# Data processing agreement (DPA) — draft stub

**Status:** outline only / **not legal advice**  
**Finalize-ready draft:** [../bonterms-dpa-draft.md](../bonterms-dpa-draft.md) (TDD-444)  
**Non-claim:** this stub is not a signed DPA and does not assert GDPR, HIPAA,
SOC 2, or ISO certification readiness.

## Suggested sections (for counsel to complete)

1. Parties and roles (controller / processor as applicable to the deployment)
2. Nature of processing — **synthetic attacker interaction** and operational
   telemetry; not processing of real personal data as a primary purpose
3. Categories of data — protocol metadata, evidence refs, optional Ops notes
4. Subprocessors — operator-selected sinks only; sensor zero-egress default
5. Security measures — reference SEC-001…012 / SEC-AG-* and containment docs
6. Breach notification — operator runbooks; kill-switch independence
7. International transfers — jurisdiction filters / AGTI scrub (SEC-AG-004)
8. Audit / deletion — evidence retention under operator control

## Project pointers (non-exhaustive)

- [privacy-pack.md](../../compliance/privacy-pack.md)
- [applicability.md](../../compliance/applicability.md)
- [ADR 0008](../../adr/0008-safe-agentic-roles.md)
