Data Processing Agreement
Draft for solicitor and privacy review before production use. Last updated 8 October 2026.
Execution required
Draft schedule for Article 28 review. Complete and sign with the customer before processing production personal data where a processor agreement is required.
Processing particulars
Subject: warehouse commercial exception records. Duration: the agreed service and retention periods. Purpose: capture, evidence, review, approval, resolution and audit on documented customer instructions. Data subjects may include customer employees, warehouse staff, supplier contacts and customer approvers. Data includes work contact details, operational records and approval evidence.
Processor obligations to finalise
Document confidentiality, appropriate security measures, access controls, instructions, rights assistance, incident notification, deletion/return, audit assistance and handling unlawful instructions. Agree responsibilities and practical response routes; no unverified certification or deadline is promised.
Subprocessors and transfers
List contracted entities, service functions, locations and safeguards. Agree prior authorisation, changes/objection process and equivalent downstream obligations. Review the public Subprocessor List as a configuration disclosure, not as an executed contractual schedule.
Security annex
Reference tenant isolation, role checks, reviewed actions, audit events, verified approval links and server-side credentials. Confirm backup/restore evidence, malware controls, monitoring ownership, retention and incident procedures before execution.