Requesting a DPA and compliance documents
Updated 1 min read
Most documents a procurement or security review asks for are either published or available on request. Start with the published set; ask for the rest through the Compliance contact.
Published documents
- Data processing addendum, including the sub-processor list
- Privacy notice
- Terms of service
- Acceptable use policy
- Refund policy
- Sourcing and compliance: the sourcing standard and the status of each certification
The DPA needs no signature
The data processing addendum takes effect when you accept the terms of service. If your procurement process requires a countersigned copy, request one from the Compliance contact.
Requesting other material
- Open the contact page and use the Compliance address listed there.
- Name the documents you need, for example the sourcing attestation or a provenance record for a specific address.
- Say who the material is for and whether your organisation needs a non-disclosure agreement in place first. Some material, such as the sourcing attestation, is shared only under NDA.
Certifications that are in progress are labelled as such on the sourcing page. Treat that page as the current status; support does not quote dates for them.