1. Definitions
"Processor," "Controller," "Personal Data," "Processing," "Data Subject," and related terms have the meanings given in the applicable data-protection law (GDPR / UK GDPR / CCPA / DPDP Act 2023). The Zyber Securityis the "Processor" and the Client is the "Controller."
2. Scope & duration
This DPA applies to any Personal Data processed under the Master Service Agreement (MSA) between the parties and any Statement of Work executed under it. It ends when all such engagements end and all Personal Data has been returned or deleted.
3. Processing instructions
- Subject matter: security assessments, penetration tests, compliance audits, and related professional services described in the MSA / SoW.
- Duration: term of the MSA / SoW plus post-termination obligations.
- Nature and purpose: assessment, testing, reporting, and remediation guidance.
- Categories of Data Subjects: as agreed per SoW, typically Client's employees, contractors, or test-account personas.
- Categories of Personal Data: as agreed per SoW, minimized to what is necessary for the assessment.
4. Processor obligations
- Process only on documented Controller instructions.
- Ensure personnel are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures (see Schedule A below).
- Not engage sub-processors without Controller's prior general or specific written authorization.
- Assist Controller in fulfilling Data Subject rights requests.
- Notify Controller without undue delay after becoming aware of a Personal Data breach (target: within 24 hours).
- Support DPIAs and prior consultations with supervisory authorities.
- Return or delete Personal Data at end of Services (Controller's choice), and delete existing copies unless retention is required by law.
5. Sub-processors
Current sub-processor list: hosting (cloud region and vendor per SoW), email delivery, error monitoring, backup storage. Changes are notified with at least 30 days notice; Controller may object on reasonable data-protection grounds.
6. International transfers
For EU→third-country transfers, the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) apply — Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor) as applicable. For UK transfers, the UK IDTA applies. For DPDP-outbound transfers, contract-based safeguards under Section 16 apply.
7. Audit rights
Controller may audit Processor's compliance no more than once per year on 30 days written notice, at Controller's expense, subject to reasonable confidentiality and scheduling constraints. Processor may satisfy audit rights by providing a current ISO 27001 certification, SOC 2 Type 2 report, or comparable independent attestation.
8. Liability
Liability under this DPA is subject to the limitations in the MSA, except where mandatory law disapplies such limits (e.g., GDPR Article 82 personal liability).
9. Schedule A — Technical and organizational measures
- Access control: role-based, least-privilege, MFA-enforced on all administrative access.
- Encryption: TLS 1.3 in transit; AES-256 at rest; hardware-security-module-protected keys where practicable.
- Segregation: separate environments for each engagement; no data commingling across clients.
- Personnel: background-screened; annual training; NDAs; least-privilege access.
- Physical: cloud-provider-attested (ISO 27001 / SOC 2) data-center controls.
- Incident response: 24-hour breach-notification target; documented response playbook.
- Business continuity: geo-redundant backups; documented DR plan tested annually.
10. Contact
DPO / Privacy contact: privacy@thezybersecurity.com.
This DPA is a template ready to be reviewed and finalized by counsel before signature.