DPA, SCC, and cross-border data contracts

Processing, sharing, and transfer are three different papers. A DPA is not SCCs. This cluster is not a privacy-law opinion.

Scope processing, sharing, and transfer paper. Not a privacy-law hub.

A first DPA pointer can ride with a single SaaS matter. Keeping a subprocessor list current is a module workstream.

Data Processing Agreement

Processor terms. Needed whenever a destination vendor sees personal data. Startups skip this until a Singapore or EU buyer asks.

Data Sharing Agreement

Controller-to-controller sharing, not processing. Joint marketing and group companies use it.

Data Transfer Agreement

A named transfer mechanism. Distinct from the DPA that sits under it.

Standard Contractual Clauses

Standard contractual clauses for some outbound transfers. US systems holding EU/UK data often need this pointer.

Subprocessor Agreement

The vendor’s vendor. Mid-market buyers want the list as a pack fact.

Privacy Addendum

Adds privacy terms onto an MSA or SaaS form that lacked them.

Security Addendum

Technical and organisational measures. Numbers the client already claims belong in the pack.

Information Security Agreement

A standalone information-security agreement, heavier than an addendum.

Data Breach Response Addendum

Who notifies whom, and in how many hours, as the client already promised customers.

Questions

Must a startup SaaS pack include a DPA?

If a destination vendor or the product touches personal data, a DPA pointer belongs in the pack.

Are SCCs the same as a DPA?

No. SCCs are a named transfer mechanism. A DPA sits under processing.

Who keeps the subprocessor list current?

Mid-market modules can scope that as a workstream. Orbid does not act as privacy counsel.

DPA, SCC, and Cross-Border Data Contracts | Orbid