Confidentiality, data & IP

Data Protection Clause: Controller vs Processor, Subprocessors, Transfers, Breach Notice

Also known as: DPA, data processing addendum

ByArshita Anand

A data protection clause governs how a vendor handles personal data on your behalf. It fixes who is the controller and who is the processor, restricts what the processor can do with the data, controls who else the processor can hand it to (subprocessors), sets the legal mechanism for moving data across borders, and locks in how fast you get told about a breach. Most of this lives in a separate Data Processing Addendum (DPA), and the breach-notice timeline plus the subprocessor terms are where the real exposure sits.

TL;DR

  • A data protection clause defines the controller (decides why and how data is used) and the processor (acts only on the controller's instructions). Get the roles right; the obligations and liability flow from them.
  • The vendor may use your data only on your documented instructions and only to deliver the service, never to train its own models or build its own products unless you agree in writing.
  • Subprocessors are the vendor's vendors. Require a current list, advance notice of changes, a right to object, and flow-down terms so the chain stays as protective as your contract.
  • For data leaving the EU, UK, or other regulated regions, the contract needs a valid transfer mechanism (Standard Contractual Clauses or an adequacy basis). A DPA with no transfer terms is incomplete.
  • The breach-notice timeline is the most negotiated number. Push for "without undue delay and no later than 48 to 72 hours." "Promptly" or "as required by law" is too soft to act on.

What a data protection clause actually does

The clause translates privacy law into binding contract terms between you and a vendor. Five mechanics carry the weight.

1. Role allocation. It names who is the controller and who is the processor (or, under some US laws, business and service provider). The controller sets the purposes; the processor follows instructions. If both decide jointly, they may be joint controllers, which carries shared liability.

2. Use restrictions. It limits the processor to processing the data only for the contracted service and only on your instructions. This is what stops a vendor from monetizing, selling, or training on your data.

3. Subprocessor controls. It governs whether and how the processor can engage others to touch the data, what notice you get, and whether those subprocessors are bound by equivalent terms.

4. Security and breach notice. It requires appropriate technical and organizational measures and sets how quickly and in what detail the processor must tell you about a personal data breach.

5. Transfers, audits, and deletion. It sets the cross-border transfer mechanism, your audit rights, and what happens to the data when the contract ends (return or delete, on a defined timeline).

Why it matters: the dollars at stake

Picture a company (the controller) using a SaaS analytics vendor (the processor) that holds personal data on 500,000 of the company's customers. The vendor suffers a breach.

Here is the example math on how the DPA terms change the controller's exposure.

  • With a vague breach clause ("notify as required by applicable law"), the controller learns of the breach 18 days after the vendor did, blows its own 72-hour regulatory notification window, and faces regulator scrutiny plus reputational fallout. Illustrative regulatory exposure under a strict regime can reach into the millions for a breach this size.
  • With a 48-hour notice clause plus a duty to provide breach details and cooperate, the controller notifies regulators and affected individuals on time, which is both legally required and the single biggest factor in limiting penalties and lawsuits.
  • If the DPA also lets the vendor use the data to improve its own products, the controller may have an additional, separate compliance problem: data used for a purpose its customers never consented to.

Same breach. The notice timeline and the use restriction decide whether the controller is a diligent victim or a non-compliant defendant. That is why in-house counsel treat the DPA as a real negotiation, not a formality to sign at the end.

Who wants what

Controller (your company, the customer)Processor (the vendor)
RoleController; vendor is a pure processorSometimes wants joint-controller or independent-controller status
Use of dataService only, no training or product improvementRight to use de-identified or aggregated data to improve service
SubprocessorsPrior written consent or right to objectList plus general authorization, notice only
Breach noticeWithout undue delay, max 48-72 hours"Promptly" or "as required by law"
Transfer mechanismSCCs or adequacy, named and attachedVendor's standard SCCs, take it or leave it
Audit rightsOn-site audit on noticeThird-party report (SOC 2 / ISO) in lieu of audit
Deletion on exitReturn and delete, certifiedDelete with a backup-retention carve-out
LiabilityData claims outside the general capData claims inside the general cap

The pattern: the controller wants tight purpose limits, fast notice, and visibility into the chain; the processor wants flexibility, light-touch notice, and audit-by-report.

Market-standard language

A typical core of a DPA reads close to this:

DATA PROTECTION.

(a) Roles. The parties acknowledge that, for Personal Data processed under
the Agreement, Customer is the Controller and Provider is the Processor.
Provider will process Personal Data only on Customer's documented
instructions, including the Agreement, and only as needed to provide the
Services.

(b) Confidentiality and Security. Provider will ensure persons authorized
to process Personal Data are under a duty of confidentiality and will
implement appropriate technical and organizational measures to protect
Personal Data against accidental or unlawful destruction, loss,
alteration, or unauthorized disclosure.

(c) Subprocessors. Provider may engage Subprocessors only under a written
contract imposing data-protection obligations no less protective than those
in this DPA. Provider will maintain a current list of Subprocessors,
provide at least thirty (30) days' notice of any intended change, and
Customer may object on reasonable data-protection grounds.

(d) Breach Notice. Provider will notify Customer without undue delay, and
in any event within forty-eight (48) hours, after becoming aware of a
Personal Data Breach, and will provide enough detail for Customer to meet
its own notification obligations and will cooperate in good faith.

(e) Transfers. Where processing involves a transfer of Personal Data to a
country without an adequacy decision, the parties agree the Standard
Contractual Clauses, attached as Exhibit [X], apply and are incorporated
by reference.

(f) Deletion. On termination, Provider will, at Customer's choice, return
or delete all Personal Data and certify deletion, except for copies
required to be retained by law.

Subsection (a) is the keystone. If the roles are wrong, every obligation below them is allocated to the wrong party.

The negotiation: standard, fallback, walk-away

IssueOpening positionFallback both acceptWalk-away
Breach notice24 hoursWithout undue delay, max 48-72 hours"Promptly" or "as required by law"
Use of dataService only, no exceptionsService plus de-identified, aggregated analyticsRight to train models on identifiable data
SubprocessorsPrior written consent each timeList plus 30-day notice and right to objectUnlimited, no notice
TransfersSCCs attached and namedSCCs incorporated by referenceNo transfer mechanism at all
AuditOn-site audit on noticeSOC 2 / ISO report plus audit for causeNo audit, no report
DeletionReturn and delete, certifiedDelete with narrow backup carve-outIndefinite retention
Liability for data claimsOutside the general capHigher super-cap for data claimsInside the general fees-based cap

The standard compromise on subprocessors is general authorization plus a current list, advance notice, and a right to object. The standard compromise on audits is a current third-party report (SOC 2 Type II or ISO 27001) with a contractual audit right reserved for cause.

Common carve-outs and variations

The variations that change how the clause behaves:

  • Joint or independent controller status. Some vendors process data for their own purposes too (fraud scoring, benchmarking). That can make them an independent or joint controller, which shifts liability. Know which role applies before you sign.
  • De-identified and aggregated data. Vendors often want to use anonymized or aggregated data to improve the service. This can be acceptable if the data is truly de-identified and cannot be re-linked, but define the standard tightly.
  • Cross-border transfers. For data leaving the EU or UK, the contract needs SCCs or an equivalent. For US-only data, state laws (such as the California regime) impose their own service-provider terms instead.
  • Sub-processing chains. A subprocessor that engages its own subprocessors creates a chain. The flow-down obligation must reach all the way down, and the top-level processor stays liable for the whole chain.

A controller-protective deletion fallback looks like this:

Within thirty (30) days after termination, Provider will delete all
Personal Data in its and its Subprocessors' possession and certify
deletion in writing, except for copies stored in routine backups, which
Provider will delete on its standard backup cycle and will not access or
process except as required for backup integrity.

