Officially approved IT Park Uzbekistan resident — Merahkie Silk Road MCHJ

MERAHKIE SILK ROAD LLC · UZBEKISTAN

Data Processing Agreement

A model data processing agreement for review and adaptation.

Data Processing Agreement

Model Data Processing Agreement — draft for completion and legal review. This template is not legal advice and should not be signed without completing the schedules and confirming the applicable law.

1. Parties and relationship

Identify the controller and processor by full legal name, address and authorised contact. Specify the services and the main agreement to which this DPA applies.

2. Processing details

Document the subject matter, duration, purposes, operations, data-subject categories and personal-data categories. Include only data that is actually processed.

3. Documented instructions

The processor will process personal data only on documented instructions from the controller, unless applicable law requires otherwise. Any additional processing must be assessed and documented.

4. Confidentiality and security

Personnel with access must be subject to confidentiality duties. The parties should document technical and organisational safeguards appropriate to risk, including access control, encryption where appropriate, backups, vulnerability management, incident handling and staff training.

5. Subprocessors

List approved subprocessors and their functions. Set the authorisation process for new subprocessors and require equivalent data-protection obligations in written contracts.

6. Assistance and incidents

Specify how the processor will assist with data-subject requests, impact assessments, regulator enquiries and security incidents. Agree a practical incident notification deadline and required details in the signed schedule.

7. International transfers and localisation

List hosting locations, transfer destinations and the legal mechanism relied upon for each transfer. Obtain local counsel advice on Uzbek data localisation and cross-border transfer rules and assess GDPR transfer rules where applicable.

8. Audits and evidence

Specify available compliance documentation, reasonable audit rights, confidentiality safeguards and any third-party certification evidence that actually exists.

9. Retention, return and deletion

At the end of the services, the processor will return or delete personal data as agreed, subject to legally required retention and documented backup cycles. Set the retention periods and deletion process in the schedule.

10. Liability, term and disputes

Define the term, precedence over the main agreement, liability allocation, governing law and dispute-resolution forum in the signed contract. Attach a processing schedule and subprocessors list.

Schedule checklist

  • Controller and processor details
  • Processing purpose, duration and operations
  • Data subjects and data categories
  • Security measures and incident contact
  • Approved subprocessors and hosting locations
  • International transfer mechanism and deletion schedule

This model does not itself certify compliance with GDPR or Uzbek law.

Plan your next technology project

Share your requirements with our team.