This structured template is intentionally excluded from search indexing. It must be completed and approved for the operator’s legal entity, jurisdiction, Cloud environment, providers, billing and service commitments before public launch.
1. Parties and roles
Identify the customer, Cloud operator, controller/processor roles and precedence with the main agreement.
2. Processing details
Define subject matter, duration, nature, purpose, data categories and data subjects for configured support workflows.
3. Documented instructions
Limit processing to the agreement, customer configuration, lawful instructions and required legal disclosures.
4. Confidentiality and personnel
Describe authorized-person confidentiality, access control and training obligations.
5. Security measures
Attach the current technical and organizational measures for access, application security, encryption, backups, monitoring, incidents and provider governance.
6. Subprocessors
State the current list, locations, engagement requirements, change-notice process and customer objection procedure.
7. International transfers
Define the applicable transfer mechanism and supplementary measures where required.
8. Data-subject requests
Describe customer assistance, authentication, timing and limits for access, correction, deletion and portability requests.
9. Incidents
Define notification triggers, contact channel, information supplied, cooperation and remediation responsibilities.
10. Return, deletion and audit
Define export, deletion, backup lifecycle, evidence provision, audits and termination assistance.
Publication checklist
- Insert the correct legal entity, registered address and contact details.
- Align the text with the actual Cloud service, billing model, regions and provider list.
- Obtain review for applicable jurisdictions, customer types and contractual commitments.
- Publish an effective date, version history and material-change communication process.