Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Seirbhísí Rialachais Intleachta Saorga

This Schedule forms part of the Master Service Agreement (“Agreement”) between the Client and GDPRLocal Ltd. (the “Service Provider”). It sets out the scope of AI governance services to be delivered by the Service Provider. Terms used in this Schedule have the same meaning as in the Agreement.

1. Service provider duties 

1.1. Service provider duties. In accordance with the Agreement, Schedule and the Statement of Work (SoW), the Service Provider shall provide the services set out in Section 3 of this Schedule, including supporting the Client in the design, governance, maintenance, and continuous improvement of its AI Management System (“AIMS”) as described in the Statement of Work that forms a part of this Schedule.

1.3 Additional services. Any services requested by the Client that fall outside the scope of the AI governance described in the attached Scope of Work [SOW] shall constitute additional services which may be provided only pursuant to a separate agreement.

2. Service Levels and Deliverables

2.1 Service delivery. The Service Provider shall deliver the Services described in the SOW in accordance with the scope set out herein and at intervals agreed between the Client’s representative and Service Provider compliance executive taking into account the nature, scope, context and risk profile of the Client’s AI governance posture.

2.2 Advice and reporting. The Service Provider shall provide advice, recommendations and reports within specified timeframes agreed between the Parties in the SOW, taking into account the complexity and urgency of the matter. The form, frequency and timing of any reports, meetings or other deliverables shall be as set out in the applicable SOW.

3. Scope of Services

3.1 Core pillars. The Service Provider shall provide the Client with high-level support and guidance in the design, governance, maintenance, and continuous improvement of its AIMS across the following core pillars:

  1. AI Governance and Accountability. The Service Provider shall:
  • Advise management and relevant staff on the governance and operation of the AIMS, including leadership commitment, policy direction, and the assignment of roles and responsibilities;
  • Guide and support the Client including drafting the policies, procedures, registers, and supporting documentation necessary for the establishment and maintenance of the AIMS;
  • Advise on updates required to AI-related data protection policies, procedures, and documentation, including acceptable use policies, privacy policies, terms and conditions, roles and responsibilities, and training plans; and
  • Conduct monthly coordination meetings with the Client’s designated representative to review progress, discuss priorities, and align on upcoming activities.
  1. AI Risk Management. The Service Provider shall:
  • Create a tailored AI risk assessment methodology and define the risk assessment plan
  • Work together with the Client in completing AI risk assessments, including the systematic identification of technical, ethical, and legal risks associated with AI systems throughout their lifecycle;
  • Work together with the Client in completing AI impact assessments to evaluate the potential consequences of AI systems on individuals, groups of individuals, and the organisation; 
  • Advise on the governance of key AIMS processes, including third party risk management, incident management, and internal audit; and
  • Review audit/assessment findings once completed by the Client and provide observations and recommendations.
  1. Ethics and Transparency. The Service Provider shall:
  • Advise the Client on ensuring that its AI systems are developed and used responsibly, with due regard to fairness, data privacy, security, and explainability of AI-driven decisions;
  • Review the Client’s internal AI compliance documentation and provide recommendations for improvement; and
  • Work together with the Client in drafting missing ethical and transparency documentation, based on deliverables agreed at the monthly meetings and confirmed in monthly plans; and
  • Advise the Client on AI literacy requirements applicable to its organisation and provide guidance on training obligations.
  1. Continuous Monitoring and Improvement. The Service Provider shall:
  • Support the Client’s continuous oversight of the AIMS throughout the AI system lifecycle, including guidance on the maintenance of the AI Tracker;
  • Report on relevant Service Provider activities and the Client’s AI compliance status at agreed intervals;
  • Advise the Client on AI literacy requirements applicable to its organisation and provide guidance on training obligations; and
  • Provide ad hoc AI compliance support by email and/or video call, as reasonably required by the Client.

3.2 Access to Service Provider Resources. In addition to the monthly provided services, the Client shall have ongoing access to the Service Provider’s portal and documentation produced as part of this Agreement.

4. Client Responsibilities

4.1 Operational Duties. In addition to the responsibilities set out in the Agreement, the Client shall:

a) designate a primary contact person responsible for coordinating with the Service Provider in relation to the Services;

b) ensure timely access to relevant stakeholders, including representatives from Data & Engineering, IT, Legal, Risk Management, HR, and any other relevant departments, as reasonably required for the performance of the Services;

c) determine or confirm, on a monthly basis, the priorities and focus areas for the Services;
d) provide, in a timely manner, all inputs, information, instructions, approvals, access, and other cooperation reasonably required for the Service Provider to perform the Services.

