01
Scope
A signed data processing agreement should define the parties, covered services, processing instructions, data categories and affected individuals.
02
Security schedule
The agreement should record verified technical and organizational measures for the selected deployment.
03
Subprocessors and locations
Current subprocessors, hosting locations and transfer mechanisms should be disclosed and approved through the commercial review.
04
Incidents and assistance
Notification, data-subject assistance, audit support, deletion and return requirements should be written into the signed agreement.
05
Contract controls
This public overview is not a signed DPA and creates no product-processing commitment on its own.