Data Processing Agreement / DPDP Addendum Template
Document control
| Field | Value |
|---|---|
| Document status | Active template / policy document |
| Owner | Legal / Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
This document provides the standard structure and baseline clauses for a Data Processing Agreement (DPA) or DPDP Addendum to be used when Hybrowlabs processes personal data on behalf of a customer or engages a subprocessor to process personal data.
The objective is to clearly document processing roles, purpose, scope, security obligations, confidentiality, subprocessor controls, incident notification, data return/deletion, and cooperation responsibilities.
When to use this addendum
Use this addendum when:
- Hybrowlabs receives, stores, accesses, migrates, supports, or processes customer personal data.
- Hybrowlabs provides implementation, development, managed services, support, integration, hosting, migration, or operational services involving personal data.
- A customer requires DPDP, privacy, security, or data-processing terms.
- Hybrowlabs engages a vendor/subprocessor that may access or process personal data.
- A statement of work or master services agreement does not already include sufficient data-processing clauses.
Parties and roles
The agreement should identify the parties and their privacy roles.
| Party | Typical role | Responsibility |
|---|---|---|
| Customer | Data Fiduciary / Controller equivalent | Determines the purpose and means of processing customer personal data. |
| Hybrowlabs | Data Processor / Processor equivalent, unless otherwise agreed | Processes personal data according to customer instructions and agreed service scope. |
| Approved subprocessor | Subprocessor | Processes personal data only for the approved service and under written obligations. |
The final agreement must reflect the actual role allocation for the specific engagement.
Processing instructions
Hybrowlabs will process personal data only:
- According to the customer's documented instructions.
- As required to perform the agreed services.
- As required by applicable law.
- As necessary to maintain security, continuity, troubleshooting, auditability, and support obligations under the agreement.
If Hybrowlabs believes an instruction creates a material security, privacy, or legal risk, it should notify the customer through the agreed escalation channel where appropriate.
Processing schedule
Each DPA/addendum should include a processing schedule.
| Field | Description |
|---|---|
| Services covered | Implementation, support, development, hosting, integration, migration, managed service, or other applicable service. |
| Processing purpose | Why personal data is processed. |
| Data categories | Identity, contact, HR, payroll, user account, technical logs, documents, or other applicable categories. |
| Data principal categories | Employees, contractors, applicants, customers, vendors, end users, business contacts, or other applicable categories. |
| Systems / locations | Approved systems or environments where data is processed or stored. |
| Access groups | Teams or roles permitted to access the data. |
| Subprocessors | Approved third parties involved in processing. |
| Retention period | Contractual, legal, operational, or customer-defined retention period. |
| Deletion / return method | Return, deletion, anonymization, backup expiry, or other agreed method. |
Confidentiality obligations
Hybrowlabs personnel and approved subprocessors must protect personal data as confidential information.
Requirements:
- Access only for authorized business purposes.
- No unauthorized disclosure or sharing.
- Confidentiality obligations in employment, contractor, or vendor terms.
- Secure handling of documents, exports, logs, and screenshots.
- Return or deletion of confidential information when no longer required.
Security obligations
Hybrowlabs should maintain appropriate technical and organizational measures based on the nature of processing and risk.
Baseline security controls
- Role-based or least-privilege access.
- Authentication controls and MFA for sensitive/administrative access where supported.
- Encryption in transit for external access.
- Encryption at rest where supported and appropriate to data sensitivity.
- Secure credential and key management.
- Vulnerability and patch management.
- Logging and monitoring of relevant security events where feasible.
- Endpoint security and secure configuration.
- Backup and recovery controls for systems under Hybrowlabs responsibility.
- Secure deletion, return, or retention controls at exit.
- Incident response and escalation process.
Security evidence
Where requested and contractually permitted, Hybrowlabs may provide relevant policy documents, security summaries, architecture/control descriptions, access-control evidence, vulnerability remediation summaries, or other approved evidence.
Raw operational data, credentials, internal trackers, unrelated customer data, and sensitive infrastructure details should not be shared unless specifically approved and sanitized.
Access to personal data
Access to personal data must be restricted to authorized personnel with a legitimate business need.
Controls should include:
- Documented access request and approval.
- Role-based access where feasible.
- Periodic access review for sensitive systems.
- Prompt revocation on role change, offboarding, or end of need.
- Restricted privileged access.
- No credential sharing.
- Logging of administrative actions where supported.
Subprocessor management
Hybrowlabs may engage subprocessors only where required for service delivery and where appropriate controls are in place.
Subprocessor requirements
Subprocessors should be subject to written terms requiring:
- Confidentiality.
- Security safeguards appropriate to the processing.
- Processing only for the approved purpose.
- Incident notification to Hybrowlabs.
- Assistance with deletion, return, or investigation where applicable.
- No further subcontracting without appropriate controls.
Subprocessor register
A subprocessor register should include:
- Vendor/subprocessor name.
- Service provided.
- Data categories processed.
- Processing purpose.
- Location/region, where relevant.
- Security review status.
- Contract status.
- Owner.
- Approval date and review date.
Customer approval or notification should follow the applicable contract.
International transfer / location of processing
Where processing location is relevant, the agreement should document approved storage/processing locations or cloud/service regions.
If personal data is transferred across jurisdictions, the transfer should be supported by appropriate contractual, legal, and security safeguards, as applicable.
