Template. Fill in the blanks, sign, and email it to chris@otree.org; we will countersign it. To get an editable copy, print this page to PDF, or copy it into a word processor. Background: Data protection & ethics.

Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into between:

  1. Controller: (institution name), with its address at , represented by (the "Controller"); and
  2. Processor: oTree Limited, a company incorporated in Hong Kong, contact: chris@otree.org (the "Processor").

It applies to the Processor's hosting of oTree experiments on on.otree.org (the "Service") for the Controller's researchers, as described in Annex I. It forms part of the terms under which the Controller uses the Service.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

2. Roles and instructions

2.1 The Controller determines the purposes and means of the Processing, and the Processor processes Personal Data on its behalf.

2.2 The Processor processes Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by law; in that case the Processor informs the Controller before processing, unless the law prohibits this. The Controller's use and configuration of the Service, and this DPA, are its documented instructions. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR.

2.3 The Controller is responsible for the lawfulness of the Processing, including having a legal basis, informing Data Subjects, obtaining any consent and ethics approval, and minimizing the Personal Data it collects.

3. Processor obligations

The Processor shall:

  1. ensure that persons authorized to process the Personal Data are bound by confidentiality;
  2. implement the technical and organizational measures in Annex II (GDPR Art. 32);
  3. taking into account the nature of the Processing, assist the Controller by appropriate technical and organizational measures in responding to Data Subject requests, and forward to the Controller any such request it receives directly;
  4. assist the Controller with its obligations under GDPR Arts. 32–36, taking into account the nature of Processing and the information available to the Processor;
  5. make available to the Controller the information necessary to demonstrate compliance with this DPA.

4. Sub-processors

4.1 The Controller gives general authorization for the sub-processors listed in Annex III.

4.2 The Processor will notify the Controller by email at least 14 days before adding or replacing a sub-processor that processes Personal Data. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate its use of the Service.

4.3 The Processor imposes on each sub-processor data-protection obligations no less protective than this DPA, and remains liable to the Controller for its sub-processors' performance.

5. Location and international transfers

5.1 Personal Data is stored in the European Union (Frankfurt, Germany).

5.2 The Processor is established in Hong Kong, and its administrators may access the Personal Data remotely from outside the EEA for maintenance and support. To the extent that this is a transfer of Personal Data to a third country, the parties incorporate the SCCs, Module Two (controller to processor), by reference, with the Controller as data exporter and the Processor as data importer, and with the following choices: Clause 7 (docking) applies; in Clause 9, option 2 (general authorization) applies, with the notice period in section 4.2; the optional wording in Clause 11 does not apply; in Clauses 17 and 18, the law and courts are those of the EU Member State in which the Controller is established. Annexes I–III of this DPA serve as the annexes to the SCCs. The competent supervisory authority is that of the Controller's Member State. If the SCCs conflict with this DPA, the SCCs prevail.

6. Personal Data Breaches

The Processor notifies the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provides the information reasonably available to it to help the Controller meet its obligations under GDPR Arts. 33 and 34.

7. Deletion and return

The Controller can download and delete its Personal Data at any time through the Service. At the end of the Service, or on the Controller's written request, the Processor deletes the Personal Data, unless the law requires it to be kept. Copies in backups and logs are deleted within 30 days.

8. Audits

The Processor answers the Controller's reasonable written security and data-protection questionnaires. If these are insufficient to demonstrate compliance, or if a Supervisory Authority requires it, the Controller may carry out an audit, or have an independent auditor bound by confidentiality do so, at most once a year, on 30 days' notice and at the Controller's expense.

9. Liability

Each party's liability under this DPA is subject to the limitations agreed for the Service, except where such limitations are not permitted by applicable law (including GDPR Art. 82 and the SCCs).

10. Term

This DPA applies for as long as the Processor processes Personal Data for the Controller. Sections 6, 7 and 9 survive its termination.

Signatures

ControllerProcessor: oTree Limited
NameChris Wickens
TitleDirector
Date
Signature

Annex I: Description of the Processing

Data exporter (Controller)As above. Contact person / DPO:
Data importer (Processor)oTree Limited, Hong Kong. Contact: chris@otree.org
Research project(s) (or: all projects of the Controller's researchers)
Data subjectsParticipants in the Controller's research studies
Categories of dataResponses and behavior in the experiment, as defined by the Controller's experiment code; pseudonymous participant IDs from recruitment panels; technical data (IP address, browser, timestamps) in server access logs
Special categoriesNone, unless the Controller's study collects them:
Frequency of transferContinuous, for the duration of the studies (remote administrative access only)
Nature and purposeHosting and running online experiments; storing the resulting data until the Controller downloads and deletes it
RetentionUntil deleted by the Controller; backups and logs up to 30 days after that

Annex II: Technical and organizational measures

Annex III: Authorized sub-processors

Sub-processorServiceLocation of Personal Data
DigitalOcean, LLCServer hosting (infrastructure)Frankfurt, Germany
DigitalOcean, LLCHosting of otreehub.com, which receives crash reports (see Annex II)Singapore