DODVIR

Data Processing Addendum

The data-processing and security framework for contracted services.

Effective date:

When this addendum applies

This DPA applies only when an executed DODVIR order incorporates it and DODVIR processes personal data on the customer’s documented instructions. The order identifies the controller, processor, subject matter, duration, categories of data and data subjects, governing law, and authorized services.

Processor duties

  • Process personal data only on documented instructions and notify the customer if an instruction appears unlawful.
  • Bind authorized personnel to confidentiality and apply proportionate technical and organizational safeguards.
  • Assist with data-subject requests, security assessments, deletion or return, and legally required impact assessments.
  • Notify the customer without undue delay after confirming a personal-data breach and provide available scope, impact, containment, and remediation information.

Subprocessors and transfers

The order or attached processor schedule lists subprocessors, processing locations, and transfer mechanisms. A new subprocessor requires the contractual notice period and an opportunity to object on reasonable data-protection grounds. Public launch is blocked unless that schedule is approved and current.

Security appendix

  • Role-based and least-privilege access, separate runtime credentials, multi-factor authentication for privileged providers, and periodic access review.
  • TLS at the public edge, encrypted backups, secret-manager delivery, signed release artifacts, logging, monitoring, incident response, and tested restoration.
  • Documented retention, deletion, vulnerability handling, dependency review, and customer isolation controls.
  • Annual review of this appendix and evidence delivery under reasonable confidentiality restrictions.
Back to home