The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.
There are no requirements to purchase services. No credit card needed to sign up, and once registered services may be purchased and activated at any time.
This Data Processing Agreement (“DPA”) supplements the GDPRLocal Master Services Agreement (the “Agreement”) entered into by and between the customer signing this DPA (“Customer”) and GDPRLocal Ltd, with registered seat at 1st Floor Front Suite 27–29 North Street, Brighton, England BN1 1EB (“GDPRLocal”), on behalf of itself and its affiliates. By executing this DPA, the Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Affiliates.
2.1 The Customer may act as a controller or processor; except as expressly set out, GDPRLocal is a processor. The Customer shall process Personal Data and provide instructions in compliance with Data Protection Laws, and is solely responsible for the accuracy, quality, and legality of Personal Data and the lawfulness of its instructions.
2.2 GDPRLocal shall not process Personal Data for purposes other than those set out in the Agreement and Exhibit A, inconsistent with the Customer’s documented instructions, or in violation of Data Protection Laws. Where required by a Supervisory Authority to which GDPRLocal is subject, GDPRLocal will inform the Customer before processing unless prohibited by law.
2.3 Following completion of the Services, at the Customer’s choice, GDPRLocal shall return or delete the Customer’s Personal Data unless further storage is required or authorised by law.
2.4 CCPA. GDPRLocal is a service provider for CCPA purposes (where applicable), shall not sell personal information, and shall not retain or disclose personal information except as necessary for the Services.
GDPRLocal shall ensure that any person it authorises to process Personal Data has agreed to protect Personal Data in accordance with confidentiality obligations in the Agreement. The Customer agrees that GDPRLocal may disclose Personal Data to its employees, contractors, advisers, auditors or other third parties as reasonably required.
4.1 The Customer authorises GDPRLocal to engage its Affiliates and Authorised Sub-Processors on the List to process Personal Data in connection with the Services.
4.2 A list of current Authorised Sub-Processors is set out in Exhibit B(4). GDPRLocal will provide a mechanism to subscribe to notifications of new Sub-Processors. At least fifteen (15) days before enabling a new third party, GDPRLocal will add it to the List and notify subscribers. The Customer may object in writing within 15 days on reasonable data-protection grounds.
4.3 If the Customer reasonably objects and GDPRLocal cannot provide a commercially reasonable alternative, the Customer may discontinue the affected Service (without relief from owed fees).
4.4 Non-objection within 15 days means deemed acceptance.
4.5 GDPRLocal will enter into a written agreement with each Authorised Sub-Processor imposing comparable data-protection obligations and remains liable to the Customer for the Sub-Processor’s performance.
GDPRLocal shall maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Exhibit C sets out the security measures.
6.1 General. GDPRLocal may transfer Personal Data outside the EEA, UK, or Switzerland as necessary to provide the Services. GDPRLocal’s primary processing operations take place in the UK. Where transferred to a jurisdiction without adequacy, GDPRLocal will ensure appropriate safeguards.
6.2 Ex-EEA Transfers — EU SCCs. Ex-EEA Transfers are made under the EU SCCs (Module One for controller-to-controller; Module Two for controller-to-processor; Module Three for processor-to-sub-processor). For each module: optional docking clause (Clause 7) does not apply; Clause 9 Option 2 (general written authorisation) applies; in Clause 17 (Option 1) Irish law governs; Clause 18(b) selects courts of Ireland; Exhibit B contains Annex I/III information; Exhibit C contains Annex II information.
6.3 Ex-UK Transfers. Made under the UK SCCs (EU SCCs as amended by the UK Addendum in Exhibit D).
6.4 Transfers from Switzerland. Made under the EU SCCs as modified for the FADP / Revised FADP and the FDPIC.
6.5 Supplementary Measures. As of the date of this DPA the Data Importer has received no Government Agency Requests. Future Government Agency Requests will be redirected to the Customer where lawful, with notice and cooperation where permitted.
6.6 If a transfer mechanism ceases to be valid or is suspended by a supervisory authority, the Data Importer may amend or put in place alternative arrangements as required.
7.1 GDPRLocal shall notify the Customer within three (3) business days of any Data Subject Request received in relation to the Customer’s data. GDPRLocal will forward the request and the Customer is responsible for responding unless otherwise agreed.
7.2 GDPRLocal shall provide reasonable assistance to the Customer in responding to Data Subject Requests, at the Customer’s cost where legally permitted.
8.1 GDPRLocal shall provide reasonable cooperation with DPIAs and Supervisory Authority engagement.
8.2 GDPRLocal shall maintain compliance records for one (1) year after termination of the Agreement and make them available for the Customer’s review at GDPRLocal’s offices on 30 business days’ notice.
8.3 On the Customer’s reasonable written request, GDPRLocal will either (i) make available certifications/reports demonstrating compliance with prevailing data security standards, or (ii) where (i) is insufficient under Data Protection Laws, allow the Customer’s independent third-party auditor to inspect (once per calendar year, during business hours, restricted to data relevant to the Customer, at the Customer’s cost).
8.4 GDPRLocal shall notify the Customer within 72 hours if it believes an instruction infringes Data Protection Laws.
9.1 GDPRLocal shall inform the Customer of a Personal Data Breach without undue delay and in any case within 48 hours of becoming aware, and take such remediation steps as are within reasonable control.
9.2 GDPRLocal shall provide reasonable cooperation with notification obligations to Supervisory Authorities and data subjects.
9.3 The obligations in 9.1 and 9.2 do not apply where the breach results from the actions/omissions of the Customer. GDPRLocal’s reporting is not an acknowledgement of fault or liability.
With respect to Company Account Data and Company Usage Data, GDPRLocal is an independent controller (not a joint controller). GDPRLocal processes such data to manage the relationship, for core business operations, fraud / security prevention, identity verification, legal / regulatory obligations, and as otherwise permitted by Data Protection Laws.
In the event of conflict, the order of precedence set out in MSA §1.2 applies, save that the Standard Contractual Clauses prevail over all other documents in matters they expressly cover. Claims brought in connection with this DPA are subject to the exclusions and limitations in the Agreement.
This DPA is incorporated into and forms an integral part of the Master Services Agreement. This DPA is deemed executed upon execution of the MSA, commences on the same effective date, and remains in force for the duration of the MSA plus the period necessary for the parties to perform their respective obligations (including deletion / return of personal data).
__________________________________________________
Nature and Purpose of Processing: GDPRLocal will process the Customer’s Personal Data as necessary to provide the Services. Activities include: receiving, protecting, holding, erasing, analysing, and sharing data (the latter via sub-processors).
Duration of Processing: As long as required to provide the Services, for GDPRLocal’s legitimate business needs, or as required by law. Company Account / Usage Data per GDPRLocal’s privacy policy.
Categories of Data Subjects: the Customer’s employees, consultants, contractors, agents; data subjects; individuals submitting DSARs / RTEs to the Customer.
Categories of Personal Data: names, contact information, phone numbers, business emails, addresses, roles and job titles, financial information, or any information provided by individuals submitting DSARs/RTEs. Plus Company Account / Usage Data per this DPA.
Sensitive Data: None intended to be transferred.
B(1) Parties. Data exporter: Customer (Controller). Data importer: GDPRLocal (Processor).
B(2) Description of Transfer. As Exhibit A.
B(3) Recipients. As listed in B(4).
B(4) List of pre-approved sub-processors:
Competent Supervisory Authority. Supervisory authority of the Data Exporter per Clause 13 EU SCCs; UK ICO for UK Addendum purposes.