Terms

The GDPRLocal Master Service Agreement and additional Terms herein govern our products, services and customer relationships.

There are no requirements to purchase services.  No credit card needed to sign up, and once registered services may be purchased and activated at any time.

Data Protection Officer Services

This Schedule forms part of the Master Services Agreement (“Agreement”) between the Customer (acting in the capacity of “Controller”) and GDPRLocal Ltd (“GDPRLocal”). It sets out the scope of Data Protection Officer (“DPO”) services to be delivered by GDPRLocal. Terms used in this Schedule have the same meaning as in the Master Services Agreement or the General Data Protection Regulation (EU 2016/679) (“GDPR”).

In this Schedule, references to “Controller” are references to the Customer acting in the capacity of a controller under the GDPR.

1. Scope of Services

1.1 Designation. The Controller appoints GDPRLocal as its external Data Protection Officer (“DPO”) in accordance with Article 37 GDPR. GDPRLocal accepts this appointment and agrees to perform the DPO Services described in this Schedule in compliance with the GDPR.

1.2 DPO duties. In accordance with Article 39 GDPR, GDPRLocal shall:

  • inform and advise the Controller and the employees who carry out processing of their obligations pursuant to the GDPR;
  • monitor compliance with the GDPR, and with the policies of the Controller in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
  • provide advice where requested as regards the data protection impact assessment and monitor its performance pursuant to Article 35;
  • cooperate with the Supervisory Authority;
  • act as the contact point for the Supervisory Authority on issues relating to processing, including the prior consultation referred to in Article 36, and consult, where appropriate, with regard to any other matter.

The DPO shall, in the performance of its tasks, have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.

1.3 Additional services. Any services requested by the Controller that fall outside the scope of the DPO Services described in this Schedule may be requested as billable additional services and Tasks in accordance with the Master Services Agreement.

2. Independence of the DPO

2.1 Independence. The parties expressly acknowledge and agree that:

  • the DPO role is a statutory function governed by Articles 37–39 GDPR and GDPRLocal’s performance of the Services is subject to those provisions;
  • GDPRLocal shall not receive any instructions from the Controller regarding the exercise of the DPO’s tasks as required by Article 38(3) GDPR. This Schedule shall not be construed to restrict or limit GDPRLocal’s ability to perform the DPO role independently and in accordance with GDPR requirements;
  • the Controller shall not dismiss or penalise GDPRLocal for the performance of the DPO’s tasks pursuant to Article 38(3) GDPR. Any termination of this Schedule by the Controller on grounds that are directly attributable to the legitimate exercise of DPO functions shall be null and void to the extent it conflicts with Article 38(3) GDPR;
  • GDPRLocal may report directly to the highest management level of the Controller as required by Article 38(3) GDPR, and the Controller shall facilitate this access.

2.2 Conflict of interest. The Controller shall ensure that any additional tasks assigned to GDPRLocal do not create a conflict with the DPO’s responsibilities or compromise its independence, in accordance with Article 38(6) GDPR.

3. Service Levels and Deliverables

3.1 Service delivery. GDPRLocal shall deliver the Services described in this Schedule at intervals agreed between the Customer Contact (identified in the Customer’s account profile) and GDPRLocal, taking into account the nature, scope, context and risk profile of the Controller’s processing activities.

3.2 Advice and reporting. GDPRLocal shall provide advice, recommendations and reports within reasonable timeframes agreed between the parties from time to time, taking into account the complexity and urgency of the matter.

4. Controller Obligations

In addition to the obligations set out in MSA §6, the Controller shall:

4.1 provide GDPRLocal with resources and access to information, systems and personnel reasonably necessary for the performance of the Services, in accordance with Article 38(2) GDPR. The Controller shall ensure GDPRLocal is involved in a timely manner in any project or change that involves the processing of personal data;

4.2 promptly notify GDPRLocal of (a) any suspected or actual data breach; (b) any communication from a Supervisory Authority; and (c) any data subject request relating to rights under the GDPR;

4.3 publish the DPO’s contact details and communicate them to the Supervisory Authority as required by Article 37(7) GDPR, using the contact details set out in the Appendix to this Schedule, and update such notices promptly upon written notice from GDPRLocal of any change.

5. Services Outside the Scope

5.1 The Services are limited to the statutory DPO tasks described in clause 1.2. The Services do not include the provision of legal advice, legal opinions, or legal representation in litigation, regulatory proceedings, or any other formal proceedings. Where legal advice or representation is required, the Controller should seek independent legal counsel.

5.2 GDPRLocal’s role in relation to data subject rights requests is advisory and supervisory in nature. The operational handling and fulfilment of data subject rights requests, including subject access, erasure, and portability, remains the sole responsibility of the Controller.

5.3 Any services outside the statutory DPO role, including operational implementation of compliance measures or broader data protection consultancy, may be requested as billable additional services and Tasks in accordance with the Master Services Agreement.

