Template. Fill in the blanks, sign, and email it to chris@otree.org; we will countersign it. To get an editable copy, print this page to PDF, or copy it into a word processor. Background: Data protection & ethics.
This Data Processing Agreement ("DPA") is entered into between:
It applies to the Processor's hosting of oTree experiments on on.otree.org (the "Service") for the Controller's researchers, as described in Annex I. It forms part of the terms under which the Controller uses the Service.
"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
2.1 The Controller determines the purposes and means of the Processing, and the Processor processes Personal Data on its behalf.
2.2 The Processor processes Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by law; in that case the Processor informs the Controller before processing, unless the law prohibits this. The Controller's use and configuration of the Service, and this DPA, are its documented instructions. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR.
2.3 The Controller is responsible for the lawfulness of the Processing, including having a legal basis, informing Data Subjects, obtaining any consent and ethics approval, and minimizing the Personal Data it collects.
The Processor shall:
4.1 The Controller gives general authorization for the sub-processors listed in Annex III.
4.2 The Processor will notify the Controller by email at least 14 days before adding or replacing a sub-processor that processes Personal Data. The Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate its use of the Service.
4.3 The Processor imposes on each sub-processor data-protection obligations no less protective than this DPA, and remains liable to the Controller for its sub-processors' performance.
5.1 Personal Data is stored in the European Union (Frankfurt, Germany).
5.2 The Processor is established in Hong Kong, and its administrators may access the Personal Data remotely from outside the EEA for maintenance and support. To the extent that this is a transfer of Personal Data to a third country, the parties incorporate the SCCs, Module Two (controller to processor), by reference, with the Controller as data exporter and the Processor as data importer, and with the following choices: Clause 7 (docking) applies; in Clause 9, option 2 (general authorization) applies, with the notice period in section 4.2; the optional wording in Clause 11 does not apply; in Clauses 17 and 18, the law and courts are those of the EU Member State in which the Controller is established. Annexes I–III of this DPA serve as the annexes to the SCCs. The competent supervisory authority is that of the Controller's Member State. If the SCCs conflict with this DPA, the SCCs prevail.
The Processor notifies the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provides the information reasonably available to it to help the Controller meet its obligations under GDPR Arts. 33 and 34.
The Controller can download and delete its Personal Data at any time through the Service. At the end of the Service, or on the Controller's written request, the Processor deletes the Personal Data, unless the law requires it to be kept. Copies in backups and logs are deleted within 30 days.
The Processor answers the Controller's reasonable written security and data-protection questionnaires. If these are insufficient to demonstrate compliance, or if a Supervisory Authority requires it, the Controller may carry out an audit, or have an independent auditor bound by confidentiality do so, at most once a year, on 30 days' notice and at the Controller's expense.
Each party's liability under this DPA is subject to the limitations agreed for the Service, except where such limitations are not permitted by applicable law (including GDPR Art. 82 and the SCCs).
This DPA applies for as long as the Processor processes Personal Data for the Controller. Sections 6, 7 and 9 survive its termination.
| Controller | Processor: oTree Limited | |
|---|---|---|
| Name | Chris Wickens | |
| Title | Director | |
| Date | ||
| Signature |
| Data exporter (Controller) | As above. Contact person / DPO: |
|---|---|
| Data importer (Processor) | oTree Limited, Hong Kong. Contact: chris@otree.org |
| Research project(s) | (or: all projects of the Controller's researchers) |
| Data subjects | Participants in the Controller's research studies |
| Categories of data | Responses and behavior in the experiment, as defined by the Controller's experiment code; pseudonymous participant IDs from recruitment panels; technical data (IP address, browser, timestamps) in server access logs |
| Special categories | None, unless the Controller's study collects them: |
| Frequency of transfer | Continuous, for the duration of the studies (remote administrative access only) |
| Nature and purpose | Hosting and running online experiments; storing the resulting data until the Controller downloads and deletes it |
| Retention | Until deleted by the Controller; backups and logs up to 30 days after that |
| Sub-processor | Service | Location of Personal Data |
|---|---|---|
| DigitalOcean, LLC | Server hosting (infrastructure) | Frankfurt, Germany |
| DigitalOcean, LLC | Hosting of otreehub.com, which receives crash reports (see Annex II) | Singapore |