Bonterms Help Center

How to Use the Bonterms DPA

Use the Bonterms Data Processing Addendum (DPA) to address data protection obligations in connection with your Cloud Terms or related cloud services agreement.

Steps:

  1. Review the DPA with your lawyer or legal counsel (see example)
  2. Prepare your DPA Setup Page (see example)
    • Identify the parties and complete the Key Terms:  Agreement, DPA Effective Date and Subprocessor List
    • Propose any Additional Terms (additions to, or modifications of the DPA)
  3. Prepare your Schedules (see examples)
  4. Send your DPA Setup Page and Schedules to your Counterparty
  5. Negotiate the DPA Setup Page and Schedules
  6. Sign the DPA Setup Page and create your DPA
  7. Incorporate the DPA into your Cloud Terms by either:
    • Adding the DPA as an Attachment to an Agreement created using the Cloud Terms and referencing it under Attachments on your Cloud Terms Cover Page (if executing concurrently); or
    • Amending an existing Agreement to add the DPA as an Attachment.

FAQs for the DPA

What data transfers is the DPA generally designed to cover?

  • The DPA is generally designed to cover a U.S.-based Provider (processor) interacting with a U.S. or global Customer (controller or processor) uploading personal data from U.S. or E.U. data subjects as part of its Customer Data under the Cloud Service.

How is the DPA structured between the main body and Schedules?

  • The main body of the DPA is designed to generally cover E.U./U.K. GDPR, Swiss and common U.S. state law data privacy principles. Cross-border transfers and U.S. state and other jurisdiction-specific issues may be addressed by the parties on Schedule 3 (Cross-Border Transfer Mechanisms) or Schedule 4 (Region-Specific Terms).

Why are the DPA Schedules provided as "examples"?

  • Because the Schedules must be customized to reflect the particulars of the transaction, and given the flux in the regulations themselves, we provide Schedules to the DPA under the Resources tab as “examples” in Word. You are free to create your own Schedules or start from the Bonterms examples and modify as you see fit.

What data transfers is the DPA not designed to cover?

  • The DPA is not designed to cover Provider’s use of personal data in its capacity as a controller (such as registration data) nor controller-controller transfers.

Can I use the DPA without using the Cloud Terms?

  • The Bonterms DPA is an Attachment to the Cloud Terms. This means it uses terms defined in the Cloud Terms (such as Affiliate, Agreement, Cloud Service, Customer Data, Order and Subscription Term) and relies on the larger contractual structure of the Cloud Terms (see, for example, the introduction to and Section 2.4 of the DPA and Sections 1, 5.3, 14.4, 16.5 and 22.10 of the Cloud Terms). 
  • Using the Bonterms DPA with a different underlying agreement would require a legal analysis of the differences with that agreement and, if a decision is made to proceed, drafting of any necessary corresponding provisions through a DPA Setup Page or other addendum.

Will the DPA work for my particular circumstances?

  • To understand if the DPA will work in any particular circumstance you should consult with a U.S. or global privacy lawyer, as applicable.

 

Video walkthrough of How to Use the Bonterms DPA:

Updated

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request