How it plays out on a deal
For a data room, the seller is usually the controller and the room provider a processor. The DPA covers security measures, sub-processors, breach notification, transfers abroad and deletion at the end of the contract.
Most established vendors publish a standard DPA. Buyers in regulated sectors sometimes need changes, such as shorter breach notification times or a fixed sub-processor list, so it helps to ask early whether the vendor negotiates its DPA and on which plans.
What to check in a review or demo
- 1Whether a standard DPA is published and signed as part of the order.
- 2The breach notification period and the sub-processor list.
- 3How data is deleted at the end of the contract and whether deletion is confirmed in writing.
Read alongside
- GDPRThe EU's privacy law since 2018.
- Data residencyWhich jurisdiction physically hosts a room's files, and whether the customer can pick it, for instance an EU, UK, US or Australian region chosen when the room is created.
- HIPAAThe 1996 US federal law, with its Privacy and Security Rules, covering patient records held by health plans, providers and their vendors.
- Data room archiveThe frozen copy of everything that was in the room, handed over after signing or shutdown on an encrypted drive or as a secure download, ideally with the index and activity history attached.