PRIMEPRO – DATA
PROCESSING ADDENDUM
1.1
Words that
are capitalised but have not been defined in this DPA have the meanings given
to them in the Terms. In addition,
in this DPA the following definitions have the meanings given below:
Adequacy
Decision means any valid adequacy decision as referred to
in Article 45 of the EU GDPR.
Adequacy
Regulation means any valid adequacy regulation as referred
to in Article 45 of the UK GDPR.
Controller has the meaning given to that term in Data
Protection Laws.
Data
Protection Laws means, as binding on either party or the
Services or the PrimePRO Software:
(b)
the
UK GDPR and the UK DPA 2018;
(c)
any
laws which implement or supplement any such laws; and
(d)
any
laws which replace, extend, re-enact, consolidate or amend any of the foregoing.
Data
Protection Losses means all liabilities, including all:
(a)
costs
(including legal costs), claims, demands, actions, settlements, interest,
charges, procedures, expenses, losses and damages (including relating to
material or non-material damage); and
(b)
to
the extent permitted by Relevant Law:
(i)
administrative
fines, penalties, sanctions, liabilities or other remedies imposed by a
Supervisory Authority;
(ii)
compensation
which is ordered by a court or Supervisory Authority to be paid to a Data
Subject; and
(iii)
the
reasonable costs of compliance with investigations by a Supervisory Authority.
Data Subject has the meaning given to that term in Data
Protection Laws.
Data Subject
Request means a request made by a Data Subject to
exercise any rights of Data Subjects under Chapter III of the GDPR in relation
to any Protected Data.
EEA Data
Protection Laws means Data Protection Laws applicable
under the laws of the European Economic Area, the European Union or any of
their member states.
EEA
Protected Data means Protected Data to which any EEA Data Protection
Laws apply.
EU GDPR means the General Data Protection Regulation,
Regulation (EU) 2016/679.
GDPR means the EU GDPR and the UK GDPR (as applicable in the circumstances).
International
Recipient means the organisations, bodies, persons and
other recipients to which Transfers of the Protected Data are prohibited
without your prior written authorisation.
Lawful
Safeguards means such legally enforceable mechanism(s) for
Transfers of Personal Data as may be permitted under Data Protection Laws from
time to time.
Onward
Transfer means a Transfer from one International
Recipient to another International Recipient.
Personal
Data has the meaning given to that term in Data
Protection Laws.
Personal
Data Breach means any breach of security leading to the
accidental or unlawful destruction, loss, alteration, unauthorised disclosure
of, or access to, any Protected Data.
processing has the meaning given to that term in Data
Protection Laws (and related terms such as process, processes and processed have corresponding meanings).
Processing
Instructions has the meaning given to that term in paragraph 3.1.1.
Processing
End Date: means the earlier of:
(a)
the
end of the provision of the relevant Services or the PrimePRO Software related
to processing of the Protected Data; or
(b)
once
processing by PrimePRO of any Protected Data is no longer required for the
purpose of PrimePRO’s performance of its relevant obligations under our
Agreement.
Processor has the meaning given to that term in Data
Protection Laws.
Protected
Data means Personal Data received from or on behalf your,
or otherwise obtained or accessed by PrimePRO in connection with the
performance of the Services or the provision of the PrimePRO Software.
Relevant Law means:
(a)
in respect of EEA Protected Data, all applicable
law(s) of the European Economic Area and European Union and of the relevant
member state(s) of either; and
(b)
in respect of UK Protected Data, all applicable law(s) of the
United Kingdom (or of any part of the United Kingdom).
Sub-Processor means a Processor engaged by us or by any other
Sub-Processor for carrying out processing activities in respect of the
Protected Data on your behalf.
Supervisory
Authority means any local, national or multinational
agency, department, official, parliament, public or statutory person or any
government or professional body, regulatory or supervisory authority, board or
other body responsible for administering Data Protection Laws.
Transfer bears the same meaning as the word ‘transfer’ in
Article 44 of the GDPR (and related terms such as Transfers,
Transferred and Transferring
have corresponding meanings).
UK Data Protection Laws means the Data Protection
Laws applicable under the laws of the United Kingdom (or of any part of the
United Kingdom), including the UK GDPR and UK DPA 2018.
UK DPA 2018 means
the United Kingdom’s Data Protection Act 2018.
UK GDPR has the meaning given to that term in the UK DPA
2018.
UK Protected
Data means Protected Data to which any UK Data Protection
Laws apply.
