Data protection
US commercial-market reference points; verify against the matter's jurisdiction pack. This family is the most regime-dependent of the twelve — the required terms differ materially between the EU/UK regimes, US state privacy laws, and sectoral rules. Identify which regimes apply to the data in the deal before judging any clause.
Balanced position
Roles are expressly assigned (who determines purposes and means, who processes on instructions). The processing party processes personal data only on documented instructions and only to provide the service; it implements stated technical and organizational security measures, notifies the other party of a personal-data breach without undue delay, assists with data-subject requests and compliance obligations, binds subprocessors to equivalent terms (with a published list and a notice-and-objection mechanism), supports audits or supplies recognized audit reports, deletes or returns data at the end of the engagement, and uses a lawful transfer mechanism for any cross-border transfer that requires one.
Provider shall process Personal Data only on Customer's documented
instructions and solely to provide the Service; implement the technical and
organizational measures described in Annex [Security]; notify Customer
without undue delay after becoming aware of a Personal Data Breach; engage
subprocessors only under written terms no less protective than this DPA,
maintaining a current subprocessor list and giving Customer prior notice of
additions with a right to object; and, at Customer's election on termination,
delete or return all Personal Data except as retention is required by law.
Common one-sided variants
Tilted toward the processing party (often the provider):
- Rights to use personal data for its own purposes — analytics, product improvement on identifiable data, or marketing — outside the customer's instructions.
- Breach notice diluted to a long fixed window, conditioned on confirmed impact, or omitted; no subprocessor list, flow-down, or objection right.
- Security obligations stated as "industry standard" with no annex, certification, or audit mechanism behind them.
Tilted toward the controller/customer:
- Unlimited on-site audit rights at any time at the provider's cost, where a recognized third-party audit report would serve.
- Breach-notice windows so short they are operationally impossible, paired with uncapped liability for any security incident regardless of fault.
- Instructions defined so broadly that any customer request, however far outside the service, becomes a contractual processing obligation.
Fallback ladder
- Full balanced position: instructions-only processing, security annex, undue-delay breach notice, subprocessor controls, deletion/return, lawful transfer mechanism (preferred).
- Accept audit rights satisfied by recognized third-party reports (with on-site audit reserved for cause, e.g., after a breach or regulator inquiry).
- Accept a general subprocessor authorization with a published list, change notice, and an objection right whose remedy is termination of the affected service with a pro-rata refund.
- Accept aggregated/de-identified usage data rights only where re-identification is contractually prohibited and the definition of de-identified meets the applicable regime's standard.
Below rung 4 — own-purpose use of identifiable personal data, or no breach notice obligation — escalate.
Rationale: Data-protection terms carry regulatory exposure that the liability clause may not cap; roles, breach notice, and transfers are the items regulators and counterparties test first.