Data Processing Agreement Template (Canada)

Updated on August 24, 2026

This Canada data processing agreement is the local equivalent of Jotform's US business associate agreement. Outside the United States, a HIPAA BAA is usually the wrong document; the better match is a controller-processor, customer-vendor or privacy data handling agreement.

Use it when one party processes personal information for another and the services contract needs instructions, security, breach notice, sub-processing, transfer and exit terms.

2 of 14 blanks filled

Tap any highlighted blank in the document below and type straight into it.Free — no sign-up, no watermark

Data Processing Agreement

Effective date:
Customer:
Supplier:
Role classification:
Governing law:

1. Processing details

Services involving personal data: . Personal data types: . Data subject categories: .

2. Instructions and permitted use

will process personal data only for the services and documented instructions stated here: . must promptly tell if it believes an instruction conflicts with applicable privacy law.

3. Confidentiality and security

will restrict access to authorised personnel bound by confidentiality and will maintain the following security measures: .

4. Breach and incident notice

will notify without undue delay and no later than hours after becoming aware of a personal data breach or security incident affecting the services, then provide reasonable follow-up information as it becomes available.

5. Sub-processors and transfers

Approved sub-processors: . International transfers: . New sub-processors or materially changed transfer arrangements require the notice, objection or approval process agreed by the parties.

6. Assistance and records

will provide reasonable assistance with individual rights requests, security assessments, audits, regulator enquiries, data protection impact assessments and records needed to demonstrate compliance.

7. Return, deletion and survival

At the end of the services, personal data will be handled as follows: . Confidentiality, security, audit, breach cooperation and deletion evidence duties continue while the supplier retains personal data.

Customer

Date:

Supplier

Date:

The Canada document starts with role classification

PIPEDA keeps the organisation accountable for personal information transferred to a third party for processing and expects contractual or other means to provide a comparable level of protection. Provincial privacy or health laws may add terms.

The template therefore asks whether the supplier is a processor, service provider, contractor, independent controller or joint controller before the obligations are finalised. Do not use a processor contract where both parties decide purposes independently.

Instructions and security must be operational

A strong DPA does more than say comply with privacy law. It states what personal data is processed, whose data it is, why it is processed, where it may go, who may access it and which security measures apply.

The document includes a security schedule so encryption, access control, logging, backup, staff confidentiality, vulnerability management and incident handling can be stated in plain language.

Breach notice should be faster than the legal clock

The processor or service provider should notify the customer quickly enough for the customer to assess notification duties. Waiting until every fact is known can make the controller miss a legal or contractual deadline.

The template uses a short breach-notice field, then allows follow-up reports as facts are confirmed.

Transfers and sub-processors need a real approval path

Cloud hosting, support desks and analytics tools often create hidden sub-processing or international-transfer issues. The template requires a sub-processor approval route, destination list and transfer mechanism rather than a vague outsourcing permission.

If the supplier changes its stack, the customer gets notice and an objection path where local law or the deal requires it.

Why it is better than a copied HIPAA BAA

Jotform source document is healthcare-specific and US-specific. This page keeps the search benefit of the BAA batch but gives non-US users a local privacy agreement that does not invent HIPAA duties where they do not apply.

For Canada, the guidance cites local privacy authority or statute sources and keeps regulated health, public-sector and cross-border transfers flagged for local review.

Canada data processing agreement guide

Role classification
Confirms whether the supplier is a processor, service provider, independent controller or joint controller.
Processing details
Records subject matter, duration, nature, purpose, data categories and data-subject categories.
Documented instructions
Limits processing to the customer instructions and the services contract.
Confidentiality
Requires staff and authorised users to be bound by confidentiality.
Security measures
Turns security from a generic promise into a schedule of technical and organisational controls.
Breach notice
Gives the customer time to assess notification obligations and mitigation steps.
Sub-processors
Controls hosting, support, contractors and downstream vendors.
Individual rights assistance
Requires help with access, correction, erasure, objection or local equivalent requests.
Transfers
Records destinations and transfer mechanism or customer approval.
Exit
Requires return, deletion, backup handling and retained-copy justification.

Canada privacy checklist

Review these points before attaching the DPA to the services contract.

  • Classify the relationship before using the template

    PIPEDA keeps the organisation accountable for personal information transferred to a third party for processing and expects contractual or other means to provide a comparable level of protection. Provincial privacy or health laws may add terms.

    OPC PIPEDA accountability bulletin
  • Document the processing details

    The schedule asks for subject matter, duration, nature, purpose, personal-data types, data-subject categories and the controller/customer instructions so the contract is more than a confidentiality addendum.

    OPC PIPEDA accountability bulletin
  • Write down security measures

    Security is not left as a promise to be reasonable. The template asks for access control, encryption or equivalent safeguards, resilience, backup, logging, staff confidentiality and incident response.

  • Set a breach escalation path

    PIPEDA reporting turns on a real risk of significant harm, so the processor/vendor must escalate fast enough for the organisation to assess that threshold.

    PIPEDA breach safeguards text
  • Control sub-processors

    The processor must not add a sub-processor without the agreed authorisation route and must impose equivalent protection on that sub-processor.

  • Handle international transfers separately

    The transfer schedule asks for destination countries, transfer mechanism and supplementary measures where needed. Do not treat a normal services contract as a transfer assessment.

    OPC PIPEDA accountability bulletin
  • Return or delete data at exit

    The exit clause requires return, deletion or legally required retention to be stated, including backup deletion timing and certificate evidence where appropriate.

How to use this Canada data processing agreement

  1. Map the processing. List personal data, data subjects, systems, countries and sub-processors.
  2. Classify roles. Decide whether the supplier acts under instructions or decides purposes independently.
  3. Write instructions. State the permitted services, purposes and limits on use.
  4. Add security measures. Use concrete controls rather than a broad compliance promise.
  5. Set breach notice. Choose a notice period short enough for the customer to assess notification duties.
  6. Approve sub-processors. List current sub-processors and the process for changes.
  7. Plan exit. State return, deletion, backup and retained-copy rules before the service ends.

Canada data processing agreement FAQs

Is this a business associate agreement?

No. In Canada, the better equivalent is a data processing or privacy data handling agreement based on local privacy law, not HIPAA.

When do I need a DPA?

Use one when a supplier processes personal information for a customer, especially where the customer sets the purpose and the supplier acts on instructions.

Can a supplier be an independent controller?

Yes. If the supplier decides its own purposes and means, a processor agreement may be the wrong instrument and a data sharing or controller-to-controller arrangement may be needed.

What should the security schedule include?

Access controls, encryption or equivalent safeguards, logging, backup, resilience, staff confidentiality, vulnerability management and incident response.

How quickly should breaches be reported?

The template lets you choose the period. In practice, it should be short enough for the customer to assess legal notification duties and reduce harm.

Are sub-processors allowed?

Only through the approval route in the agreement. Current sub-processors should be listed and changes should trigger notice.

Does this handle international transfers?

It creates a transfer schedule, but parties still need to confirm the correct local transfer mechanism and any risk assessment.

Can this sit inside a services contract?

Yes. It is usually attached to a business contract or SaaS/services agreement and should prevail for privacy terms if there is a conflict.

Related templates

Disclaimer

This Canada template is for general information and document drafting support only. It is not legal advice and does not replace advice from a qualified local professional for regulated transport, privacy, construction, procurement, tax or sector-specific work.