The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.
There are no requirements to purchase services. No credit card needed to sign up, and once registered services may be purchased and activated at any time.
This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of the EU AI Act Article 22 Authorised Representative Service delivered by GDPRLocal through its affiliate, Instant EU GDPR Representative Ltd (the “Appointed Representative”), an entity established in the European Union and procured by GDPRLocal to deliver the authorised representative function under this Schedule. References in this Schedule to GDPRLocal include the Appointed Representative acting in its statutory capacity, except where the context otherwise requires. Terms used in this Schedule have the same meaning as in the Master Services Agreement or the Applicable Regulations.
In this Schedule: “AI Act” means Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence; “High-Risk AI System” means an AI system classified as high-risk under Article 6 and Annexes I and III of the AI Act; “Provider” has the meaning given in Article 3 of the AI Act; “Technical Documentation” means the technical documentation required under Article 11 and Annex IV of the AI Act; “EU Declaration of Conformity” means the declaration required under Article 47; “Conformity Assessment” means the applicable conformity assessment procedure under Article 43; and “competent authorities” includes the relevant market surveillance authorities, national competent authorities, and the AI Office.
Regulatory context. The parties acknowledge that the obligations of the AI Act, including the authorised representative obligation in Article 22, apply on a phased basis and that the obligations applicable to certain High-Risk AI Systems are not yet in force at the date of this Schedule. The Customer has elected to appoint the Appointed Representative on a voluntary, readiness basis in advance of the relevant application date. The Services are provided from the Service Start Date regardless of the application date of the underlying statutory obligation.
1.1 Service Lifecycle. The Service comprises three phases:
1.2 Appointment. With effect from the Active Appointment Date, the Customer, as Provider of the High-Risk AI System(s) identified in the Statement of Work, appoints the Appointed Representative to act as its authorised representative in the Union pursuant to Article 22 of the AI Act. This Schedule, together with its Statement of Work, constitutes the written mandate required under Article 22(1) of the AI Act. Onboarding activities under clause 1.1(a) commence from the Service Start Date. The appointment becomes contractually effective as Authorised Representative on successful completion of the Verification Phase, at which point the Core Obligations in clause 1.3 apply on an ongoing basis. The Appointed Representative accepts this appointment and agrees to perform the services in compliance with Article 22 of the AI Act. The mandate does not make the Appointed Representative the Provider of the High-Risk AI System, does not transfer any Provider obligation to the Appointed Representative, does not confer authority to make substantive decisions on the Customer’s behalf, and does not constitute legal representation in litigation or enforcement proceedings.
1.3 Core Obligations (Article 22(3) mandate). From the point at which GDPRLocal assumes the active role under clause 1.1(c), GDPRLocal shall (through the Appointed Representative), on the terms of the mandate:
1.4 Verification Report and Remediation. Where GDPRLocal identifies material conformity gaps or deficiencies during the Verification Phase, GDPRLocal will issue a Verification Report to the Customer detailing the findings and recommended remediation pathways. Consultancy, Project or other services required to support the Customer’s remediation are available under clause 1.9 (Additional and spin-off services), at the discounted Professional Services Rate set out in the Rate Card.
1.5 Point of contact. In accordance with Article 22(4) of the AI Act, the mandate empowers the competent authorities to address the Appointed Representative, in addition to or instead of the Provider, on all issues relating to ensuring compliance of the High-Risk AI System with the AI Act.
1.6 Mandatory termination and notification duty. The Customer acknowledges that, under Article 22(4) of the AI Act, the Appointed Representative is required to terminate the mandate if it considers or has reason to consider that the Provider is acting contrary to its obligations under the AI Act, and in that event to inform the relevant market surveillance authority, as well as the relevant notified body where applicable, of the termination and the reasons for it. This is a mandatory statutory duty. Its exercise in good faith by the Appointed Representative shall not constitute a breach of this Agreement, and the consequences of termination in clause 6.8 apply. The Customer accepts sole responsibility for any regulatory consequence arising from such a termination, including any resulting coverage gap.
