The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.
There are no requirements to purchase services. No credit card needed to sign up, and once registered services may be purchased and activated at any time.
This Schedule forms part of the Master Service Agreement (“Agreement”) between the Client and GDPRLocal Ltd. (the “Service Provider”). It sets out the scope of AI governance services to be delivered by the Service Provider. Terms used in this Schedule have the same meaning as in the Agreement.
1.1. Service provider duties. In accordance with the Agreement, Schedule and the Statement of Work (SoW), the Service Provider shall provide the services set out in Section 3 of this Schedule, including supporting the Client in the design, governance, maintenance, and continuous improvement of its AI Management System (“AIMS”) as described in the Statement of Work that forms a part of this Schedule.
1.3 Additional services. Any services requested by the Client that fall outside the scope of the AI governance described in the attached Scope of Work [SOW] shall constitute additional services which may be provided only pursuant to a separate agreement.
2.1 Service delivery. The Service Provider shall deliver the Services described in the SOW in accordance with the scope set out herein and at intervals agreed between the Client’s representative and Service Provider compliance executive taking into account the nature, scope, context and risk profile of the Client’s AI governance posture.
2.2 Advice and reporting. The Service Provider shall provide advice, recommendations and reports within specified timeframes agreed between the Parties in the SOW, taking into account the complexity and urgency of the matter. The form, frequency and timing of any reports, meetings or other deliverables shall be as set out in the applicable SOW.
3.1 Core pillars. The Service Provider shall provide the Client with high-level support and guidance in the design, governance, maintenance, and continuous improvement of its AIMS across the following core pillars:
3.2 Access to Service Provider Resources. In addition to the monthly provided services, the Client shall have ongoing access to the Service Provider’s portal and documentation produced as part of this Agreement.
4. Client Responsibilities
4.1 Operational Duties. In addition to the responsibilities set out in the Agreement, the Client shall:
a) designate a primary contact person responsible for coordinating with the Service Provider in relation to the Services;
b) ensure timely access to relevant stakeholders, including representatives from Data & Engineering, IT, Legal, Risk Management, HR, and any other relevant departments, as reasonably required for the performance of the Services;
c) determine or confirm, on a monthly basis, the priorities and focus areas for the Services;
d) provide, in a timely manner, all inputs, information, instructions, approvals, access, and other cooperation reasonably required for the Service Provider to perform the Services.
4.2 Acknowledgements. The Client acknowledges and agrees that:
a) the Service Provider provides oversight, framework design, and advisory services only, and does not assume any operational, managerial, or decision-making role within the Client’s organisation;
b) the Service Provider does not act as an AI Risk Owner or AI Incident Owner. Ultimate accountability for the identification, assessment, acceptance, mitigation, and reporting of AI-related risks and incidents remains solely with the Client;
c) the Services constitute governance and compliance consulting and do not amount to formal legal advice or legal opinions. The Client is responsible for obtaining independent legal review of all policies, procedures, and documentation prior to adoption or implementation;
d) services defined in this Agreement do not include advice and guidance related to technical implementation or product development activities, including without limitation writing code, conducting software testing, security testing, building or training models, engineering system architectures, or acting as developers, engineers, or data scientists;
e) in the event of Client inactivity, delay, or failure to provide required information or inputs, including monthly priorities (Art. 4.1 (c) and (d)) or responses to reasonable requests or calls to action, the Service Provider may determine the scope, prioritisation, and sequencing of the Services to be performed during the relevant monthly service period, using the monthly hours and service capacity allocated under this Agreement and acting in accordance with its reasonable professional judgment. Any Services performed by the Service Provider in such circumstances shall be deemed duly performed and delivered for that monthly service period, and the fees for that period shall remain due in full and non-refundable. The Client shall have no right to any refund, credit, set-off, re-performance, or other fee adjustment arising from such inactivity, delay, or failure to cooperate. The Service Provider shall not be liable for any resulting delay, gap, deficiency, or reduced effectiveness to the extent caused by the Client’s failure to provide the required cooperation.
