Processing Agreement: Definition, Terms, Example
Jump to Section
What is a Processing Agreement?
A processing agreement is a contract between one party and another, typically their processor. It defines the terms of how the processing company will process payments. It also tells the business what to do if there are any disputes about the transactions.
The most important thing for business owners to understand is that signing a processing agreement can significantly impact their business operations, so it's essential to understand it thoroughly before signing on the dotted line. Processing agreements include feeds, dispute and resolution agreements, and what to do if either party decides to terminate.
Common Sections in Processing Agreements
Below is a list of common sections included in Processing Agreements. These sections are linked to the below sample agreement for you to explore.
Processing Agreement Sample
Exhibit 10.4
DATA PROCESSING AGREEMENT
THIS DATA PROCESSING AGREEMENT (“Data Processing Agreement”) is made and entered into on 23 July 2020 (“Effective Date”) by and between
| 1. | Mateon Therapeutics INC., a company organized and existing under the laws of Delaware and having its registered office at 29397 Agoura Rd., Suite 107, Agoura Hills, CA 91301, USA (“Controller”); and |
| 2. | Impatients N.V., acting under the name myTomorrows, a company organized and existing under the laws of the Netherlands and having its registered office at Anthony Fokkerweg 61, 1059 CP Amsterdam, the Netherlands (“Processor”); |
Each of the above parties are individually referred to as “Party” and jointly as “Parties”.
RECITALS
| A. | WHEREAS, Controller and Processor entered into a service agreement as of 23 July 2020 (“Agreement”) pursuant to which Processor agreed to provide certain services to Controller as specified in the Agreement, including any statements of work, and Privacy Annex (Annex 1) to this Data Processing Agreement (“Services”); |
| B. | WHEREAS, Controller engages Processor to on behalf of Controller process Personal Data defined in the Privacy Annex (Annex 1) and any other personal data processed by Processor on behalf of Controller pursuant to the Agreement (“Personal Data”); |
| C. | WHEREAS, this Data Processing Agreement includes the terms and conditions governing the processing of Personal Data by Processor on behalf of Controller with the aim to ensure the Parties comply with Applicable Laws as defined below. |
NOW, THEREFORE, the Parties agree as follows:
1. DEFINITIONS AND INTERPRETATION
1.1. For the purposes of this Data Processing Agreement, the following terms shall have the following definitions and interpretation:
“Applicable Laws” means any EU, EU Member State, national, regional and local laws, rules, regulations, declarations, requirements, guidelines approved by supervisory or other competent bodies and polices that apply to or govern the processing of Personal Data as set out in the Privacy Annex (Annex 1), including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and relevant national laws, as amended from time to time.
“EEA” means European Economic Area.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
“Subprocessor” means any data processor (including any third party and any Processor Affiliate) engaged by Processor to process personal data on behalf of Controller.
| Page 1 of 7 |
“Supervisory Authority” means (a) an independent public authority which is established by a Member State pursuant to Article 51 GDPR; and (b) any similar regulatory authority responsible for the enforcement of Applicable Laws.
1.2 Other terms like “process/processing”, “data subject”, “(data) processor”, “(data) controller”, “data protection impact assessment”, etc. shall have the meaning ascribed to them in the Applicable Laws with regard to the Personal Data.
2. PROCESSING OF PERSONAL DATA
2.1. Processor shall provide the Services and shall process the Personal Data within the context of the Agreement on behalf of Controller and for the specific purposes as set out in the Privacy Annex (Annex 1) to this Data Processing Agreement.
2.2. Processor represents and warrants that it shall not process, transfer, modify, amend or alter the Personal Data or disclose or permit the disclosure of the Personal Data to any third party other than in accordance with the Controller’s documented instructions (in the Principal Agreement or otherwise), unless processing is required by EU or Member State law to which Processor is subject, in which case Processor shall to the extent permitted by such law inform Controller of that legal requirement before processing that Personal Data. Processor shall not process Personal Data for own purposes, except where it is regarded as data controller for the processing of Personal Data.
