Data processing agreement

A data processing agreement is a legally binding contract that states the rights and obligations of Proton (acting as a data processor) and your company (acting as a data controller) concerning the protection of personal data. It completes Proton’s Terms and Conditions and applies to personal data processing activities subject to GDPR.

In accordance with GDPR Article 28(new window), Section 3, our data processing agreement includes assurances that:

  • Proton agrees to process personal data only on written instructions of your company.
  • Everyone who comes into contact with data at Proton is sworn to confidentiality.
  • Proton uses appropriate technical and organizational measures are used to protect the security of the data.
  • Proton will not subcontract to another processor unless instructed to do so in writing by your company, in which case another DPA will need to be signed with the sub-processor (pursuant to Sections 2 and 4 of Article 28).
  • Proton will help your company uphold its obligations under the GDPR, particularly concerning data subjects’ rights(new window).
  • Proton will help your company maintain GDPR compliance with regard to Article 32(new window) (security of processing) and Article 36(new window) (consulting with the data protection authority before undertaking high-risk processing).

You can download past versions of our data processing agreement in PDF format.