AI Data Processing
Agreement Template
An AI data processing agreement sets the terms for an AI vendor handling personal data on your behalf. Use this editable Word template to define permitted use, model training restrictions, sub-processors, security, transfers and deletion.
What to check in an AI vendor DPA
Start with the vendor’s role and actual data flows. Then check whether the agreement covers prompts, outputs, model training, retention and sub-processors. Adapt these clauses to the service and the law that applies.
The DPA Template
Expand each section to view the template clauses. Have your legal counsel review and customise before execution. Note: this is a template, not legal advice.
1Section 1, Scope & Subject Matter
This Data Processing Agreement ("Agreement") forms part of the Master Services Agreement between [Controller Name] ("Controller") and [Processor/Vendor Name] ("Processor").
Processor will process personal data on behalf of Controller for the purpose of providing [describe AI service, e.g. AI-powered document analysis, AI writing assistance, AI code generation] as defined in the Master Services Agreement.
The processing activities may include collection, storage, analysis, structuring, retrieval, use, disclosure, and deletion of personal data as necessary to provide the contracted services. Processing shall occur exclusively in automated form unless otherwise agreed in writing.
[e.g. Employees and contractors of the Controller; customers and prospects of the Controller; end users of the Controller's products, customise as applicable]
[e.g. Names, email addresses, job titles, professional communications, document content, usage data, customise based on actual data flows. Specify separately if any special category data under GDPR Article 9 is processed]
Processing will continue for the term of the Master Services Agreement and until all personal data is returned or deleted in accordance with Section 6 of this Agreement.
Important: AI-specific clause, Processor shall not use Controller's personal data, prompts, or outputs to train, fine-tune, or improve Processor's AI models or any third-party AI models. Processing shall be limited solely to delivering the contracted services.
2Section 2, Controller & Processor Obligations
Processor Obligations
- Process personal data only on documented instructions from the Controller, including with regard to transfers to third countries
- Ensure that persons authorised to process the personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement and maintain the technical and organisational security measures described in Section 4
- Immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law
- Not engage any sub-processor without prior specific or general written authorisation from the Controller, as detailed in Section 3
- Assist the Controller in fulfilling data subject rights requests (access, erasure, portability, restriction) within 5 business days of receiving a request
- Assist the Controller in ensuring compliance with obligations relating to security, breach notification, DPIAs, and prior consultation with supervisory authorities
- Delete or return all personal data to the Controller at the end of the service relationship, in accordance with Section 6
- Make available all information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits by the Controller or a mandated auditor
Controller Obligations
- Ensure a valid legal basis exists for all personal data provided to the Processor
- Ensure data subjects have been informed of processing via the Controller's privacy notice prior to data being submitted to the Processor
- Provide instructions that comply with applicable data protection law
- Complete a Data Protection Impact Assessment (DPIA) where required before deploying the AI service
3Section 3, Sub-Processor Management
AI vendors typically use multiple sub-processors for model hosting, compute, storage, and infrastructure. This section governs those relationships.
General Consent & Notification
Controller provides general written authorisation for the Processor to engage sub-processors as listed in Appendix B (Sub-Processor List). Processor must provide written notice to Controller at least [30] days before adding or replacing any sub-processor. Controller has the right to object to new sub-processors within [14] days of notification. If Controller objects and the parties cannot resolve the objection, Controller may terminate the affected services without penalty.
Sub-Processor List Requirements (Appendix B must include)
- Sub-processor name and registered address
- Country of processing (including where data centre infrastructure is located)
- Services provided by the sub-processor
- Categories of personal data processed
- Transfer mechanism applied (EU adequacy decision, SCCs, BCRs, or other)
Flow-Down Obligations
Processor shall impose the same data protection obligations set out in this Agreement on all sub-processors by way of a contract. Processor remains fully liable to Controller for the performance of sub-processors' obligations. Processor shall provide evidence of sub-processor contracts upon request.
4Section 4, Data Security Measures
Processor shall implement and maintain, at minimum, the following technical and organisational measures. Evidence of compliance must be provided upon request or via audit.
