Data processing agreement framework
A procurement-ready outline for the customer-controller and HRMS-processor relationship.
Last structured: 6 August 2026Status of this document
This is a non-binding structural outline. The final DPA must be drafted and approved by qualified counsel based on the legal entity, product architecture, customer roles, applicable law and actual subprocessor arrangements.
Roles and instructions
Define when the customer determines purposes and means of employee-data processing and when duoHR acts only on documented instructions.
Processing details
Describe categories of data subjects, personal data, processing activities, purposes, duration and service locations in a schedule.
Confidentiality and security
Set contractual obligations for authorised personnel, technical and organisational measures, access, encryption, resilience, testing and incident handling.
Subprocessors
Define authorisation, change notice, contractual flow-down and customer objection procedures.
Assistance and rights
Describe assistance for data-subject requests, impact assessments, regulator enquiries and other applicable obligations.
Return and deletion
Define export, return, retention and deletion processes at contract end, subject to lawful retention.
Audit and evidence
Specify the assurance evidence, questionnaires, reports or audit rights appropriate to the service and customer risk.