[HEADER — replace with your organisation’s letterhead, if used]
Data Processing Addendum
Where a vendor processes personal data on our behalf
Engaging a processor does not transfer the obligation. The organisation that determines what happens to the data remains responsible under the Act, and is the one that must notify the Commission if the vendor is breached. This addendum is the control that makes that responsibility manageable — particularly the requirement that the vendor tell you immediately.
THIS ADDENDUM forms part of the agreement dated [DATE] between:
(1)[COMPANY NAME], UEN [UEN] (the "Organisation"); and
(2)[VENDOR NAME], [registration details] (the "Processor").
Where this Addendum conflicts with the agreement, this Addendum prevails in respect of personal data.
1. Definitions and Scope
1.1"Personal Data" has the meaning given in the Personal Data Protection Act 2012. "Act" means that Act and any subsidiary legislation. "Commission" means the Personal Data Protection Commission.
1.2The Processor processes Personal Data on behalf of and for the purposes of the Organisation. The Organisation determines the purposes and means of processing.
1.3The details of the processing are set out in Schedule 1.
1.4Where the Processor determines its own purposes for any Personal Data, it acts as an organisation in its own right for that processing and bears its own obligations under the Act.
2. Processor Obligations
2.1The Processor shall process Personal Data only on the documented instructions of the Organisation, and only for the purposes in Schedule 1.
2.2The Processor shall not use Personal Data for its own purposes, including to develop, train or improve its own products or models, or for analytics, benchmarking or marketing, without the Organisation’s prior written consent.
2.3The Processor shall not sell, licence or otherwise disclose Personal Data to any third party except as permitted by this Addendum or required by law. Where disclosure is required by law, the Processor shall notify the Organisation first unless prohibited from doing so.
2.4The Processor shall make reasonable security arrangements to protect Personal Data against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, at least to the standard in Schedule 2.
2.5The Processor shall ensure that personnel with access to Personal Data are subject to confidentiality obligations, are trained, and have access only on a need-to-know basis.
2.6The Processor shall not retain Personal Data for longer than necessary for the purposes, and shall comply with the retention periods in Schedule 1.
2.7The Processor shall assist the Organisation in meeting its obligations under the Act, including responding to access and correction requests, and shall not respond directly to an individual without the Organisation’s instruction.
3. Data Breach
3.1The Processor shall notify the Organisation of any data breach affecting Personal Data immediately, and in any event within [24] hours of becoming aware of it, by email to [EMAIL] and telephone to [PHONE].