6. Confidentiality (Service-specific supplement to MSA §7)

6.1 The parties expressly acknowledge that GDPRLocal, in its capacity as DPO, is subject to the obligation of secrecy or confidentiality concerning the performance of DPO tasks pursuant to Article 38(5) GDPR. This obligation operates independently of and in addition to the mutual confidentiality obligations in MSA §7. In particular:

  • GDPRLocal may disclose the Controller’s Confidential Information without prior consent in the event of a disclosure to the Supervisory Authority in the performance of the DPO’s statutory duties pursuant to Article 39(1)(d) and (e) GDPR;
  • GDPRLocal shall not be required to disclose to the Controller the identity of any individual who has provided information to the DPO where maintaining such confidentiality is required for the performance of the DPO role, including where a data subject or employee has raised a concern with the DPO in confidence; and
  • the Controller shall not instruct or request GDPRLocal to disclose the source of any information received in confidence in the exercise of the DPO’s statutory functions. Any such instruction shall be void and of no effect.

7. Liability and Indemnity (Service-specific supplement to MSA §10 / §11)

7.1 Acknowledgements. The parties acknowledge and agree that:

  • under the GDPR, primary legal responsibility for compliance rests with the Controller. The appointment of a DPO does not transfer Controller responsibility to GDPRLocal;
  • Supervisory Authorities may, in certain circumstances, have direct recourse against individuals performing DPO functions. This Schedule does not constitute an indemnity by the Controller in favour of GDPRLocal in respect of regulatory enforcement actions taken against GDPRLocal in the exercise of its independent statutory DPO functions, except as provided in clause 7.3 below;
  • GDPRLocal’s liability under this Schedule is assessed in the context of an advisory role, not a decision-making or Controller role.

7.2 Limitation of liability (service-specific).

7.2.1 Subject to clause 7.4, the aggregate liability of either party under this Schedule shall not exceed the total fees paid or payable by the Controller to GDPRLocal in respect of the DPO Service in the twelve (12) month period immediately preceding the event giving rise to the claim.

7.2.2 Neither party shall be liable for indirect, consequential, special, or punitive loss.

7.2.3 GDPRLocal shall have no liability for: loss arising from the Controller’s failure to implement DPO recommendations; regulatory finding, fine, or enforcement action arising from the Controller’s processing activities; loss arising from inaccurate, incomplete, or misleading information provided to GDPRLocal; loss attributable to the Controller’s failure to comply with clauses 2.2 and 4.

7.3 Indemnity.

7.3.1 The Controller shall indemnify and hold harmless GDPRLocal against any losses, costs, claims, damages, fines, or regulatory sanctions (including reasonable legal costs) arising from: any claim by a Supervisory Authority or third party attributable to the Controller’s failure to implement GDPRLocal’s reasonable DPO recommendations or the Controller’s failure to comply with applicable law; any claim arising from processing carried out by the Controller in respect of which GDPRLocal gave written advice that was not followed; the Controller’s failure to fulfil its obligations under clauses 2.2 and 4.

7.3.2 The indemnity does not apply to the extent that the relevant loss is directly and principally attributable to GDPRLocal’s own gross negligence or wilful misconduct. For the avoidance of doubt, GDPRLocal’s good-faith exercise of independent DPO judgement (including any recommendation, assessment, or opinion issued in the performance of the statutory DPO role) shall not constitute negligence or misconduct.

7.4 Exclusions from cap. The liability cap in clause 7.2 does not apply to: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; any other liability that cannot be limited by applicable law.

7.5 Professional Indemnity Insurance. GDPRLocal shall maintain throughout the term professional indemnity insurance in an amount no less than £1,000,000 per claim and in the aggregate per policy year. Evidence available on reasonable written request.

8. Term and Termination (Service-specific)

8.1 Term. This Schedule commences on the Service Start Date and continues for an initial term of twelve (12) months (“Initial Term”), unless terminated earlier in accordance with this clause 8 or MSA §12. It auto-renews for successive twelve-month Renewal Terms unless notice of non-renewal is given at least ninety (90) days prior to the end of the then-current term.

8.2 Termination for convenience. Notwithstanding MSA §12.3, either party may terminate this Schedule on not less than ninety (90) days’ prior written notice, exercisable only after expiry of the Initial Term, subject to the regulatory notification requirements in clause 8.5.

8.3 Termination for cause.

8.3.1 Termination for cause is governed by MSA §12.2 (material breach, insolvency, cessation of business), with the additional service-specific provisions in this clause 8.3.

8.3.2 The Controller may terminate this Schedule with immediate effect only if GDPRLocal is found to have acted in bad faith or in serious and wilful breach of professional obligations in the direct performance of its DPO duties under this Schedule, as determined by a final, non-appealable decision of a competent court or supervisory authority. This restriction is required to give effect to Article 38(3) GDPR.

8.3.3 GDPRLocal may terminate this Schedule with immediate effect if (a) the Controller repeatedly fails to implement GDPRLocal’s reasonable recommendations such that continued performance would require remaining associated with materially non-compliant processing; (b) the Controller attempts to instruct GDPRLocal in a manner that would compromise the independence required under Article 38(3) GDPR; or (c) the Controller fails to pay undisputed fees within 30 days of the due date and fails to remedy within 15 days of written notice.

