This Schedule sets out the terms on which the Supplier processes personal data on behalf of the Customer and forms part of the agreement. It is intended to satisfy the requirements of Article 28 of the UK GDPR.
In this Schedule, the terms controller, processor, data subject, personal data, personal data breach, processing and appropriate technical and organisational measures have the meanings given to them in the Data Protection Laws.
Processing Instructions: the documented instructions of the Customer set out in this Schedule and as otherwise notified by the Customer to the Supplier in writing from time to time; and Sub-processor: any third party engaged by the Supplier to process personal data in connection with the Services.
The Parties acknowledge that, for the purposes of the Data Protection Laws, the Customer is the controller and the Supplier is the processor in respect of the personal data processed under this agreement. The nature and details of the processing are set out in Annex 1 (Details of Processing).
Each Party shall comply with its respective obligations under the Data Protection Laws. Nothing in this Schedule relieves either Party of its own direct responsibilities and liabilities under the Data Protection Laws.
The Supplier shall process the personal data only on and in accordance with the Customer's documented Processing Instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by applicable law; in which case, the Supplier shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Supplier shall immediately inform the Customer if, in its opinion, a Processing Instruction infringes the Data Protection Laws.
The Supplier shall ensure that any person authorised to process the personal data (including its staff and Sub-processors) is subject to a binding duty of confidentiality in respect of that personal data and processes it only on the Customer's instructions.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, the Supplier shall implement and maintain the appropriate technical and organisational measures set out in Annex 2 (Technical and Organisational Measures) to ensure a level of security appropriate to the risk, including as appropriate the measures referred to in Article 32 of the UK GDPR.
The Supplier shall not engage any Sub-processor without the prior specific or general written authorisation of the Customer. The Customer provides its general authorisation to the engagement of the Sub-processors listed in Annex 1. Where the Supplier intends to appoint a new Sub-processor or replace an existing one, it shall give the Customer prior written notice and a reasonable opportunity to object, and shall not appoint that Sub-processor if the Customer reasonably objects.
The Supplier shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those set out in this Schedule, and shall remain fully liable to the Customer for the performance of each Sub-processor's obligations.
The Supplier shall not transfer any personal data to a country outside the United Kingdom, or to an international organisation, without the Customer's prior written consent, and shall in any event ensure that any such transfer is effected by a transfer mechanism that complies with the Data Protection Laws (including the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any transfer risk assessment and supplementary measures required).
Taking into account the nature of the processing, the Supplier shall assist the Customer by appropriate technical and organisational measures, insofar as is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising the data subject's rights under the Data Protection Laws.
The Supplier shall assist the Customer in ensuring compliance with its obligations relating to security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner, taking into account the nature of the processing and the information available to the Supplier.
The Supplier shall notify the Customer without undue delay, and in any event within [●] hours, after becoming aware of a personal data breach affecting the personal data, and shall provide the Customer with sufficient information to allow the Customer to meet its obligations to report or inform data subjects and the Information Commissioner. The Supplier shall co-operate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the breach.
On termination or expiry of the agreement, and at the choice of the Customer, the Supplier shall return to the Customer or securely delete all the personal data and delete existing copies, save to the extent that applicable law requires the Supplier to retain that personal data. This paragraph operates in addition to, and is consistent with, clause 7.7 (Data on exit).
The Supplier shall make available to the Customer all information necessary to demonstrate compliance with the obligations set out in Article 28 of the UK GDPR and this Schedule, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. This paragraph operates in addition to the audit and information rights set out in clause 7.
The Customer provides its general authorisation to the engagement of the Sub-processors set out in the table below, in accordance with paragraph 6 (Sub-processing).
| Sub-processor | Location | Data processed |
|---|---|---|
Amazon Web Services | London, United Kingdom (eu-west-2) — UK/EEA data residency | Primary cloud hosting infrastructure: storage, compute, databases and encrypted backups for all Client Data. |
Datadog | European Union (EU1 region — Frankfurt, Germany) | Application performance monitoring, logging and infrastructure telemetry (may include technical and usage data and limited personal data contained in logs). |
Google Cloud | London / European Union (europe-west2) | Supplementary cloud infrastructure and managed data processing services. |
Google Workspace | European Union / United Kingdom | Business email, document storage and collaboration (may contain personal data within correspondence and files). |
Cloudflare | Global edge network (UK/EU points of presence) | Content delivery, DNS, DDoS mitigation and web application firewall; processes network traffic metadata and IP addresses in transit. |