# Data processing agreement — discussion draft

Version 2026-09-06. Requires completed schedules, review and signature; not an executed agreement.

Customer/controller: [legal entity, address, authorised signatory, privacy contact].
Processor: [verified Mazi contracting entity, address, registration, authorised signatory].
Effective date, engagement and duration: [complete].

## Proposed contractual structure

Use the European Commission controller–processor clauses as a starting point where applicable, with counsel confirming the parties' roles and any international-transfer requirements:
https://commission.europa.eu/publications/standard-contractual-clauses-controllers-and-processors-eueea_en

Attach the selected clauses and complete their annexes before signature. This document does not substitute for them.

## Engagement-specific processing schedule

- Purpose: coordinating the agreed employee relocation and settling-in services.
- People: named assignees, authorised HR contacts and family members only where included in scope.
- Records: contact details, case correspondence, employment information and the specific documents requested for each agreed service. Identify any health, child or other sensitive data separately and establish the appropriate processing conditions.
- Operations: collection, access-controlled storage, review, communication, authorised disclosure, export and deletion.
- Instructions: specify who may request changes, approved recipients and prohibited uses. Separate independent legal-counsel processing from processing on customer instructions.
- Security schedule: record the deployed access model, storage configuration, administrative access, incident procedure and tested recovery process; attach dated evidence.
- Subprocessors: identify actual contracting providers, purpose, location, transfer mechanism, authorisation and change-notice process. Verify hosting, database, AI and email providers before signature.
- Assistance and incidents: name responsible contacts, notification process and agreed response arrangements for rights requests, security incidents, assessments and regulator enquiries.
- End of engagement: agree return format, deletion timetable, documented legal holds and backup expiry treatment.
- Assurance: agree evidence requests, audit arrangements and remediation tracking.

Open fields must be resolved by both parties. Do not sign on behalf of an unregistered entity or describe untested controls as verified.