1.7 Nature of Verification. Verification under this Schedule confirms that the EU Declaration of Conformity, the Technical Documentation, and any applicable Conformity Assessment have been drawn up and are, on their face, complete and organised in a form suitable for regulatory inspection, based on the documents and information provided by the Customer. Verification is not, and shall not be represented as, a substantive re-assessment, audit, certification, or warranty of the conformity, safety, or performance of the High-Risk AI System, which remain the sole responsibility of the Provider.
1.8 Ongoing regulatory guidance. As part of the active subscription, GDPRLocal shall provide reasonable ongoing regulatory updates and guidance in relation to the AI Act as it evolves, proportionate to the nature, scale and risk profile of the Customer’s AI activities. Ongoing regulatory guidance is advisory in nature and does not include substantive project work, drafting, or consultancy, which are available under clause 1.9.
1.9 Additional and spin-off services. Any services requested by the Customer that fall outside the Core Obligations in clause 1.3, including without limitation AI governance framework implementation, risk management frameworks, risk assessments, conformity assessment support, AI policies and procedures, internal governance documentation, employee training, management workshops, or ongoing AI Act advisory work beyond clause 1.8, fall outside this Schedule. Such services are available as Consultancy or Project services and are billed as Additional Services and Tasks in accordance with MSA §5.5, at the discounted Professional Services Rate set out in the Rate Card.
2.1 Service Delivery. GDPRLocal shall act on instructions from the Customer Contact identified in the Customer’s account profile, or any other person expressly authorised by the Customer in writing.
2.2 Verification hours allocation. The one-off Onboarding & Verification Fee includes an initial allocation of sixty (60) professional service hours for Documentation Verification, as set out in the Rate Card. Where verification requires additional hours because of the scale, complexity, jurisdictional scope, or compliance maturity of the Customer’s AI activities, additional hours are billed at the discounted Professional Services Rate set out in the Rate Card. Where material gaps are identified, remediation work is available under clause 1.9.
2.3 Reasoned requests and deadlines. Where GDPRLocal receives a reasoned request from a competent authority, or any communication requiring a response within a defined deadline, GDPRLocal shall notify the Customer Contact without undue delay and specify the response deadline. If the Customer fails to provide the necessary information, documentation, or instructions in time, GDPRLocal may (a) provide a holding acknowledgement to the authority, or (b) notify the authority that the matter is being forwarded to the Provider. The Customer acknowledges that GDPRLocal cannot be held responsible for missed deadlines caused by the Customer’s failure to provide timely information or instructions.
In addition to the obligations set out in MSA §6, the Customer shall:
3.1 provide GDPRLocal with such information, documents and cooperation as are reasonably necessary for the performance of the Services, including: accurate details of the Customer’s legal entity as Provider; identification and description of the High-Risk AI System(s) within scope and their intended purpose; the Technical Documentation; the EU Declaration of Conformity; where applicable, the notified body certificate and Conformity Assessment records; and access to the automatically generated logs to the extent under the Provider’s control;
3.2 during the Verification Phase, provide the Verification team with reasonable access, cooperation, and timely responses;
3.3 ensure that the Technical Documentation, the EU Declaration of Conformity, and all related documentation are, and remain throughout the term, complete, accurate, and up to date, and provide updated versions to GDPRLocal promptly following any change;
3.4 respond promptly to all communications forwarded by GDPRLocal and provide timely instructions, information and decisions necessary for the handling of such communications;
3.5 promptly notify GDPRLocal of: (a) any serious incident or malfunctioning of the High-Risk AI System; (b) any substantial modification to the High-Risk AI System, or change to its intended purpose, that affects its conformity or the scope of this appointment; (c) any communication received by the Customer from a competent authority, the AI Office, or a notified body; (d) any corrective action, withdrawal, or recall in respect of the High-Risk AI System; and (e) any litigation, enforcement, or regulatory proceeding relating to the High-Risk AI System;
3.6 carry out, as Provider, the registration obligations under Article 49 of the AI Act (with such support from GDPRLocal as is provided for under clause 1.3(e)), and ensure that the information referred to in Annex VIII is correct and kept up to date;
3.7 retain sole responsibility for the conformity, safety, and performance of the High-Risk AI System, and for the accuracy, completeness, and currency of the Technical Documentation, the EU Declaration of Conformity, the Conformity Assessment, and the logs; and
3.8 not take any action that would (a) expose GDPRLocal or the Appointed Representative to enforcement proceedings or regulatory sanctions other than as an unavoidable consequence of the authorised representative role; (b) require GDPRLocal or the Appointed Representative to make any inaccurate representation to a competent authority; or (c) cause GDPRLocal or the Appointed Representative to act in violation of Applicable Regulations.
4.1 Unless expressly agreed as an Additional Service, the Services shall not include the preparation of, or substantive advice on, the Technical Documentation, the EU Declaration of Conformity, or the Conformity Assessment, nor any act to make the High-Risk AI System compliant, nor the provision of legal advice or legal representation. Where such work is required, it may be requested under clause 1.9 or the Customer should seek independent legal counsel.
4.2 GDPRLocal and the Appointed Representative shall not assume management responsibility, operational control, or decision-making authority in respect of the High-Risk AI System, all of which remain with the Provider.
4.3 The Appointed Representative does not certify, warrant, or accept responsibility for the conformity, safety, performance, or outputs of the High-Risk AI System.
4.4 Any services outside the statutory Article 22 authorised representative role may be requested as billable Additional Services and Tasks in accordance with the Master Services Agreement and the Rate Card.
5.1 Acknowledgement of Liability Framework. The parties acknowledge:
5.2 Limitation of Liability (service-specific).
5.2.1 Subject to clause 5.5, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Customer in respect of the Service (excluding the documentation retention Exit Fee under clause 6.6 and the documentation export fee under clause 6.7) in the twelve (12) month period immediately preceding the event giving rise to the claim.
5.2.2 Neither party shall be liable for indirect, consequential, special, or punitive loss.
5.2.3 Without limiting clause 5.2.1, GDPRLocal and the Appointed Representative shall have no liability for, and the Customer retains sole responsibility for: any harm, injury, death, damage, or loss caused by or arising from the High-Risk AI System itself, its outputs, performance, or safety; any product liability, defect, or safety claim relating to the High-Risk AI System; any fine, penalty, or sanction imposed on the Customer; any loss arising from the Customer’s failure to comply with the AI Act or to provide accurate, complete, or timely Technical Documentation, EU Declaration of Conformity, logs, or instructions; any loss attributable to the Customer’s failure to notify a relevant event under clause 3; and any loss arising from GDPRLocal’s good-faith forwarding of communications, or good-faith exercise of the duty in clause 1.6, where the Customer failed to respond adequately.
5.3 Customer Indemnity. The Customer shall indemnify, defend, and hold harmless GDPRLocal, the Appointed Representative, and their respective affiliates, officers, employees, and agents (each an “Indemnified Person”) against all losses (including reasonable legal costs on a full indemnity basis) arising from: enforcement or regulatory proceedings relating to the High-Risk AI System; any third-party, product-liability, personal-injury, or safety claim arising from or connected with the High-Risk AI System; any national-law liability imposed on the authorised representative in respect of the Provider’s non-compliance; the Customer’s failure to meet its obligations under clause 3; the inaccuracy or incompleteness of the Technical Documentation, EU Declaration of Conformity, or logs; and the costs of responding to reasoned requests or proceedings on the Customer’s behalf.
5.4 Defence procedure. On notification of any potentially indemnifiable claim: GDPRLocal notifies the Customer promptly; the Customer assumes conduct of the defence at its cost (the Indemnified Person may participate at the Customer’s cost, and no settlement adverse to the Indemnified Person may be made without its consent); the Indemnified Person cooperates reasonably; and, failing assumption of the defence within 15 Business Days, GDPRLocal may take over conduct at the Customer’s cost.
5.5 Exclusions from Limitation. The liability cap in clause 5.2 does not apply to: the Customer’s indemnity obligations under clause 5.3; liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be limited by Applicable Regulations.
5.6 Professional Indemnity Insurance. GDPRLocal shall maintain throughout the term professional indemnity insurance in an amount no less than £1,000,000 per claim and in the aggregate per policy year. Evidence is available on reasonable written request.
6.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (the “Initial Term”) measured from the date on which GDPRLocal assumes the active role under clause 1.1(c), unless terminated earlier in accordance with this clause 6 or MSA §12. It auto-renews for successive twelve-month Renewal Terms unless notice of non-renewal is given at least ninety (90) days prior to the end of the then-current term.
6.2 Fees. The fees for the Service are set out in the Rate Card and comprise:
All fees are exclusive of VAT and any applicable taxes.
6.3 Termination for Convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule on not less than ninety (90) days’ prior written notice, exercisable only after expiry of the Initial Term. The 90-day notice reflects GDPRLocal’s legitimate interest in continuity and the Customer’s need to identify a replacement authorised representative to avoid violating Article 22 of the AI Act.
6.4 Mandatory statutory termination. GDPRLocal may terminate this Schedule with immediate effect where required to do so under Article 22(4) of the AI Act, as described in clause 1.6.
6.5 Additional Termination Right. GDPRLocal may additionally terminate with immediate effect if (a) the Customer provides materially inaccurate documentation such that performance would involve misrepresentation to a competent authority; or (b) the Customer’s instructions would require unlawful action or expose GDPRLocal or the Appointed Representative to disproportionate liability.
6.6 Documentation retention (10-year statutory obligation) and mandatory Exit Fee. The Customer acknowledges that the Appointed Representative’s obligation under clause 1.3(b) to keep the Technical Documentation, the EU Declaration of Conformity, the notified body certificate (where applicable), and the Provider contact details at the disposal of the competent authorities for ten (10) years after the High-Risk AI System was placed on the market or put into service is a mandatory statutory obligation that survives termination or expiry of this Schedule and continues for the full statutory retention period irrespective of whether the subscription remains active. Because this obligation is compulsory and survives non-payment of the subscription, an Exit Fee is payable on termination or expiry, as set out in the Rate Card. The Exit Fee is compulsory (not optional), non-refundable, and is charged as a single prepaid lump sum on termination or expiry. It funds secure, compliant storage of the retained documentation and on-demand access to competent authorities and the Customer during the retention period. GDPRLocal shall make the retained documentation available to competent authorities as required by the AI Act, and to the Customer on demand.
6.7 Optional documentation export. At any time until expiry of the ten-year retention period, the Customer may request that GDPRLocal package and deliver all retained Technical Documentation, the EU Declaration of Conformity, the notified body certificate (where applicable), service records, regulatory correspondence, and related compliance documentation to a newly appointed authorised representative or to the Customer, for the one-off fee set out in the Rate Card (the “Full Compliance Library Export”). Exercise of this option does not discharge the Customer’s obligation to appoint a replacement authorised representative where required by the AI Act, nor GDPRLocal’s own statutory retention obligation for the balance of the retention period unless and to the extent lawfully transferred to the incoming representative.
6.8 Consequences of Termination. Within five (5) Business Days of termination, GDPRLocal ceases holding out as the Customer’s authorised representative and, where required, notifies the relevant competent authority. Within fifteen (15) Business Days, GDPRLocal delivers a copy of the communications log and confirms the documentation held under clause 6.6. The Customer pays all outstanding fees and costs, including the mandatory Exit Fee under clause 6.6. Clauses 1.3(b), 1.6, 5, 6.6, 6.7 and this clause 6.8 survive termination.
6.9 Regulatory Notice. The Customer accepts sole responsibility for appointing a replacement authorised representative before or immediately upon termination to avoid violating Article 22 of the AI Act. GDPRLocal will cooperate as a courtesy with any replacement at its then-current standard rates.
This Statement of Work (“SOW”) is appended to and forms part of Service Schedule 10 (EU AI Act Article 22 Authorised Representative Service), which in turn forms part of the Master Services Agreement between the Customer and GDPRLocal Ltd. Capitalised terms have the same meaning as in the Schedule or the Agreement.
