MCM-58 — Data Processing Agreement & Controller/Processor Clarity
A standard DPA and a documented controller/processor determination per deployment model.
MCM-58 — Data Processing Agreement & Controller/Processor Clarity
← Back to Legal & Compliance Readiness overview
As Legal Counsel,
I want a standard Data Processing Agreement and a documented controller/processor determination for each deployment model,
so that MCM's data-handling obligations under GDPR/CCPA (and equivalent regimes) are clear and enforceable before any customer's cloud data is accessed.
Acceptance Criteria
- A standard DPA template exists covering: categories of data processed (cloud inventory, security findings, cost/billing data, IAM configuration metadata), sub-processors used (including any third-party AI model provider), data retention and deletion timelines, and cross-border transfer mechanisms (Standard Contractual Clauses or equivalent).
- For each deployment model (customer-hosted/on-prem vs. MCM-hosted private instance), a controller-vs-processor determination is documented and reviewed by Legal Counsel before that model is offered to a customer.
- The DPA is a mandatory exhibit to the master agreement — no customer contract is countersigned without it attached.
- A sub-processor list is maintained and kept current; adding a new sub-processor triggers a defined customer-notice period before it takes effect.
- Data deletion/return obligations on contract termination are defined and testable — a documented deletion procedure with a maximum completion window, not just a promise in prose.
Technical Design
The DPA's declared data categories have to track what the platform actually collects, so Legal Counsel reviews the union of data surfaced by discovery, governance, secops, finops, and the AI assistant against the DPA each release — a module quietly collecting a new category of customer data is what silently outdates the agreement. The sub-processor list is updated the same way, whenever a new external dependency (most notably an AI model provider) is introduced.
MCM-57 — Legal & Compliance Readiness for Customer Deployment
Overview of the legal and compliance deliverables that must be in place before MCM is deployed into a customer's environment.
MCM-59 — Cross-Account Access & Least-Privilege Commitments
Documented, contractually-committed least-privilege scopes for every cross-account role MCM requests.