2.3. Controller represents and warrants that it is fully authorized and entitled to provide the Personal Data to Processor for processing and let Processor process the Personal Data for the purposes of the Agreement and for the specific purposes as set out in the Privacy Annex (Annex 1) and in execution of the Services.
3. DATA SUBJECT RIGHTS
3.1. Processor shall promptly, and in any case within five (5) working days, notify Controller if it receives a request from a data subject under any Applicable Laws in respect of Personal Data, including requests by a data subject to exercise rights in Chapter III of GDPR, and shall provide full details of that request.
3.2. Processor shall provide all reasonable assistance to Controller to enable Controller to comply with any exercise of rights by a data subject under any Applicable Laws in respect of Personal Data and comply with any assessment, enquiry, notice or investigation under Applicable Laws in respect of Personal Data or this Data Processing Agreement.
4. SECURITY OF PERSONAL DATA
4.1. Without prejudice to any other security requirements agreed upon between the Parties, Processor shall protect the processing of Personal Data and ensure a level of security of the Personal Data appropriate to the risk in accordance with Article 32 GDPR, among others by taking appropriate technical and organisational measures, that in view of the current state of the art and the related costs are in line with the nature of the Personal Data to be processed, the scope, context and purposes of the processing of the Personal Data, as well as the risk varying according to likelihood and severity for the rights and freedoms of data subjects. These measures encompass, where appropriate:
4.1.1. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
4.1.2. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
| Page 2 of 7 |
4.1.3. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing.
4.2. The Parties acknowledge that security requirements are constantly changing, and that effective security requires frequent evaluation and regular improvements of outdated security measures. Processor shall therefore continuously evaluate the technical and organisational measures as described herein and shall tighten, supplement and improve these security measures to maintain compliance with Applicable Laws.
5. PERSONAL DATA BREACHES
5.1. Processor shall notify Controller without unreasonable delay upon becoming aware of a Personal Data Breach in connection with the processing of Personal Data and shall provide Controller with information to allow Controller to meet any obligations to report a Personal Data Breach under the Applicable Laws. Such notification shall as a minimum:
5.1.1. describe the nature of the Personal Data Breach, the data subjects concerned, and the Personal Data records concerned;
5.1.2. communicate the name and contact details of Processor’s data protection officer or other relevant contact form whom more information may be obtained;
5.1.3. describe the likely consequences of the Personal Data Breach; and
5.1.4. describe the measures taken or proposed to address the Personal Data Breach.
5.2. Processor shall provide all reasonable assistance and shall take all reasonably steps to assist in the investigation, mitigation and remediation of each Personal Data Breach to enable Controller to (i) perform a thorough investigation into the Personal Data Breach, (ii) formulate a correct response; and (iii) to take further steps in respect of the Personal Data Breach in order to meet any requirements under the Applicable Laws.
6. SUBPROCESSORS
6.1. From the Effective Date of this Data Processing Agreement, Processor may use the Subprocessors set out in the Privacy Annex (Annex 1). Processor may use additional Subprocessors to process Personal Data only with the prior written approval of Controller, which approval shall not be unreasonably withheld.
7. INTERNATIONAL TRANSFERS
7.1. If and insofar the Personal Data is processed outside of the EEA, the Parties shall only process the Personal Data when there is an adequate level of protection in place.
8. CONFIDENTIALITY
8.1. In accordance with the confidentiality provisions of the Agreement, Processor shall keep Personal Data confidential. For the avoidance of doubt, all Personal Data shall be considered as Confidential Information in the Agreement.
9. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
9.1. Processor shall provide reasonable assistance to Controller with any data protection impact assessments which are required under Article 35 GDPR and with any prior consultations to any Supervisory Authority of Controller or any of its affiliates which are required under Article 36 GDPR, in each case in relation to processing of Personal Data by Processor on behalf of Controller and taking into account the nature of the processing and information available to Processor.
| Page 3 of 7 |
10. PROVISION OF INFORMATION AND AUDITS
10.1. Processor shall make available to Controller on request any relevant information that is reasonably necessary to demonstrate compliance with this Data Processing Agreement.
10.2. Processor shall allow for and reasonably contribute to audits of the processing of Personal Data and the premises where such processing takes place. Processor shall provide all reasonable cooperation to Controller in respect of any such audit and shall at the request of Controller, provide Controller with evidence of compliance with its obligations under this Data Processing Agreement. Processor shall immediately inform Controller if, in its opinion, an instruction pursuant to this Clause 10 infringes any Applicable Laws.
11. INDEMNITY AND LIABILITY
11.1. Notwithstanding any provisions of the Agreement or this Data Processing Agreement to the contrary, each Party shall indemnify, defend and hold harmless the other Party from any claims (including third party claims), suits, demands, judgements, actions, liabilities, expenses (including reasonable attorney’s fees) and damages of any kind relating to its breach of this Data Processing Agreement, and/or its negligence or wilful misconduct.
11.2. Notwithstanding any provisions of the Agreement or this Data Processing Agreement to the contrary, the limitation of liability set forth in the Agreement shall also apply to this Data Processing Agreement.
12. DURATION AND TERMINATION
12.1. This Data Processing Agreement shall remain in full force and effect for the duration that Processor processes Personal Data on behalf of Controller under the Agreement.
12.2. Any obligation imposed on either Party under this Data Processing Agreement, or any provision that by their nature is intended to survive this Data Processing Agreement shall survive any termination or expiration of this Data Processing Agreement.
13. STORAGE, RETURN AND DESTRUCTION
13.1. Processor shall store the Personal Data no longer than strictly necessary (i) for the provision of Services; (ii) if a storage period is agreed between the Parties, no longer than this storage period; or (iii) to comply with statutory obligations.
13.2. Processor shall promptly, of the earlier of: (i) no longer processing of Personal Data; or (ii) termination of the Agreement, at the choice of Controller either: (a) return a complete copy of all Personal Data to Controller and securely wipe all other copies of Personal Data processed by Processor or any Subprocessor; or (b) securely wipe all copies of Personal Data processed by Processor or any Subprocessor; and in each case provide written confirmation to Controller that it has complied with this Clause 13, except insofar Processor is required by Applicable Laws to retain such Personal Data.
14. MISCELLANEOUS
14.1. Modifications or amendments of this Data Processing Agreement shall only be effective if made in writing and signed by an authorized representative of both Parties.
14.2. If any provision of this Data Processing Agreement is invalid or unenforceable, then the remainder shall remain valid and in force.
14.3. In the event of inconsistencies between the provisions of this Data Processing Agreement and the Agreement and/or any Scope of Work, the provisions of this Data Processing Agreement shall prevail with regard to the Parties’ data protection obligations.
| Page 4 of 7 |
14.4. This Data Processing Agreement shall be governed by and in accordance with the laws of the Netherlands, without giving effect to any choice of law principles that would require the application of the laws of a different jurisdiction. Any disputes arising out or in connection with this Data Processing Agreement shall be brought exclusively before the competent court of Amsterdam, the Netherlands.
IN WITNESS WHEREOF, the Parties hereto have executed this Data Processing Agreement as of the Effective Date by their duly authorized signatories.
| Impatients N.V. | Mateon Therapeutics INC. | |||
| Signature: | /s/ Vuong Trieu | Signature: | /s/ Peter Erik de Ridders | |
| By: | Vuong Trieu | By: | Pieter Erik de Ridders | |
| Title: | CEO | Title: | General Counsel | |
| Date: | 24 July 2020 | Date: | 23 July 2020 | |
| Page 5 of 7 |
PRIVACY ANNEX (ANNEX 1)
1. SUBJECT MATTER OF THE PROCESSING OF PERSONAL DATA
Processor and Controller have entered into the Agreement pursuant to which Processor agreed to provide certain Services to Controller, wherein Processor, as a service provider to Controller, shall conduct Expanded Access Program management and RWD collection management for (potential) patients on behalf of Controller. In providing these Services, Processor shall process Personal Data of these (potential) patients. This Annex 1 states which Personal Data will be processed by Processor and for what purposes.
