Templates Compliance & Regulatory Data Protection Agreement - GDPR (New York Addendum)

Data Protection Agreement - GDPR (New York Addendum)

Ready to Edit

DATA PROTECTION AGREEMENT (INTERNATIONAL) - NEW YORK ADDENDUM

New York Overlay Review

Before use, counsel must determine whether New York privacy, security, breach-notification, consumer-rights, biometric, health, financial, employment, or industry-specific law applies and add the required controller/processor, service-provider/contractor, sale/share, audit, deletion, assistance, and certification terms. This file is not stamped as fully verified until those state authorities are checked against current official sources.

☐ New York role definitions and contract requirements mapped

☐ State consumer-request assistance and use restrictions mapped

☐ Security and breach-notification allocation mapped

☐ Sensitive-data and sector-specific terms mapped

☐ Conflict and precedence rules with the GDPR terms documented

(Controller-to-Processor Base Under Regulation (EU) 2016/679)


TABLE OF CONTENTS

  1. Document Header
  2. Definitions
  3. Operative Provisions
    3.1 Processing Scope & Instructions
    3.2 Compliance with Applicable Data Protection Law
    3.3 Sub-Processing
    3.4 Security of Processing
    3.5 International Data Transfers
    3.6 Cooperation & Data Subject Rights
    3.7 Records; DPIA & Consultations
    3.8 Deletion or Return of Personal Data

  4. Representations & Warranties

  5. Covenants & Restrictions
  6. Default & Remedies
  7. Risk Allocation
    7.1 Indemnification
    7.2 Limitation of Liability
    7.3 Insurance
    7.4 Force Majeure

  8. Dispute Resolution

  9. General Provisions
  10. Execution Block
  11. Annexes

1. DOCUMENT HEADER

This Data Protection Agreement (“Agreement”) is entered into and made effective as of [EFFECTIVE DATE] (“Effective Date”) by and between:

(a) [FULL LEGAL NAME OF DATA EXPORTER], a company incorporated under the laws of [COUNTRY/STATE], with its registered office at [ADDRESS] (“Controller” or “Data Exporter”); and

(b) [FULL LEGAL NAME OF DATA IMPORTER], a company incorporated under the laws of [COUNTRY/STATE], with its registered office at [ADDRESS] (“Processor” or “Data Importer”).

Governing Law. This Agreement is governed by the laws of [JURISDICTION], without displacing the GDPR or other mandatory data-protection law that applies to the Processing. Any SCC governing-law and forum selections must satisfy Clauses 17 and 18 of the selected SCC module and prevail for disputes under those Clauses.

Recitals
A. The Controller wishes to engage the Processor to perform certain services that require the Processor to Process Personal Data on the Controller’s behalf.
B. The parties desire to ensure that such Processing is conducted in accordance with GDPR and with due respect for the rights and freedoms of Data Subjects.
C. The parties therefore agree to the terms and conditions set forth below.


2. DEFINITIONS

For ease of reference, capitalized terms have the meanings set out below and shall apply equally to singular and plural forms. Terms not defined herein have the meanings ascribed to them in the GDPR.

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means direct or indirect ownership of more than fifty percent (50%) of the voting interests of an entity.

“Applicable Data Protection Law” means all data protection and privacy laws and regulations applicable to the Processing of Personal Data under this Agreement, including GDPR and, where relevant, the laws of any other country.

“Data Subject”, “Personal Data”, “Processing”, “Controller”, “Processor”, “Personal Data Breach”, and “Supervisory Authority” shall have the meanings given in GDPR Art. 4.

“International Transfer” means any transfer of Personal Data that is subject to Chapter V GDPR.

“Standard Contractual Clauses” or “SCCs” means the clauses annexed to Commission Implementing Decision (EU) 2021/914, as may be amended or replaced (“2021 SCCs”).

“Technical and Organisational Measures” or “TOMs” means the measures described in Annex II.


3. OPERATIVE PROVISIONS

3.1 Processing Scope & Instructions

(a) Subject-Matter. The Processor shall Process Personal Data solely for the purpose of providing [DESCRIPTION OF SERVICES] (“Services”) pursuant to [REFERENCE TO MASTER SERVICES AGREEMENT OR STATEMENT OF WORK].
(b) Documented Instructions. The Controller instructs the Processor to Process Personal Data (i) as necessary to provide the Services; (ii) as documented in Annex I; and (iii) as further instructed by the Controller in writing. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
(c) Duration. Processing shall commence on the Effective Date and continue until the earliest of (i) termination or expiry of the Services, or (ii) deletion/return of all Personal Data in accordance with Section 3.8.

