Security & Compliance

Data Protection and Compliance Framework

Who decides what in an agreement workflow, where data is processed, and how a deletion request is handled — the questions enterprise procurement teams ask, answered as a framework rather than a claim.

Data Controller, Platform Provider and Implementation Partner

The first step in any enterprise buyer's security review is clarifying roles. During the contracting process three distinct actors appear, each carrying a distinct set of responsibilities; the questions of who decides, who processes, and who can access what are answered within this frame.

  • The customer, as the contracting party, is the data controller and decides which data is processed, for what purpose, and for how long. Which fields are filled in, the list of signers, the retention period and the deletion conditions are all determined by the customer's own business process and applicable regulations.
  • Docusign provides the platform on which contract data is processed; through its eSignature and CLM products it operates the technical infrastructure for signing, archiving and audit trail. Access to contract content by users outside those defined in the customer's environment falls within the scope of access granted by the customer.
  • Netkur, as a Docusign partner, is the implementation partner delivering setup, integration, training and support services. Netkur has no purpose of its own for accessing contract content; during support it acts within the explicit authorisation and limited scope granted by the customer.
  • This distribution explains why audit trail records are kept on the platform and why a data request must first be directed at the customer. Each actor operates the controls within its own responsibility; this separation is the foundational security component of contract management.

Data Residency, Retention and Deletion Settings

The question buyers most often ask — 'where is my data stored' — is clarified at the start of the project. Geographic residency, retention period and deletion processes are configured according to the customer's own policy and regulatory requirements; this configuration becomes part of the contract.

  • Data residency: The region in which data will be held (e.g. Europe, North America, Asia-Pacific) is determined at the start of the project based on the customer's request. The choice of region appropriate to the customer's jurisdiction is settled during the enterprise approval process.
  • Retention period: Retention periods are configured according to the customer's own records management policy. Different retention periods can be defined for completed agreements versus cancelled or declined drafts; these periods are determined during implementation.
  • Deletion request: Deletion requests initiated by the customer are carried out in line with the policy defined on the platform. Retention periods applicable to data held in backups may extend from the moment of the request until the end of the backup cycle; this limit is documented explicitly in project materials.
  • Configuration records: Configuration decisions such as region selection, retention periods and deletion policy are reflected in the audit trail. These records are made available on the customer's request during audits or regulatory examinations.

Access Security, Authentication and Audit Trail

Who can access contract data and under which conditions is a decisive criterion for enterprise buyers. The platform allows access control to be integrated with the customer's enterprise identity infrastructure and ensures every access is reflected in the audit trail.

  • Enterprise identity integration: Enterprise users access the platform through the customer's Identity Provider (IdP) infrastructure (e.g. SAML-based SSO, OpenID Connect). This set-up allows the user lifecycle (provisioning, deprovisioning, role change) to be managed from a single source.
  • Multi-factor authentication (MFA): MFA can be made mandatory for sensitive operations (e.g. sending an agreement, bulk signing, permanent deletion). Conditional access (IP, device, location) policy is defined on the customer's IdP side.
  • Role-based access and authorisation matrix: Roles such as administrator, preparer, signer and observer are defined separately. The authorisation matrix at template, folder and user level is set up at the start of the project in line with the customer's policy.
  • Audit trail: Logins, document views, downloads, signatures, declines, cancellations and administrator actions are recorded with a timestamp. Audit trail records cannot be deleted; on request they can be exported for legal purposes.

Differences Between GDPR, POPIA and KVKK Frameworks

The European, South African and Turkish jurisdictions each have their own data protection framework. This section briefly explains what each framework is; it does not claim which one is 'applicable' nor that the platform achieves full alignment with any of them. The assessment is made by the buyer according to its own jurisdiction and use case.

  • GDPR (General Data Protection Regulation) — European Union: Applies to all organisations processing personal data within the EU's borders. The data controller carries obligations of explicit consent, purpose limitation, data minimisation and notification; breach notification must be made within 72 hours.
  • POPIA (Protection of Personal Information Act) — South Africa: Built on registration with the information regulator, notification, data minimisation and explicit consent. Cross-border data transfer requires evidence of an adequate level of protection.
  • KVKK (Kişisel Verilerin Korunması Kanunu) — Turkey: Applicable to data controllers established in Turkey and to foreign organisations processing data in Turkey. Explicit consent, VERBİS registration, personal data inventory and cross-border transfer rules are core obligations.
  • Where the frameworks intersect: All frameworks overlap around data minimisation, purpose limitation, retention limitation, data subject rights and breach notification. Differences mostly surface in thresholds, registration requirements and enforcement mechanisms.
  • Assessment: An organisation determines which framework applies based on its own jurisdiction, data flows and use case. The platform supports the technical controls (audit trail, region selection, access control, deletion) that the customer needs to meet its own compliance obligations; it does not guarantee compliance itself.

Questions for the Procurement and Legal Teams

The typical questions that procurement, legal and information security teams seek answers to before selecting a contract platform are compiled below. This list can be shared with stakeholders during the procurement process; the answers are tied to formal documentation at the start of the project.

  • Data processing agreement (DPA): What is the scope of the data processing agreement between the customer and the platform provider, the sub-processor list and the change mechanism? How do the notification and objection periods work when a new sub-processor is added?
  • Sub-processor list: Is it documented which sub-processors the platform uses, in which regions they are based and which data categories they access? How are changes to the list communicated?
  • Breach notification: In the event a data breach is detected, what is the notification period, scope and format? Once the customer is notified, is sufficient time allowed to fulfil formal notification obligations?
  • Retention and deletion: How is a request by the customer to permanently delete a specific agreement or the entire account carried out? What is the deletion cycle from backups and what are the limits of the delay within that cycle?
  • Audit trail evidence: In the event of a dispute or formal audit, is it contractually defined who can access audit trail records, in which format and within which period? How is the integrity of the records preserved?
  • Authorisation management: When the customer's enterprise IdP is disconnected, what is the state of accounts remaining on the platform, and how are administrative account access records and privileged access management audited?

Operating in Turkey as well? Local requirements — KEP, UETS and e-correspondence are documented in their own section.

Working through a security questionnaire?

We answer data processing, retention and audit-trail questions for your specific rollout, and share the vendor's current documentation on request.

Contact Us