# DPA Template v1 (GDPR Article 28)

# Data Processing Agreement (DPA)

**Version:** 1.0 | **Date:** 2026-05-01 | **Compliance:** GDPR Article 28, Norwegian Personal Data Act

---

## Overview

This Data Processing Agreement (DPA) governs ALAI Holding AS' role as **Data Processor** when delivering AI services to clients who are **Data Controllers**.

**GDPR Article 28(3) requires DPAs to specify 8 mandatory items. This template includes all 8.**

## When is a DPA Required?

**Execute DPA if ALAI processes personal data on behalf of client:**

- AI system processes customer names, emails, or IDs
- AI training uses client employee data
- System logs contain IP addresses or user activity
- Client explicitly requests GDPR compliance documentation

**Skip DPA if:**

- Pure technical audit (code review, architecture assessment) with no personal data access
- AI model training on fully anonymized datasets
- Consulting engagement with no data processing

## GDPR Article 28(3) Mandatory Items

<table id="bkmrk-%23requirementtemplate"><thead><tr><th>\#</th><th>Requirement</th><th>Template Section</th><th>Proveo Status</th></tr></thead><tbody><tr><td>1</td><td>Subject matter</td><td>2.1 (AI services)</td><td>✓ PASS</td></tr><tr><td>2</td><td>Duration</td><td>2.2 (duration of main agreement)</td><td>✓ PASS</td></tr><tr><td>3</td><td>Nature &amp; purpose</td><td>2.3 (data types listed)</td><td>✓ PASS</td></tr><tr><td>4</td><td>Type of personal data</td><td>2.3 (identification, business, technical, AI training)</td><td>✓ PASS</td></tr><tr><td>5</td><td>Categories of data subjects</td><td>2.4 (customers, employees, end-users)</td><td>✓ PASS</td></tr><tr><td>6</td><td>Obligations of controller</td><td>Section dedicated to controller rights</td><td>✓ PASS</td></tr><tr><td>7</td><td>Authorization of sub-processors</td><td>3.4 (table + 30-day notice clause)</td><td>✓ PASS</td></tr><tr><td>8</td><td>Processor obligations</td><td>Section 3 (comprehensive)</td><td>✓ PASS</td></tr></tbody></table>

## Sub-Processors

ALAI uses the following approved sub-processors:

<table id="bkmrk-vendorservicelocatio"><thead><tr><th>Vendor</th><th>Service</th><th>Location</th><th>Safeguards</th></tr></thead><tbody><tr><td>**Anthropic PBC**</td><td>AI model API (Claude)</td><td>USA (AWS us-east-1)</td><td>SOC 2 Type II, GDPR DPA, **Standard Contractual Clauses (SCCs)**</td></tr><tr><td>**Microsoft Azure**</td><td>Cloud infrastructure, hosting</td><td>EU West / Norway East</td><td>ISO 27001, SOC 2, GDPR compliant, Microsoft DPA</td></tr><tr><td>**Cloudflare Inc.**</td><td>CDN, DDoS protection, DNS</td><td>Global (EU data residency)</td><td>ISO 27001, SOC 2 Type II, GDPR DPA</td></tr><tr><td>**Brevo**</td><td>Transactional email</td><td>EU (Frankfurt)</td><td>GDPR compliant, ISO 27001</td></tr></tbody></table>

**⚠️ NOTE:** Actual SCC documents from Anthropic are PENDING (see `dpa-vendor-log.md`). CEO must collect these before executing DPA with clients.

**30-day notice rule:** ALAI will notify clients 30 days before adding/changing sub-processors. Clients may object within this period.

## Key Timelines

<table id="bkmrk-eventdeadlinenotesbr"><thead><tr><th>Event</th><th>Deadline</th><th>Notes</th></tr></thead><tbody><tr><td>**Breach notification**</td><td>24 hours</td><td>ALAI notifies client of personal data breach within 24h of discovery</td></tr><tr><td>**Data deletion/return**</td><td>30 days</td><td>Upon contract termination, ALAI deletes or returns all personal data within 30 days</td></tr><tr><td>**Audit response**</td><td>14 days</td><td>ALAI responds to client audit questions within 14 days</td></tr><tr><td>**Sub-processor change notice**</td><td>30 days</td><td>Clients receive 30-day advance notice before sub-processor changes</td></tr></tbody></table>

## Technical and Organizational Measures (TOMs)

The DPA references **Annex B: TOMs** which documents ALAI's security measures:

- **Encryption:** TLS 1.3 (transit), AES-256 (rest)
- **Access control:** MFA for all production access
- **Logging:** All personal data access logged
- **Backups:** Daily backups, 24h recovery time
- **Training:** Annual GDPR training for staff
- **Penetration testing:** Annual external security testing

Full TOMs document: [TOMs ALAI AI Services v1](https://docs.alai.no/books/legal-templates-v1/page/toms-alai-ai-services-v1)

## Audit Rights

Clients have the right to audit ALAI's compliance with this DPA:

- **Frequency:** Once per year without cost to client
- **Additional audits:** By agreement, with reasonable cost coverage
- **Access:** Client or designated representative may access ALAI premises and systems
- **Response time:** ALAI responds to audit questions within 14 days

## Cross-Border Data Transfers

**Non-EEA transfers:** Anthropic (USA) processes data outside EEA. This requires **Standard Contractual Clauses (SCCs)** per GDPR Chapter V.

**Status:** DPA template references SCCs (section 5.1). CEO must obtain actual SCC documents from Anthropic before executing client DPAs.

**Action Required:** See `dpa-vendor-log.md` for draft vendor email. CEO must send and track responses.

## Proveo Legal Review Status

Proveo review (2026-05-01): **19/20 PASS**

<table id="bkmrk-critical-itemstatusg"><thead><tr><th>Critical Item</th><th>Status</th></tr></thead><tbody><tr><td>GDPR Art.28 mandatory items (all 8 present)</td><td>✓ PASS</td></tr><tr><td>Sub-processor list complete</td><td>✓ PASS</td></tr><tr><td>24h breach notification + 30d deletion realistic</td><td>✓ PASS</td></tr><tr><td>Audit rights defined</td><td>✓ PASS</td></tr><tr><td>SCCs for non-EEA referenced</td><td>✓ PASS (reference) | ⚠️ Documents pending</td></tr><tr><td>TOMs Annex B referenced</td><td>✓ PASS</td></tr></tbody></table>

**Known Gap:** SnowIT relationship undocumented. If SnowIT processes client data, SnowIT must be added to sub-processor list. Separate workstream required.

## Usage Workflow

1. **CEO confirms engagement involves personal data processing**
2. **CEO fills template variables:** Client name/org.nr, data types (section 2.3), data subject categories (section 2.4)
3. **Attach TOMs as Annex B**
4. **Upload DPA + TOMs to Documenso** (two-document bundle)
5. **Client review:** May request security changes (e.g., ISO 27001 certification, on-premise deployment)
6. **CEO escalates material changes to Lexicon**
7. **Both parties sign via Documenso**
8. **Archive signed DPA + TOMs to Paperless-ngx** with tags: `legal-contract`, `dpa`, `gdpr`, `ai-services`

## Full Template

**Source File:** `~/Public/legal/ai-services/DPA-template-v1.md`

Full bilingual template available at source location (23K file). Contact CEO for access or see client onboarding workflow.

---

*For client onboarding process, see [Client Onboarding Checklist](https://docs.alai.no/books/legal-templates-v1/page/client-onboarding-checklist).*