🔥 20% OFF
SEO from $99/mo
Free Site Analysis
Claim Now

Data Processing Agreement (DPA) Template

Version: 2.0 | Effective: July 15, 2026 | Status: Template — Execute per engagement

⚠️ How to Use This Template

  1. This DPA is incorporated by reference into the Service Agreement (MSA/SoW) between CyberSpeed LLC ("Processor") and the Client ("Controller").
  2. Complete all [BRACKETED FIELDS] with engagement-specific details.
  3. Both parties sign the Service Agreement; this DPA becomes legally binding upon execution.
  4. Attach Annex A (Processing Details), Annex B (Technical & Organisational Measures), and Annex C (Subprocessor List).
  5. For DIFC/ADGM entities: Ensure governing law/jurisdiction clauses align (DIFC Courts / ADGM Courts).

DATA PROCESSING AGREEMENT

Between

Controller:[CLIENT LEGAL ENTITY NAME]
Address: [CLIENT REGISTERED ADDRESS]
Trade Licence No.: [CLIENT TRADE LICENCE NUMBER]
Contact: [CLIENT DPO / PRIVACY CONTACT NAME, EMAIL, PHONE]
Processor:CyberSpeed LLC
Address: FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE
Trade Licence No.: [CYBERSPEED TRADE LICENCE NUMBER]
Contact: dpo@cyberspeedllc.com | +971 4 200 0000

(collectively, the "Parties"; each a "Party")


1. Definitions & Interpretation

Capitalised terms not defined here have meanings in the Service Agreement, UAE Federal Decree-Law No. 45 of 2021 (PDPL), DIFC Data Protection Law No. 5 of 2020 (DIFC DP Law), ADGM Data Protection Regulations 2021 (ADGM DP Regs), and GDPR (EU 2016/679) where applicable.

"Personal Data"
Any information relating to an identified or identifiable natural person (Data Subject) — PDPL Art. 1, GDPR Art. 4(1).
"Processing"
Any operation on Personal Data (collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, destruction) — PDPL Art. 1, GDPR Art. 4(2).
"Data Subject"
The natural person to whom Personal Data relates.
"Subprocessor"
Any third party engaged by Processor to Process Personal Data on Controller's behalf.
"DPIA"
Data Protection Impact Assessment (PDPL Art. 25, GDPR Art. 35).
"Security Incident"
Breach of security leading to accidental/unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data (PDPL Art. 21, GDPR Art. 33).

2. Processing Details (Annex A)

The subject-matter, nature, purpose, duration, categories of Personal Data, and categories of Data Subjects are set out in Annex A attached hereto. Processor shall Process Personal Data only:

  • As documented in Annex A and the Service Agreement
  • On Controller's documented instructions (including this DPA)
  • For the duration of the Service Agreement + 30 days post-termination for orderly return/deletion

If Processor cannot comply with Controller's instructions due to applicable law, Processor shall inform Controller promptly (unless prohibited by law).


3. Processor Obligations

3.1 Lawful Processing

Processor shall Process Personal Data only on Controller's documented instructions and in accordance with applicable law (PDPL, DIFC DP Law, ADGM DP Regs, GDPR where relevant).

3.2 Confidentiality

Processor ensures all personnel authorised to Process Personal Data are subject to written confidentiality obligations (employment contracts, NDAs, contractor agreements).

3.3 Security Measures (Annex B)

Processor implements technical and organisational measures per Annex B to ensure a level of security appropriate to the risk, including:

  • Pseudonymisation and encryption (AES-256 at rest, TLS 1.2+ in transit)
  • Access controls: least privilege, MFA, role-based access, regular access reviews
  • Availability & resilience: automated backups (encrypted, geo-redundant), point-in-time recovery, DR testing
  • Integrity: tamper-evident logs, checksums, change management
  • Regular testing: annual penetration test (CREST), quarterly vulnerability scans, monthly patch cycles
  • Organisational: ISO 27001-aligned ISMS, staff training (onboarding + annual), incident response plan

3.4 Subprocessing (Annex C)

  • Processor may engage Subprocessors listed in Annex C (updated from time to time).
  • Processor notifies Controller of intended new Subprocessors with 30 days' written notice. Controller may object within 15 days on reasonable grounds (data protection, compliance). If unresolved, Controller may terminate affected Service(s) without penalty.
  • Processor enters into written agreements with Subprocessors imposing equivalent data protection obligations.
  • Processor remains fully liable for Subprocessor acts/omissions.

3.5 International Data Transfers

  • Primary hosting: UAE (Azure UAE North / AWS Middle East / GCP Dubai) — no transfer.
  • Where Subprocessors/Processor infrastructure outside UAE/GCC: transfer mechanisms per Annex C (UAE Data Office adequacy, SCCs, BCRs, or explicit consent).
  • Processor shall not transfer Personal Data outside agreed locations without Controller's prior written consent.

3.6 Data Subject Rights Assistance

Processor shall assist Controller (at no additional cost for reasonable requests) in fulfilling Data Subject rights under applicable law: access, rectification, erasure, restriction, portability, objection, automated decision-making.

