Technology & Digital

Sub-Processor Agreement

Data-processing addendum engaging a sub-processor under GDPR Article 28 and CCPA, flowing down the processor's obligations including security measures, audit rights, and breach notification.

📄 2 signers📅 30-day expiry🏷 Technology & Digital🔖 gdpr, data-processing, privacy

About this template

The Sub-Processor Agreement is a ready-to-use technology & digital template you can send for signature in minutes. It is written for 2 signers (processor and subprocessor) and, by default, expires 30 days after it is sent if left unsigned. It covers gdpr, data processing, privacy. Like every Abundera Sign template it is a convenience draft structured for ESIGN Act and UETA compliance, not a substitute for legal advice. Each signed copy is sealed with PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package in WORM storage.

Document Preview

# Sub-Processor Agreement This **Sub-Processor Agreement** (this "Agreement"), effective as of the date of last signature (the "Effective Date"), is entered into by and between: **Processor:** ___________, a ___________ organized under the laws of ___________ ("Processor"); and **Sub-Processor:** ___________, a ___________ organized under the laws of ___________ ("Sub-Processor"). Each is a "Party"; together they are the "Parties." ## Recitals WHEREAS, Processor provides certain services (the "Services") to its customers ("Controllers") and in connection with those Services processes Personal Data on behalf of Controllers pursuant to a data processing agreement between Processor and each Controller; WHEREAS, Processor wishes to engage Sub-Processor to perform certain processing activities set out in **Annex I** as part of the Services; WHEREAS, as a condition of such engagement, Processor is required to enter into a sub-processing agreement with Sub-Processor that flows down obligations equivalent to those imposed on Processor under applicable data protection law; NOW, THEREFORE, in consideration of the mutual covenants herein and other good and valuable consideration, the Parties agree as follows. ## 1. Definitions 1.1 **"Controller"** means the natural or legal person, public authority, agency, or other body that determines the purposes and means of the processing of Personal Data, as that term (or the equivalent "Business") is used under Applicable Data Protection Law. 1.2 **"Applicable Data Protection Law"** means, as applicable to a given processing activity: (a) Regulation (EU) 2016/679 (the "GDPR") and any national implementing legislation; (b) the UK GDPR as defined in the Data Protection Act 2018; (c) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"); and (d) any other data protection or privacy law, regulation, or binding regulatory guidance that applies to the processing of Personal Data under this Agreement. 1.3 **"Data Subject"** means an identified or identifiable natural person whose Personal Data is processed under this Agreement. 1.4 **"Personal Data"** means any information relating to an identified or identifiable natural person; for the purposes of CCPA, it includes "personal information" as defined therein. 1.5 **"Personal Data Breach"** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed. 1.6 **"Processing"** and **"process"** have the meanings given under Applicable Data Protection Law and include any operation performed on Personal Data. 1.7 **"Sub-Processing Services"** means the processing activities described in Annex I that Sub-Processor will carry out on behalf of Processor. ## 2. Scope and Nature of Processing 2.1 Sub-Processor shall process Personal Data solely to the extent necessary to perform the Sub-Processing Services as described in Annex I and only on documented instructions from Processor, unless required to process by applicable law, in which case Sub-Processor shall inform Processor of that legal requirement before processing (unless the law prohibits such disclosure on grounds of public interest).

Fields (23)

processor legal name
text · required
processor entity type
select · required
processor jurisdiction
text · required
subprocessor legal name
text · required
subprocessor entity type
select · required
subprocessor jurisdiction
text · required
further subprocessor notice days
number · required
breach notification hours
number · required
deletion confirmation days
number · required
audit notice days
number · required
governing law jurisdiction
text · required
processing subject matter
textarea · required
processing nature purpose
textarea · required
personal data types
textarea · required
data subject categories
textarea · required
processing duration
text · required
permitted transfer destinations
text · required
vuln remediation days
number · required
additional security measures
textarea · required
processor signatory name
text · required
processor signatory title
text · required
subprocessor signatory name
text · required
subprocessor signatory title
text · required

Related Technology & Digital templates

All 39 Technology & Digital templates →  ·  Browse all templates →

Send this template with cryptographic proof

Every signed document gets PAdES-LTA digital signatures, dual RFC 3161 timestamps, and a tamper-evident evidence package sealed in WORM storage.

Try the DemoView PricingFounding Member — 50% Off