Data Processing Agreement Framework (DPA) – GDPR Article 28
Enterprise framework for processing personal data on behalf of the customer, to be completed with annexes covering purposes, data categories, data subjects, duration, technical measures and sub-processors.
Regulatory and governance references
- Regulation (EU) 2016/679, Article 28 and Articles 32-36, 44-49
- Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses, where applicable
- Regulation (EU) 2025/327 (EHDS), where relevant
- Applicable national healthcare and research law of the controller
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Subject Matter, Definitions and Parties
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. Qualification of Privacy Roles
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller, joint controller and processor are functional qualifications rather than contractual labels. Parties must assess who determines purposes and essential means for each activity; joint-controller arrangements and DPAs must reflect the actual allocation and define responsibilities, rights channels and cooperation.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. Subject, Nature, Purpose and Duration of Processing
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. Categories of Data and Data Subjects
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Documented Controller Instructions
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
The responsible legal entity must be unambiguously identifiable. Corporate details, contact channels and the relevant privacy role are kept separate from the commercial product name; a division or internal business unit does not change legal ownership unless expressly stated.
UESE processes controller data only on documented instructions, including instructions on transfers and deletion. Where an instruction appears to breach applicable law, UESE informs the controller to the extent permitted and may suspend execution pending clarification.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. Duty to Inform of Unlawful Instructions
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
UESE processes controller data only on documented instructions, including instructions on transfers and deletion. Where an instruction appears to breach applicable law, UESE informs the controller to the extent permitted and may suspend execution pending clarification.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. Confidentiality and Personnel Authorisation
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Permissions are assigned by role and organisational scope under least privilege. They should be periodically reviewed and updated when duties change; high-impact operations, exports and administrative functions are restricted to expressly authorised roles.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. Technical and Organisational Measures
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. Pseudonymisation and Minimisation
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Each processing operation must respect purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality. Configuration should avoid unnecessary free-text fields, uncontrolled copies and excessive transfers; synthetic or properly anonymised data should be preferred for testing and training where feasible.
Where technically feasible, direct identity remains with the healthcare or research institution and the platform uses pseudonymous identifiers. Re-identification keys should be segregated, protected and accessible to a restricted group; re-identification should occur only where permitted by protocol and legal basis.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. Sub-processors: Authorisation and Equivalent Duties
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Recipients are limited to authorised persons and necessary providers. Before entrusting processing to third parties, role, security, location, onward subcontracting and contractual terms are assessed; the sub-processor chain is governed under GDPR Article 28 and the agreed authorisation mechanism.
Permissions are assigned by role and organisational scope under least privilege. They should be periodically reviewed and updated when duties change; high-impact operations, exports and administrative functions are restricted to expressly authorised roles.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. International Transfers and Third-Country Access
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Any third-country transfer is subject to GDPR Chapter V and must be mapped before activation. In the absence of an adequacy decision, Standard Contractual Clauses, a transfer impact assessment and supplementary measures may be required; remote access from a third country is assessed as part of the same risk.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Assistance with Data Subject Rights
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Access, rectification, erasure, restriction, objection and portability requests are handled according to the actual role. Where UESE is processor it does not replace the controller’s decision-making, but provides tools and information compatible with the nature of processing and security requirements.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Assistance with DPIAs and Prior Consultation
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
UESE provides architecture, security and data-flow information reasonably necessary for the controller’s DPIA. The controller remains responsible for deciding whether a DPIA or prior consultation is required and for accepting residual risk, unless separate advisory services are expressly commissioned outside the processor role.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
14. Personal Data Breaches
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Events are classified by severity and impact, contained and documented. Where UESE acts as processor it notifies the controller without undue delay after becoming aware of a personal data breach and provides available information for GDPR Articles 33 and 34 assessments; regulatory notifications remain with the competent party.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
15. Security, Incidents and Forensic Cooperation
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Events are classified by severity and impact, contained and documented. Where UESE acts as processor it notifies the controller without undue delay after becoming aware of a personal data breach and provides available information for GDPR Articles 33 and 34 assessments; regulatory notifications remain with the competent party.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
16. Audits, Verification and Compliance Information
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
17. Return and Deletion at Termination
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Retention periods are defined by data category and purpose. Exit must distinguish export, return, logical deletion, storage deletion and backup cycles; legal duties, disputes or legal hold may justify limited segregated retention that is documented and not reused for other purposes.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
18. Mandatory Retention and Legal Hold
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Retention periods are defined by data category and purpose. Exit must distinguish export, return, logical deletion, storage deletion and backup cycles; legal duties, disputes or legal hold may justify limited segregated retention that is documented and not reused for other purposes.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
19. Health and Genomic Data
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Health and genetic data are special categories under GDPR Article 9. The controller must identify an Article 6 legal basis and an Article 9 condition, assess applicable health and research law and implement appropriate safeguards; pseudonymisation reduces risk but does not automatically make data anonymous.
FASTQ, BAM/CRAM and large datasets should not pass through ordinary PHP shared-hosting uploads. The platform governs metadata, references, checksums and permissions, while large payloads belong in authorised storage under territorial and contractual conditions compatible with the project.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
20. EHDS, Research and Secondary Use
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
EHDS applies on a phased timetable. Substantial secondary-use rules begin to apply from 26 March 2029, with remaining categories including genomic data from 26 March 2031. Dates and obligations must be checked against the law in force and implementing acts when the project is deployed.
Primary use concerns care for the individual; secondary use concerns additional permitted purposes such as research and innovation under specific procedures and safeguards. The platform does not assume that data collected for care may be reused for research without analysis of legal basis, permits and applicable restrictions.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
21. Liability, Indemnities and Contractual Limits
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
22. Operational Annexes, Priority and Amendments
This DPA is a framework model for situations where UESE ITALIA S.p.A. acts as processor under GDPR Article 28. To become contractually operative it must be read with the governing agreement and completed by annexes describing the actual purposes, duration, categories of data subjects and data, instructions, technical and organisational measures, sub-processors and transfers.
Requests are prioritised by impact and urgency. Response time measures acknowledgement and engagement, not necessarily resolution; critical priorities require defined escalation channels, contacts and minimum diagnostic information.
Controller instructions must be sufficiently precise and current. Material changes to purpose, data categories, transfers, sub-processors or measures require updated annexes and, where needed, refreshed risk assessment and DPIA.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.