Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Article 27 UK Representative Services

This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of Article 27 UK Representative services to be delivered by GDPRLocal (the “Appointed Representative”). Terms used in this Schedule have the same meaning as in the Master Services Agreement or the Applicable Regulations.

1. Scope of Services

1.1 Designation. With effect from the Service Start Date, the Customer appoints the Appointed Representative to act as its representative in the United Kingdom pursuant to Article 27 of the Applicable Regulations. This Schedule constitutes the written mandate required under Article 27(1) UK GDPR. The Appointed Representative accepts this appointment and agrees to perform the Representative services described in this Schedule in compliance with Article 27 of the Applicable Regulations. The mandate does not confer authority to make substantive decisions on behalf of the Customer regarding processing activities, to bind the Customer to any compliance undertaking, or to act as legal representative in litigation or enforcement proceedings.

1.2 Article 27 Representative duties. In accordance with Article 27 of the Applicable Regulations, GDPRLocal shall (through the Appointed Representative):

  • act as a contact point for competent Supervisory Authorities on all issues related to the processing activities covered by the relevant mandate;
  • act as a contact point for data subjects on issues relating to such processing activities;
  • receive and transmit communications addressed to the Appointed Representative and forward such communications to the Customer without undue delay;
  • hold a copy of the Customer’s Article 30 Records of Processing Activities, where applicable, and make such records available to Supervisory Authorities upon request;
  • cooperate with Supervisory Authorities in the performance of the Appointed Representative’s own direct obligations under Article 31 UK GDPR;
  • support the Customer in responding to Supervisory Authority inquiries and investigations or enforcement actions and coordinate responses but not assume decision-making authority;
  • provide general guidance on UK regulatory expectations related to the representative function and notify the Customer of relevant regulatory developments affecting Article 27 obligations.

2. Service Levels and Deliverables

2.1 Service Delivery. GDPRLocal shall act on instructions from the Customer Contact identified in the Customer’s account profile, or any other person expressly authorised by the Customer in writing.

2.2 Advice and reporting. Where GDPRLocal receives a communication from a Supervisory Authority or Data Subject requiring a response within a defined deadline, GDPRLocal shall notify the Customer Contact immediately and specify the response deadline. If the Customer fails to provide instructions in time, GDPRLocal may either (a) respond with a holding acknowledgement, or (b) notify the Supervisory Authority or Data Subject that the matter is being forwarded to the Customer. The Customer acknowledges that GDPRLocal cannot be held responsible for missed deadlines caused by the Customer’s failure to provide timely instructions.

3. Customer Obligations

In addition to the obligations set out in MSA §6, the Customer shall:

3.1 provide GDPRLocal with such information, documents and cooperation as are reasonably necessary for the performance of the Services, including: accurate details of the Customer’s legal entity or entities covered by the appointment; details of the processing activities within the scope of the relevant appointment; and a copy of the Records of Processing Activities;

3.2 respond promptly to all communications forwarded by GDPRLocal and provide timely instructions, information and decisions necessary for the handling of such communications;

3.3 promptly notify GDPRLocal of: (a) any suspected or actual data breach; (b) any change to the Customer’s processing activities that materially affects the scope or nature of the representative appointment; (c) any direct communication received by the Customer from a Supervisory Authority; (d) any litigation or regulatory proceeding initiated against the Customer relating to its processing of personal data of data subjects in the United Kingdom; and (e) any data subject request relating to rights under the UK GDPR;

3.4 publish the UK Representative contact details and communicate them to the Supervisory Authority as required by the UK GDPR, using the contact details for the Appointed Representative set out in the Appendix to this Schedule, and ensure that those contact details are accurately reflected in all of the Customer’s privacy notices, website privacy policies, and communications to data subjects as required by Articles 13 and 14 UK GDPR;

3.5 retain sole responsibility for the accuracy, completeness, and currency of the ROPA. The Appointed Representative’s obligation under Article 30(4) UK GDPR is contingent upon the Customer providing an accurate ROPA;

3.6 not take any action that would (a) expose GDPRLocal or the Appointed Representative to enforcement proceedings or regulatory sanctions other than as an unavoidable consequence of the Appointed Representative’s role; (b) require GDPRLocal or the Appointed Representative to make any inaccurate representation to a Supervisory Authority; or (c) cause GDPRLocal or the Appointed Representative to act in violation of Applicable Regulations.

4. Services Outside the Scope

4.1 Unless expressly agreed at activation, the Services shall not include substantive GDPR compliance advice or services (which are covered under separate Service Schedules if applicable) or the provision of legal advice or legal representation. Where legal advice is required, the Customer should seek independent legal counsel.

4.2 GDPRLocal and the Appointed Representative shall not assume management responsibility or operational decision-making authority.

4.3 The Appointed Representative’s role in relation to data subject rights requests is advisory and supervisory; operational handling of DSARs remains the Customer’s sole responsibility.