Processor shall notify Controller within 48 hours of receiving any direct Data Subject request.

3.7 DPIA Assistance

Processor shall assist Controller in conducting DPIAs where Processing is likely to result in high risk (PDPL Art. 25, GDPR Art. 35), providing necessary technical information.

3.8 Records of Processing Activities (ROPA)

Processor maintains records of Processing activities performed on behalf of Controller per PDPL Art. 11, GDPR Art. 30(2), available to Controller and supervisory authority on request.


4. Security Incidents & Breach Notification

  • Processor shall notify Controller without undue delay, and within 24 hours of becoming aware of a Security Incident affecting Controller's Personal Data.
  • Notification includes: nature of breach, categories/approximate number of Data Subjects/records affected, likely consequences, measures taken/proposed, contact details for DPO.
  • Processor shall cooperate with Controller in investigating, mitigating, and notifying supervisory authority (UAE Data Office / DIFC Commissioner / ADGM Registrar) within 72 hours per PDPL Art. 21 / GDPR Art. 33.
  • Processor shall not notify Data Subjects directly without Controller's prior written authorisation (Controller's legal obligation).

5. Data Retention, Return & Deletion

  • Processor retains Personal Data only for the duration of the Service Agreement + 30 days post-termination/expiration for orderly transition.
  • Upon Controller's written instruction (or expiry of retention period), Processor shall return or securely delete all Personal Data and existing copies (including backups), and certify deletion in writing within 14 days.
  • If law requires retention beyond termination, Processor shall: (a) notify Controller; (b) restrict Processing to storage/legal compliance only; (c) delete when legally permitted.

6. Audits & Inspections

  • Controller may audit Processor's compliance with this DPA upon 30 days' written notice, max once per 12 months (or additional if Security Incident or regulatory investigation).
  • Audit scope: security measures, Subprocessor compliance, ROPA, breach logs, deletion certification.
  • Processor provides: ISO 27001/SOC 2 Type II reports, penetration test summaries, vulnerability scan results, Subprocessor audit certifications — Controller may rely on these in lieu of on-site audit where sufficient.
  • Audit at Controller's cost unless material non-compliance found (then Processor bears reasonable costs).
  • Controller treats audit findings as Confidential Information.

7. Liability & Indemnification

  • Processor's total aggregate liability for DPA breaches capped at 100% of fees paid under Service Agreement in preceding 12 months (aligned with Service Agreement limitation).
  • Cap does not apply to: (a) Processor's breach of confidentiality; (b) wilful misconduct/fraud; (c) Subprocessor liability (Processor liable); (d) data protection authority fines directly caused by Processor's gross negligence.
  • Each Party indemnifies the other for third-party claims arising from indemnifying Party's breach of this DPA.

8. Term & Termination

  • This DPA commences on Service Agreement Effective Date and continues until all Personal Data is returned/deleted per Section 5.
  • Either Party may terminate this DPA with 30 days' written notice if other Party materially breaches and fails to cure within notice period.
  • Immediate termination for: insolvency, regulatory prohibition, loss of required licences.
  • Sections 3.2, 3.3, 4, 5, 7, 9, 10, 11 survive termination.

9. Governing Law & Jurisdiction

  • This DPA governed by laws of the United Arab Emirates and Emirate of Dubai.
  • Disputes resolved per Service Agreement Section 17 (DIAC arbitration, Dubai seat, English language).
  • If Controller is DIFC entity: DIFC Courts, DIFC Law, DIAC Rules.
  • If Controller is ADGM entity: ADGM Courts, ADGM Regulations, ADGM Arbitration Regulations.

10. General

  • Entire Agreement: This DPA + Annexes + Service Agreement = entire understanding on data protection.
  • Amendments: Written, signed by both Parties.
  • Assignment: Neither Party may assign without consent (not unreasonably withheld). Permitted: affiliate, successor, acquirer (with notice).
  • Notices: Written, email to DPOs + courier to registered addresses.
  • Severability: Invalid provision severed; remainder enforceable.
  • No Third-Party Beneficiaries: Except supervisory authorities.

SIGNATURES

This DPA is executed as a deed / under hand on the dates below.

CONTROLLER: [CLIENT LEGAL ENTITY NAME]

By: _______________________________

Name: _______________________________

Title: _______________________________

Date: _______________________________

PROCESSOR: CYBERSPEED LLC

By: _______________________________

Name: _______________________________

Title: _______________________________

Date: _______________________________


ANNEX A — PROCESSING DETAILS

Complete per engagement. Attach to executed DPA.