- All personal data encrypted at rest using AES-256 or equivalent
- All data in transit encrypted using TLS 1.2 or higher
- Encryption keys managed using HSM or equivalent key management system
- Customer data stored in logically isolated environments
- Role-based access control (RBAC) with least-privilege principle
- Multi-factor authentication (MFA) required for all privileged access
- Access logs maintained and reviewed; privileged access reviewed quarterly
- Background checks for personnel with access to personal data
- Annual penetration test by independent third-party security firm
- Vulnerability scanning run at least monthly
- Critical vulnerabilities patched within 72 hours; high within 14 days
- Bug bounty programme or equivalent responsible disclosure process
- ISO 27001 certification (or equivalent), provide certificate upon request
- SOC 2 Type II audit report, provide upon request under NDA
- Annual third-party security assessment
- Right to audit by Controller or mandated third party with 30 days notice
- Data submitted by Controller isolated from data of other customers
- Prompt and output logs retained for [X days] and then deleted
- Model training firewalled from customer data, confirmed by technical attestation
- AI model versioning and change management process documented
- Recovery Time Objective (RTO): [X hours], confirm with vendor
- Recovery Point Objective (RPO): [X hours], confirm with vendor
- Business continuity plan tested annually
- Uptime SLA: [X]%, as specified in the MSA
5Section 5, Cross-Border Data Transfers
This section applies where personal data originating in the European Economic Area (EEA) or United Kingdom is transferred to or accessed from a country not covered by an EU or UK adequacy decision.
Where personal data is transferred from the EEA to a third country, Processor shall execute the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) as applicable. The relevant module (Controller-to-Processor) shall be incorporated by reference into this Agreement. Processor shall maintain executed SCCs with all sub-processors processing EEA personal data.
Where personal data is transferred from the United Kingdom, Processor shall execute the UK IDTA or UK Addendum to the EU SCCs as appropriate. Processor shall provide evidence of executed UK transfer mechanisms upon request.
Processor shall cooperate with Controller in completing any Transfer Impact Assessment required by applicable data protection law. Processor shall provide information about the legal framework of the destination country and any access rights of public authorities that may affect the protection of personal data transferred under this Agreement.
Where personal data is transferred to a country covered by an EU or UK adequacy decision (e.g. transfers to the United States covered by the EU-US Data Privacy Framework), Processor shall certify or maintain certification under the applicable framework, and shall notify Controller immediately upon loss or suspension of that certification.
6Section 6, Breach Notification & Termination
Breach Notification
Processor shall notify Controller without undue delay and within 24 hours of becoming aware of a personal data breach affecting Controller's data. This timeline is required to allow Controller to meet its GDPR Article 33 obligation to notify supervisory authorities within 72 hours.
Breach notification must include, where available:
- Description of the nature of the personal data breach including categories and approximate number of data subjects and records affected
- Name and contact details of the data protection officer or other point of contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
- Timeline of when the breach was first detected and by whom
Breach notification contact: [Controller Security/DPO contact email]
Data Return & Deletion on Termination
- Upon expiry or termination of the Master Services Agreement, Processor shall cease processing Controller's personal data immediately
- Processor shall, at Controller's choice, either return all personal data to Controller in a commonly used machine-readable format within [30] days, or securely delete all personal data within [30] days
- Processor shall provide written confirmation of deletion including the deletion method used and the date of deletion
- Processor may retain personal data only to the extent required by applicable law, and only for the duration required by that law
- Sub-processors shall be subject to the same return/deletion obligations and Processor shall confirm sub-processor deletion within [45] days of termination
Audit Rights
Controller or its mandated auditor may audit Processor's compliance with this Agreement upon [30] days written notice, no more than once per calendar year (unless a breach has occurred). Processor shall cooperate fully with all audits and provide access to relevant systems, processes, and personnel. Processor may satisfy audit rights by providing a current ISO 27001 certificate or SOC 2 Type II report under NDA where appropriate.
How to Negotiate an AI Vendor DPA
Follow these steps to review, negotiate, and execute a DPA with your AI vendors. Involve your legal counsel and DPO throughout the process.
FAQ
Frequently Asked Questions
Do I need a DPA with every AI vendor?
Can AI vendors use my data to train their models?
What should I check in an AI vendor's sub-processor list?
What is the 72-hour breach notification requirement?
Track DPA Status Across All Your AI Vendors
Aona maintains a live vendor register that tracks which AI tools have executed DPAs, which are pending review, and which are flagged for renewal. Get full visibility of your AI vendor compliance posture without the spreadsheet maintenance.