4.2 Acknowledgements. The Client acknowledges and agrees that:

a) the Service Provider provides oversight, framework design, and advisory services only, and does not assume any operational, managerial, or decision-making role within the Client’s organisation;
b) the Service Provider does not act as an AI Risk Owner or AI Incident Owner. Ultimate accountability for the identification, assessment, acceptance, mitigation, and reporting of AI-related risks and incidents remains solely with the Client;

c) the Services constitute governance and compliance consulting and do not amount to formal legal advice or legal opinions. The Client is responsible for obtaining independent legal review of all policies, procedures, and documentation prior to adoption or implementation;
d) services defined in this Agreement do not include advice and guidance related to technical implementation or product development activities, including without limitation writing code, conducting software testing, security testing, building or training models, engineering system architectures, or acting as developers, engineers, or data scientists;

e) in the event of Client inactivity, delay, or failure to provide required information or inputs, including monthly priorities (Art. 4.1 (c) and (d)) or responses to reasonable requests or calls to action, the Service Provider may determine the scope, prioritisation, and sequencing of the Services to be performed during the relevant monthly service period, using the monthly hours and service capacity allocated under this Agreement and acting in accordance with its reasonable professional judgment. Any Services performed by the Service Provider in such circumstances shall be deemed duly performed and delivered for that monthly service period, and the fees for that period shall remain due in full and non-refundable. The Client shall have no right to any refund, credit, set-off, re-performance, or other fee adjustment arising from such inactivity, delay, or failure to cooperate. The Service Provider shall not be liable for any resulting delay, gap, deficiency, or reduced effectiveness to the extent caused by the Client’s failure to provide the required cooperation.

5. Term and Renewal

5.1 Initial Term. This Schedule shall commence on the date of execution of the Agreement and shall remain in force for an initial term of twelve (12) months, unless terminated earlier in accordance with this Schedule or the Agreement.

5.2 Renewal. Unless otherwise agreed in writing, this Schedule shall automatically renew for successive periods of twelve (12) months under the same terms and conditions.

6. Termination for Convenience

6.1 Notice. Either Party may terminate this Schedule for convenience by providing at least thirty (30) days’ prior written notice to the other Party by email, such notice to be effective prior to the start of the next billing cycle.

6.2 Post termination. Upon termination, and subject to payment of all outstanding fees, the Service Provider shall provide the Client with a final export of the AI Tracker.

7. Order of Precedence and Execution

7.1 Conflict Resolution. In the event of any conflict or inconsistency between the provisions of this Schedule and the Agreement, the provisions of this Schedule shall prevail.

7.2 Execution of this Schedule. This Schedule is incorporated into and forms an integral part of the Agreement entered into between the Client and the Service Provider. This Schedule shall be deemed executed upon execution of the Agreement and shall commence on the same effective date as the Agreement.


Appendix to Schedule: Statement of Work – AI Governance Services

This Statement of Work (“SoW”) is appended to and forms part of the Schedule – AI Governance Services, which in turn forms part of the Master Service Agreement (“Agreement”) between [Client] (the “Client”) and GDPRLocal Ltd. (the “Service Provider”). Capitalised terms have the same meaning as in the Schedule or the Agreement.

Effective Date: [date] 

  • Client Details
Company name:
Address: 
Point of contact: 
Role:
Email
  • Service Provider Details
DPO name:Adam Brogden, GDPRLocal
Address: 1st Floor Front Suite, 27–29 North Street, Brighton, England BN1 1EB
Email:dpo.support@gdprlocal.com
Tel:+44 1772 217 800

Parties shall notify each other within [30] business days in advance of any permanent change to designated personnel.

AI Governance Services and Deliverables 

The table below outlines the range of AI Governance Services that may be provided under this SoW based on deliverables agreed at monthly meetings and confirmed in monthly plans. 

AIMS Service AreaDeliverables 
AI Governance and AccountabilityAI Policy
AI Governance Policy
AIMS Scope Policy
Roles and Responsibilities Matrix
AI Support and Operations Policy
AI Resources Process
Privacy Policy Alignment to AIMS
T&C Alignment to AIMS
Business Continuity Plan Alignment to AIMS
Register of Legal and Regulatory Requirements Alignment to AIMS
AI Risk ManagementAI Risk RegisterAI Risk Management policyAI Impact Assessment process AI Risk Assessment MethodologyAI Risk Assessment template (NIST)AI Risk Treatment AI Risk Treatment PlanAI Impact Assessment Methodology AI Impact Assessment template (Microsoft)AI Impact Assessment ReportAI Tool Approval ProcessAI Tool Risk Assessment  AI Tool Register
AI Incident Response Plan
AI Incident Response Checklist
AI Incident Register
AI Incident Classification Scheme
Ethics and Transparency AI Model Card (external)AI Model Operational Use Policy (Internal)
AI Use Policy (external)
AI Acceptable Use Policy (internal)
AI Literacy Process with Supporting Forms
AI Training Plan
AI Literacy Employee Handbook
*Targeted research on AI regulatory developments and applicable laws, and advising the Client on updates to the AIMS required to maintain alignment with evolving requirements is outside the scope of these Services and shall be treated as an Additional Service.
Continuous Monitoring and ImprovementAI Improvement Policy
AI TrackerAI Performance EvaluationAI Corrective Action Form Post market AI System monitoring planInternal Audit Process with supporting forms (Internal audit program, Internal Audit Report and Internal Audit Checklist)
  • Review of Services

This SoW may be reviewed and updated by written agreement between the Parties where required to reflect material changes to the Client’s AIMS, service requirements, or compliance priorities.

  • Signatures

Agreed and executed by the authorised representatives of the Parties:

For and on behalf of [CLIENT FULL LEGAL NAME] (Client)

______________

For and on behalf of GDPRLocal Ltd. (Service Provider)

______________