# Data Processing Agreement (DPA)This Data Processing Agreement is entered into between:**Controller**: [Your Organization] ("Controller")**Processor**: [Vendor Name] ("Processor")## 1. Subject Matter and Duration**Subject Matter**: Provision of [Service Description]**Duration**: As per Main Agreement**Nature and Purpose**: Processing personal data to provide AI agent services## 2. Obligations of the ProcessorThe Processor shall:a) Process personal data only on documented instructions from the Controller;b) Ensure persons authorized to process personal data have committed to confidentiality;c) Implement appropriate technical and organizational measures (Article 32);d) Respect conditions for engaging sub-processors (Article 28(2) and (4));e) Assist the Controller in responding to data subject rights requests;f) Assist the Controller in ensuring compliance with Articles 32-36 (security, breach notification, DPIA);g) Delete or return all personal data after end of provision of services;h) Make available all information necessary to demonstrate compliance.## 3. Technical and Organizational Measures**Encryption**:- TLS 1.3 in transit- AES-256 at rest**Access Control**:- Multi-factor authentication- Role-based access control- Least privilege principle**Monitoring**:- 24/7 security monitoring- Audit logging- Intrusion detection## 4. Sub-ProcessorsApproved Sub-Processors:- Google Cloud Platform (infrastructure) - [DPA Link]- Anthropic/Google (LLM providers) - [DPA Link]Controller authorizes engagement of sub-processors listed above.Processor must notify Controller of any intended changes (addition/replacement) with 30 days notice.## 5. Data Subject RightsProcessor shall assist Controller in responding to data subject requests:- Access (Article 15)- Rectification (Article 16)- Erasure (Article 17)- Restriction (Article 18)- Portability (Article 20)- Objection (Article 21)Response time: Within 72 hours of Controller request## 6. Personal Data Breach NotificationProcessor shall notify Controller without undue delay (and within 24 hours) after becoming aware of a personal data breach.Notification must include:- Nature of breach- Categories and approximate number of data subjects affected- Likely consequences- Measures taken or proposed## 7. Audits and InspectionsProcessor shall allow Controller (or auditor) to conduct audits annually.Processor shall provide all information necessary to demonstrate compliance.---**Controller**: ________________________ Date: __________**Processor**: ________________________ Date: __________