# Data Processing Addendum (DPA)

> **DRAFT — not legal advice.** This template was prepared from regulatory and industry
> guidance for ngnsimulation's institutional/white-label customers. It must be reviewed and
> finalized by qualified Alberta counsel before execution. Bracketed `[…]` items are to be
> completed.

This Data Processing Addendum (**"DPA"**) forms part of the agreement (the **"Agreement"**)
between **[REGISTERED LEGAL NAME]** (**"Processor"**, "we", "us") and the customer identified
in the Agreement (**"Controller"**, "you") for the provision of the Services. It governs the
Processing of Personal Information by us on your behalf.

## 1. Definitions

Terms not defined here have the meaning given in the Agreement or in applicable Data
Protection Law.

- **"Applicable Data Protection Law"** — all privacy and data protection laws applicable to
  the Processing, including Alberta's *Personal Information Protection Act* (**PIPA**), Canada's
  *PIPEDA*, Quebec's *Law 25*, and, where applicable, the EU/UK **GDPR**.
- **"Personal Information" / "Personal Data"** — information about an identifiable individual
  Processed under the Agreement.
- **"Processing"**, **"Controller"**, **"Processor"**, **"Sub-processor"**, **"Data Subject"** —
  as defined in Applicable Data Protection Law (for PIPA/PIPEDA, "Processor" means our role as a
  service provider acting on your behalf).
- **"Security Incident"** — a breach of security safeguards leading to the accidental or
  unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal
  Information.

## 2. Roles & scope

2.1 As between the parties, **you are the Controller** of the Personal Information and **we are
the Processor**, Processing it only on your documented instructions, including as set out in
the Agreement and **Annex 1**.

2.2 You are responsible for the lawfulness of the Personal Information you provide and for
having the necessary consents and notices for the Processing.

2.3 We will inform you if, in our opinion, an instruction infringes Applicable Data Protection
Law (without obligation to provide legal advice).

## 3. Our obligations

We will:

- Process Personal Information only on your documented instructions, including for
  international transfers, unless required by law (in which case we will notify you unless
  legally prohibited);
- Ensure persons authorized to Process Personal Information are bound by confidentiality;
- Implement the technical and organizational measures in **Annex 2**;
- Not sell Personal Information and not use it for our own independent purposes;
- Assist you, taking into account the nature of Processing, with Data Subject requests, security,
  breach notification, and data protection impact assessments;
- Make available information reasonably necessary to demonstrate compliance with this DPA.

## 4. Sub-processors

4.1 You provide **general authorization** for us to engage Sub-processors to Process Personal
Information. Our current Sub-processors are listed at **/subprocessors** and in **Annex 3**.

4.2 We will impose data protection obligations on each Sub-processor that are no less protective
than those in this DPA, and we remain responsible for their performance.

4.3 We will give you at least **[30] days'** notice of any intended addition or replacement of a
Sub-processor. You may object on reasonable data protection grounds; the parties will work in
good faith to resolve the objection.

## 5. Data Subject requests

We will, taking into account the nature of the Processing, assist you by appropriate technical
and organizational measures, insofar as possible, to respond to requests from Data Subjects
exercising their rights under Applicable Data Protection Law. If we receive such a request
directly, we will (unless prohibited) direct the Data Subject to you and not respond except on
your instruction.

## 6. Security Incidents

6.1 We will notify you **without undue delay**, and in any event within **[72] hours** of
becoming aware of a Security Incident affecting your Personal Information.

6.2 Our notice will describe, to the extent known, the nature of the incident, the categories
and approximate number of Data Subjects and records affected, likely consequences, and the
measures taken or proposed.

6.3 We will reasonably cooperate with you in your assessment of whether the incident creates a
**real risk of significant harm** under PIPA/PIPEDA and in meeting your notification obligations
to regulators (including the Alberta OIPC) and affected individuals. As Processor, we will not
notify regulators or Data Subjects on your behalf unless you instruct us to.

## 7. International transfers

Where Personal Information of EEA/UK Data Subjects is transferred outside those regions, the
parties will rely on the European Commission's **Standard Contractual Clauses** (and the UK
Addendum), which are incorporated by reference, or another lawful transfer mechanism. Canadian
data-residency options are described in **Annex 1** where elected.

## 8. Audit

We will make available information necessary to demonstrate compliance and allow for and
contribute to audits, including inspections, conducted by you or an auditor you mandate, no more
than **[once per 12 months]** (except where required by a regulator or following a Security
Incident), on reasonable notice, during business hours, subject to confidentiality. We may
satisfy audit requests by providing third-party reports or certifications where available.

## 9. Return & deletion

On termination or expiry of the Agreement, we will, at your choice, delete or return all
Personal Information and delete existing copies within **[60] days**, unless retention is
required by law (in which case we will protect it and Process it only as required for that
purpose).

## 10. Canadian & Quebec specifics

10.1 We will Process Personal Information in a manner consistent with your obligations under
PIPA and PIPEDA.

10.2 Where **Quebec Law 25** applies, the parties will complete any required privacy impact
assessment cooperation, confirm the necessity/proportionality of transfers, and document the
agreed safeguards.

## 11. General

11.1 **Order of precedence.** In the event of conflict, this DPA prevails over the Agreement
with respect to the Processing of Personal Information; the Standard Contractual Clauses prevail
over both for transfers they govern.

11.2 **Liability.** Each party's liability under this DPA is subject to the limitations of
liability in the Agreement.

11.3 **Governing law.** This DPA is governed by the law of the **Province of Alberta and the
federal laws of Canada applicable therein**, except where the Standard Contractual Clauses
require otherwise.

---

## Annex 1 — Details of Processing

- **Subject matter:** provision of the Services described in the Agreement.
- **Duration:** the term of the Agreement plus any retention period in Section 9.
- **Nature & purpose:** hosting, storage, and processing of learner/user data to deliver
  exam-preparation and learning Services.
- **Types of Personal Information:** [account identifiers, contact details, learning/performance
  data, usage/technical data, support communications].
- **Categories of Data Subjects:** [the Controller's learners, staff, and authorized users].
- **Data residency elected:** [Canada region / other — specify].

## Annex 2 — Technical & organizational security measures

[Encryption in transit (TLS); encryption at rest where applicable; access controls and
least-privilege; authentication; logging and monitoring; vulnerability management; secure
development practices; vendor risk management; backup and recovery; personnel confidentiality and
training; incident response. Complete to reflect actual controls.]

## Annex 3 — Approved Sub-processors

See the current list at **/subprocessors**. [Insert point-in-time copy at execution.]
