Back
Draft – have this reviewed by qualified legal counsel before use. Only the German (DE) version is legally binding. This English version is provided for informational purposes only.

Data Processing Agreement

pursuant to Art. 28 GDPR

§ 1 Parties

This Data Processing Agreement ("DPA") is entered into between:

Controller (Client):
 ,  , Email:  

Processor:
Y. Baris Ozgun, Krefelder Str. 4, 10555 Berlin, Deutschland, Email: contact@thebozgun.com

This DPA forms part of the main contract and takes precedence over it with respect to data protection matters. Subject matter:  .

§ 2 Duration

This DPA takes effect on the date of last signature and ends upon termination of the main contract. Obligations that by nature survive termination (confidentiality, deletion) remain in force.

§ 3 Nature, Scope and Purpose of Processing

The Processor processes personal data solely for the purpose of providing the agreed services ( ). Processing activities include: collection, storage, transmission, processing and deletion. Processing for any other purpose is prohibited.

§ 4 Categories of Data and Data Subjects

Data categories:  

Data subjects:  

Special categories under Art. 9 GDPR are not processed unless separately agreed in writing.

§ 5 Controller's Right to Issue Instructions

The Processor processes personal data solely on documented instructions from the Controller. Instructions shall be given in writing; verbal instructions must be confirmed in writing without undue delay.

If the Processor considers an instruction to be in breach of data protection law, it shall immediately inform the Controller and may suspend execution pending clarification.

§ 6 Obligations of the Processor

Confidentiality (Art. 28(3)(b), Art. 29 GDPR): All persons authorised to process personal data are bound by confidentiality obligations and trained in applicable data protection requirements.

Security (Art. 32 GDPR): The Processor implements all technical and organisational measures required by Art. 32 GDPR, as detailed in Annex 1.

The Processor assists the Controller in complying with obligations under Art. 32–36 GDPR.

§ 7 Sub-processors

Sub-processors may only be engaged with the Controller's prior written approval. Approved sub-processors are listed in Annex 2. Intended changes are communicated at least 14 days in advance; the Controller may object, triggering a right of extraordinary termination for both parties.

Sub-processors are bound by the same data protection obligations as the Processor (Art. 28(4) GDPR).

§ 8 Assistance with Data Subject Rights

The Processor assists the Controller in fulfilling data subject requests under Art. 15–22 GDPR. Requests addressed to the Processor are forwarded to the Controller without undue delay.

§ 9 Notification of Personal Data Breaches

Personal data breaches are reported to the Controller immediately, and in any event within 24 hours of becoming aware, including the nature of the breach, affected categories, likely consequences, and measures taken.

§ 10 Deletion and Return of Data

Upon completion of services or on the Controller's instruction, all personal data is deleted or returned and existing copies deleted, unless retention is required by law. Deletion is confirmed in writing.

§ 11 Audit and Inspection Rights

The Processor makes all necessary information available to demonstrate compliance and permits audits (including on-site inspections) by the Controller or its appointed auditor (14 days notice, once per year, costs borne by the Controller).

§ 12 Liability

Each party is liable for data protection breaches within its own scope of responsibility under Art. 82 GDPR. The Processor's total aggregate liability per incident is capped at  . This cap does not apply in cases of wilful misconduct, gross negligence, or injury to life, body or health.

§ 13 Final Provisions

Written form: Amendments require written form. No oral collateral agreements exist.

Governing law: Law of the Federal Republic of Germany.

Jurisdiction: Exclusive place of jurisdiction: Berlin.

Severability: Invalid provisions are replaced by valid ones closest to their economic purpose.

Signatures

Place, Date

 ,  

Controller – Signature

Name / Position

 

Place, Date

 ,  

Processor – Signature

Name / Position

Y. Baris Ozgun

Annex 1 – Technical and Organisational Measures (Art. 32 GDPR)

Control areaDescription
Physical access controlRemote work from home office, lockable workspace, no own server rooms; physical infrastructure exclusively with providers listed in Annex 2.
System access controlPassword manager, strong individual passwords, two-factor authentication on all accounts, fully encrypted hard drive.
Data access controlRole-based access rights on a least-privilege basis, separate credentials per client and per environment.
Transmission controlTLS encryption for all transmissions, SSH access exclusively via key, no transmission over unencrypted channels.
Input controlVersion control with Git, traceable commit history, logging of changes to production systems.
Order controlProcessing exclusively on documented instructions from the controller, orders in written form.
Availability controlRegular automated backups, recovery tests, redundant infrastructure of the hosting providers used.
Separation controlSeparate environments and databases per client and per project (Development, Staging, Production).
EncryptionTLS 1.2 or higher in transport, encryption of data at rest, encrypted backups.

Annex 2 – List of Approved Sub-processors

ProviderPurpose / ServiceCountry
to be determined on a project basis
to be determined on a project basis
to be determined on a project basis

Changes are communicated at least 14 days before taking effect.