Skip to content
Book a Demo
DPA.00 / DATA PROCESSING AGREEMENT

Data Processing Agreement

This DPA describes the terms under which AfriGRC Processes Personal Data on behalf of a Customer, as a Processor acting on that Customer's instructions. It follows the standard structure of a data processing agreement — the specific commitments within it are still being finalized as part of formal legal review.

Last Updated
August 5, 2026
Effective Date
To be confirmed upon legal review
Version
0.1 (Draft)

This page is a working draft of our Data Processing Agreement, published for transparency ahead of formal legal review. It does not constitute legal advice, is not a substitute for a signed agreement, and should not be treated as a final, legally approved, or binding document until AfriGRC confirms it has completed that review.

DPA.01 / DEFINITIONS

Terms used throughout this agreement.

Controller
The entity that determines the purposes and means of Processing Personal Data. For data a Customer submits to the Platform, the Customer is typically the Controller.
Processor
AfriGRC, acting on behalf of and under the documented instructions of a Customer, in respect of Personal Data the Customer submits to the Platform.
Sub-processor
A third party engaged by AfriGRC to Process Personal Data on AfriGRC's behalf, in support of the Services — see Sub-processor Engagement below and our published Sub-processors list.
Data Subject
An identified or identifiable natural person to whom Personal Data relates.
Personal Data
Any information relating to a Data Subject, submitted by a Customer to the Platform as part of its Content.
Processing
Any operation performed on Personal Data, whether or not by automated means — including collection, storage, use, disclosure, and deletion.
Data Protection Laws
The data protection and privacy laws applicable to the Processing of Personal Data under this DPA, which may include GDPR, Nigeria's NDPA, South Africa's POPIA, and other applicable frameworks.
Standard Contractual Clauses
The contractual mechanism(s) that may be used to lawfully transfer Personal Data across a border, where required — see International Transfers below.
DPA.02 / ROLES & RESPONSIBILITIES

Who is the Controller, who is the Processor.

TR.01

Customer as Controller

For Personal Data a Customer submits to the Platform as Content, the Customer determines the purposes and means of Processing, and is the Controller.

TR.02

AfriGRC as Processor

AfriGRC Processes that Personal Data solely to provide the Services, and only on the Customer's documented instructions.

TR.03

Processing on Instructions

AfriGRC will not Process Personal Data for any purpose other than providing the Services, except where required by applicable law.

TR.04

Confidentiality of Personnel

Personnel authorized to Process Personal Data are bound by confidentiality obligations, whether contractual or statutory.

TR.05

Assistance With Data Subject Requests

AfriGRC will provide reasonable assistance to a Customer responding to a Data Subject request, to the extent the Customer cannot reasonably do so itself.

DPA.03 / PROCESSING DETAILS

The standard 'Annex' structure of a DPA.

Subject matter, duration, nature, purpose, and the categories of data subjects and Personal Data involved.

Processing Details
AspectDetail
Subject MatterAfriGRC's Processing of Personal Data submitted by the Customer in connection with its use of the AfriGRC platform.
DurationFor the term of the underlying Services agreement between AfriGRC and the Customer, plus any period required by applicable law afterward.
Nature & PurposeHosting, storing, and processing Customer Content to provide the governance, risk, and compliance functionality of the Services.
Categories of Data SubjectsThe Customer's authorized Users and Administrators, and any individuals whose Personal Data appears within Content the Customer submits to the Platform.
Categories of Personal DataAccount and profile data of authorized Users, and any Personal Data a Customer chooses to include within its own Content — such as a name referenced in a risk record or policy document.
DPA.04 / SUB-PROCESSOR ENGAGEMENT

Categories today, a full list as it's finalized.

AfriGRC may engage Sub-processors to Process Personal Data in support of the Services — for example, an infrastructure provider that hosts the Platform. See our Sub-processors list for the categories of Sub-processors currently engaged.

A mechanism for notifying Customers of a new Sub-processor, and the process for objecting to one, is still being finalized as part of formal legal review. In the meantime, contact our Legal team using the details in Contact Information below with any Sub-processor question specific to your agreement.

DPA.05 / SECURITY MEASURES

Governed by our Trust Centre, not restated here.

AfriGRC maintains technical and organizational measures designed to protect Personal Data, described in full in our Security & Trust Centre. A dedicated security-measures annex, appropriate for a signed DPA, is still being finalized as part of formal legal review.

DPA.06 / INTERNATIONAL TRANSFERS

Transfer mechanisms depend on deployment and jurisdiction.

Where Processing Personal Data under this DPA involves a cross-border transfer, AfriGRC intends to rely on an appropriate legal mechanism — such as Standard Contractual Clauses — for that transfer. The specific mechanism depends on the jurisdictions involved and the specifics of a given deployment.

This section will name the specific mechanisms AfriGRC relies on, and reference any applicable clauses as a formal annex, once that analysis has been completed as part of formal legal review.

DPA.07 / AUDIT RIGHTS

Placeholder architecture — not yet drafted legal language.

This section will describe how a Customer can obtain reasonable assurance of AfriGRC's compliance with this DPA — for example, through security documentation available via our Trust Centre, a completed security questionnaire, or a right to conduct or commission an audit under specific conditions.

The specific mechanics — notice period, frequency, and scope — have not yet been finalized, and are intentionally not fabricated here pending formal legal review.

DPA.08 / CHANGES TO THIS DPA

Every revision, in one place.

  • Establishes the page structure: Definitions, Roles & Responsibilities, Processing Details, and the sections that follow.
  • Sub-processor names, audit mechanics, and international transfer mechanisms are placeholder architecture pending legal review.
DPA.09 / CONTACT INFORMATION

Questions about this agreement.

Legal Team

Requests for a signed Data Processing Agreement, or questions about its terms.

Contact Legal

Commercial Team

Requests tied to a specific order form or agreement.

Contact Sales

Privacy

General questions about how AfriGRC handles Personal Data — see our Privacy Policy for full detail.

Contact Privacy Team

Support

Technical questions about an existing Subscription.

Contact Support
DPA.10 / GET IN TOUCH

Need a signed Data Processing Agreement?

Reach our Legal team to request a signed DPA for your organization, or talk to Sales about a specific deployment.

Data Processing Agreement — AfriGRC