Skip to main content
Required by EU law for organizations with 50+ employees

DORA contracting template #

Template date: September 6, 2026

This page is a procurement template, not a binding addendum, compliance certification, legal opinion, or representation that EthicsPortal is suitable for a particular regulated function. Publication, a subscription, acceptance of the Data Processing Agreement , or a customer’s unilateral classification of the Service does not incorporate this template into any agreement.

A DORA addendum becomes binding only when the Financial Entity and EthicsPortal sign a written DORA order that:

  1. identifies both parties and their authorized representatives;
  2. identifies the covered Service, start date, term and countries of provision and processing;
  3. records the Financial Entity’s DORA status and the parties’ agreed treatment of the Service, including whether it supports a critical or important function (“CIF”);
  4. attaches or identifies fixed versions of the Terms, DPA, SLA, service description, security measures and ICT service supply chain;
  5. specifies notice periods, quantitative service levels, transition period, included assistance and all pre-agreed rates; and
  6. is signed by both parties.

The complete signed order and its schedules form one downloadable and durable contractual record. Public website pages are procurement information only and are not incorporated unless the signed order identifies a dated version or attaches a snapshot.

To request a scoped and countersigned DORA order, contact legal@ethicsportal.eu .

The provider-side evidence available for due diligence and the register of information is published in the DORA ICT third-party map .


1. Parties and definitions #

Provider: EthicsPortal, a trade name used by Yaroslav Shmarov, a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland (NIP: 5272755790), at ul. Obrzeżna 1A, 02-691 Warsaw, Poland.

Financial Entity: The customer identified in the signed DORA order.

Service: The EthicsPortal reporting channel components specifically identified in the signed DORA order.

CIF Service: The Service only where the signed DORA order records the parties’ agreed treatment of it as supporting a critical or important function. A notice or classification made by the Financial Entity alone does not expand the Provider’s contractual obligations.

Terms defined in Regulation (EU) 2022/2554 (“DORA”) carry their DORA meanings. An ICT subcontractor is a third party to which the Provider subcontracts all or part of an ICT service supporting the Service. A Material ICT Subcontractor is an ICT subcontractor whose failure could materially impair a CIF Service.

2. Contract documents and precedence #

The signed DORA order must list every incorporated document by title, date or version and, where available, digest. It prevails over the Terms, DPA and SLA only to the extent of an express conflict concerning DORA. No marketing page, trust page, incident page, policy, roadmap, questionnaire answer or later website change amends the contract unless both parties agree in writing.

Unless the signed DORA order expressly states otherwise, all claims arising from the order, this addendum, the Terms, DPA, SLA and Service are subject collectively to the single aggregate liability cap in the Terms. Nothing limits liability that cannot lawfully be limited.

3. Scope, locations and subcontracting #

The signed DORA order must describe the covered functions and services, processing and provision locations, permitted subcontracting, applicable data categories, and the division of responsibilities. The current provider-side baseline is available in the DORA map , but it must be verified and fixed in the signed order before reliance.

The Provider gives the change notice specified in the signed order before changing a covered country, region, direct ICT subcontractor or Material ICT Subcontractor. For a CIF Service, the order must also identify the material service chain and the applicable conditions required by Delegated Regulation (EU) 2025/532, including:

The Provider does not represent an unverified downstream provider, certification or contractual right as equivalent compliance. If a required downstream right is unavailable, that gap must be recorded before the order is signed.

4. Data, security and service levels #

The DPA governs processing of personal data. The signed DORA order must attach or identify the applicable security schedule and SLA, including:

Targets published on the website are the current standard offering, not a warranty for a DORA engagement unless the signed order incorporates them.

5. Data access, recovery, return and deletion #

Standard in-product exports and the return or deletion rights in the DPA remain available on their stated terms. The signed DORA order must specify any additional machine-readable export, recovery assistance, delivery deadline and format required for termination, insolvency, resolution or discontinuation.

