Legal

Data Processing Agreement

Last Updated | August 9, 2026

This page explains when a Data Processing Agreement may apply to a RAEFORM client engagement and how to request one.

01

When a Data Processing Agreement Applies

RAEFORM may process personal information on behalf of clients while providing business support, administrative, operational, implementation, technology, or related services.

Where RAEFORM processes personal information as a Personal Information Processor on behalf of a client acting as a Personal Information Controller, the parties may enter into a Data Processing Agreement (“DPA”) where required by law, contract, or the nature of the engagement.

The RAEFORM DPA may address:

  • Roles and responsibilities of the parties
  • Nature and purpose of processing
  • Categories of personal information and data subjects
  • Client instructions
  • Confidentiality
  • Security safeguards
  • Authorized subprocessors
  • Assistance with data-subject requests
  • Personal data breach response
  • International data transfers
  • Retention, return, and deletion
  • Audit and compliance information
  • Allocation of responsibilities

The Data Privacy Act regulates both personal information controllers and processors and requires appropriate safeguards for personal information processing.

A DPA does not automatically apply to every RAEFORM engagement. Its applicability depends on the services performed and the parties' respective data-processing roles.

Clients who require a DPA may contact:

RAEFORM Business Support Services Email: hello@byraeform.com

Copy away. Great ideas deserve to inspire.