LICENSEWARE

ADP client agreements and the Data Privacy Appendix

This article is about the contract documents that ADP publishes around its client agreement: the Client Contract Portal, the Data Privacy Appendix, the Marketplace Terms of Service and the adp.com web site terms. It does not reproduce a client's own master services agreement, which is not public. It is not legal advice.

On This Page

ADP client agreements are the written contracts under which ADP provides payroll, HR and related services to employers. They are not published. What ADP publishes around them is a short list of documents on the ADP Client Contract Portal, a set of terms for its Marketplace and application listings, and the terms for its web sites. This article explains how those documents are meant to fit together and what each says that matters to a licence manager.

Contract framework

The Client Contract Portal opens with a rule of applicability: “The documents published on this website apply to you only if you have a written agreement with ADP that specifically references them.”[1] It adds a rule about versions. ADP may update the documents, but unless an update adds commitments to the client or is required by law, “the documents applicable to you will be those that are published as of the effective date of your agreement with ADP.”[1] See ADP contract documents apply only if the client's agreement references them and Portal version in force is the one published at the agreement's effective date.

At the time of retrieval the portal listed only the Data Privacy Appendix, in English and French, with its prior versions. The versions are dated by their file names: version 4 of 2026-06-10, version 3 effective 2026-02-15 to 2026-06-09, version 2 effective 2025-10-15 to 2026-02-14 and version 1 effective 2025-02-28 to 2025-10-14.[1] On the portal’s own wording, a client whose agreement took effect before 2026-06-10 would be under the version published at that date, unless a later version adds ADP commitments or is required by law. A licence manager should record the agreement’s effective date and the version identifier printed on each page of the appendix.

Other ADP documents live elsewhere. Product-specific terms such as the Vantage HCM online terms and the Workforce Manager additional terms are hosted on adp.com and are described in the Vantage HCM and Workforce Manager article. Application terms for Marketplace listings are described in the Marketplace and API Central article.

Data Privacy Appendix

The Data Privacy Appendix “is a data processing agreement under Applicable Law and supplements the Agreement between ADP and Client.”[2] The version retrieved is identified as ADP-DPA-V4-20260610. Its structure is Part I (general), Part II (GDPR and UK GDPR), Part III (miscellaneous) and Schedule 1 (subprocessors).

Roles and use of data

The client may provide only data that is required to perform the services, was collected in accordance with applicable law and that the client has authority to provide.[2] ADP acts as a data processor for the limited purposes in the agreement and “will not: (a) ‘sell’ or ‘share’ Client Personal Data.”[2] See ADP acts as data processor and will not sell or share client personal data. ADP may also process data to meet its legal obligations, for example sanctions compliance, and to prevent or investigate fraud.[2] The appendix separately allows ADP to use aggregated or anonymized data under the agreement but promises not to re-identify anonymized data.[2]

Client audit of ADP

The audit clause is the one in the appendix most likely to be tested. ADP answers the client’s questions and provides its trust package of security materials. Where applicable law requires it and the client reasonably considers the documents insufficient, the client may have a qualified independent third-party assessor audit the facilities ADP uses. Audits are limited to once per year during regular business hours, need written notice at least 45 days ahead and an ADP-approved audit plan, take place in the presence of an ADP representative, and may not disrupt processing or compromise other clients’ data. The appendix states that “ADP will charge Client a reasonable fee for such audit.”[2] See Client audit of ADP data processing is limited to once a year with 45 days notice and a fee.

Assistance and fees

ADP assists with individual rights requests, complaints and impact assessments, including transfer impact assessments, but “reserves the right to charge for such assistance rendered.”[2] See ADP may charge for assisting with the client's privacy obligations. A client that expects frequent employee data requests should check whether its agreement fixes a rate.

Subprocessors and transfers

Schedule 1 lists subprocessor information by region and service category rather than naming each subprocessor in the document. For the United States it groups Payroll Services, Enterprise HR, Lyric HCM, Payforce, Vantage HCM and Workforce Now with links by account type, and separate rows for Compliance Services, HRO Services and other lines.[2] For data under the GDPR or UK GDPR, a client may object to a new subprocessor within 30 days of written notice, on objective justifiable grounds. If the parties cannot agree, ADP either keeps the subprocessor away from the data or lets the client terminate the relevant services under the agreement.[2] See Clients may object to a new subprocessor within 30 days. International transfers rely on ADP’s Binding Corporate Rules, called the ADP Privacy Codes, or on other lawful mechanisms such as standard contractual clauses.[2]

Return, deletion and precedence

On termination ADP complies with its contractual return obligations unless the data is already returned or can be downloaded through the product, and deletes client personal data “in accordance with ADP’s then current applicable records retention schedule,” with archive copies allowed where law, written client authorization or dispute resolution requires.[2] See Client personal data is deleted under ADP's records retention schedule. In a conflict the appendix sets the order: applicable law, the ADP Privacy Codes, the appendix, then the agreement.[2] See Data Privacy Appendix ranks above the agreement in a conflict. The appendix also states that it gives client employees no rights beyond those they already have under applicable law.[2]

Marketplace Terms of Service

Clients that buy applications through ADP Marketplace accept a separate set of terms. They grant permission to use the Marketplace solely for internal business purposes to browse, buy, log into and manage subscriptions and create user accounts for the client’s personnel.[3] For an application provided by ADP, the terms grant “a non-exclusive, non-transferable license, during the term set out on your Order, solely for Your internal business purposes.”[3] See ADP Application licence is for the client's internal business purposes.

Several clauses affect licence management directly.

A shorter text shown on marketplace.adp.com says the app terms “amend any Master Services Agreement or other similar agreement between You and ADP governing your receipt of ADP services,” and that ADP, not its platform provider AppDirect, supports the application.[4]

Web site terms

The adp.com terms of use apply to access to ADP’s web sites. They bar scraping above human-like request rates and harvesting of personal data, and they define an Unauthorized Third Party as any business that accesses ADP sites using a client’s or employee’s credentials, naming data scrapers and data aggregators. ADP may suspend a client site without notice if unauthorized use is suspected.[5] See ADP web sites prohibit use of client credentials by unauthorized third parties. The terms are governed by New Jersey law and New Jersey or federal courts sitting in New Jersey.[5] See ADP web site terms are governed by New Jersey law.

Out of scope

This article does not reproduce ADP’s master services agreement, order forms, fee schedules, service level terms or termination provisions, none of which was available. It does not cover ADP’s Binding Corporate Rules in detail, nor the subprocessor lists behind the links in Schedule 1, which are provided only for applicable solutions.[2] Documents on adp.com were read through a web browser.

References

  1. ADP Client Contract PortalStates when published ADP contract documents apply to a client. Undated.Retrieved 2026-10-08.
  2. ADP Data Privacy Appendix (ADP-DPA-V4-20260610)Part I general; Part II GDPR/UK GDPR; Part III miscellaneous; Schedule 1 subprocessors. Version dated 2026-06-10 by its identifier.Effective 2026-06-10. Retrieved 2026-10-08.
  3. ADP Marketplace Terms of ServiceTerms between ADP and a Marketplace client. Undated.Retrieved 2026-10-08.
  4. ADP Marketplace app Terms and ConditionsShort terms amending the client's master services agreement. Footer 2020; undated.Retrieved 2026-10-08.
  5. ADP Terms and Conditions (adp.com Legal)Terms of use for ADP web sites. Undated; footer 2026.Retrieved 2026-10-08.

See also

Catalog Rows Cited

21Rules

Esc