of relevant SOC 2, ISO, or similar third-party security reports where appropriate

Data rights and end-of-service obligations

  • Assistance with applicable consumer or data-subject requests
  • Data return and deletion requirements
  • U.S. state privacy-law processor or service-provider restrictions

Liability and the main agreement: The template generally connects liability under the DPA to the limitations and risk allocation established in the primary services agreement. The DPA and main agreement should be reviewed together to avoid inconsistent or conflicting terms.

Before you use this

A template is a starting point, not advice. This one is drafted for the common case; your product, your counterparty and your jurisdiction will each pull it in a direction the document cannot anticipate. Nothing here creates an attorney-client relationship, and if the agreement matters, have a lawyer read it, ours or anyone else’s.