2.1
We
each agree that, for the Protected Data, where you are the Controller and we
are your Processor, this DPA shall apply. Nothing in this DPA or any other
part of our Agreement relieves you of any responsibilities or liabilities under
any Data Protection Laws.
2.2
To
the extent you are not sole Controller of any Protected Data you warrant that you
have full authority and authorisation of all relevant Controllers to instruct us
to process the Protected Data in accordance with our Agreement.
2.3
We
will process Protected Data in compliance with:
2.3.1
the
obligations of Processors under Data Protection Laws in respect of the
performance of our obligations under our Agreement; and
2.3.2
the
terms of our Agreement.
2.4
You
will ensure that each Authorised User will at all times comply with:
2.4.1
all
Data Protection Laws in connection with the processing of Protected Data, the
use of the PrimePRO Software (and each part) and the exercise and performance
of your respective rights and obligations under our Agreement, including
maintaining all relevant regulatory registrations and notifications as required
under Data Protection Laws; and
2.4.2
the
terms of our Agreement.
2.5
You
warrant, represent and undertake, that at all times:
2.5.1
the
processing of all Protected Data (if processed in accordance with our
Agreement) will comply in all respects with Data Protection Laws, including in
terms of its collection, use and storage;
2.5.2
fair
processing and all other appropriate notices have been provided to the Data
Subjects of the Protected Data (and all necessary consents from such Data
Subjects obtained and at all times maintained) to the extent required by Data
Protection Laws in connection with all processing activities in respect of the
Protected Data which may be undertaken by us and our Sub-Processors in
accordance with our Agreement;
2.5.3
the
Protected Data is accurate and up to date;
2.5.4
you
will establish and maintain adequate security measures to safeguard the
Protected Data in your possession or control (including from unauthorised or
unlawful destruction, corruption, processing or disclosure) and maintain
complete and accurate backups of all Protected Data provided to us (or anyone
acting on its behalf) so as to be able to immediately recover and reconstitute
such Protected Data in the event of loss, damage or corruption of such
Protected Data by us or any other person;
2.5.5
all
instructions given by you to us in respect of Personal Data will at all times
be in accordance with Data Protection Laws; and
2.5.6
you
have undertaken due diligence in relation to our processing operations and
commitments and are satisfied (and all times you continue to receive the
benefit of any Services and/or use the PrimePRO Software remain satisfied)
that:
2.5.6.1
our
processing operations are suitable for the purposes for which you propose to receive
the benefit of any Services and use the PrimePRO Software and engage us to
process the Protected Data;
2.5.6.2
the
technical and organisational measures adopted by us will (if we comply with our
obligations) ensure a level of security appropriate to the risk in regards to
the Protected Data as required by Data Protection Laws; and
2.5.6.3
we
have sufficient expertise, reliability and resources to implement technical and
organisational measures that meet the requirements of Data Protection Laws.
3.
Instructions
and details of processing
3.1
Insofar
as we process Protected Data on your behalf, we:
3.1.1
unless
required to do otherwise by Relevant Law, will (and will take steps to ensure
each person acting under its authority will) process the Protected Data only on
and in accordance with your documented instructions as set out in our Agreement
(including with regard to Transfers of Protected Data to any International
Recipient), as updated with both of our agreement from time to time (Processing Instructions);
3.1.2
if
Relevant Law requires us to process Protected Data other than in accordance
with the Processing Instructions, will notify you of any such requirement
before processing the Protected Data (unless Relevant Law prohibits such
information on important grounds of public interest); and
3.1.3
will
promptly inform you if we become aware of a Processing Instruction that, in our
opinion, infringes Data Protection Laws, provided that:
3.1.3.1
this
will be without prejudice to paragraphs 2.4 and 2.5; and
3.1.3.2
to
the maximum extent permitted by Relevant Law, we will have no liability howsoever
arising (whether in contract, tort (including negligence) or otherwise) for any
losses, costs, expenses or liabilities (including any Data Protection Losses)
arising from or in connection with any processing in accordance with the
Processing Instructions following your receipt of the information required by
this paragraph 3.1.3.
3.2
You
acknowledge and agree that the execution of any computer command to process
(including deletion of) any Protected Data made in the use of any of the PrimePRO
Software by an Authorised User will be a Processing Instruction (other than to
the extent such command is not fulfilled due to technical, operational or other
reasons by us). You will ensure that Authorised Users do not execute any such
command unless authorised by you (and by all other relevant Controller(s)) and
acknowledge and accept that if any Protected Data is deleted pursuant to any
such command we are under no obligation to seek to restore it.
4.
Technical
and organisational measures
4.1
We
will implement and maintain technical and organisational measures:
4.1.1
which
are appropriate, having regard to the nature of the processing, the nature of
the Personal Data being processed, the measures available, the cost of
implementing such measures and the risks to individuals of the unlawful or
unauthorised processing of that Personal Data in relation to the processing of
Protected Data by us; and
4.1.2
to
assist you insofar as is possible (taking into account the nature of the
processing) in the fulfilment of your obligations to respond to Data Subject
Requests relating to Protected Data, in each case at your cost on a time and
materials basis in accordance with our standard rates. We each have agreed that
(taking into account the nature of the processing) our compliance with
paragraph 6.1 will constitute our sole obligations under this
paragraph 4.1.2.
5.
Using
staff and other Processors
5.1
We have your general
authorisation for the engagement (whether directly or via a Sub-Processor) of
any Sub-Processors from time to time. As at the Effective Date, PrimePRO
engages the Sub-Processors made available at https://primepro.net/sub-processors/ (Sub-Processor List). PrimePRO shall update the
Sub-Processor List whenever it intends to make any changes concerning the
addition or replacement of a Sub-Processor or any changes to the processing
they will undertake. You shall be responsible for monitoring the Sub-Processor
List and any changes made to that list by PrimePRO at all times. If you wish to
object (which you shall only do so on reasonable grounds) to the appointment of
any Sub-Processor or to any change to any processing undertaken by any
Sub-Processor, you will notify PrimePRO in writing to sub-processors@primepro.net within 5 days of the relevant change
being published by PrimePRO on https://primepro.net/sub-processors/
(the
Objection Period). You will not unreasonably withhold, condition, delay or object to
the appointment of any Sub-Processor. PrimePRO shall be permitted
to engage such new or replacement Sub-Processor(s) following the end of the
Objection Period if you do not object prior to the end of the Objection Period
in the manner required by this paragraph.
5.2.1
prior
to the relevant Sub-Processor carrying out any processing activities in respect
of the Protected Data, ensure each Sub-Processor is appointed under a written
contract containing materially the same obligations as under paragraphs 2 to 12 (inclusive) (including those obligations
relating to sufficient guarantees to implement appropriate technical and
organisational measures);
5.2.2
ensure
each such Sub-Processor complies with all such obligations; and
5.2.3
remain
fully liable for all the acts and omissions of each Sub-Processor as if they
were our own.
5.3
We
will ensure that all
natural persons
authorised by us (or by any Sub-Processor) to process Protected Data are
subject to a binding written contractual obligation to keep the Protected Data
confidential (except where disclosure is required in accordance with Relevant
Law, in which case we will, where practicable and not prohibited by Relevant
Law, notify you of any such requirement before such disclosure).
6.
Assistance
with compliance and Data Subject rights
6.1
We
will refer all Data Subject Requests we receive to you without undue delay. You
will pay us for all work, time, costs and expenses incurred by us or any
Sub-Processor(s) in connection with such activity, calculated on a time
and materials basis at our then
current rates.
6.2
We
will provide such assistance as you reasonably require (taking into account the
nature of processing and the information available to us) to you in ensuring
compliance with your obligations under Data Protection Laws with respect to:
6.2.2
data
protection impact assessments (as such term is defined in Data Protection
Laws);
6.2.3
prior
consultation with a Supervisory Authority regarding high risk processing; and
6.2.4
notifications
to the Supervisory Authority and/or communications to Data Subjects by you in
response to any Personal Data Breach,
provided you will pay us for
all work, time, costs and expenses incurred us or any Sub-Processor(s) in
connection with providing the assistance in this paragraph 6.2, calculated on a time
and materials basis at our then
current rates.
7.
International
data Transfers
7.1
Subject
to paragraph 7.2, PrimePRO shall not Transfer
(nor permit any Transfer or Onward Transfer of) any Protected Data
outside the United Kingdom or the EEA without your prior written authorisation
except where required by Relevant Law.
7.2
All
Transfers of Protected Data by PrimePRO to an International Recipient
(including any Onward Transfer) shall:
7.2.1
to
the extent required under Data Protection Laws, be effected by way of Lawful
Safeguards and in accordance with paragraph 7.3 and Our Agreement; and
7.2.2
be
made pursuant to a written contract that includes equivalent obligations on
each Sub-Processor in respect of Transfers of Protected Data to International
Recipients as apply to PrimePRO under this paragraph 7.
The provisions of this DPA
shall constitute your instructions with respect to Transfers of Protected Data
for the purposes of this DPA.
7.3
The
Lawful Safeguards employed by PrimePRO in connection with Our Agreement shall
be as follows:
7.3.1
any
relevant Adequacy Decision or Adequacy Regulation (as applicable);
7.3.2
in
the absence of an appropriate Adequacy Decision or Adequacy Regulation (as
applicable), relevant standard contractual clauses approved by any applicable
Supervisory Authority; and/or
7.3.3
an
alternative Lawful Safeguard.
7.4
PrimePRO
and each Sub-Processor is not obliged to make any unlawful Transfer of
Protected Data and shall not be liable to the extent that it (or any
Sub-Processor) is delayed in or fails to perform any obligation under Our
Agreement due to:
7.4.1
there
being no available valid Lawful Safeguard agreed under paragraph 7.3 from time to time for any of the Transfers
authorised by you; or
7.4.2
PrimePRO
or any Sub-Processor declining to permit any Transfer(s) on the basis it
believes (acting
reasonably) that the
circumstances in paragraph 7.4.1 apply.
7.5
You
acknowledge that due to the nature of cloud services, the Protected Data may be
Transferred to other geographical locations in connection with use of the PrimePRO
Software further to access and/or computerised instructions initiated by
Authorised Users. You acknowledge that we do not control such processing and
you will ensure that Authorised Users (and all others acting on its behalf)
only initiate the Transfer of Protected Data to other geographical locations if
Lawful Safeguards are in place and that such Transfer is in compliance with all
Relevant Laws.
8.1
We
will maintain, in accordance with Data Protection Laws binding on us, written
records of all categories of processing activities carried out on your behalf.
8.2
On
request, we will provide you (or auditors mandated by you) with a copy of the
third party certifications and audits to the extent made generally available to
our customers. Such information will be confidential to us and will be our
Confidential Information as defined in our Agreement, and will be treated in
accordance with applicable terms.
8.3
In
the event that you, acting reasonably, deem the information provided in
accordance with paragraph 8.2 insufficient to satisfy your obligations under
Data Protection Laws, we will, on request by you make available to you such
information as is reasonably necessary to demonstrate our compliance with our
obligations under this DPA and Article 28 of the GDPR, and allow for and
contribute to audits, including inspections, by you (or another auditor
mandated by you) for this purpose provided:
8.3.1
such
audit, inspection or information request is reasonable, limited to information
in our possession or control and is subject to you giving us reasonable (and in
any event at least 60 days’) prior notice of such audit, inspection or
information request;
8.3.2
we
each (each acting reasonably and consent not to be unreasonably withheld or
delayed) will agree the timing, scope and duration of the audit, inspection or
information release together with any specific policies or other steps with
which you or a third party auditor will comply (including to protect the
security and confidentiality of other customers, to ensure we are not placed in
breach of any other arrangement with any other customer and so as to comply
with the remainder of this paragraph 8.3);
8.3.3
you
will ensure that any such audit or inspection is undertaken during our normal
business hours, with minimal disruption to our businesses;
8.3.4
the
duration of any audit or inspection will be limited to one Business Day;
8.3.5
all
costs of such audit or inspection or responding to such information request will
be borne by you, and our costs, expenses, work and time incurred in connection
with such audit or inspection will be reimbursed by you on a time and materials
basis in accordance with our then current rates;
8.3.6
your
rights under this paragraph 8.3 may only be exercised once in any consecutive 12 month
period, unless otherwise required by a Supervisory Authority or if you
(acting reasonably) believe we are in breach of this DPA;
8.3.7
you
will promptly (and in any event within one Business Day) report any non-compliance
identified by the audit, inspection or release of information to us;
8.3.8
you
agree that all information obtained or generated by you or your auditor(s) in
connection with such information requests, inspections and audits will be our
Confidential Information as defined in our Agreement, and will be treated in
accordance with applicable terms;
8.3.9
you
will ensure that each person acting on your behalf in connection with such
audit or inspection (including the personnel of any third party auditor) will
not by any act or omission cause or contribute to any damage, destruction, loss
or corruption of or to any systems, equipment or data in our control or
possession while conducting any such audit or inspection; and
8.3.10
this
paragraph 8.3 is subject to paragraph 8.4.
