US Data Processing Addendum (DPA) template
Overview
Unlike the EU's GDPR, the United States has no single federal statute requiring a data processing agreement between a business and its service providers. Instead, this addendum is drafted to satisfy the strictest applicable state requirement — currently the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), which does impose specific contractual requirements when a "business" shares personal information with a "service provider" or "contractor" — plus contractual best practice drawn from the comparable requirements in Virginia's Consumer Data Protection Act (VCDPA), Colorado's Colorado Privacy Act (CPA), Connecticut's Data Privacy Act (CTDPA), Utah's Consumer Privacy Act (UCPA), and the growing list of other state comprehensive privacy laws, most of which now require similar processing-restriction and security-obligation language in vendor contracts. This is a genuinely fragmented landscape: there is no "US GDPR." Each state law defines covered entities, thresholds, and required contract terms slightly differently, and new states continue to enact their own comprehensive privacy statutes. A business operating nationally should treat the CCPA/CPRA service-provider contract requirements as the practical baseline, since California's law is both the most detailed and the most likely to apply given the size of the California market, and layer in any additional terms required by other states where the business has material operations or customers. If the vendor has any EU exposure — EU customers, EU personal data, or an EU-based sub-processor — this addendum is drafted to also interoperate with the vendor's own GDPR-side DPA obligations, since a US vendor processing EU personal data remains subject to GDPR regardless of the US law analysis. When to use it: whenever a service provider processes personal information on behalf of a business under a services or SaaS agreement, particularly where either party is subject to CCPA/CPRA or another state comprehensive privacy law. Parties: the "Business" (the customer, who determines the purposes and means of processing) and the "Service Provider" or "Processor" (the vendor, who processes personal information only for the business purposes specified in the agreement). Key clauses: purpose limitation (service provider processes personal information only for the specific business purposes disclosed in the agreement, and may not sell or share it, or use it for the service provider's own purposes outside the direct business relationship, as those terms are defined under CCPA/CPRA); confidentiality; reasonable security measures; sub-processor flow-down obligations; assistance with consumer rights requests (access, deletion, correction, opt-out) that a business must fulfill under applicable state law; breach notification, mapped to the specific timelines of the applicable state breach-notification statute (all 50 states now have one, and requirements vary materially by state); data return or deletion at the end of the engagement; audit rights; and certification of compliance. Pitfalls to avoid: treating this addendum as sufficient for a business with genuine EU exposure, which still needs a GDPR-compliant Article 28 DPA layered on top; assuming a single set of state requirements covers every state your business operates in, when state privacy laws continue to diverge; and omitting a breach notification timeline that is fast enough for the business to meet its own state-law notification deadlines, which range from "without unreasonable delay" to specific day counts depending on the state.
Information to customize
Business's legal name
Business's principal place of business
Service Provider's legal name
Service Provider's principal place of business
Reference to the main services agreement
Specific business purposes for processing
Categories of personal information processed
Applicable state privacy laws (e.g. CCPA/CPRA, VCDPA, CPA)
Authorized sub-processors, if any
Breach notification period (hours or days)
Does the Service Provider process any EU personal data?
Period for data deletion/return at end of contract
Date of signature
Customize your template
Signature recipient
Frequently asked questions
- Is there a US federal law that requires this addendum, like GDPR does in the EU?
- No. The United States has no single federal privacy law equivalent to GDPR. This addendum is built around the CCPA/CPRA service-provider contract requirements (the most detailed and commonly adopted state baseline) plus similar requirements in Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws.
- Does this addendum cover GDPR if our service provider has EU customers or data?
- No, not on its own. If there is genuine EU exposure, the parties need a separate GDPR-compliant Article 28 data processing agreement, typically using the EU Standard Contractual Clauses, in addition to this US-focused addendum.
- Which state privacy laws apply to us?
- It depends on where your business operates and where your customers or data subjects are located. Businesses with any California customers should generally treat CCPA/CPRA as the baseline, and layer in additional state-specific obligations (Virginia, Colorado, Connecticut, Utah, and others) as applicable.
- How fast must a service provider report a data breach?
- There is no single federal deadline. All 50 states have their own breach notification statute with different triggers and timelines, so the notification period in this addendum should be fast enough to let the business meet the shortest deadline among the states where its affected consumers reside.
- Can our service provider sell or share the personal information it processes for us?
- No — under CCPA/CPRA and similar state laws, a service provider is generally prohibited from selling or sharing personal information it receives, or using it for purposes outside the specific business relationship, unless the parties agree otherwise and the arrangement still complies with applicable law.
Related templates
Information about this template
- Last updated
- 31 August 2026
- Country
- US
- Legal notice
- This template is provided for general informational purposes and must be adapted to your specific situation and governing state law. It does not constitute legal advice.