Data Processing Addendum
Bentley Systems has published a Data Processing Addendum (DPA) governing how personal data is handled under existing software and service agreements, clarifying roles and compliance requirements for both parties.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
The DPA, incorporated into existing Bentley Systems agreements, defines Bentley as the data processor and the customer as the controller for personal data processed under those contracts. It specifies that in cases of conflict, the DPA terms take precedence over other agreement provisions. The document applies to all Bentley software licenses, products, and services provided to the customer and its affiliates, where applicable.
The addendum outlines definitions for key terms such as 'Personal Data,' 'Processing,' 'Controller,' and 'Processor,' aligning them with standards like GDPR, CCPA, and other US state privacy laws. It also distinguishes Bentley’s role as an independent controller for Account Data and Usage Data, which are used to manage user accounts, authenticate access, and improve service functionality.
Bentley commits to processing personal data only as instructed by the customer and to engaging subprocessors under strict requirements outlined in Section 5 of the DPA. The agreement requires both parties to comply with applicable data protection laws and regulations, including breach notification and supervisory authority oversight.
The DPA incorporates EU Standard Contractual Clauses and the UK International Data Transfer Agreement where necessary, ensuring compliance with cross-border data transfer rules. It remains in effect for the duration of the agreement and any extensions or renewals, with updates to reflect changes in data protection laws.