Service Agreement Reference[MSA/SoW Number & Date]
Processing Purposes[e.g., Web/App Development, SEO Analytics, Shopify Order Processing, AI Model Training, Ad Campaign Management, Expert HR Processing]
Categories of Personal Data[e.g., Contact/Identity Data, Technical/Usage Data, Financial/Payment Data, HR/Employee Data, Health/Clinical Data (if applicable), Content/Communications Data]
Special Category Data (PDPL/GDPR Art. 9)[Yes/No — if Yes, specify: Health, Biometric, etc. + lawful basis]
Categories of Data Subjects[e.g., Client employees, Client customers/end-users, Website visitors, Job applicants, Contractors]
Processing Operations[Collection, Storage, Analysis, Transformation, Transmission, Hosting, AI Training/Inference, Reporting, Deletion]
Data Retention Period[Per Service Agreement + 30 days post-termination; or specify per data category]
Geographic Processing Locations[Primary: UAE (Azure UAE North / AWS ME / GCP Dubai). Subprocessor locations per Annex C.]
Data Transfers Outside UAE/GCC[Yes/No — if Yes, mechanism: Adequacy / SCCs / BCRs / Consent — details per Annex C]
Controller Instructions[As documented in Service Agreement, this DPA, and written instructions via email/ticketing system]

ANNEX B — TECHNICAL & ORGANISATIONAL MEASURES (TOMs)

Processor's baseline TOMs. Enhanced measures per engagement documented in Service Agreement.

Control DomainMeasures ImplementedVerification
Access ControlZero-trust network, MFA mandatory, RBAC, least privilege, quarterly access reviews, privileged access management (PAM), session recordingSOC 2 Type II, ISO 27001 Annex A.9
EncryptionAES-256 at rest (managed keys / customer-managed keys option), TLS 1.3 in transit, encrypted backups, encrypted email (TLS + S/MIME option)Penetration test, crypto review
Network SecurityWAF (Cloudflare), DDoS protection, micro-segmentation, VPC isolation, private endpoints, egress filtering, IDS/IPSMonthly vuln scans, annual pen test
Application SecuritySDLC with SAST/DAST/SCA, dependency scanning, container hardening, WAF rules, CSP, HSTS, secure headers, secrets management (Vault)SAST/DAST per release, annual pen test
Data Integrity & AvailabilityAutomated daily backups (30-day retention), point-in-time recovery (7 days), cross-region replication, RPO < 1hr, RTO < 4hr, DR test semi-annuallyDR test report, backup restore test
Logging & MonitoringCentralised SIEM (90-day hot, 1-year cold), real-time alerting, audit trails (immutable), UEBA, file integrity monitoringLog retention audit, alert response SLA
Vulnerability ManagementMonthly automated scans, quarterly authenticated scans, patch SLA: Critical 48h / High 7d / Medium 30d, dependency monitoring (Dependabot/Renovate)Patch compliance report
Incident ResponseIR Plan (NIST 800-61), 24/7 on-call, 1h acknowledgement, 4h containment, 24h root cause, 72h notification, post-incident reviewTabletop exercise quarterly, IR drill annually
Personnel SecurityBackground checks (onboarding), annual security awareness training, phishing simulations (quarterly), NDAs, clean desk, MDM for endpoints, offboarding < 24hTraining completion report, phishing results
Supplier/Subprocessor ManagementVendor risk assessment (SIG Lite), DPAs with all subprocessors, annual security review, right-to-audit contracts, concentration risk monitoringVendor register, annual review
Physical SecurityCo-location data centres (Tier III+): biometric access, CCTV 90-day, environmental controls, fire suppression, redundant power/coolingData centre certifications (ISO 27001, SOC 2)
Privacy by Design/DefaultData minimisation, purpose limitation, retention automation, DPIA for new features, default-off for optional processing, DPO consultationDPIA register, DPO sign-off

ANNEX C — SUBPROCESSOR LIST & TRANSFER MECHANISMS

Current as of July 2026. Updated with 30 days' notice per Section 3.4.

SubprocessorServiceLocationTransfer MechanismDPAs in Place
Microsoft AzureCloud hosting (UAE North)UAENo transfer (UAE)Yes (Microsoft DPA)
Amazon Web ServicesCloud hosting (ME Central / UAE)UAE / BahrainUAE Adequacy / SCCsYes (AWS DPA)
Google Cloud PlatformCloud hosting (Dubai region)UAENo transfer (UAE)Yes (GCP DPA)
CloudflareWAF, CDN, DNS, Bot ManagementGlobal (edge)SCCs (EU/US)Yes (Cloudflare DPA)
StripePayment processingUSA / IrelandSCCs (Controller-Processor)Yes (Stripe DPA)
Atlassian (Jira/Confluence)Project management, documentationUSA / GermanySCCsYes (Atlassian DPA)
Slack (Salesforce)Team communicationUSASCCsYes (Slack DPA)
GitHub (Microsoft)Source code hosting, CI/CDUSASCCsYes (GitHub DPA)
OpenAILLM API (GPT models)USASCCs + Supplementary measuresYes (OpenAI DPA)
AnthropicLLM API (Claude models)USASCCs + Supplementary measuresYes (Anthropic DPA)
Pinecone / WeaviateVector database (RAG)USA / EUSCCsYes (Vendor DPA)
SendGrid (Twilio)Transactional emailUSASCCsYes (Twilio DPA)
HubSpotCRM, marketing automationUSA / GermanySCCsYes (HubSpot DPA)

Contact for DPA Matters

CyberSpeed LLC — Data Protection Officer

Email: dpo@cyberspeedllc.com

Phone: +971 4 200 0000

Postal: FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO