Model Data Processing Agreement — draft for completion and legal review. This template is not legal advice and should not be signed without completing the schedules and confirming the applicable law.
1. Parties and relationship
Identify the controller and processor by full legal name, address and authorised contact. Specify the services and the main agreement to which this DPA applies.
2. Processing details
Document the subject matter, duration, purposes, operations, data-subject categories and personal-data categories. Include only data that is actually processed.
3. Documented instructions
The processor will process personal data only on documented instructions from the controller, unless applicable law requires otherwise. Any additional processing must be assessed and documented.
4. Confidentiality and security
Personnel with access must be subject to confidentiality duties. The parties should document technical and organisational safeguards appropriate to risk, including access control, encryption where appropriate, backups, vulnerability management, incident handling and staff training.
5. Subprocessors
List approved subprocessors and their functions. Set the authorisation process for new subprocessors and require equivalent data-protection obligations in written contracts.
6. Assistance and incidents
Specify how the processor will assist with data-subject requests, impact assessments, regulator enquiries and security incidents. Agree a practical incident notification deadline and required details in the signed schedule.
7. International transfers and localisation
List hosting locations, transfer destinations and the legal mechanism relied upon for each transfer. Obtain local counsel advice on Uzbek data localisation and cross-border transfer rules and assess GDPR transfer rules where applicable.
8. Audits and evidence
Specify available compliance documentation, reasonable audit rights, confidentiality safeguards and any third-party certification evidence that actually exists.
9. Retention, return and deletion
At the end of the services, the processor will return or delete personal data as agreed, subject to legally required retention and documented backup cycles. Set the retention periods and deletion process in the schedule.
10. Liability, term and disputes
Define the term, precedence over the main agreement, liability allocation, governing law and dispute-resolution forum in the signed contract. Attach a processing schedule and subprocessors list.
Schedule checklist
- Controller and processor details
- Processing purpose, duration and operations
- Data subjects and data categories
- Security measures and incident contact
- Approved subprocessors and hosting locations
- International transfer mechanism and deletion schedule
This model does not itself certify compliance with GDPR or Uzbek law.