2. NATURE AND PURPOSE OF THE PROCESSING OF PERSONAL DATA
Controller shall obtain the necessary consent of the (potential) patients participating in Expanded Access Programs, to be processed by Processor for the following purposes:
| ● | Expanded Access Program management on Mateon’s behalf for the Services as specifically described in the Agreement (and separate Statements of Work). | |
| ● | RWD collection management on Mateon’s behalf for the Services as specifically described in the Agreement (and separate Statements of Work). |
3. CATEGORIES OF PERSONAL DATA TO BE PROCESSED
Processor shall process the following (categories of) Personal Data in the performance of the Services to Controller under the Agreement:
| ● | Personal identification data including first name, last name, initials, date of birth, sex/gender, email address, phone number, city of residence, country of residence. | |
| ● | Technical/device data including browser, IP-address, usernames. | |
| ● | Personal medical data including relevant health care information (e.g. weight, heart rate, disability), relevant demographics, relevant disease history, dosing, safety data, effectiveness data, ethnic origin (if necessary). |
4. CATEGORIES OF DATA SUBJECTS TO WHOM THE PERSONAL DATA RELATES
Processor shall process the Personal Data of the following (categories of) data subjects in the execution of the Services to Controller under the Agreement:
| ● | Patients participating in an Expanded Access Program | |
| ● | Patients participating in RWD collection. |
5. LIST OF SUBPROCESSORS
Processor uses the following Subprocessors in the execution of the Services to Controller under the Agreement:
| Name | Description | Location | ||
| Microsoft Azure / Dynamics 365 | Provides applications and servers that myTomorrows uses for general day-to-day business and performance of its day-to-day services to clients (e.g. emails and storage). | EU | ||
| Castor EDC | Provides an application and servers for the collection and management of data that is used by myTomorrows in the performance of the Services, including RWD collection. | EU |
| Page 6 of 7 |
6. DATA PROTECTION CONTACTS
All notices, requests, demands and approvals under this Data Processing Agreement and with regard to any privacy matters shall be sent to the following contacts:
| myTomorrows | ||
| Name: | Pieter Erik de Ridders | |
| Function: | General Counsel and Data Protection Officer | |
| Email: | pietererik.deridders@mytomorrows.com | |
| Phone: | +31 (0)88 525 3 888 | |
| Mateon Therapeutics | ||
| Name: | ||
| Function: | ||
| Email: | ||
| Phone: | ||
| Page 7 of 7 |
Reference:
Security Exchange Commission - Edgar Database, EX-10.4 5 ex10-4.htm, Viewed January 27, 2022, View Source on SEC.
Who Helps With Processing Agreements?
Lawyers with backgrounds working on processing agreements work with clients to help. Do you need help with a processing agreement?
Post a project in ContractsCounsel's marketplace to get free bids from lawyers to draft, review, or negotiate processing agreements. All lawyers are vetted by our team and peer reviewed by our customers for you to explore before hiring.
ContractsCounsel is not a law firm, and this post should not be considered and does not contain legal advice. To ensure the information and advice in this post are correct, sufficient, and appropriate for your situation, please consult a licensed attorney. Also, using or accessing ContractsCounsel's site does not create an attorney-client relationship between you and ContractsCounsel.
Meet some of our Processing Agreement Lawyers
Mike R.
Practicing attorney and former law professor with 28 year's experience, including class actions and appeal. Primary practice areas: commercial litigation, contracts, business counseling, formation, collections, asset protection, employment, and government regulation. Extensive law teaching experience, including legal writing, legal research, contract drafting, civil procedure, contracts, conflict of laws, and business organizations. Attorney Rusco heads Rusco Law. Rusco Law attorneys practice in California, New York, Texas, Colorado, and Wisconsin. For more information, please visit www.ruscolaw.com. For more information about business counseling services, please visit https://www.ruscolaw.com/practice-areas-and-services-offered. Rusco Law combines big-firm expertise with small-firm personal attention to give a limited set of clients unparalleled representation and service. We provide: • Complete litigation services, from pre-filing demands through Supreme Court appeals. Extensive experience in commercial, employment, tribal, and personal injury matters. • Sophisticated business counseling with an emphasis on start ups, including formation, risk management, internal governance, employment policy, regulatory advocacy, and trademark/trade secret/patent protection. • Detailed contract negotiation, review, and compliance monitoring, including major construction and service agreements. • Full-spectrum legal support for principals and their families, including passionate injury representation, including childcare and playground accidents.
"Was flexible in scope as things changed. Helped get the job done."
Anna C.
I am a business attorney focused on practical, efficient contract drafting, review, and negotiation for healthcare organizations and growth-stage and established businesses. My work includes commercial agreements such as NDAs, MSAs/SOWs, leases, vendor and services agreements, SaaS, and employment and severance agreements. I partner closely with clients to identify key legal and business risks, deliver clear, business-minded redlines with concise issue summaries, and keep transactions moving. Clients value my responsive turnaround, judgment, and ability to balance risk with commercial objectives.
"Working with Anna was great! She took the time to review and build out all the documents I needed (privacy policy, t&c, health data policy, etc.) to start going on my online business. Would definitely work with her again."
Aury L.
I am an experienced U.S. attorney focused on contract drafting, review, and transactional legal support for businesses and individuals. My practice emphasizes clear, practical, and risk-focused legal guidance across commercial agreements, corporate matters, and regulatory compliance. I work efficiently in remote, document-based engagements and prioritize responsiveness, precision, and business-oriented solutions. Clients value my ability to translate complex legal issues into actionable advice and well-structured agreements that support their objectives while minimizing risk.
John P.
specializes in corporate governance, data privacy, intellectual property, and employment law. A former VP of Legal & Compliance and interim CFO, he has led legal operations across fundraising, acquisitions, and data privacy initiatives.
January 22, 2026
Kevin G.
For more than three decades, Kevin M. Gross has served as a trusted legal advisor to senior management and executive teams providing guidance on global compliance issues (anti-corruption, trade regulation, AML/KYC, privacy, and conflicts of interest), strategic concerns, due diligence, and risk mitigation strategies. In 2020, he founded C&R Consulting Group LLC to provide practical, cost-effective compliance and risk services to small and medium sized businesses. Prior to starting his own consulting firm, Kevin worked at Penumbra, Inc., a global healthcare company that manufactures and sells medical devices to healthcare providers, hospitals and clinics in more than 100 countries. At Penumbra, Kevin was the primary legal advisor to the company’s international sales and marketing executives. In addition, as Penumbra’s principal compliance lawyer, he conducted risk assessments and provided guidance and solutions to Penumbra’s internal compliance team. He oversaw due diligence on Penumbra’s international distributors, regulatory and sales agents, and other commercial partners. Prior to joining Penumbra, Kevin spent 15 years inside Chevron’s legal, compliance and upstream law departments, where he advised senior management on the company’s compliance and risk programs. Kevin overhauled Chevron’s hotline and investigations programs, strengthened internal controls and compliance procedures, and developed best practices and training for compliance personnel and investigators. Kevin also managed and conducted dozens of sensitive, high-profile investigations across six continents (internal and external), including FCPA, cybersecurity threats, and high-value theft and procurement frauds. Kevin directed outside counsel responses to SEC and DOJ inquiries, which were terminated without further action. He developed and conducted FCPA and compliance training for leadership teams and others across the enterprise. Prior to his tenure at Chevron, Kevin spent a decade as a senior enforcement attorney at the US Securities and Exchange Commission Division of Enforcement. At the SEC, he investigated and prosecuted cases involving securities fraud, insider trading, accounting fraud, options backdating, Ponzi schemes, and FCPA violations. Kevin filed and litigated SEC administrative and federal court actions against companies and individuals accused of violating federal securities laws. Early in his career, Kevin was a commercial litigator at Faegre Drinker LLP, an AmLaw 100 firm where he oversaw the investigation and resolution of insurance coverage disputes and other commercial litigation matters. In this role, Kevin took and defended hundreds of depositions, argued dozens of motions, and brought several cases to jury trials in US district courts. Kevin has received numerous accolades from clients and industry leaders, and is a frequent speaker at ACC, ACI, BECA, Consero and other conferences.
Neil R.
Neil Rust is a transactional attorney with almost four decades of experience ranging across a broad range of fields, including M&A, finance, structured finance, VC and general corporate. Before moving to Oregon, Mr. Rust was a partner at the Los Angeles office of an international law for 26 years and the Century City office of a national law firm for 5 years. During his big firm tenure, Neil Rust gathered experience across multiple industries and enjoys counselling clients as much as drafting and negotiating.
February 12, 2026
Chase L.
Chase D. Lambert, Esq. is a distinguished commercial business litigation attorney with a profound academic background and extensive experience in both transactional and litigation legal realms. A graduate of Kansas State University, Chase holds a Dual Major in Entrepreneurship and Finance, accompanied by a Minor in Economics, reflecting a multifaceted understanding of business dynamics and economic principles. Continuing his academic journey, Chase pursued his legal education at Pepperdine Law, where he further honed his expertise with an emphasis in Entrepreneurship through the prestigious Palmer Institute for Entrepreneurship in the Law. This specialized training equipped him with a nuanced understanding of legal intricacies within entrepreneurial ventures, empowering him to offer comprehensive legal solutions tailored to the unique needs of business clients. Throughout his career, Chase has demonstrated an unwavering commitment to excellence and client satisfaction. With a diverse clientele spanning across various industries, he has successfully navigated complex legal landscapes, adeptly handling a myriad of transactional and litigation matters with precision and efficacy. With a strategic mindset and a passion for advocating on behalf of businesses, Chase is dedicated to delivering unparalleled legal representation characterized by diligence, integrity, and a results-driven approach. His legal acumen, coupled with his understanding of business dynamics, renders him a formidable asset for clients seeking proficient legal counsel in commercial litigation matters. Beyond his professional endeavors, Chase remains actively engaged in the legal community, continuously seeking opportunities to stay abreast of emerging trends and advancements in commercial law. Committed to excellence in every aspect of his practice, he remains poised to provide comprehensive legal guidance and steadfast advocacy to businesses navigating the complexities of the legal landscape
Find the best lawyer for your project
Browse Lawyers Now
Quick, user friendly and one of the better ways I've come across to get ahold of lawyers willing to take new clients.
View Trustpilot ReviewHow It Works
Financial lawyers by top cities
- Austin Financial Lawyers
- Boston Financial Lawyers
- Chicago Financial Lawyers
- Dallas Financial Lawyers
- Denver Financial Lawyers
- Houston Financial Lawyers
- Los Angeles Financial Lawyers
- New York Financial Lawyers
- Phoenix Financial Lawyers
- San Diego Financial Lawyers
- Tampa Financial Lawyers
Processing Agreement lawyers by city
- Austin Processing Agreement Lawyers
- Boston Processing Agreement Lawyers
- Chicago Processing Agreement Lawyers
- Dallas Processing Agreement Lawyers
- Denver Processing Agreement Lawyers
- Houston Processing Agreement Lawyers
- Los Angeles Processing Agreement Lawyers
- New York Processing Agreement Lawyers
- Phoenix Processing Agreement Lawyers
- San Diego Processing Agreement Lawyers
- Tampa Processing Agreement Lawyers
Contracts Counsel was incredibly helpful and easy to use. I submitted a project for a lawyer's help within a day I had received over 6 proposals from qualified lawyers. I submitted a bid that works best for my business and we went forward with the project.
View Trustpilot Review
I never knew how difficult it was to obtain representation or a lawyer, and ContractsCounsel was EXACTLY the type of service I was hoping for when I was in a pinch. Working with their service was efficient, effective and made me feel in control. Thank you so much and should I ever need attorney services down the road, I'll certainly be a repeat customer.
View Trustpilot Review
I got 5 bids within 24h of posting my project. I choose the person who provided the most detailed and relevant intro letter, highlighting their experience relevant to my project. I am very satisfied with the outcome and quality of the two agreements that were produced, they actually far exceed my expectations.
View Trustpilot Review