4.4 Any services outside the statutory Article 27 representative role may be requested as billable additional services and Tasks in accordance with the Master Services Agreement.

5. Liability and Indemnity (Service-specific supplement to MSA §10 / §11)

5.1 Acknowledgement of Liability Framework. The parties acknowledge:

  • Under the UK GDPR (per the English High Court in Rondon v LexisNexis, and consistent with ICO and EDPB guidance), the Appointed Representative is not substitutively liable for the Customer’s UK GDPR breaches. Direct liability is limited to its own statutory obligations under Articles 30(4) and 31 UK GDPR.
  • The Appointed Representative’s exposure to enforcement proceedings arises from its position as the Customer’s local contact point and is a structural feature of the Article 27 role, not a reflection of culpability. The contractual allocation of risk reflects this.

5.2 Limitation of Liability (service-specific).

5.2.1 Subject to clause 5.5, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Customer in respect of the Article 27 UK Representative Service in the twelve (12) month period immediately preceding the event giving rise to the claim.

5.2.2 Neither party shall be liable for indirect, consequential, special, or punitive loss.

5.2.3 GDPRLocal and the Appointed Representative shall have no liability for: GDPR fines or sanctions imposed on the Customer; loss arising from the Customer’s failure to comply with Applicable Regulations or provide accurate/timely ROPA or instructions; consequence of failure to update privacy notices with correct contact details; loss attributable to the Customer’s failure to notify of a relevant event per clause 3; loss arising from GDPRLocal’s good-faith forwarding of communications where the Customer failed to respond adequately.

5.3 Customer Indemnity. The Customer shall indemnify, defend, and hold harmless GDPRLocal, the Appointed Representative, and their respective affiliates, officers, employees, and agents (each an “Indemnified Person”) against losses (including reasonable legal costs on a full indemnity basis) arising from: enforcement proceedings; Data Subject claims relating to the Customer’s processing; Customer’s failure to meet clause 3 obligations; failure to provide an accurate ROPA; and costs of responding to Enforcement Proceedings or Supervisory Authority inquiries on the Customer’s behalf.

5.4 Defence procedure. On notification of any potentially indemnifiable claim: GDPRLocal notifies the Customer promptly; the Customer assumes conduct of defence at its cost (Indemnified Person may participate at Customer’s cost; no settlement adverse to the Indemnified Person without consent); the Indemnified Person cooperates reasonably; failing assumption within 15 Business Days, GDPRLocal may take over conduct at the Customer’s cost.

5.5 Exclusions from Limitation. The liability cap in clause 5.2 does not apply to: the Customer’s indemnity obligations under clause 5.3; liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; any other liability that cannot be limited by Applicable Regulations.

5.6 Professional Indemnity Insurance. GDPRLocal shall maintain throughout the term professional indemnity insurance in an amount no less than £1,000,000 per claim and in the aggregate per policy year. Evidence available on reasonable written request.

6. Term and Termination (Service-specific)

6.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (“Initial Term”), unless terminated earlier in accordance with this clause 6 or MSA §12. It auto-renews for successive twelve-month Renewal Terms unless notice of non-renewal is given at least ninety (90) days prior to the end of the then-current term.

6.2 Termination for Convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule on not less than ninety (90) days’ prior written notice, exercisable only after expiry of the Initial Term. The 90-day notice reflects GDPRLocal’s legitimate interest in continuity and the Customer’s need to identify a replacement Article 27 representative to avoid violating Article 27 UK GDPR.

6.3 Additional Termination Right. GDPRLocal may additionally terminate with immediate effect if (a) the Customer provides materially inaccurate ROPA information such that performance would involve misrepresentation to Supervisory Authorities; or (b) the Customer’s instructions would require unlawful action or expose GDPRLocal or the Appointed Representative to disproportionate liability.

6.4 Right of Resignation in Enforcement Situations. Market standard practice for Article 27 representatives establishes a specific right of resignation where the Customer stops cooperating during Enforcement Proceedings. GDPRLocal may resign with immediate effect if:

  • Enforcement Proceedings are commenced against the Appointed Representative and the Customer (i) fails to assume defence within 15 Business Days; (ii) fails to provide adequate instructions within deadlines; or (iii) fails to cooperate;
  • the Customer ceases to respond to GDPRLocal’s communications for 15+ Business Days during a live SA inquiry or Enforcement Proceeding;
  • the Customer is conducting processing constituting a serious ongoing UK GDPR violation that it refuses to remedy following written notice.

Immediate resignation in such circumstances shall not constitute a breach. The Customer accepts sole responsibility for any regulatory consequence of a coverage gap.

6.5 Consequences of Termination. Within 5 Business Days: GDPRLocal ceases holding out as the Customer’s representative and notifies relevant Supervisory Authorities where required by national law; the Customer updates all privacy notices to remove the Appointed Representative’s details. Within 15 Business Days: GDPRLocal delivers a copy of the ROPA + communications log. Any pending Enforcement Proceedings handled per transitional arrangements (or, failing those within 10 Business Days, GDPRLocal may notify the relevant Supervisory Authority of termination and direct it to the Customer). Customer pays outstanding fees and costs. Clauses 5 and 6.5 survive termination.