The Provider will use the contingency arrangements identified in the signed order to preserve access and return data in those events. Performance remains subject to applicable law, technical feasibility, security requirements and the availability of systems and subcontractors outside the Provider’s control. This clause does not promise continued operation after the Provider has lost the legal or technical ability to perform; the signed order must record the relevant continuity limitations and customer-side contingency measures.

6. ICT incidents and assistance charges #

The Provider’s required incident notifications under the DPA and delivery of information already produced in the ordinary incident response are included in the subscription fee.

Additional DORA assistance—such as customer-specific classification, regulatory forms, meetings, bespoke evidence, extended root-cause analysis or support for authority submissions—is provided only to the extent stated in the signed DORA order. The order must set an hourly rate, included hours (if any), authorization process and expense treatment before service begins. No rate left blank or described as “to be agreed” satisfies this template.

7. Cooperation, audits and authorities #

The Provider will cooperate with the Financial Entity’s competent and resolution authorities to the extent required by DORA and the signed order. Authority access is not made conditional on routine customer-audit notice periods.

For customer and mandated-auditor reviews, the signed order must specify the scope, procedure, frequency, confidentiality safeguards, remote-first process, included assistance and pre-agreed rate for additional Provider time. Audits must relate to the covered Service and protect other customers’ data and security. These logistical and cost provisions must not impede the effective exercise of a competent authority’s rights or the unrestricted access, inspection, audit and copying rights required for a CIF Service.

The Provider operates no office or data centre of its own. Its direct audit surface is the application and the documentation under its control. Supplier premises, reports and certifications are available only to the extent of the Provider’s verified contractual rights and the supplier’s applicable terms.

8. Training and threat-led penetration testing #

Participation in the Financial Entity’s security-awareness or digital-operational-resilience training is subject to the remote format, frequency, included hours and pre-agreed rate stated in the signed DORA order.

Where a competent authority scopes the Service into threat-led penetration testing, participation requires a separate written statement of work covering scope, rules of engagement, test environment, safety, confidentiality, responsibility for third-party effects, remediation and costs. The Financial Entity bears the testing provider’s fees and the Provider’s time is charged at the rate fixed in the signed DORA order unless that order includes specified hours.

Testing may not endanger other customers or production data. Where DORA permits, the parties may use pooled testing or an equivalent environment.

9. Termination #

Ordinary cancellation remains governed by the Terms and the subscription order. The DORA order does not create an additional right to terminate at any time for any reason.

The signed DORA order must state its minimum notice periods and the Financial Entity’s termination rights for the circumstances required by DORA, including material legal or contractual breach, material changes affecting performance, evidenced weaknesses in ICT risk management, supervisory impediment, and non-compliant material subcontracting changes. Immediate suspension or shorter notice remains available where required by law or reasonably necessary to address non-payment, fraud, misuse or a security threat.

10. Exit and transition for a CIF Service #

For a CIF Service, the signed DORA order must set an adequate transition period based on the covered function and exit plan. During that period:

The order must define extension, early termination and deletion instructions. It must not assume that the Provider can continue full service after insolvency, resolution, legal prohibition or technical incapacity.

11. Customer responsibilities and no compliance warranty #

The Financial Entity remains responsible for determining DORA applicability, classifying its functions, conducting due diligence and concentration-risk assessment, maintaining its register of information, testing its exit strategy, providing accurate instructions and obtaining any necessary regulatory approval.

The Financial Entity must promptly provide the information and access reasonably needed for performance, mitigate avoidable loss, maintain appropriate internal controls, and use exports and contingency measures available to it.

The Provider supplies information and contractual commitments about the Service. It does not warrant that the Financial Entity’s use of the Service, this template, or any signed order by itself ensures the Financial Entity’s compliance with DORA or any other law.

12. Governing law and language #

The signed DORA order is governed by Polish law and the forum stated in the Terms, without prejudice to powers that applicable law gives competent, resolution or oversight authorities.

This template is drafted in English. Any translation is for convenience; the English text controls unless a signed DORA order expressly states otherwise.


Contact #

Contracts: legal@ethicsportal.eu Security and incidents: security@ethicsportal.eu Commercial matters: support@ethicsportal.eu

Last updated: