Data protection and business associate addendum
**Document control**
| Field | Value | |---|---| | Organization | [COMPANY NAME] | | Owner | [OWNER NAME / ROLE] | | Approver | [APPROVER NAME / ROLE] | | Version | [VERSION] | | Effective date | [YYYY-MM-DD] | | Next review | [YYYY-MM-DD] |
**Mapped requirements:** GDPR Articles 28, 32, 33 and Chapter V; HIPAA 45 CFR §§164.308, 164.312, 164.314, 164.504(e) (educational mapping).
> Select and adapt only the modules that apply. This template is not a substitute for legal analysis of party roles, data flows, governing law, or required regulatory language.
1. Parties and precedence This Addendum forms part of [MASTER AGREEMENT] between [COMPANY NAME] (“Provider”) and [CUSTOMER LEGAL NAME] (“Customer”), effective [DATE]. If this Addendum conflicts with the Agreement on covered processing, this Addendum controls to the stated extent.
2. Processing details Subject matter and duration: [DESCRIBE]. Nature and purpose: [DESCRIBE]. Data subjects: [CATEGORIES]. Personal data/ePHI: [CATEGORIES]. Processing locations: [LOCATIONS].
3. GDPR processor module Where Customer is controller and Provider is processor, Provider will process personal data only on documented instructions; ensure authorized personnel are bound to confidentiality; implement appropriate Article 32 measures; engage subprocessors under equivalent obligations and [NOTICE/AUTHORIZATION PROCESS]; assist with data-subject requests, DPIAs, security, breach notification, and regulator consultation; delete or return data at termination unless law requires retention; and provide information reasonably necessary to demonstrate Article 28 compliance.
International transfers use [ADEQUACY / SCC MODULE / OTHER MECHANISM]. The parties will complete required annexes and transfer assessments.
4. HIPAA business associate module To the extent Provider is a business associate, Provider may use or disclose PHI only as permitted by this Addendum or required by law; will apply appropriate safeguards and comply with applicable Security Rule provisions; report impermissible uses, disclosures, breaches, and security incidents as required within [TIME]; ensure subcontractors handling PHI agree to equivalent restrictions; support access, amendment, and accounting obligations; make records available to HHS as required; and return or destroy PHI at termination where feasible.
5. Security schedule and signatures Minimum measures: [ACCESS CONTROLS], [ENCRYPTION], [LOGGING], [BACKUPS], [VULNERABILITY MANAGEMENT], and [INCIDENT RESPONSE]. Liability, audit rights, notice contacts, and signatures: [INSERT COUNSEL-APPROVED TERMS].
---
**Disclaimer:** Educational template only — not legal advice, an audit opinion, or a guarantee of compliance. Adapt with qualified counsel and your auditor or assessor. ComplianceBase is vendor-neutral and independent.