Legal
Data Processing Addendum
Shieldra data processing commitments under the GDPR, UK GDPR, and CCPA/CPRA. This DPA forms part of the Shieldra Terms of Service and prevails over them in any conflict concerning personal data.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Under the GDPR, Shieldra is the processor and the Customer is the controller; under CCPA/CPRA, Shieldra is a service provider.
- Shieldra processes personal data only on the Customer’s documented instructions.
- Sub-processors are permitted, and Shieldra remains responsible for their compliance under terms no less protective than this DPA.
- Shieldra notifies the Customer of a personal data breach without undue delay and within 72 hours of becoming aware.
- Health data or PHI is only in scope under a separate Business Associate Agreement.
Roles and scope
This Data Processing Addendum forms part of the Shieldra Terms of Service between Shieldra AI, Inc. and the Customer, and applies to the processing of personal data on the Customer’s behalf in connection with the services. Where the GDPR applies, Shieldra acts as processor and the Customer as controller; where the CCPA/CPRA applies, Shieldra acts as a service provider. In any conflict concerning personal data, this DPA prevails over the Terms.
Subject matter, duration, nature, and purpose
- Subject matter: processing of personal data submitted to the services by or on behalf of the Customer
- Duration: the term of the Customer’s subscription
- Nature and purpose: compliance management, document analysis, AI-assisted gap analysis, evidence collection, vendor risk management, training tracking, and reporting
- Categories of personal data: identification and contact data, employment data, system access logs, and any data the Customer chooses to upload — which may include health data or PHI only under a separate BAA
Processing obligations
Shieldra processes personal data only on the Customer’s documented instructions, including with regard to international transfers, unless otherwise required by law. If Shieldra believes an instruction infringes the GDPR or other applicable data protection law, it will say so unless legally prohibited from doing so.
Personnel authorized to process personal data are bound by appropriate confidentiality obligations and have received data protection training. Shieldra’s security program is described on the public security page and is independently assessed.
Sub-processors and international transfers
The Customer authorizes Shieldra to engage sub-processors for specific processing activities. Shieldra remains responsible for each sub-processor’s compliance and imposes data protection obligations on them no less protective than those in this DPA. The current list of sub-processors, their locations, and their roles is published on the sub-processors page.
Where personal data is transferred internationally, Shieldra conducts transfer impact assessments and implements supplementary measures where required.
Data subject requests and breach notification
Taking into account the nature of the processing, Shieldra assists the Customer by appropriate technical and organizational measures, so far as possible, in fulfilling the Customer’s obligations to respond to data subject requests. Where Shieldra receives a request directly from a data subject, it refers them to the Customer or to the privacy request page unless legally required to respond directly.
Shieldra notifies the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Data, providing the information the Customer needs to meet its own notification obligations. Shieldra also provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
Frequently asked questions
Is Shieldra a controller or a processor?
Under the GDPR, Shieldra is the processor and the Customer is the controller. Under the CCPA/CPRA, Shieldra acts as a service provider. Shieldra processes personal data only on the Customer’s documented instructions.
How quickly does Shieldra report a personal data breach?
Without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, together with the information the Customer needs to meet its own breach notification obligations.
Does the DPA cover PHI?
No. Health data and protected health information are only in scope under a separate Business Associate Agreement. The standard service is a No-PHI platform for compliance documentation and evidence.
Where can I see the current sub-processor list?
The sub-processors page lists every third party involved in delivering the service, along with its purpose and processing location. Shieldra remains responsible for sub-processor compliance under terms no less protective than the DPA.