8.4
You
acknowledge and accept that relevant contractual terms agreed with
Sub-Processor(s) may mean that we or you may not be able to undertake or
facilitate an information request or audit or inspection of any or all
Sub-Processors pursuant to paragraph 8.3 and:
8.4.1
your
rights under paragraph 8.3 will not apply to the extent inconsistent with
relevant contractual terms agreed with Sub-Processor(s);
8.4.2
to
the extent any information request, audit or inspection of any Sub-Processor
are permitted in accordance with this paragraph 8.4, equivalent restrictions and obligations on you
to those in paragraphs 8.3.1 to 8.3.10 (inclusive) will apply together with any
additional or more extensive restrictions and obligations applicable in the
circumstances; and
8.4.3
paragraphs
8.2 and 8.3 will be construed accordingly.
9.1
In
respect of any Personal Data Breach, we will, without undue delay:
9.1.1
notify
you of the Personal Data Breach; and
9.1.2
provide
you with details of the Personal Data Breach.
10.
Deletion
of Protected Data and copies
Following the end of the provision of the Services
and the PrimePRO Software (or any part) relating to the processing of Protected
Data we will dispose of Protected Data in accordance with our obligations under
our Agreement. We will have no liability (howsoever arising, including in
negligence) for any deletion or destruction of any such Protected Data
undertaken in accordance with our Agreement. PrimePRO shall (and shall ensure
that each of the Sub-Processors shall) delete the Protected Data (and all
copies) within a reasonable time after the Processing End Date except to the
extent that storage of any such data is required by Relevant Law (and, if so, PrimePRO
shall inform you of any such requirement and shall (and shall ensure any
relevant Sub-Processor shall) securely delete such data promptly once it is
permitted to do so under Relevant Law).
11.1
You
will indemnify and keep us indemnified in respect of all Data Protection Losses
suffered or incurred by, awarded against or agreed to be paid by, us and any
Sub-Processor arising from or in connection with any: non-compliance by you with
the Data Protection Laws;
processing carried out by us or any Sub-Processor pursuant to any Processing
Instruction that infringes any Data Protection Law; or breach by you of any of your
obligations under this DPA,
except to the extent that we are liable under paragraph 11.2.
11.2
We
will be liable for Data Protection Losses (howsoever arising, whether in
contract, tort (including negligence) or otherwise) under or in connection with
our Agreement:
11.2.1
only
to the extent caused by the processing of Protected Data under our Agreement
and directly resulting from our breach of our Agreement; and
11.2.2
in
no circumstances to the extent that any Data Protection Losses (or the
circumstances giving rise to them) are contributed to or caused by any breach
of our Agreement by you (including in accordance with paragraph 3.1.3).
11.3
If
one of us receives a compensation claim from a person relating to processing of
Protected Data in connection with our Agreement, the Services or the PrimePRO
Software, it will promptly provide the other one with notice and full details
of such claim.
11.4
We
each agree that you will not be entitled to claim back from us any part of any
compensation paid by you in respect of such damage to the extent that you are
liable to indemnify or otherwise compensate us in accordance with our
Agreement.
11.5
This
paragraph 11 is intended to apply to the allocation of
liability for Data Protection Losses as between us, including with respect to
compensation to Data Subjects, notwithstanding any provisions under Data
Protection Laws to the contrary, except:
11.5.1
to
the extent not permitted by Relevant Law (including Data Protection Laws); and
11.5.2
that
it does not affect the liability of either party to any Data Subject.
This DPA will survive
termination (for any reason) or expiry of our Agreement and continue until no
Protected Data remains in our or any Sub-Processor’s possession or control,
except that paragraphs 10 to 12 (inclusive) will continue indefinitely.
APPENDIX – DETAILS OF processing
Subject-matter
of processing:
The
supply of the Services and the provision of the PrimePRO Software.
Duration
of the processing:
Until the
earlier of final termination or final expiry of our Agreement.
Nature
and purpose of the processing:
Processing
in accordance with the rights and obligations of the parties under our
Agreement;
Processing as required to provide
the Services and the PrimePRO Software; and
Processing as initiated, requested
or instructed by Authorised Users in connection with their use of the Services,
the PrimePRO Software or by you, in each case in a manner consistent with our
Agreement.
Type
of Personal
Data:
Name,
title, address, marital status, gender, bank details, date of birth, telephone
number, mobile number, email address, nationality, photographs, employment
history, information contained within IDs and National Insurance number.
Categories
of Data Subjects:
Authorised
Users, candidates, agency workers, next-of-kin and referees.
Version: July 2023
This site uses cookies to help make your experience the best we can. You can find out more about the cookies we use by reading our cookie policy.