Skip to main content
Trust Center

Data Processing Agreement Overview

PrismCDM processes customer data only on documented customer instructions and only for the purpose of providing the contracted service. The Data Processing Agreement defines the legal obligations governing that processing; the platform architecture enforces tenant isolation, Source Fidelity, provenance, and security controls throughout the data lifecycle.

1. The DPA and the architecture

The PrismCDM Data Processing Agreement (DPA) is the controller-to-processor agreement required by Article 28 of the EU General Data Protection Regulation, the equivalent UK provisions, the California Consumer Privacy Act service-provider framework, and equivalent regimes in other jurisdictions.

The DPA defines the contractual responsibilities. The platform architecture implements those responsibilities through tenant isolation, least-privilege access, encryption, auditability, and Source Fidelity controls. Legal commitment and technical enforcement work together.

2. When the DPA applies

  • When the customer is established in, or processes personal data of individuals located in, the European Economic Area, the United Kingdom, or Switzerland.
  • When the customer is a California Consumer Privacy Act business and PrismCDM is acting as a service provider.
  • When the customer is subject to other applicable data protection laws that require a written processor agreement.
  • By default for any commercial customer engagement, so that data protection commitments are explicit from the start of the relationship.

3. Responsibility matrix

The DPA distributes responsibility between the customer (as controller) and PrismCDM (as processor). The distribution at a glance.

AreaCustomerPrismCDM
Purpose of processingDefinesExecutes
Data ownershipRetainsNever acquires
Processing instructionsIssuesFollows
Security controlsReviewsImplements
Data subject requestsDetermines responseAssists
Subprocessor selectionMay object on reasonable groundsSelects and notifies
Deletion or returnRequestsPerforms

4. What the DPA covers

  • Roles and instructions. The customer is the controller; PrismCDM is the processor. PrismCDM processes personal data only on documented customer instructions.
  • Confidentiality. Personnel with access to personal data are subject to confidentiality obligations.
  • Security measures. PrismCDM implements appropriate technical and organizational measures as described at /trust/security.
  • Subprocessing. The DPA governs how PrismCDM may engage subprocessors, the notice period for changes, and the customer's right to object on reasonable grounds. Categories are listed at /trust/subprocessors.
  • Assistance with data subject requests. PrismCDM assists the customer in responding to access, rectification, deletion, restriction, and portability requests.
  • Assistance with assessments. PrismCDM provides the information reasonably required for the customer to conduct data protection impact assessments and prior consultations.
  • Personal data breaches. PrismCDM notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, with the information needed to meet notification obligations.
  • Return or deletion. On termination of the underlying agreement, PrismCDM returns or deletes personal data per the customer's choice, subject to retention obligations imposed by applicable law.

5. Data lifecycle

Personal data processed by PrismCDM moves through a defined lifecycle. Each step has corresponding contractual commitments in the DPA and architectural enforcement in the platform.

  1. Customer Data
  2. Received
  3. Processed
  4. Stored
  5. Protected
  6. Returned or Deleted

6. International transfer mechanisms

Where the DPA covers transfers of personal data outside the EEA, the United Kingdom, or Switzerland, it incorporates the appropriate transfer mechanism selected by the parties during contracting. Available mechanisms include the Standard Contractual Clauses (Module Two: controller to processor), the UK International Data Transfer Agreement, and the UK Addendum to the EU Standard Contractual Clauses.

7. Subprocessor controls

  • PrismCDM provides the customer with the current list of subprocessors at execution and on request.
  • PrismCDM provides advance notice of new subprocessors as set in the DPA.
  • The customer may object to a new subprocessor on reasonable grounds; PrismCDM works in good faith to resolve the objection.
  • All subprocessors are bound by written agreements requiring confidentiality, security, and processing limitations equivalent to the DPA itself.

8. Audit rights

The DPA provides the customer with the right to audit PrismCDM's compliance with the DPA, typically satisfied by:

  • The current architectural and operational documentation provided during the Compliance Review.
  • Third-party attestations and security reports when available (see the Architecture and Assurance Roadmap).
  • Direct audits where required by applicable law or by the customer's regulator, conducted in line with the audit-process terms in the DPA.

Because PrismCDM records provenance, evidence classification, and integrity anchors for regulated operations, many customer audit objectives can be satisfied through platform-generated inspection evidence rather than bespoke evidence collection.

9. What the DPA does not do

  • Does not transfer ownership of customer data to PrismCDM.
  • Does not authorize PrismCDM to use customer data for purposes unrelated to providing the contracted service.
  • Does not permit training shared AI models on customer data without explicit agreement.
  • Does not replace the customer's own regulatory obligations.
  • Does not waive the customer's rights under applicable data protection law.

10. Architecture as enforcement

The DPA defines the legal obligations governing personal data processing. PrismCDM's architecture, including tenant isolation, Source Fidelity, provenance, and auditability, provides the technical enforcement of those obligations.

11. How to execute a DPA

Customers entering a commercial relationship with PrismCDM receive the DPA alongside the Master Services Agreement. To request the DPA in advance of a commercial conversation, contact us through /contact with reason “Compliance Review”.

12. Document relationships

DocumentPurpose
Master Services AgreementCommercial terms governing the engagement
Data Processing AgreementPersonal data processing under GDPR and equivalent regimes
Business Associate AgreementHIPAA-specific PHI obligations
Responsible AI ArchitectureAI governance commitments
SecurityTechnical and organizational controls
Privacy NoticePrismCDM as controller for its own processing

13. Related Trust Center documents

Version
1.0
Effective Date
July 2026
Last Updated
July 2026