The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.
There are no requirements to purchase services. No credit card needed to sign up, and once registered services may be purchased and activated at any time.
This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of Article 27 UK Representative services to be delivered by GDPRLocal (the “Appointed Representative”). Terms used in this Schedule have the same meaning as in the Master Services Agreement or the Applicable Regulations.
1. Scope of Services
1.1 Designation. With effect from the Service Start Date, the Customer appoints the Appointed Representative to act as its representative in the United Kingdom pursuant to Article 27 of the Applicable Regulations. This Schedule constitutes the written mandate required under Article 27(1) UK GDPR. The Appointed Representative accepts this appointment and agrees to perform the Representative services described in this Schedule in compliance with Article 27 of the Applicable Regulations. The mandate does not confer authority to make substantive decisions on behalf of the Customer regarding processing activities, to bind the Customer to any compliance undertaking, or to act as legal representative in litigation or enforcement proceedings.
1.2 Article 27 Representative duties. In accordance with Article 27 of the Applicable Regulations, GDPRLocal shall (through the Appointed Representative):
2. Service Levels and Deliverables
2.1 Service Delivery. GDPRLocal shall act on instructions from the Customer Contact identified in the Customer’s account profile, or any other person expressly authorised by the Customer in writing.
2.2 Advice and reporting. Where GDPRLocal receives a communication from a Supervisory Authority or Data Subject requiring a response within a defined deadline, GDPRLocal shall notify the Customer Contact immediately and specify the response deadline. If the Customer fails to provide instructions in time, GDPRLocal may either (a) respond with a holding acknowledgement, or (b) notify the Supervisory Authority or Data Subject that the matter is being forwarded to the Customer. The Customer acknowledges that GDPRLocal cannot be held responsible for missed deadlines caused by the Customer’s failure to provide timely instructions.
3. Customer Obligations
In addition to the obligations set out in MSA §6, the Customer shall:
3.1 provide GDPRLocal with such information, documents and cooperation as are reasonably necessary for the performance of the Services, including: accurate details of the Customer’s legal entity or entities covered by the appointment; details of the processing activities within the scope of the relevant appointment; and a copy of the Records of Processing Activities;
3.2 respond promptly to all communications forwarded by GDPRLocal and provide timely instructions, information and decisions necessary for the handling of such communications;
3.3 promptly notify GDPRLocal of: (a) any suspected or actual data breach; (b) any change to the Customer’s processing activities that materially affects the scope or nature of the representative appointment; (c) any direct communication received by the Customer from a Supervisory Authority; (d) any litigation or regulatory proceeding initiated against the Customer relating to its processing of personal data of data subjects in the United Kingdom; and (e) any data subject request relating to rights under the UK GDPR;
3.4 publish the UK Representative contact details and communicate them to the Supervisory Authority as required by the UK GDPR, using the contact details for the Appointed Representative set out in the Appendix to this Schedule, and ensure that those contact details are accurately reflected in all of the Customer’s privacy notices, website privacy policies, and communications to data subjects as required by Articles 13 and 14 UK GDPR;
3.5 retain sole responsibility for the accuracy, completeness, and currency of the ROPA. The Appointed Representative’s obligation under Article 30(4) UK GDPR is contingent upon the Customer providing an accurate ROPA;
3.6 not take any action that would (a) expose GDPRLocal or the Appointed Representative to enforcement proceedings or regulatory sanctions other than as an unavoidable consequence of the Appointed Representative’s role; (b) require GDPRLocal or the Appointed Representative to make any inaccurate representation to a Supervisory Authority; or (c) cause GDPRLocal or the Appointed Representative to act in violation of Applicable Regulations.
4. Services Outside the Scope
4.1 Unless expressly agreed at activation, the Services shall not include substantive GDPR compliance advice or services (which are covered under separate Service Schedules if applicable) or the provision of legal advice or legal representation. Where legal advice is required, the Customer should seek independent legal counsel.
4.2 GDPRLocal and the Appointed Representative shall not assume management responsibility or operational decision-making authority.
4.3 The Appointed Representative’s role in relation to data subject rights requests is advisory and supervisory; operational handling of DSARs remains the Customer’s sole responsibility.
4.4 Any services outside the statutory Article 27 representative role may be requested as billable additional services and Tasks in accordance with the Master Services Agreement.
5. Liability and Indemnity (Service-specific supplement to MSA §10 / §11)
5.1 Acknowledgement of Liability Framework. The parties acknowledge:
5.2 Limitation of Liability (service-specific).
5.2.1 Subject to clause 5.5, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Customer in respect of the Article 27 UK Representative Service in the twelve (12) month period immediately preceding the event giving rise to the claim.
5.2.2 Neither party shall be liable for indirect, consequential, special, or punitive loss.
5.2.3 GDPRLocal and the Appointed Representative shall have no liability for: GDPR fines or sanctions imposed on the Customer; loss arising from the Customer’s failure to comply with Applicable Regulations or provide accurate/timely ROPA or instructions; consequence of failure to update privacy notices with correct contact details; loss attributable to the Customer’s failure to notify of a relevant event per clause 3; loss arising from GDPRLocal’s good-faith forwarding of communications where the Customer failed to respond adequately.
5.3 Customer Indemnity. The Customer shall indemnify, defend, and hold harmless GDPRLocal, the Appointed Representative, and their respective affiliates, officers, employees, and agents (each an “Indemnified Person”) against losses (including reasonable legal costs on a full indemnity basis) arising from: enforcement proceedings; Data Subject claims relating to the Customer’s processing; Customer’s failure to meet clause 3 obligations; failure to provide an accurate ROPA; and costs of responding to Enforcement Proceedings or Supervisory Authority inquiries on the Customer’s behalf.
5.4 Defence procedure. On notification of any potentially indemnifiable claim: GDPRLocal notifies the Customer promptly; the Customer assumes conduct of defence at its cost (Indemnified Person may participate at Customer’s cost; no settlement adverse to the Indemnified Person without consent); the Indemnified Person cooperates reasonably; failing assumption within 15 Business Days, GDPRLocal may take over conduct at the Customer’s cost.
5.5 Exclusions from Limitation. The liability cap in clause 5.2 does not apply to: the Customer’s indemnity obligations under clause 5.3; liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; any other liability that cannot be limited by Applicable Regulations.
5.6 Professional Indemnity Insurance. GDPRLocal shall maintain throughout the term professional indemnity insurance in an amount no less than £1,000,000 per claim and in the aggregate per policy year. Evidence available on reasonable written request.
6. Term and Termination (Service-specific)
6.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (“Initial Term”), unless terminated earlier in accordance with this clause 6 or MSA §12. It auto-renews for successive twelve-month Renewal Terms unless notice of non-renewal is given at least ninety (90) days prior to the end of the then-current term.
6.2 Termination for Convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule on not less than ninety (90) days’ prior written notice, exercisable only after expiry of the Initial Term. The 90-day notice reflects GDPRLocal’s legitimate interest in continuity and the Customer’s need to identify a replacement Article 27 representative to avoid violating Article 27 UK GDPR.
6.3 Additional Termination Right. GDPRLocal may additionally terminate with immediate effect if (a) the Customer provides materially inaccurate ROPA information such that performance would involve misrepresentation to Supervisory Authorities; or (b) the Customer’s instructions would require unlawful action or expose GDPRLocal or the Appointed Representative to disproportionate liability.
6.4 Right of Resignation in Enforcement Situations. Market standard practice for Article 27 representatives establishes a specific right of resignation where the Customer stops cooperating during Enforcement Proceedings. GDPRLocal may resign with immediate effect if:
Immediate resignation in such circumstances shall not constitute a breach. The Customer accepts sole responsibility for any regulatory consequence of a coverage gap.
6.5 Consequences of Termination. Within 5 Business Days: GDPRLocal ceases holding out as the Customer’s representative and notifies relevant Supervisory Authorities where required by national law; the Customer updates all privacy notices to remove the Appointed Representative’s details. Within 15 Business Days: GDPRLocal delivers a copy of the ROPA + communications log. Any pending Enforcement Proceedings handled per transitional arrangements (or, failing those within 10 Business Days, GDPRLocal may notify the relevant Supervisory Authority of termination and direct it to the Customer). Customer pays outstanding fees and costs. Clauses 5 and 6.5 survive termination.
6.6 Regulatory Notice. The Customer accepts sole responsibility for appointing a replacement Article 27 representative before or immediately upon termination to avoid violating Article 27 UK GDPR. GDPRLocal will cooperate as a courtesy with any replacement at its then-current standard rates.
__________________________________________________
This Statement of Work (“SOW”) is appended to and forms part of this Schedule, which in turn forms part of the Master Services Agreement between the Customer and GDPRLocal Ltd. Capitalised terms have the same meaning as in the Schedule or the Agreement.
The SOW is generated and recorded by GDPRLocal at the point of Service activation (whether via the GDPRLocal platform or by written confirmation) and captures the bespoke scope, fees, and operational parameters of this engagement. Customer identity is auto-populated from the Customer’s account profile and is not re-captured here.
1. Customer Details
| Company Name | [Company Name] |
| Contact Name | [Contact Name] |
| Contact Email | [Contact Email] |
| Contact Number | [Contact Number] |
2. Effective Date and Term
3. Service Scope
4. Service Fees
5. Designated Personnel
| Appointed Representative entity | GDPRLocal Ltd |
| Registered address | 1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB, United Kingdom |
| contact@gdprlocal.com | |
| Tel | +44 1772 217 800 |
6. Privacy Notice Wording
The Customer shall publish, in its privacy notices, website privacy policies, and any other communications required by Articles 13 and 14 UK GDPR, the following wording (or equivalent that conveys the same information):
“Our UK Representative under Article 27 UK GDPR is GDPRLocal Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB. Web: https://gdprlocal.com. UK data subjects and supervisory authorities may contact our UK Representative at contact@gdprlocal.com or +44 1772 217 800.”
The Customer shall update such notices promptly upon written notice from GDPRLocal of any change to those contact details.
7. UK Representative Services and Deliverables
| Service | Services included | Timeline |
| Appointment & Representation | Formal designation as UK Representative under Article 27 UK GDPR for processing activities falling under Article 3(2) UK GDPR; authorised representation mandate; inclusion in privacy notice | One-off (onboarding) |
| Regulatory Point of Contact | Receipt and forwarding of Supervisory Authority communications; coordination support for responses | Forwarding within 1–3 business days |
| Data Subject Contact Function | Receipt and forwarding of data subject requests (DSARs); logging where applicable | Forwarding within 1–3 business days |
| Records of Processing Activities (ROPA) | Maintain access to Article 30 records for regulatory inspection; secure storage / access; provision to authorities on request | Ongoing / on request |
| Regulatory Cooperation Support | Communication coordination during inquiries or investigations; tracking of regulatory exchanges | As required |
| Communication Handling & Escalation | Timely escalation of regulatory or high-risk communications; priority flagging of urgent matters | As required |
| Compliance Interface | High-level guidance related to Article 27 obligations; notifications of relevant regulatory developments; practical guidance (non-legal advice) | As needed |
8. Review of Services
This SOW may be reviewed and updated by written agreement between the parties where required to reflect material changes to the Customer’s processing activities, service requirements, or compliance priorities. Any such update will be recorded as a revised SOW associated with the Customer’s account.
9. Acceptance
This SOW is deemed accepted by the Customer at the moment of Service activation (whether via in-portal activation or written confirmation accepted by GDPRLocal). No physical signature is required.