Every agreement type the register recognises
40 types in 6 families. Each page says what the agreement normally carries, what each customer's regimes expect of it, and quotes the clauses.
Master and framework agreements
7 typesThe umbrella the other documents hang from: the master agreement, the customer's own purchasing terms, the public framework and the call-off under it. The processing terms, the security schedule, the audit right, the breach clock and the cap usually live here or in a schedule to it.
Subscription, licence and SaaS
7 typesWhat the customer uses: the SaaS subscription, the order form under it, the on-premises licence, the API terms, support and hosting. Each is an ICT service when the customer is a financial entity, and each carries the customer's data somewhere.
Services, SOWs, outsourcing and managed services
8 typesWhat the supplier does for the customer: statements of work, professional services, outsourcing, managed services, implementation, service levels, resourcing and exit. Outsourcing and managed services are where the regimes expect the most.
Data agreements
8 typesThe documents that exist because of the data: the DPA, the BAA, data sharing and data licences, transfer clauses, the CCPA service provider terms and the security schedule. On a customer's other lines, one of these counts as shown.
Confidentiality and pre-contract
5 typesWhat comes before the contract: the NDA, the letter of intent, the memorandum of understanding, the pilot and the tender terms. Most carry no processing and no clock; a pilot that touches real data is the exception the register looks for.
Channel and partner
5 typesHow the product reaches customers through others: resale, referral and alliance, OEM and white label, marketplace listings and distribution. The regimes read these lightly unless the partner handles the end customer's data.