Data Processing Agreement
This DPA describes the terms under which AfriGRC Processes Personal Data on behalf of a Customer, as a Processor acting on that Customer's instructions. It follows the standard structure of a data processing agreement — the specific commitments within it are still being finalized as part of formal legal review.
- Last Updated
- August 5, 2026
- Effective Date
- To be confirmed upon legal review
- Version
- 0.1 (Draft)
This page is a working draft of our Data Processing Agreement, published for transparency ahead of formal legal review. It does not constitute legal advice, is not a substitute for a signed agreement, and should not be treated as a final, legally approved, or binding document until AfriGRC confirms it has completed that review.
Terms used throughout this agreement.
- Controller
- The entity that determines the purposes and means of Processing Personal Data. For data a Customer submits to the Platform, the Customer is typically the Controller.
- Processor
- AfriGRC, acting on behalf of and under the documented instructions of a Customer, in respect of Personal Data the Customer submits to the Platform.
- Sub-processor
- A third party engaged by AfriGRC to Process Personal Data on AfriGRC's behalf, in support of the Services — see Sub-processor Engagement below and our published Sub-processors list.
- Data Subject
- An identified or identifiable natural person to whom Personal Data relates.
- Personal Data
- Any information relating to a Data Subject, submitted by a Customer to the Platform as part of its Content.
- Processing
- Any operation performed on Personal Data, whether or not by automated means — including collection, storage, use, disclosure, and deletion.
- Data Protection Laws
- The data protection and privacy laws applicable to the Processing of Personal Data under this DPA, which may include GDPR, Nigeria's NDPA, South Africa's POPIA, and other applicable frameworks.
- Standard Contractual Clauses
- The contractual mechanism(s) that may be used to lawfully transfer Personal Data across a border, where required — see International Transfers below.
Who is the Controller, who is the Processor.
Customer as Controller
For Personal Data a Customer submits to the Platform as Content, the Customer determines the purposes and means of Processing, and is the Controller.
AfriGRC as Processor
AfriGRC Processes that Personal Data solely to provide the Services, and only on the Customer's documented instructions.
Processing on Instructions
AfriGRC will not Process Personal Data for any purpose other than providing the Services, except where required by applicable law.
Confidentiality of Personnel
Personnel authorized to Process Personal Data are bound by confidentiality obligations, whether contractual or statutory.
Assistance With Data Subject Requests
AfriGRC will provide reasonable assistance to a Customer responding to a Data Subject request, to the extent the Customer cannot reasonably do so itself.
The standard 'Annex' structure of a DPA.
Subject matter, duration, nature, purpose, and the categories of data subjects and Personal Data involved.
| Aspect | Detail |
|---|---|
| Subject Matter | AfriGRC's Processing of Personal Data submitted by the Customer in connection with its use of the AfriGRC platform. |
| Duration | For the term of the underlying Services agreement between AfriGRC and the Customer, plus any period required by applicable law afterward. |
| Nature & Purpose | Hosting, storing, and processing Customer Content to provide the governance, risk, and compliance functionality of the Services. |
| Categories of Data Subjects | The Customer's authorized Users and Administrators, and any individuals whose Personal Data appears within Content the Customer submits to the Platform. |
| Categories of Personal Data | Account and profile data of authorized Users, and any Personal Data a Customer chooses to include within its own Content — such as a name referenced in a risk record or policy document. |
Categories today, a full list as it's finalized.
AfriGRC may engage Sub-processors to Process Personal Data in support of the Services — for example, an infrastructure provider that hosts the Platform. See our Sub-processors list for the categories of Sub-processors currently engaged.
A mechanism for notifying Customers of a new Sub-processor, and the process for objecting to one, is still being finalized as part of formal legal review. In the meantime, contact our Legal team using the details in Contact Information below with any Sub-processor question specific to your agreement.
Governed by our Trust Centre, not restated here.
AfriGRC maintains technical and organizational measures designed to protect Personal Data, described in full in our Security & Trust Centre. A dedicated security-measures annex, appropriate for a signed DPA, is still being finalized as part of formal legal review.
Transfer mechanisms depend on deployment and jurisdiction.
Where Processing Personal Data under this DPA involves a cross-border transfer, AfriGRC intends to rely on an appropriate legal mechanism — such as Standard Contractual Clauses — for that transfer. The specific mechanism depends on the jurisdictions involved and the specifics of a given deployment.
This section will name the specific mechanisms AfriGRC relies on, and reference any applicable clauses as a formal annex, once that analysis has been completed as part of formal legal review.
Placeholder architecture — not yet drafted legal language.
This section will describe how a Customer can obtain reasonable assurance of AfriGRC's compliance with this DPA — for example, through security documentation available via our Trust Centre, a completed security questionnaire, or a right to conduct or commission an audit under specific conditions.
The specific mechanics — notice period, frequency, and scope — have not yet been finalized, and are intentionally not fabricated here pending formal legal review.
Every revision, in one place.
- Establishes the page structure: Definitions, Roles & Responsibilities, Processing Details, and the sections that follow.
- Sub-processor names, audit mechanics, and international transfer mechanisms are placeholder architecture pending legal review.
Questions about this agreement.
Legal Team
Requests for a signed Data Processing Agreement, or questions about its terms.
Contact LegalPrivacy
General questions about how AfriGRC handles Personal Data — see our Privacy Policy for full detail.
Contact Privacy TeamNeed a signed Data Processing Agreement?
Reach our Legal team to request a signed DPA for your organization, or talk to Sales about a specific deployment.