Data Processing Agreement
Processor terms. Needed whenever a destination vendor sees personal data. Startups skip this until a Singapore or EU buyer asks.
Processing, sharing, and transfer are three different papers. A DPA is not SCCs. This cluster is not a privacy-law opinion.
Scope processing, sharing, and transfer paper. Not a privacy-law hub.
A first DPA pointer can ride with a single SaaS matter. Keeping a subprocessor list current is a module workstream.
Processor terms. Needed whenever a destination vendor sees personal data. Startups skip this until a Singapore or EU buyer asks.
Controller-to-controller sharing, not processing. Joint marketing and group companies use it.
A named transfer mechanism. Distinct from the DPA that sits under it.
Standard contractual clauses for some outbound transfers. US systems holding EU/UK data often need this pointer.
The vendor’s vendor. Mid-market buyers want the list as a pack fact.
Adds privacy terms onto an MSA or SaaS form that lacked them.
Technical and organisational measures. Numbers the client already claims belong in the pack.
A standalone information-security agreement, heavier than an addendum.
Who notifies whom, and in how many hours, as the client already promised customers.
If a destination vendor or the product touches personal data, a DPA pointer belongs in the pack.
No. SCCs are a named transfer mechanism. A DPA sits under processing.
Mid-market modules can scope that as a workstream. Orbid does not act as privacy counsel.