← CRA IncidentOps
Template document. Before publication the operator must complete the bracketed fields and obtain legal review.

Data Processing Agreement (DPA)

1. Roles

The customer is the controller and [Operator name] is the processor of personal data contained in the customer's cases, evidence, contacts and logs (Art. 28 GDPR).

2. Subject and duration

Processing to provide CRA IncidentOps for the term of the subscription and until the data is deleted.

3. Instructions and confidentiality

The processor acts only on the customer's documented instructions; staff access is restricted and bound by confidentiality. The operator console shows subscription details and usage counts only, never case content.

4. Technical and organisational measures

See the security measures.

5. Subprocessors

The current list is on the subprocessors page. Customers are notified of new subprocessors in advance and may object.

6. Assistance

The processor assists with data subject requests, impact assessments and breach notifications, and notifies the customer of a personal data breach without undue delay.

7. Return and deletion

Customer administrators can export all data; deletion takes place 30 days after the request, and backups are removed within [period].

8. Audits

[Procedure for information requests and audits.]