Data Processing Agreement
This page explains when a Data Processing Agreement may apply to a RAEFORM client engagement and how to request one.
When a Data Processing Agreement Applies
RAEFORM may process personal information on behalf of clients while providing business support, administrative, operational, implementation, technology, or related services.
Where RAEFORM processes personal information as a Personal Information Processor on behalf of a client acting as a Personal Information Controller, the parties may enter into a Data Processing Agreement (“DPA”) where required by law, contract, or the nature of the engagement.
The RAEFORM DPA may address:
- Roles and responsibilities of the parties
- Nature and purpose of processing
- Categories of personal information and data subjects
- Client instructions
- Confidentiality
- Security safeguards
- Authorized subprocessors
- Assistance with data-subject requests
- Personal data breach response
- International data transfers
- Retention, return, and deletion
- Audit and compliance information
- Allocation of responsibilities
The Data Privacy Act regulates both personal information controllers and processors and requires appropriate safeguards for personal information processing.
A DPA does not automatically apply to every RAEFORM engagement. Its applicability depends on the services performed and the parties' respective data-processing roles.
Clients who require a DPA may contact:
RAEFORM Business Support Services Email: hello@byraeform.com