8.4 Consequences of Termination. GDPRLocal provides a written handover report within 15 Business Days covering outstanding DPO matters, pending regulatory correspondence, and open DSAR requests (limited to matters in progress at termination, no new work). Transitional cooperation with any incoming DPO for up to 30 days at GDPRLocal’s standard rates, subject to settlement of outstanding fees. Within 30 days, return or destruction of Confidential Information on written request (subject to lawful retention exceptions). Clauses 6, 7, and 8.4 survive termination.

8.5 Regulatory notice. The parties shall cooperate to ensure that the termination of this Schedule is managed in compliance with any applicable supervisory authority requirements, including notifying the relevant Supervisory Authority of the termination of the DPO appointment, updating published DPO contact details and any registrations with Supervisory Authorities, and ensuring that the Controller does not operate without a lawfully appointed DPO during any mandatory appointment period.

The Controller accepts sole responsibility for ensuring the continuity of its DPO appointment following the termination of this Schedule.

__________________________________________________

Appendix to Schedule 4 — Statement of Work (DPO Services)

Note: This Statement of Work (“SOW”) is appended to and forms part of Service Schedule 4 (Data Protection Officer Services), which in turn forms part of the Master Services Agreement (“MSA”) between [Company name] (the “Controller”) and GDPRLocal Ltd (“GDPRLocal”). Capitalised terms have the same meaning as in the Schedule or the MSA.

Effective Date: the date the DPO Services are activated per the Service Activation Record.

Initial Term: 12 months from the Effective Date, automatically renewing in accordance with Schedule 4 §8.1.

Customer Details

Company Name[Company Name]
Contact Name[Contact Name]
Contact Email[Contact Email]
Contact Number[Contact Number]

DPO Details

Appointed DPO entityGDPRLocal Ltd
Registered address1st Floor Front Suite, 27–29 North Street, Brighton, England BN1 1EB
Emaildpo.support@gdprlocal.com
Tel+44 1772 217 800

DPO Services and Deliverables

The following sets out the DPO Services to be provided under this SOW.

DPO ServiceServices included
Inform and advise the Controller, its management and staff on their obligations under the GDPR. Ongoing throughout the contract term.
Monitor the Controller’s compliance with the GDPR and with the Controller’s data protection policies and procedures, including through periodic compliance reviews, internal audits, and review of relevant data protection documentation.Initial compliance review at the start of the engagement and an annual compliance review to be completed no later than the end of each contract year.
Review and update the Controller’s Records of Processing Activities as part of ongoing compliance monitoring.Once per contract year, and updated within one calendar month of notification of any material new or changed processing activity. Records of Processing Activities template included.
Advise the Controller on staff training needs in relation to data protection compliance and, where expressly agreed, support awareness-raising activities.One training needs assessment per contract year, documented in a Staff Training Policy and Plan.
Provide advice on DPIAs and, where relevant, other privacy risk assessments, and monitor their performance.Strategic DPIA advice based on the initial compliance review, updated annually. DPIA strategic advice provided on notification of a proposed new or changed processing activity or system. *Creation of DPIAs is outside the scope of these Services and shall be treated as an Additional Service (Tasks framework, MSA §5.5).
Act as a contact point for data subjects on issues relating to the processing of their personal data and the exercise of their rights under the GDPR, including by guiding the Controller in handling data subject rights requests where required.DPO contact details made available to data subjects. GDPRLocal portal access to Privacy Manager included. The operational handling and fulfilment of data subject rights requests, including subject access, erasure, and portability, remains the sole responsibility of the Controller. *Direct support provided to the Controller in relation to its management of data protection rights matters is outside the scope of these Services and shall be treated as an Additional Service.
Act as a contact point for the competent Supervisory Authority on issues relating to the processing of personal data and cooperate with the Supervisory Authority where required.DPO contact details made available to relevant Supervisory Authorities. Initial regulatory advice included. *Direct support provided to the Controller in relation to its management of Supervisory Authority requests is outside the scope of these Services and shall be treated as an Additional Service.
Advise the Controller, where required, on personal data breach notification obligations under Articles 33 and 34 GDPR following notification of a suspected or confirmed breach.Data Breach Manager access on GDPRLocal portal included. Initial advice provided upon notification of a suspected or confirmed personal data breach. Data Breach Policy template included. *Direct support provided to the Controller in relation to its management of data breaches is outside the scope of these Services and shall be treated as an Additional Service.
Report periodically to the Controller’s highest management level on compliance status, material data protection risks, and recommendations arising from the performance of the DPO’s duties.DPO meetings included, at intervals agreed and confirmed with the Controller. Compliance DPO report delivered every 6 months.

Review of Services

This SOW may be reviewed and updated by written agreement between the Parties where required to reflect material changes to the Controller’s processing activities, service requirements, or compliance priorities.

Execution

This written agreement is agreed and executed by the authorised representatives of the Parties.