6.6 Regulatory Notice. The Customer accepts sole responsibility for appointing a replacement Article 27 representative before or immediately upon termination to avoid violating Article 27 UK GDPR. GDPRLocal will cooperate as a courtesy with any replacement at its then-current standard rates.

__________________________________________________

Appendix to Schedule 2 — Statement of Work (Article 27 UK Representative Services)

This Statement of Work (“SOW”) is appended to and forms part of this Schedule, which in turn forms part of the Master Services Agreement between the Customer and GDPRLocal Ltd. Capitalised terms have the same meaning as in the Schedule or the Agreement.

The SOW is generated and recorded by GDPRLocal at the point of Service activation (whether via the GDPRLocal platform or by written confirmation) and captures the bespoke scope, fees, and operational parameters of this engagement. Customer identity is auto-populated from the Customer’s account profile and is not re-captured here.

1. Customer Details

Company Name[Company Name]
Contact Name[Contact Name]
Contact Email[Contact Email]
Contact Number[Contact Number]

2. Effective Date and Term

  • Effective Date: the date and time of Service activation (the “Service Start Date”).
  • Initial Term: twelve (12) months from the Service Start Date [Service Activation Date], in accordance with Schedule §6.1, unless variation is negotiated. 
  • Auto-renewal and notice as per Schedule §6.1.

3. Service Scope

  • Territory of representation: the United Kingdom (Article 27 UK GDPR).
  • Processing activities in scope: as set out in the Customer’s Records of Processing Activities (ROPA) provided to GDPRLocal under §3.5 of the Schedule.
  • ROPA reference: ROPA appended at activation, or to be provided by the Customer within 15 days of activation.
  • Scope exclusions (if any): any processing activities expressly outside the Rep’s scope, otherwise “none”.

4. Service Fees

  • Subscription fee: as set out in the Rate Card current at activation.
  • Billing cadence: [monthly / annual], per the Customer’s selection at activation (MSA §5.2).
  • Negotiated variation (if any, it will be provided in separate written documentation).
  • Currency: GBP. All fees exclusive of VAT and any applicable taxes.

5. Designated Personnel

Appointed Representative entityGDPRLocal Ltd
Registered address1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB, United Kingdom
Emailcontact@gdprlocal.com
Tel+44 1772 217 800
  • Designated Representative Contact: the named individual at the Appointed Representative performing the Article 27 representative role from time to time will be communicated to the Customer following activation. GDPRLocal will notify the Customer of any permanent change to the designated contact within thirty (30) business days. The Customer shall similarly notify GDPRLocal of any permanent change to the Customer Contact identified in the account profile.

6. Privacy Notice Wording

The Customer shall publish, in its privacy notices, website privacy policies, and any other communications required by Articles 13 and 14 UK GDPR, the following wording (or equivalent that conveys the same information):

“Our UK Representative under Article 27 UK GDPR is GDPRLocal Ltd, 1st Floor Front Suite, 27-29 North Street, Brighton, England, BN1 1EB. Web: https://gdprlocal.com. UK data subjects and supervisory authorities may contact our UK Representative at contact@gdprlocal.com or +44 1772 217 800.”

The Customer shall update such notices promptly upon written notice from GDPRLocal of any change to those contact details.

7. UK Representative Services and Deliverables

ServiceServices includedTimeline
Appointment & RepresentationFormal designation as UK Representative under Article 27 UK GDPR for processing activities falling under Article 3(2) UK GDPR; authorised representation mandate; inclusion in privacy noticeOne-off (onboarding)
Regulatory Point of ContactReceipt and forwarding of Supervisory Authority communications; coordination support for responsesForwarding within 1–3 business days
Data Subject Contact FunctionReceipt and forwarding of data subject requests (DSARs); logging where applicableForwarding within 1–3 business days
Records of Processing Activities (ROPA)Maintain access to Article 30 records for regulatory inspection; secure storage / access; provision to authorities on requestOngoing / on request
Regulatory Cooperation SupportCommunication coordination during inquiries or investigations; tracking of regulatory exchangesAs required
Communication Handling & EscalationTimely escalation of regulatory or high-risk communications; priority flagging of urgent mattersAs required
Compliance InterfaceHigh-level guidance related to Article 27 obligations; notifications of relevant regulatory developments; practical guidance (non-legal advice)As needed

8. Review of Services

This SOW may be reviewed and updated by written agreement between the parties where required to reflect material changes to the Customer’s processing activities, service requirements, or compliance priorities. Any such update will be recorded as a revised SOW associated with the Customer’s account.

9. Acceptance

This SOW is deemed accepted by the Customer at the moment of Service activation (whether via in-portal activation or written confirmation accepted by GDPRLocal). No physical signature is required.