{"id":28243,"date":"2018-05-23T12:58:33","date_gmt":"2018-05-23T04:58:33","guid":{"rendered":"https:\/\/zegal.com\/data-processing-addendum\/"},"modified":"2024-08-20T16:44:13","modified_gmt":"2024-08-20T08:44:13","slug":"data-processing-addendum","status":"publish","type":"page","link":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/","title":{"rendered":"Data Processing Addendum"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-data-processing-addendum\"><span class=\"ez-toc-section\" id=\"What_is_a_Data_Processing_Addendum\"><\/span><b>What is a Data Processing Addendum?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">To begin, a <\/span><b>Data Processing Addendum<\/b><span style=\"font-weight: 400;\"> is a contract between data controllers and data processors. The main purpose of a Data Processing Addendum (DPA) is to protect the user\u2019s data in compliance with the GDPR or any other Privacy Laws.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">For example,<\/span> <span style=\"font-weight: 400;\">you have a business that operates through a website and collects the information of the visitors visiting your website. But, at some point, your business has to work with some other third-party processor to handle some of the data. Therefore, at that time a \u201cData Processing Addendum\u201d will help your business legally if said third-party misuses your user\u2019s data.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Importantly, one of the key changes introduced by the GDPR is that a clear framework of responsibility is established for data protection. Essentially, a data controller may only appoint processors that provide a \u201csufficient guarantee\u201d to meet the requirements of the GDPR. A data processor may only act on \u201cdocumented instructions\u201d of the controller. And, must comply with a number of requirements to ensure that the controller will fulfil its obligations under the GDPR.<\/span><span style=\"font-weight: 400;\">&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-do-i-need-a-data-processing-addendum\"><span class=\"ez-toc-section\" id=\"Do_I_need_a_Data_Processing_Addendum\"><\/span><b>Do I need a Data Processing Addendum?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">If you\u2019re running a business that works with user\u2019s data, then you need a Data Processing Addendum. Having a <\/span>Data Processing Addendum<span style=\"font-weight: 400;\"><strong>&nbsp;<\/strong>will help your business in a legal dispute if a third-party try to misuse your user\u2019s data. It offers protection for your company for any third party act that is not in compliance with GDPR or other privacy laws.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Essentially, without a Data Processing Addendum your business might be at risk if a third-party provider tries to manipulate your user\u2019s data. This is the case because the wrong-doings of that third-party would otherwise fall on your company\u2019s head. Additionally, there are not only legal ramifications but also the damage to the reputation of your company that may result in a decrease in revenue.&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-gdpr-pdpa\"><span class=\"ez-toc-section\" id=\"What_is_GDPR_PDPA\"><\/span><b>What is GDPR &amp; PDPA?<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">In a nutshell, every country has their own set of data protection and privacy laws. For instance, the European Union has established the <\/span><b>General Data Protection Regulation<\/b><span style=\"font-weight: 400;\"> (GDPR) act.&nbsp; In Singapore, they have <\/span><b>PDPA<\/b><span style=\"font-weight: 400;\">, which stands for Personal Data Protection Act 2010. This regulates the processing of the collection of all personal data while making any commercial transaction.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The General Data Protection Regulation (\u201c<\/span><b>GDPR<\/b><span style=\"font-weight: 400;\">\u201d) is a new privacy law in the European Union (\u201cEU\u201d) that came into force on 25 May 2018. The GDPR regulates the protection of personal data, which includes any information that can be used to identify a person, such as a name, identification number, location data, or online identifier, and a wide range of other types of information. So, having a Data Processing Addendum will help your business to protect the user\u2019s data from misuse. <\/span><span style=\"font-weight: 400;\">The GDPR applies to all businesses in the EU, including the UK. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">However, if you are a business outside the EU that collects personal data from individuals in the EU, and you make decisions about how and why personal data is used, you will be considered a \u201ccontroller\u201d under the GDPR. And, will be subject to its rules regarding the data of those individuals. If you process the personal data of individuals in the EU on behalf of a controller, you will be considered a \u201cprocessor\u201d and will also need to comply with the GDPR.<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\"><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span><b>Conclusion<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">The <\/span><b>Data Processing Addendum<\/b><span style=\"font-weight: 400;\"> supplements any service agreement (or terms of service) already in place. Importantly, the Data Processing Addendum is not just a document that is nice to have. It is mandatory The <\/span>GDPR, for instance,<span style=\"font-weight: 400;\"> requires that processing of personal data by a service provider on behalf of a data controller must be governed by a binding contract. It sets out details of the personal data by the processor on behalf of the controller and each party\u2019s responsibilities in such processing.