Viewee
Start free
Pricing
Sign in
← Legal and assurance

DRAFT - requires solicitor review before signature

Controller-to-processor terms under Article 28 UK GDPR | Version [ ] | Date [ ]

Parties and status

Registered office: 167-169 Great Portland Street 5th Floor, London, England, W1W 5PF

Viewee Limited is registered with the Information Commissioner's Office (ICO). Reference number: ZB685073

It forms part of the [Pilot Agreement / Services Agreement] dated [date] (the "Agreement"). Capitalised terms not defined here have the meaning in the Agreement.

1. Scope, roles and precedence

  1. This DPA applies where Processor processes Personal Data on behalf of Controller in providing the Viewee feedback-to-action service.

  2. The parties acknowledge that Controller is controller and Processor is processor. Each party will comply with Data Protection Laws applicable to it, including the UK GDPR and Data Protection Act 2018.

  3. If this DPA conflicts with the Agreement on processing Personal Data, this DPA prevails. The Annexes form part of this DPA.

2. Documented instructions

  1. Processor will process Personal Data only on Controller's documented instructions, including regarding transfers, unless UK law requires otherwise. In that case Processor will inform Controller before processing unless prohibited for important public-interest reasons.

  2. The Agreement, this DPA, Controller's documented configuration and support requests are the complete instructions at commencement. Additional instructions must be consistent with Data Protection Laws and may be subject to reasonable agreed charges where they change the Services.

  3. Processor will immediately inform Controller if, in its opinion, an instruction infringes Data Protection Laws and may suspend the affected processing pending clarification.

3. Confidentiality and personnel

Processor will ensure persons authorised to process Personal Data are bound by confidentiality obligations, receive appropriate data-protection and security training, and access Personal Data only as needed for their duties.

4. Security

  1. Taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing and risks to individuals, Processor will implement and maintain appropriate technical and organisational measures. The initial measures are in Annex 2.

  2. Processor will not materially reduce the overall security of the Services during the term. Controller remains responsible for secure use, user access, endpoints, exports and configurations under its control.

5. Personal data breaches

  1. Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data at [security contact/email].

  2. The notice will, as information becomes available, describe the nature of the breach, affected data subjects and records, likely consequences, measures taken or proposed, and a contact point. Processor will provide reasonable cooperation for Controller's assessment and notifications.

  3. Processor's notice is not an admission of fault or liability. Controller is responsible for determining whether to notify the ICO or individuals.

6. Data-subject rights and regulatory support

  1. Taking account of the nature of processing, Processor will provide reasonable assistance by appropriate technical and organisational measures so Controller can respond to data-subject requests.

  2. If Processor receives a request relating to Controller Personal Data, it will promptly notify Controller and will not respond except on documented instruction or where required by law.

  3. Processor will reasonably assist Controller with security obligations, breach notifications, DPIAs and prior consultation, taking account of the nature of processing and information available to Processor.

7. Subprocessors

  1. Controller gives [general / specific] written authorisation for subprocessors listed at [URL / Annex 3]. Processor will give at least [30] days' prior written notice of an intended addition or replacement, allowing Controller to object on reasonable data-protection grounds.

  2. Processor will impose written obligations on each subprocessor that provide no less protection than the relevant obligations in this DPA. Processor remains fully liable to Controller for the subprocessor's performance of those obligations.

  3. If the parties cannot resolve a valid objection, Processor may offer a commercially reasonable change or Controller may terminate the affected Services without penalty before the change takes effect.

8. International transfers

  1. The Services will host and ordinarily process Controller Personal Data in [United Kingdom / EEA: specify regions]. Remote access and support locations are [list]. Processor will not transfer Personal Data outside the UK except on documented instruction and with a lawful transfer mechanism.

  2. Where a restricted transfer is made, the parties will use [UK International Data Transfer Agreement / UK Addendum to EU Standard Contractual Clauses / adequacy regulations / other lawful mechanism], complete any required transfer risk assessment and apply supplementary measures as needed.

  3. Processor will provide information reasonably required to document the transfer and notify Controller if the mechanism can no longer be complied with.

9. Information, audits and inspections

  1. Processor will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA, including relevant independent audit reports or certifications where available.

  2. No more than once annually, and additionally after a material breach or regulator request, Controller may audit the relevant controls on at least [30] days' notice. Audits must minimise disruption, protect other customers and confidential information, and use an independent auditor bound by confidentiality. Controller bears its costs unless the audit finds a material breach by Processor.

  3. Nothing limits a competent supervisory authority's powers.

10. Return, deletion and duration

  1. This DPA starts on [date] and continues while Processor processes Controller Personal Data.

  2. On expiry or termination, at Controller's choice, Processor will return or make available an export of Controller Personal Data and delete remaining copies within [30] days, unless UK law requires storage. Backup copies will be isolated from ordinary use and deleted on the normal cycle within [90] days.

  3. Controller must request/download its export by [deadline]. Processor will confirm deletion on request. Confidentiality and provisions intended to survive will continue.

11. Records, regulator and general terms

  1. Processor will maintain records required by Article 30(2), cooperate with the ICO where required, and tell Controller of a legally binding disclosure request unless prohibited.

  2. [Liability caps and exclusions in the Agreement apply / insert negotiated data-protection liability terms].

  3. This DPA is governed by the laws of [England and Wales / jurisdiction], and courts of [jurisdiction] have [exclusive] jurisdiction, subject to regulator and data-subject rights.

Annex 1 - Processing details

ItemDescription
Subject matterHosting and operation of Viewee's feedback collection, analysis, dashboard, action-tracking, reporting, support and security functions for an adult social care pilot.
DurationEight-week pilot plus agreed export/exit period and any legally required or backup retention.
Nature and purposeCollect, transmit, validate, store, organise, classify, summarise, display, search, report, export, support, secure and delete feedback and resulting action records, solely to provide the Services.
Data subjectsResidents; family members, friends, advocates and representatives; care-home staff, agency staff, managers and professionals named in feedback; authorised users.
Personal dataNames and contact details where supplied; relationship/role; home or unit; resident/customer references; free-text feedback; ratings; dates/times; staff assignments; action notes/status/outcomes; account, device, audit and security logs.
Special categories / sensitive contentFeedback may reveal physical or mental health, disability, care needs, racial or ethnic origin, religion, sexual orientation or other Article 9 data; it may include safeguarding or criminal-offence information. Controller must identify lawful conditions and minimise collection.
FrequencyContinuous during the pilot as users submit feedback and staff manage actions.
Controller contactsPrivacy: [ ]. Security: [ ]. Instructions: [ ].

Annex 2 - Technical and organisational measures

Annex 3 - Approved subprocessors

SubprocessorServiceProcessing locationTransfer mechanism
[Cloud hosting provider]Application/database hosting[UK/EEA region][Not restricted / mechanism]
[Email/notification provider]Transactional notifications[ ][ ]
[Monitoring/support provider]Service monitoring/support[ ][ ]
[AI/analytics provider, if any][Classification/summarisation][ ][ ]

Signatures

For ControllerFor Processor

Name: [ ]

Title: [ ]

Signature: [ ]

Date: [ ]

Name: [ ]

Title: [ ]

Signature: [ ]

Date: [ ]

Footnotes and sources

  1. Information Commissioner's Office (ICO), Data protection impact assessments (DPIAs), including "How do we do a DPIA?" and "When do we need to do a DPIA?" (accessed 16 September 2026).

  2. UK GDPR, Article 35, Data protection impact assessment.

  3. UK GDPR, Article 28, Processor.

  4. Data Protection Act 2018, legislation.gov.uk.

DRAFT - requires solicitor review before signature