Customer Data Processing Addendum
A GDPR Article 28 DPA is engagement-specific: controller, processor, data, duration and security measures must be identified before signature.
This is a public review draft. It is not an offer or an operative agreement; signed service terms and approved schedules prevail.
Roles and instructions
Where VISIONCYBERX acts as processor, it processes personal data only on documented controller instructions, including for transfers, unless applicable law requires otherwise. Personnel with access are bound to confidentiality. The controller remains responsible for its purposes and lawful basis.
Security and assistance
The parties document risk-appropriate technical and organisational measures under Article 32. The processor assists, in proportion to the service and available information, with data-subject requests, security, breach handling, impact assessments and prior consultation.
Sub-processors and transfers
Sub-processors require prior specific or general written authorisation, notice of changes and an opportunity to object where general authorisation applies. Equivalent data-protection duties flow down. International transfers require an applicable GDPR transfer mechanism and safeguards.
Audit and end of service
The processor provides information needed to demonstrate compliance and permits and contributes to audits under Article 28. At the controller's choice, data is returned or deleted at the end, subject to legal retention duties.
Schedules needed
The executable annexes must specify subject matter, duration, nature and purpose, data types, data subjects, locations, approved sub-processors, security measures, breach contacts, transfer mechanism and deletion method. This page is not an executed DPA.