The SOW is generated and recorded by GDPRLocal at the point of Service activation. Placeholder fields (highlighted below) are populated from the Customer’s account and the Service Activation Record.
| Company Name | [Company Name] |
| Contact Name | [Contact Name] |
| Contact Email | [Contact Email] |
| Contact Number | [Contact Number] |
| High-Risk AI System(s) in scope | [name / description of each system] |
| Intended purpose | [intended purpose] |
| High-risk classification basis | [Annex III use case / Annex I product, and category] |
| Date placed on market / put into service | [date the High-Risk AI System was first placed on the EU market or put into service; enter ‘to be notified’ if not yet placed] |
| Territory | Europäische Union |
| Scope exclusions (if any) | [otherwise “none”] |
All fees for this Service are set out in the MSA Rate Card.
4. Designated Personnel and Documentation Storage
| Appointed Representative entity | Instant EU GDPR Representative Ltd |
| Registered address | Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland |
| contact@gdprlocal.com | |
| Tel | +44 1772 217 800 |
| Documentation storage | Secure, compliant storage maintained by GDPRLocal; access on demand to competent authorities and to the Customer |
The named individual at the Appointed Representative performing the authorised representative role from time to time will be communicated to the Customer following activation. GDPRLocal will notify the Customer of any permanent change to the designated contact within thirty (30) business days.
The Customer shall ensure that the following authorised representative details are provided to competent authorities and kept with the Technical Documentation as required by the AI Act, and included in any register or declaration where the authorised representative is required to be identified:
“EU AI Act authorised representative (Article 22, Regulation (EU) 2024/1689): Instant EU GDPR Representative Ltd, Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland. Contact: contact@gdprlocal.com, +44 1772 217 800.”
| Service | Included | Timeline |
|---|---|---|
| Appointment and mandate | Dedicated representative appointment and service onboarding. | One-off (Onboarding) |
| Scenario Mapping | High-level assessment of the organisation, AI systems, regulatory landscape, and compliance readiness to determine the scope, timeline, and approach for Verification | One-off (Onboarding) |
| Documentation Verification | Verify that the EU Declaration of Conformity and applicable Conformity Assessment have been prepared and that mandatory documentation is available and organised for regulatory inspection (Article 22(3)(a)) | Verification Phase, and on notified material change; provisioned on a first 60 professional service hours basis |
| Verification Report | Where deficiencies are identified, GDPRLocal issues a Verification Report to the Customer detailing the findings and recommended remediation pathways | End of Verification Phase |
| Activation of Authorised Representative appointment | Contractual effect of the appointment as Authorised Representative commences on successful completion of the Verification Phase | End of Verification Phase |
| Documentation retention | Keep the Provider contact details, EU Declaration of Conformity, Technical Documentation, and notified body certificate at the disposal of authorities for 10 years (Article 22(3)(b)) | Ongoing / 10 years |
| Regulatory point of contact | Receive reasoned requests and communications from competent authorities; forward to the Customer; coordinate responses (Article 22(3)(c) and (4)) | Ongoing (Active). Forwarding within 1–3 business days |
| Information and log access on request | Provide information and documentation to demonstrate conformity, including access to logs under the Provider’s control, on reasoned request (Article 22(3)(c)) | On reasoned request |
| Regulatory cooperation | Cooperate with competent authorities in actions relating to the High-Risk AI System, including risk-mitigation measures (Article 22(3)(d)) | As required |
| Registration support | Support the Customer’s compliance with (or, where undertaken by GDPRLocal, comply with) registration obligations under Article 49 and Annex VIII (Article 22(3)(e)) | As applicable |
| Ongoing regulatory updates and guidance | Reasonable ongoing regulatory updates and guidance on the AI Act as it evolves, proportionate to the Customer’s activities | Ongoing (Active) |
| Spin-off support | AI governance, risk management, risk assessments, conformity support, AI policies, training, and advisory services | On request. At the discounted Professional Services Rate (Rate Card) |
This SOW may be reviewed and updated by written agreement between the parties where required to reflect material changes to the High-Risk AI System(s), the Customer’s obligations, or compliance priorities. Any such update will be recorded as a revised SOW associated with the Customer’s account.
This SOW is deemed accepted by the Customer at the moment of Service activation (whether via in-portal activation or written confirmation accepted by GDPRLocal).