3.2 Compliance with Applicable Data Protection Law

The Processor shall comply with the GDPR obligations that apply directly to it, including the applicable requirements of Articles 28, 29, 30(2), 32, and 33(2), and shall provide the assistance described in Article 28(3)(e) and (f). The Controller remains responsible for the Controller obligations assigned to it by the GDPR, including determining lawful purposes and means and making any required data-subject or supervisory-authority notification.

3.3 Sub-Processing

(a) Authorisation Method. Select one method and complete Annex III:

Specific authorisation. Processor may appoint only the Sub-Processors specifically authorised in writing by Controller.

General written authorisation. Controller generally authorises the Sub-Processors in Annex III. Processor shall give at least [NUMBER] days' prior written notice of an intended addition or replacement, giving Controller an opportunity to object on reasonable data-protection grounds before the change takes effect.

(b) Appointment Requirements. Before a Sub-Processor Processes Personal Data, Processor shall enter into a written contract imposing the same data-protection obligations set out in this Agreement, including sufficient guarantees to implement appropriate technical and organisational measures.
(c) Liability. Processor remains fully liable to Controller for any Sub-Processor’s performance under this Agreement.

3.4 Security of Processing

(a) TOMs. Processor shall implement the TOMs described in Annex II and any additional measures required under Article 32 GDPR, taking into account the state of the art, costs, and risks.
(b) Confidentiality. Processor shall ensure that all persons authorised to Process Personal Data are subject to appropriate confidentiality obligations.

3.5 International Data Transfers

(a) Transfer Mapping. The parties shall identify each transfer subject to Chapter V GDPR and document the transfer mechanism relied upon, including any adequacy decision, appropriate safeguard under Article 46, binding corporate rules, or Article 49 derogation.

(b) 2021 Transfer SCCs. Where Decision (EU) 2021/914 is selected, the parties shall attach the complete, unmodified SCC text; select the module that matches the parties' actual roles — Module One (controller-to-controller), Module Two (controller-to-processor), Module Three (processor-to-processor), or Module Four (processor-to-controller); select the permitted options; and complete the applicable Appendix annexes. Incorporation by reference to an unspecified module is not sufficient for this Agreement.

(c) Conflicts. The selected SCCs prevail over conflicting terms of this Agreement for the transfer they govern.

(d) Transfer Assessment and Measures. The parties shall document the assessment required by the selected SCCs and implement supplementary contractual, technical, or organisational measures where needed for compliance.

3.6 Cooperation & Data Subject Rights

(a) Data Subject Requests. Processor shall promptly, and in any event within [NUMBER OF DAYS] business days, notify Controller of any Data Subject request relating to Personal Data and, if directed by Controller, assist in responding to the request.
(b) Supervisory Authority Inquiries. Processor shall notify Controller without undue delay of any inquiry or inspection by a Supervisory Authority relating to Processing under this Agreement.
(c) Data Protection Impact Assessments. Processor shall provide reasonable assistance to Controller in conducting DPIAs and prior consultations under Articles 35–36 GDPR.

3.7 Records; DPIA & Consultations

Processor shall maintain records of Processing in accordance with Article 30(2) GDPR and make such records available to Controller upon request.

3.8 Deletion or Return of Personal Data

Upon termination or expiration of the Services, Processor shall, at Controller’s choice, delete or return all Personal Data and delete existing copies, unless EU or Member State law requires storage.


4. REPRESENTATIONS & WARRANTIES

4.1 Mutual Representations. Each party represents and warrants that:
(a) it is duly organised, validly existing, and in good standing under the laws of its jurisdiction;
(b) the execution of this Agreement has been duly authorised; and
(c) its performance hereunder will not violate any applicable law or conflict with any other agreement.

4.2 Processor Warranty. Processor further warrants that it has implemented, and will maintain, TOMs sufficient to comply with Article 32 GDPR.

4.3 Survival. The representations and warranties in this Section survive termination of this Agreement for so long as either party Processes Personal Data under this Agreement.


5. COVENANTS & RESTRICTIONS

5.1 Processor shall not:
(a) Process Personal Data for its own purposes;
(b) sell, rent, or lease Personal Data; or
(c) combine Personal Data with data obtained from other sources, except as instructed by Controller.

5.2 Audit Rights.
(a) Processor shall make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR.
(b) Processor shall allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller. The parties may ordinarily coordinate timing, confidentiality, security, and disruption controls, but no frequency, notice, or site restriction may prevent an audit required to demonstrate Article 28 compliance or respond to a suspected breach, material control change, or supervisory-authority requirement.

5.3 Notice of Breach. Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data. The parties agree to a contractual outside target of [24] hours after awareness, unless completed notification within that period is infeasible; Processor shall provide available information in phases and continue supplementation.


6. DEFAULT & REMEDIES

6.1 Events of Default include:
(a) Material breach of Sections 3, 4, 5, or 7;
(b) Failure to cure any non-material breach within [30] days after written notice;
(c) Repeated minor breaches indicating a pattern of non-compliance.

6.2 Cure & Mitigation. Upon an Event of Default, Processor shall promptly:
(a) take all steps necessary to remedy the breach;
(b) provide Controller with a root-cause analysis; and
(c) implement preventive measures.

6.3 Graduated Remedies. If Processor fails to cure within the specified period, Controller may, in escalating order:
(a) suspend the relevant Processing operations;
(b) require Processor to cease all Processing; or
(c) terminate this Agreement and, if applicable, any underlying Services agreement, without penalty.

6.4 Costs & Fees. The defaulting party shall bear all reasonable costs arising from remediation, including third-party forensic services, notifications, and credit monitoring where applicable.


7. RISK ALLOCATION

7.1 Indemnification

Processor shall indemnify, defend, and hold harmless Controller, its Affiliates, and their respective officers, directors, and employees (collectively, “Controller Indemnitees”) from and against all claims, damages, fines, penalties, or costs (including reasonable attorney fees) arising out of or relating to:
(a) Processor’s breach of its obligations under this Agreement; or
(b) Processor’s violation of Applicable Data Protection Law.

7.2 Limitation of Liability

(a) Mandatory-Law Carve-Out. Nothing in this Agreement limits a supervisory authority's powers or a data subject's rights under Article 82. Any allocation between the parties operates only to the extent permitted by applicable law and does not bind a supervisory authority or data subject.
(b) Aggregate Cap. Subject to Section 7.2(a), each party’s total aggregate liability under or in connection with this Agreement shall not exceed [PERCENTAGE]% of the fees paid or payable by Controller to Processor in the [12] months preceding the event giving rise to liability.
(c) Exclusions. Liability is not limited for (i) death or personal injury; (ii) gross negligence or wilful misconduct; or (iii) fraudulent misrepresentation.

7.3 Insurance

Processor shall maintain, at its own expense, cyber/data protection liability insurance with minimum limits of [AMOUNT & CURRENCY] per incident and in the aggregate, and shall provide certificates of insurance upon request.

7.4 Force Majeure

Neither party shall be liable for failure to perform caused by events beyond its reasonable control, except that this Section shall not apply to obligations to protect Personal Data or remedy Personal Data Breaches.


8. DISPUTE RESOLUTION

8.1 Good-Faith Negotiation. The parties shall attempt in good faith to resolve any dispute arising out of or relating to this Agreement within [30] days of written notice of the dispute.

8.2 Limited Arbitration. If the dispute is not resolved through negotiation, and only with respect to monetary claims not exceeding [THRESHOLD AMOUNT & CURRENCY], either party may submit the dispute to binding arbitration under the Rules of Arbitration of the International Chamber of Commerce (“ICC”). Seat of arbitration: [CITY]. Language: [LANGUAGE]. This clause does not apply to disputes governed by the 2021 transfer SCCs, data-subject rights, or supervisory-authority powers.

8.3 Court Proceedings & Forum Selection. For all other disputes, the parties irrevocably submit to the exclusive jurisdiction of the courts of [EU MEMBER STATE CITY].

8.4 Injunctive Relief. Notwithstanding Sections 8.1–8.3, either party may seek immediate injunctive or other equitable relief before any competent court to protect Personal Data or secure compliance with this Agreement.


9. GENERAL PROVISIONS

9.1 Amendments & Updates. Any amendment must be in writing and signed by authorised representatives of both parties. Processor may propose updates required by changes in Applicable Data Protection Law; Controller shall not unreasonably withhold consent.