Jurisdiction and enforceability notes

Data protection terms sit on top of mandatory privacy law, which is what gives them teeth and what limits them:

  • The law sets a floor the contract cannot lower. Under the GDPR and similar regimes, a processor agreement must contain specified terms (purpose limitation, security, subprocessor controls, breach assistance, deletion). A DPA missing these is non-compliant regardless of what the parties agreed.
  • Breach-notice duties are statutory. A controller's own deadline to notify regulators (often 72 hours under the GDPR) and individuals runs by law. The vendor's contractual notice timeline has to be short enough to let you meet yours.
  • Transfer rules are mandatory. Moving regulated personal data to a country without an adequacy decision generally requires a recognized mechanism such as Standard Contractual Clauses. A contract that ignores this does not make the transfer lawful.
  • US state laws use different labels. Several US state privacy laws use "business" and "service provider" instead of controller and processor, with their own required contract terms. Map the roles to the governing law, do not assume GDPR vocabulary applies.
  • Liability for data claims is heavily negotiated. Regulators can fine the controller directly even when the processor caused the breach. That is why controllers push data claims outside the general liability cap.

This is general information, not legal advice for a specific deal. The required terms and enforceability turn on which privacy laws apply and the facts of the processing. For a working method, see our DPA review field guide and the DPA negotiation playbook.

Review checklist: red flags to catch

  • The roles are wrong or undefined, leaving the liability allocation unclear.
  • The use clause permits training, product improvement, or "any purpose" on identifiable data.
  • The breach-notice timeline is "promptly" or "as required by law" instead of a hard number.
  • No subprocessor list, no notice of changes, and no right to object.
  • No transfer mechanism for data that crosses a regulated border.
  • The audit right is replaced by nothing, not even a SOC 2 or ISO report.
  • Deletion on exit is silent or allows indefinite retention beyond routine backups.
  • Data claims sit inside the general fees-based cap, so a breach is capped at a year of fees.
  • The DPA does not flow down to subprocessors, breaking the chain of protection.

How it interacts with other clauses

The data protection clause does not stand alone. Read it together with:

  • Confidentiality: confidentiality covers all sensitive information; the DPA adds the specific, mandatory requirements for personal data.
  • Limitation of liability: push data-breach claims outside the general cap or onto a higher super-cap, since regulatory exposure dwarfs a year of fees.
  • Indemnification: a data-breach indemnity from the vendor covers third-party and regulator claims that flow from its failure.
  • Survival: the deletion, confidentiality, and breach-cooperation duties must survive termination.

For the broader workflow, see the in-house contract review playbook.

FAQ

What is a data protection clause or DPA? A data protection clause, often packaged as a separate Data Processing Addendum, governs how a vendor handles personal data on your behalf. It allocates controller and processor roles, restricts how the data may be used, controls subprocessors, sets breach-notice timelines, and fixes cross-border transfer terms.

What is the difference between a controller and a processor? The controller decides why and how personal data is processed. The processor acts only on the controller's documented instructions and cannot use the data for its own purposes. Getting the roles right matters because the legal obligations and liability follow from them.

How fast should a vendor have to notify you of a data breach? Push for "without undue delay and no later than 48 to 72 hours" after the vendor becomes aware of a breach. Your own regulatory deadline often runs 72 hours, so a slower vendor timeline or a vague "promptly" leaves you unable to meet it.

Do I need a transfer mechanism in the DPA? Yes, if regulated personal data crosses a border to a country without an adequacy decision. The standard mechanism is the Standard Contractual Clauses, attached or incorporated by reference. A DPA with no transfer terms does not make the transfer lawful.

Can a vendor use our data to train its AI models? Only if you agree to it in writing, and even then only within the limits of applicable privacy law and your own commitments to your customers. The safe default is to limit the vendor to processing the data to deliver the service. If you allow analytics, require true de-identification and ban re-identification.

What are subprocessors and why do they matter? Subprocessors are the vendor's own vendors that touch your data, such as a cloud host or support tool. They extend the chain of people who can access your data, so require a current list, advance notice of changes, a right to object, and contract terms that flow your protections all the way down.

Should data-breach liability sit inside or outside the general cap? Outside, or under a higher super-cap. Regulatory fines and breach-response costs routinely exceed a year of fees, so a data claim capped at the general fees-based limit leaves the controller badly under-protected for the risk it cares about most.

Stop reviewing this clause by hand.
Vaquill AI flags off-market terms against your playbook and drafts the fallback language, with every position cited. Your data stays yours. 7-day free trial.
13 min read
Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.

Research, review, and draft, with a source on every answer.

Vaquill AI reads your documents and knows the law. Every answer shows where it came from. 7-day free trial.