Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    [email protected]

Data Processing Agreement for data destruction services (GDPR Article 28 and UK GDPR)

A two-page processor agreement written around what a destruction vendor actually does: the only processing is destruction, no access to contents, custody measured in days, no sub-processors, and the transfer clauses (EU Standard Contractual Clauses Module Two and the UK Addendum) incorporated by reference with a transfer impact assessment that fits in three sentences. For organizations with EU or UK personal data on retired hardware.

Version 1.0, reviewed 2026-09-23. Free under CC BY 4.0. Not legal or assessment advice.

Who it is for

Controllers subject to the GDPR or UK GDPR who retire hardware in the United States: subsidiaries of European groups, U.S. companies with EU customers, universities with European research partners, and their U.S. destruction vendor. If the media holds protected health information as well, the Business Associate Agreement applies alongside it.

What is inside

  • Nature of the processing: destruction only, no access to contents, custody of days
  • Instructions: delivery of media is the instruction to destroy it
  • Confidentiality and Article 32 security measures, listed
  • Sub-processors: none; recyclers and carriers explained
  • Assistance with data subject requests and Articles 32 to 36
  • Breach notification within 48 hours, with the note that destroyed media cannot be breached
  • Deletion and return: the service is the deletion
  • Audits and information, including inspection at the time of service
  • International transfers: SCCs Module Two and the UK Addendum incorporated, with the options chosen and a short transfer impact assessment

The transfer clause, in short

The processor is in the United States, so delivering EEA or UK media to it for destruction is a transfer. The DPA incorporates the 2021 EU Standard Contractual Clauses, Module Two (controller to processor), with the options chosen (no docking clause, Clause 9 Option 2 with 30 days’ notice, Irish law and courts), and the UK International Data Transfer Addendum for UK data. The transfer impact assessment is three sentences long because the facts are simple: the processor never accesses the contents, the data is destroyed within days, and no authority has a practical means of obtaining data from media that no longer exists.

Why it is short

Most processor agreements are long because the processor hosts, analyzes, or supports systems that hold the data. A destruction vendor does none of that; its whole engagement is a custody window between receipt and the shredder. Every Article 28(3) element is present, and each is stated for that reality.

How to adapt it

  1. Fill the effective date and the controller’s name.

  2. Confirm the 48-hour breach notification window meets your policy; tighten it if yours is shorter.

  3. If your supervisory authority requires signed SCCs rather than incorporation by reference, execute the SCCs and the UK Addendum as separate documents; the options are already chosen in section 10.

  4. Attach to the Service Agreement or purchase order it supplements.

  5. Have counsel review; it is a standard form, not legal advice.

What it rests on

  • GDPR Article 28(3)
    The mandatory processor terms: instructions, confidentiality, security, sub-processors, assistance, deletion, audit.
  • GDPR Articles 32 to 36
    Security, breach notification, impact assessments, prior consultation.
  • Commission Decision (EU) 2021/914
    The Standard Contractual Clauses; Module Two for controller-to-processor transfers.
  • UK International Data Transfer Addendum
    Issued under section 119A of the Data Protection Act 2018.

Primary sources are linked on the Standards page.

Questions

  • Is a DPA required for a shredding vendor?

    If the vendor takes custody of media containing personal data of EU or UK residents, it is a processor, and Article 28 requires a written contract with the listed terms. The custody is brief and the processing is destruction, but the requirement applies.

  • Why does it say no sub-processors?

    Because none process personal data. Recyclers receive shredded material from which nothing can be recovered; carriers move sealed packages they cannot open. The DPA says so and commits to 30 days’ notice if that ever changes.

  • Will you sign our DPA instead?

    Yes. Send it with the quote request; we will also sign your SCCs if your policy requires signed clauses.

More answers on the FAQ.

Other templates

Download the Word file

Need it tailored, or the destruction it describes?

Request a custom quote