DATA PROCESSING AGREEMENT (DPA)
Effective Date: ___________________
This Data Processing Agreement ("DPA") is entered into between:
Campus Marg Innovative Tech Services LLP, operating as CMI BPO Services ("Processor", "Service Provider", "CMITS", "we", "our", or "us"),
and
Client Name: __________________________________________ ("Controller", "Client", or "Customer").
This DPA forms part of and is incorporated into the Master Service Agreement (MSA), Service Agreement, Statement of Work (SOW), Purchase Order, or other commercial agreement ("Principal Agreement") between the parties.
1. Purpose
The purpose of this Agreement is to establish the obligations and responsibilities of each party regarding the processing of personal data in connection with the services provided by CMI BPO Services.
2. Definitions
For the purposes of this Agreement:
Controller means the party that determines the purposes and means of processing personal data.
Processor means Campus Marg Innovative Tech Services LLP, acting on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person.
Processing includes collecting, recording, storing, organizing, modifying, transmitting, using, disclosing, deleting, or otherwise handling personal data.
Data Subject means the individual to whom the personal data relates.
3. Scope of Processing
The Processor may process personal data solely for the purpose of providing services agreed under the Principal Agreement, including:
Customer Support
Contact Center Operations
Technical Support
Recruitment Process Outsourcing (RPO)
HR Support
Back Office Processing
Data Entry
Helpdesk Services
Lead Management
Email Support
Chat Support
Voice Support
Other agreed outsourcing services
4. Categories of Personal Data
Depending on the project, processing may include:
Full Name
Email Address
Mobile Number
Postal Address
Company Information
Employee Information
Customer Information
Candidate Information
Employment Details
Educational Records
Communication Records
Transaction Information
Customer Service Records
Support Tickets
Voice Recordings (where applicable)
Chat Transcripts
Email Communications
Any additional information provided by the Controller for the agreed services
5. Categories of Data Subjects
Personal data may relate to:
Customers
Employees
Candidates
Vendors
Business Partners
Website Users
Students
Prospective Customers
Contractors
Other individuals identified by the Controller
6. Processor Obligations
The Processor shall:
Process personal data only on documented instructions from the Controller.
Process data solely for the agreed business purposes.
Maintain confidentiality of all personal data.
Ensure personnel handling personal data are subject to confidentiality obligations.
Implement reasonable technical and organizational security measures.
Notify the Controller of any known personal data breach without undue delay after becoming aware of it.
Assist the Controller, where reasonably requested, in responding to data subject rights requests.
Cooperate with the Controller regarding compliance obligations, where applicable.
7. Controller Obligations
The Controller shall:
Ensure it has a lawful basis for processing and sharing personal data.
Provide lawful instructions to the Processor.
Inform data subjects as required by applicable law.
Obtain any necessary consents where applicable.
Ensure that data supplied to the Processor is accurate and relevant.
8. Confidentiality
The Processor shall treat all personal data and confidential information as strictly confidential and shall not disclose such information except:
As instructed by the Controller.
As required by applicable law.
To authorized personnel or approved subprocessors who are bound by appropriate confidentiality obligations.
9. Security Measures
The Processor will maintain commercially reasonable administrative, technical, and organizational measures to protect personal data, including, where appropriate:
Access controls based on business need.
User authentication procedures.
Password-protected systems.
Endpoint protection and anti-malware controls.
Secure storage of data.
Backup and recovery procedures.
Employee security awareness training.
Physical security for office facilities.
Logging and monitoring where appropriate.
The specific security measures may vary based on the nature of the services and contractual requirements.
10. Subprocessors
The Processor may engage third-party service providers (subprocessors) where necessary to deliver the agreed services.
The Processor will take reasonable steps to ensure that any approved subprocessors are contractually bound to protect personal data in a manner consistent with this Agreement.
Where required by the Principal Agreement, the Processor will notify the Controller of material changes to subprocessors.
11. International Transfers
Where personal data is transferred outside the jurisdiction in which it was collected, the parties will take reasonable steps to ensure that such transfers comply with applicable legal requirements and are subject to appropriate safeguards where required.
12. Data Subject Rights
Where applicable and reasonably requested by the Controller, the Processor shall assist in responding to requests relating to:
Access
Correction
Deletion
Restriction of processing
Objection to processing
Data portability (where legally applicable)
The Controller remains responsible for responding to data subject requests unless otherwise agreed.
13. Data Breach Notification
If the Processor becomes aware of a confirmed personal data breach affecting Controller data, the Processor shall notify the Controller without undue delay after becoming aware of the breach.
The notification will include, where reasonably available:
Nature of the incident
Categories of affected data
Likely impact
Steps taken or proposed to mitigate the effects
The Processor does not guarantee uninterrupted service or absolute security, as no security system is entirely immune from risk.
14. Data Retention and Deletion
The Processor shall retain personal data only for as long as necessary to perform the agreed services, comply with applicable legal obligations, resolve disputes, or enforce contractual rights.
Upon termination of the Principal Agreement, and subject to legal or contractual retention requirements, the Processor will, upon written request, return or securely delete Controller personal data within a commercially reasonable period.
15. Audits
Where expressly agreed in writing, and subject to reasonable notice, confidentiality obligations, and operational requirements, the Controller may request information reasonably necessary to demonstrate the Processor's compliance with this DPA.
Any audit shall be conducted during normal business hours in a manner that minimizes disruption to the Processor's operations.
16. Liability
Each party shall remain responsible for its own acts and omissions.
The Processor's liability under this DPA shall be subject to the limitations of liability set out in the Principal Agreement, except where such limitations are prohibited by applicable law.
17. Term and Termination
This DPA becomes effective on the Effective Date and remains in force for the duration of the Principal Agreement or as long as the Processor processes personal data on behalf of the Controller.
Termination of the Principal Agreement shall not affect obligations relating to confidentiality, data protection, or retention where those obligations are intended to survive termination.
18. Governing Law
This Data Processing Agreement shall be governed by the laws of India, unless otherwise agreed in writing in the Principal Agreement.
Any disputes arising under this DPA shall be subject to the jurisdiction specified in the Principal Agreement.
19. Contact Information
Campus Marg Innovative Tech Services LLP
(Operating as CMI BPO Services)
Email: privacy@cmibpo.com
Phone: +91 9700880567
Website: www.cmibpo.com
20. Entire Agreement
This DPA forms part of the Principal Agreement. In the event of any inconsistency between this DPA and the Principal Agreement concerning the processing of personal data, the provisions of this DPA shall prevail to the extent of that inconsistency, unless the Principal Agreement expressly provides otherwise.
21. Signatures
For Campus Marg Innovative Tech Services LLP
Authorized Signatory: ___________________________
Name: _________________________________________
Designation: ___________________________________
Signature: _____________________________________
Date: __________________________________________
For Client
Company Name: _________________________________
Authorized Signatory: ___________________________
Name: _________________________________________
Designation: ___________________________________
Signature: _____________________________________
Date: __________________________________________
