Compliance
Data processing agreement
under GDPR Article 28.
Whenever personal data is processed on a customer's behalf, a data processing agreement is concluded. SIMO GmbH provides a template for it that is customized per customer: counterparty, processing purposes, choice of sub-processors.
What the agreement covers
The template follows the structure Article 28(3) prescribes and adds the annexes without which a processing agreement cannot realistically be audited.
- Subject matter, duration, nature and purpose of the processing under Article 28(3)(a).
- Types of personal data and categories of data subjects.
- Obligations and rights of the controller.
- Technical and organizational measures as Annex 2.
- List of approved sub-processors as Annex 3.
- EU standard contractual clauses 2021/914 as Annex 4 wherever a third-country transfer applies.
- Provisions on inspection, audit and information rights.
How to obtain it: what we need from you
The customized template is provided as a PDF on request. So that we can draft it without a round trip, please include the following straight away:
A directly downloadable, unsigned version will be added in one of the coming waves. Until then the route runs through the compliance address.
- Counterparty: company, legal form, address and authorized signatory.
- Intended processing scope: which parts of the platform, which categories of data.
- Sub-processor opt-ins: Tavily, Microsoft Graph, Stripe.