<\/span><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-you-might-also-like\"><strong>You Might Also Like<\/strong><\/h4>\n\n\n\n<p>Along with this document, make sure you see these other templates in our library:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/zegal.com\/shareholders-agreement\/\">Shareholder Agreement<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zegal.com\/option-agreement\/\">Option Agreement<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zegal.com\/option-agreement\/\">Employee Option Repurchase Agreement<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zegal.com\/share-appreciation-rights-plan\/\">Share Appreciation Rights Plan<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/zegal.com\/share-option-plan\/\">Share Option Plan<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>What is a Data Processing Addendum? To begin, a Data Processing Addendum is a contract between data controllers and data processors. The main purpose of a Data Processing Addendum (DPA) is to protect the user\u2019s data in compliance with the GDPR or any other Privacy Laws. For example, you have a business that operates through [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":[13562],"meta":{"_acf_changed":false,"_editorskit_title_hidden":false,"_editorskit_reading_time":2,"_editorskit_is_block_options_detached":false,"_editorskit_block_options_position":"{}","inline_featured_image":false,"footnotes":""},"usecases":[13749],"class_list":["post-28243","page","type-page","status-publish","hentry","template-gdpr-compliance","usecases-protect-personal-data"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.8 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Data Processing Addendum | Zegal - Automated Legal Templates<\/title>\n<meta name=\"description\" content=\"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/pages\/28243\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data Processing Addendum\" \/>\n<meta property=\"og:description\" content=\"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/\" \/>\n<meta property=\"og:site_name\" content=\"Zegal UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/getzegal\/\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-20T08:44:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zegal.com\/wp-content\/uploads\/2019\/05\/Share-document.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"700\" \/>\n\t<meta property=\"og:image:height\" content=\"440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@getzegal\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/data-processing-addendum\\\/\",\"url\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/data-processing-addendum\\\/\",\"name\":\"Data Processing Addendum | Zegal - Automated Legal Templates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#website\"},\"datePublished\":\"2018-05-23T04:58:33+00:00\",\"dateModified\":\"2024-08-20T08:44:13+00:00\",\"description\":\"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/data-processing-addendum\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zegal.com\\\/en-gb\\\/data-processing-addendum\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/data-processing-addendum\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Legal Templates\",\"item\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/all-docs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR Compliance\",\"item\":\"https:\\\/\\\/zegal.com\\\/en-hk\\\/template\\\/gdpr-compliance\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Data Processing Addendum\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#website\",\"url\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/\",\"name\":\"Zegal UK\",\"description\":\"Need legal? Click Zegal.\",\"publisher\":{\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#organization\",\"name\":\"Zegal UK\",\"url\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/zegal.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/zegal-logo-white.png\",\"contentUrl\":\"https:\\\/\\\/zegal.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/zegal-logo-white.png\",\"width\":200,\"height\":69,\"caption\":\"Zegal UK\"},\"image\":{\"@id\":\"https:\\\/\\\/zegal.com\\\/en-gb\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/getzegal\\\/\",\"https:\\\/\\\/x.com\\\/getzegal\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/getzegal\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@legalzegal\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Data Processing Addendum | Zegal - Automated Legal Templates","description":"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/pages\/28243\/","og_locale":"en_GB","og_type":"article","og_title":"Data Processing Addendum","og_description":"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!","og_url":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/","og_site_name":"Zegal UK","article_publisher":"https:\/\/www.facebook.com\/getzegal\/","article_modified_time":"2024-08-20T08:44:13+00:00","og_image":[{"width":700,"height":440,"url":"https:\/\/zegal.com\/wp-content\/uploads\/2019\/05\/Share-document.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@getzegal","twitter_misc":{"Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/","url":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/","name":"Data Processing Addendum | Zegal - Automated Legal Templates","isPartOf":{"@id":"https:\/\/zegal.com\/en-gb\/#website"},"datePublished":"2018-05-23T04:58:33+00:00","dateModified":"2024-08-20T08:44:13+00:00","description":"This addendum ensures that the processing of personal data is in compliance with data protection laws like the GDPR. Create one now!","breadcrumb":{"@id":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zegal.com\/en-gb\/data-processing-addendum\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zegal.com\/en-gb\/data-processing-addendum\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Legal Templates","item":"https:\/\/zegal.com\/en-gb\/all-docs\/"},{"@type":"ListItem","position":2,"name":"GDPR Compliance","item":"https:\/\/zegal.com\/en-hk\/template\/gdpr-compliance\/"},{"@type":"ListItem","position":3,"name":"Data Processing Addendum"}]},{"@type":"WebSite","@id":"https:\/\/zegal.com\/en-gb\/#website","url":"https:\/\/zegal.com\/en-gb\/","name":"Zegal UK","description":"Need legal? Click Zegal.","publisher":{"@id":"https:\/\/zegal.com\/en-gb\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zegal.com\/en-gb\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/zegal.com\/en-gb\/#organization","name":"Zegal UK","url":"https:\/\/zegal.com\/en-gb\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/zegal.com\/en-gb\/#\/schema\/logo\/image\/","url":"https:\/\/zegal.com\/wp-content\/uploads\/2021\/11\/zegal-logo-white.png","contentUrl":"https:\/\/zegal.com\/wp-content\/uploads\/2021\/11\/zegal-logo-white.png","width":200,"height":69,"caption":"Zegal UK"},"image":{"@id":"https:\/\/zegal.com\/en-gb\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/getzegal\/","https:\/\/x.com\/getzegal","https:\/\/www.linkedin.com\/company\/getzegal\/","https:\/\/www.youtube.com\/@legalzegal"]}]}},"_links":{"self":[{"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/pages\/28243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/comments?post=28243"}],"version-history":[{"count":0,"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/pages\/28243\/revisions"}],"wp:attachment":[{"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/media?parent=28243"}],"wp:term":[{"taxonomy":"template","embeddable":true,"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/template?post=28243"},{"taxonomy":"usecases","embeddable":true,"href":"https:\/\/zegal.com\/en-gb\/wp-json\/wp\/v2\/usecases?post=28243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}