Data principal rights support
Where applicable and contractually required, Hybrowlabs will reasonably assist the customer with requests from data principals, such as:
- Access.
- Correction.
- Update.
- Deletion.
- Grievance handling.
- Withdrawal of consent where applicable.
- Other rights recognized under applicable law.
Requests received directly by Hybrowlabs for customer-controlled data should be redirected or escalated to the customer unless otherwise agreed.
Personal data breach / privacy incident notification
Hybrowlabs must notify the customer without undue delay after becoming aware of a confirmed or reasonably suspected personal data breach affecting customer personal data, subject to the terms of the agreement.
Notification should include available information such as:
- Nature of incident.
- Affected systems or data categories.
- Approximate timeline.
- Initial containment actions.
- Known or suspected impact.
- Remediation and next steps.
- Contact point for coordination.
Notification may be updated as investigation progresses. Initial notice should not be delayed solely because all details are not yet known.
Audit and assurance support
Hybrowlabs may support reasonable customer assurance requests through:
- Security policy documents.
- Control summaries.
- Completed security questionnaires.
- Remediation summaries.
- Architecture or data-flow descriptions.
- Access-control or backup-control summaries.
- Other mutually agreed evidence.
Audit requests must be reasonable, scoped to the services, protect confidentiality of other customers and internal systems, and avoid requiring disclosure of sensitive operational details unless specifically agreed.
Data retention
Personal data should be retained only for the agreed service purpose, legal/compliance requirement, security requirement, or documented operational need.
The agreement should define:
- Retention period or retention criteria.
- Whether backups are included and how backup expiry works.
- Customer-requested deletion or return process.
- Legal hold exceptions.
- Evidence of deletion or return where required.
Return and deletion at exit
At termination, expiry, or completion of the service, Hybrowlabs should return, delete, anonymize, or retain personal data according to the agreement and applicable legal requirements.
Exit handling should include:
- Confirming data owner and requested action.
- Exporting/returning data where agreed.
- Revoking user and support access.
- Deleting temporary working copies.
- Allowing backups to expire according to backup lifecycle unless otherwise agreed and technically feasible.
- Recording completion evidence.
Restrictions on use
Hybrowlabs must not use customer personal data for:
- Personal purposes.
- Unapproved analytics.
- Marketing without authorization.
- Training public or third-party models/tools without explicit approval.
- Sharing with unrelated third parties.
- Any purpose outside the agreed service scope.
Secure development and testing
If personal data is required for development, testing, migration, debugging, or troubleshooting:
- Use minimized or masked data where feasible.
- Restrict access to authorized personnel.
- Avoid long-term local storage.
- Delete temporary extracts after use.
- Do not place personal data in source control.
- Protect logs, screenshots, and test artifacts.
Assistance and cooperation
Hybrowlabs should reasonably assist the customer with:
- Security and privacy questionnaires.
- Incident investigation.
- Data subject request support.
- Deletion/return requests.
- Subprocessor information.
- Control evidence requests.
- Regulatory or contractual compliance support where applicable.
Assistance should be limited to the agreed service scope and subject to confidentiality, security, feasibility, and commercial terms.
Liability and precedence
The DPA/addendum should be read together with the master agreement, statement of work, confidentiality agreement, and applicable policies.
If there is a conflict, the order of precedence should be defined in the contract. Legal counsel or management should review final customer-specific wording before signature.
Template clauses
Processing instruction clause
Hybrowlabs shall process personal data only for the purpose of providing the agreed services and in accordance with the customer's documented instructions, the applicable agreement, and applicable law.
Confidentiality clause
Hybrowlabs shall ensure that personnel authorized to process personal data are bound by confidentiality obligations and access such data only as required for authorized service delivery.
Security clause
Hybrowlabs shall maintain appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction, taking into account the nature of the data, processing purpose, and associated risk.
Subprocessor clause
Hybrowlabs shall ensure that approved subprocessors processing personal data are bound by written obligations that provide confidentiality, security, incident notification, and processing restrictions appropriate to the services performed.
Incident notification clause
Hybrowlabs shall notify the customer without undue delay after becoming aware of a confirmed or reasonably suspected personal data breach affecting customer personal data and shall provide relevant available information as investigation progresses.
Return/deletion clause
Upon termination or completion of services, Hybrowlabs shall return, delete, anonymize, or retain personal data in accordance with the customer's instructions, applicable agreement, and legal requirements. Backup copies may remain until expiry of the normal backup lifecycle unless otherwise agreed and technically feasible.
Customer-specific schedule template
| Field | To be completed |
|---|---|
| Customer / Data Fiduciary | |
| Hybrowlabs entity / processor | |
| Agreement / SOW reference | |
| Service description | |
| Processing purpose | |
| Data categories | |
| Data principal categories | |
| Systems/environments in scope | |
| Authorized access groups | |
| Subprocessors | |
| Processing location / region | |
| Retention period | |
| Return/deletion method | |
| Incident notification contacts | |
| Customer approval requirements | |
| Evidence to be shared |
Evidence to maintain
- Signed DPA / DPDP addendum.
- Processing schedule.
- Subprocessor register.
- Security policy pack shared with customer.
- Access-control evidence, where applicable.
- Retention/deletion or return evidence.
- Incident notification records, if any.
- Customer approval records for subprocessors or processing changes.
- Exception register.