9.2 Assignment. Neither party may assign or transfer any of its rights or obligations under this Agreement without the prior written consent of the other, except to an Affiliate or successor in a merger or sale of substantially all assets, provided such assignee agrees in writing to be bound by this Agreement.

9.3 Severability. If any provision is held unenforceable, the remainder shall remain in full force, and the invalid provision shall be replaced by a valid provision that most closely reflects the parties’ intent.

9.4 Entire Agreement. This Agreement (including its Annexes and the SCCs) constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements or understandings.

9.5 Waiver. No failure or delay by either party in exercising any right hereunder shall constitute a waiver of that or any other right.

9.6 Counterparts & Electronic Signatures. This Agreement may be executed in counterparts, each of which shall be deemed an original. Electronic signatures (including via DocuSign or similar) shall be deemed to have the same legal effect as original signatures.


10. EXECUTION BLOCK

CONTROLLER PROCESSOR
[FULL LEGAL NAME] [FULL LEGAL NAME]
By: __________________________ By: __________________________
Name: [PRINTED NAME] Name: [PRINTED NAME]
Title: [TITLE] Title: [TITLE]
Date: ___________ Date: ___________

11. ANNEXES

Annex I – Details of Processing
A. Subject matter of Processing: [DESCRIPTION]
B. Duration of Processing: [TERM OR CRITERIA]
C. Nature and purpose of Processing: [DESCRIPTION]
D. Categories of Data Subjects: [EMPLOYEES, CUSTOMERS, ETC.]
E. Types of Personal Data: [IDENTIFY DATA TYPES]
F. Special Categories and Article 10 data (if any): [IDENTIFY DATA AND SAFEGUARDS]
G. Controller rights and instructions: [DESCRIPTION]
H. Processing locations and transfer frequency: [DESCRIPTION]

Annex II – Technical & Organisational Measures

Describe the measures specifically; do not rely on generic labels. Address as applicable:

  1. Pseudonymisation and encryption: [DETAILS]
  2. Identity, authentication, authorisation, and least privilege: [DETAILS]
  3. Confidentiality, integrity, availability, and resilience: [DETAILS]
  4. Backup, restoration, continuity, and disaster recovery: [DETAILS]
  5. Logging, monitoring, detection, and incident response: [DETAILS]
  6. Vulnerability, patch, change, and configuration management: [DETAILS]
  7. Physical and environmental security: [DETAILS]
  8. Testing and effectiveness evaluation: [DETAILS]
  9. Data minimisation, quality, retention, return, and erasure: [DETAILS]
  10. Measures enabling Processor's Article 28 assistance: [DETAILS]

Annex III – Authorised Sub-Processors
| Name | Address | Service Description | Location |
|------|---------|--------------------|----------|
| [SUB-PROCESSOR 1] | | | |
| [SUB-PROCESSOR 2] | | | |

Annex IV – Transfer Mechanism

☐ No Chapter V transfer identified

☐ Adequacy decision: [IDENTIFY]

☐ Decision (EU) 2021/914 SCCs attached in full — Module [ONE / TWO / THREE / FOUR], options and Appendix completed

☐ Binding corporate rules: [IDENTIFY]

☐ Other Article 46 safeguard: [IDENTIFY]

☐ Article 49 derogation, exceptionally and after counsel review: [IDENTIFY]

Sources and References

  • EUR-Lex, Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/2016-05-04/eng
  • EUR-Lex, Commission Implementing Decision (EU) 2021/914: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj/eng
  • EUR-Lex, Commission Implementing Decision (EU) 2021/915: https://eur-lex.europa.eu/eli/dec_impl/2021/915/oj/eng

Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?
AI Legal Assistant
Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?

Insert Image

Insert Table

Watch Ezel in action (sample case)

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
data_protection_agreement_gdpr_ny.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Get your finished document

Filled in for your situation. Drafting from scratch takes hours; finish yours in about 5 minutes for $99 one time.

  • Deep Legal Knowledge
    Understands case law, statutes, and legal doctrine specific to New York.
  • Court-Ready Formatting
    Proper captions and local-rule compliance.
  • AI-Powered Editing
    Tailor every section to your case.
  • Export as PDF & Word
    Ready to file or send.
Secure checkout via Stripe
Need to customize this document?

About This Template

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Important Notice

This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Last updated: July 2026

Get your Data Protection Agreement - GDPR (New York Addendum), done and ready to use

Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.