5.1 Initial Term. This Schedule shall commence on the date of execution of the Agreement and shall remain in force for an initial term of twelve (12) months, unless terminated earlier in accordance with this Schedule or the Agreement.
5.2 Renewal. Unless otherwise agreed in writing, this Schedule shall automatically renew for successive periods of twelve (12) months under the same terms and conditions.
6.1 Notice. Either Party may terminate this Schedule for convenience by providing at least thirty (30) days’ prior written notice to the other Party by email, such notice to be effective prior to the start of the next billing cycle.
6.2 Post termination. Upon termination, and subject to payment of all outstanding fees, the Service Provider shall provide the Client with a final export of the AI Tracker.
7.1 Conflict Resolution. In the event of any conflict or inconsistency between the provisions of this Schedule and the Agreement, the provisions of this Schedule shall prevail.
7.2 Execution of this Schedule. This Schedule is incorporated into and forms an integral part of the Agreement entered into between the Client and the Service Provider. This Schedule shall be deemed executed upon execution of the Agreement and shall commence on the same effective date as the Agreement.
This Statement of Work (“SoW”) is appended to and forms part of the Schedule – AI Governance Services, which in turn forms part of the Master Service Agreement (“Agreement”) between [Client] (the “Client”) and GDPRLocal Ltd. (the “Service Provider”). Capitalised terms have the same meaning as in the Schedule or the Agreement.
Effective Date: [date]
| Company name: | |
| Address: | |
| Point of contact: | |
| Role: | |
| DPO name: | Adam Brogden, GDPRLocal |
| Address: | 1st Floor Front Suite, 27–29 North Street, Brighton, England BN1 1EB |
| Email: | dpo.support@gdprlocal.com |
| Tel: | +44 1772 217 800 |
Parties shall notify each other within [30] business days in advance of any permanent change to designated personnel.
The table below outlines the range of AI Governance Services that may be provided under this SoW based on deliverables agreed at monthly meetings and confirmed in monthly plans.
| AIMS Service Area | Deliverables |
| AI Governance and Accountability | AI Policy AI Governance Policy AIMS Scope Policy Roles and Responsibilities Matrix AI Support and Operations Policy AI Resources Process Privacy Policy Alignment to AIMS T&C Alignment to AIMS Business Continuity Plan Alignment to AIMS Register of Legal and Regulatory Requirements Alignment to AIMS |
| AI Risk Management | AI Risk RegisterAI Risk Management policyAI Impact Assessment process AI Risk Assessment MethodologyAI Risk Assessment template (NIST)AI Risk Treatment AI Risk Treatment PlanAI Impact Assessment Methodology AI Impact Assessment template (Microsoft)AI Impact Assessment ReportAI Tool Approval ProcessAI Tool Risk Assessment AI Tool Register AI Incident Response Plan AI Incident Response Checklist AI Incident Register AI Incident Classification Scheme |
| Ethics and Transparency | AI Model Card (external)AI Model Operational Use Policy (Internal) AI Use Policy (external) AI Acceptable Use Policy (internal) AI Literacy Process with Supporting Forms AI Training Plan AI Literacy Employee Handbook *Targeted research on AI regulatory developments and applicable laws, and advising the Client on updates to the AIMS required to maintain alignment with evolving requirements is outside the scope of these Services and shall be treated as an Additional Service. |
| Continuous Monitoring and Improvement | AI Improvement Policy AI TrackerAI Performance EvaluationAI Corrective Action Form Post market AI System monitoring planInternal Audit Process with supporting forms (Internal audit program, Internal Audit Report and Internal Audit Checklist) |
This SoW may be reviewed and updated by written agreement between the Parties where required to reflect material changes to the Client’s AIMS, service requirements, or compliance priorities.
Agreed and executed by the authorised representatives of the Parties:
For and on behalf of [CLIENT FULL LEGAL NAME] (Client)
______________
For and on behalf of GDPRLocal Ltd. (Service Provider)
______________