Regulated Customer Contract Checker
Regimes ยท UK GDPR

The UK GDPR

Reaches every agreement with a customer in the United Kingdom whose row names personal data. The UK text is held here only as a summary of its articles (Articles 24 to 43 on controllers and processors, 44 to 50 on transfers), so the register names the UK regime and, where it quotes, quotes the EU GDPR article of the same number and says so.

On the register, tick "UK GDPR" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: GDPR (Regulation (EU) 2016/679).

What it expects, term by term

processor termsArts. 24 to 43Where the row names personal data the supplier handles
audit rightArts. 24 to 43On an ICT service arrangement, or where processor terms are expected
breach clockArts. 24 to 43Where the row names personal data
transfer termsArts. 44 to 50Where personal data leaves the EEA and the United Kingdom for the supplier's home

Where the UK text is not held

The UK GDPR is held here only as a summary of its articles. Where a row with a UK customer needs the clause, the register quotes the EU GDPR article of the same number and says so on the row: GDPR Art. 28, GDPR Art. 33, GDPR Art. 44, GDPR Art. 46.

The clauses, quoted

6

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an auditor accepts: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract
Where it usually falls short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.

Evidence an auditor accepts: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires
Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 44 General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Evidence an auditor accepts: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data
Where it usually falls short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 46 Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Evidence an auditor accepts: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place
Where it usually falls short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
UK GDPR Arts. 24 to 43 Controller and Processor (Articles 24-43)

Per UK GDPR Articles 24-43: controller + processor + DPO + RoPA + DPIA + Privacy by Design + Records + breach notification.

Evidence an auditor accepts: UK GDPR evidence for UKGDPRREG-3
Where it usually falls short: DPO + DPIA + ICO partial
UK GDPR (summary of the articles held) in The Art of Service standards library
UK GDPR Arts. 44 to 50 Transfers and DPO (Articles 44-50)

Per UK GDPR Articles 44-50: international transfers + adequacy + SCCs + BCRs.

Evidence an auditor accepts: UK GDPR evidence for UKGDPRREG-4
Where it usually falls short: DPO + DPIA + ICO partial
UK GDPR (summary of the articles held) in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list