Data Processing Agreement

A framework for documenting processing responsibilities when InitLabel processes personal data on behalf of a customer.

1. Processing instructions

The customer determines the documented purpose and instructions for processing. InitLabel processes data only as required to perform the agreed services, subject to the contract.

2. Confidentiality

Personnel with access to customer data should be subject to appropriate confidentiality obligations.

3. Security measures

The parties should document technical and organizational measures appropriate to the nature and risk of the data and processing activity.

4. Subprocessors

Where subprocessors are used, applicable contractual requirements should address authorization, confidentiality, security, and accountability.

5. Data subject requests & incidents

The parties should cooperate on applicable data subject requests and documented incident-response procedures.