Data Processing Agreement (GDPR Article 28)
Version: DPA v1.0-draft
Controller: The Tenant customer ("Controller", "you")
Processor: [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("SafetyPermit", "Processor", "we")
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the SafetyPermit Terms of Service (ToS v1.0-draft). It governs the processing of personal data by SafetyPermit on behalf of the Tenant. Where this DPA conflicts with the Terms of Service on data-processing matters, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR, as applicable. Where the Controller operates in Australia or New Zealand, equivalent concepts under the Australian Privacy Act 1988 and the New Zealand Privacy Act 2020 apply by analogy.
2. Roles of the Parties
2.1 The Controller determines the purposes and means of processing the personal data described in Annex I.
2.2 The Processor processes that personal data only on behalf of, and on the documented instructions of, the Controller.
2.3 The Controller is responsible for the lawfulness of the processing it instructs, including establishing a lawful basis and providing notices to data subjects.
3. Subject-Matter, Duration, Nature & Purpose of Processing
3.1 Subject-matter. Provision of the SafetyPermit safety-permit management platform.
3.2 Duration. For the term of the Terms of Service plus any post-termination return/deletion and legally required retention period (see Section 11 and the Retention Schedule).
3.3 Nature of processing. Collection, recording, organisation, storage, retrieval, use, transmission (email/SMS/push notification), and deletion of personal data on the Controller's documented instruction or at end of term (subject to legal/safety-record retention), performed by automated means via cloud infrastructure.
3.4 Purpose. To enable the Controller to register workers and site staff, administer pre-work questionnaires and documentation, issue and manage safety permits, send safety-related notifications, and maintain audit and reporting records.
3.5 Categories of data subjects and personal data. As set out in Annex I.
4. Processor Obligations
The Processor will:
4.1 Process only on instructions. Process personal data only on the Controller's documented instructions (including the Terms and this DPA), unless required by applicable law, in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notice. The Processor will promptly inform the Controller if it considers an instruction infringes applicable data-protection law.
4.2 Confidentiality. Ensure that persons authorised to process the personal data are bound by appropriate confidentiality obligations.
4.3 Security (Article 32). Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as set out in Annex II.
4.4 Sub-processors. Engage sub-processors only as permitted under Section 7 and Annex III.
4.5 Assistance with data-subject rights. Taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to data-subject requests to exercise rights (access, rectification, restriction, portability, objection, and — subject to the constraint below — erasure). The platform provides self-service and admin data-access (export) tooling. Erasure constraint: because the Service is a workplace-safety system, permit and safety records (including who performed each action) are retained as a legal and safety-record obligation and are not erased or anonymised on data-subject request; the Processor assists the Controller with erasure requests only to the extent compatible with those retention obligations (GDPR Art. 17(3)(b)). See the Retention Schedule.
4.6 Assistance with compliance. Assist the Controller in ensuring compliance with obligations under Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and information available to the Processor.
4.7 Breach notification. Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, and provide information reasonably available to assist the Controller in meeting its own notification obligations. The Processor's incident-response process is described in the Breach Notification Procedure.
4.8 Deletion or return. At the Controller's choice, delete or return all personal data after the end of the provision of services, and delete existing copies, unless retention is required by applicable law (see Section 11 and the Retention Schedule).
4.9 Audits & information. Make available to the Controller information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice, confidentiality, frequency limits, and security constraints. The Processor may satisfy audit requests in whole or part through third-party certifications or reports where available.
5. Controller Obligations
The Controller will:
5.1 Provide documented, lawful instructions for processing.
5.2 Establish and maintain a lawful basis for the processing and provide required notices/consents to data subjects.
5.3 Be responsible for the accuracy, quality, and legality of the personal data and the means by which it acquired it.
5.4 Configure tenant settings (roles, retention-relevant options, notification recipients) consistent with its obligations.
6. International Data Transfers
6.1 The Processor and its sub-processors may process personal data in locations outside the Controller's country, including the United States and other regions, as set out in the Sub-processor List.
6.2 Where transfers are subject to the EU or UK GDPR, the parties will rely on an appropriate transfer mechanism, including the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs, together with any required supplementary measures.
6.3 For Australian and New Zealand personal data, the Processor will handle cross-border disclosures consistently with APP 8 (Australian Privacy Principles) and IPP 12 of the NZ Privacy Act 2020, respectively.
6.4 The specific transfer mechanism applicable to each sub-processor is recorded in the Sub-processor List and may be updated as mechanisms evolve.
7. Sub-processors
7.1 The Controller provides general authorisation for the Processor to engage the sub-processors listed in Annex III / the Sub-processor List.
7.2 The Processor will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for its sub-processors' performance.
7.3 The Processor will inform the Controller of intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable data-protection grounds. The notification mechanism and objection window are [TO BE CONFIRMED — e.g., updates to the maintained Sub-processor List with [N] days' notice].
8. Data-Subject Rights
The Processor will, to the extent it receives a request directly from a data subject relating to the Controller's data, promptly inform the Controller and not respond except on the Controller's instructions or as legally required.
9. Security Measures
The technical and organisational measures are described in Annex II. The Processor may update these measures provided the level of security is not materially reduced.
10. Liability & Indemnity
Liability arising from this DPA is subject to the limitations and exclusions in the Terms of Service, except where applicable data-protection law provides otherwise (e.g., direct liability of a processor under Article 82). [PLACEHOLDER — confirm with counsel.]
11. Term, Deletion & Return
11.1 This DPA continues for as long as the Processor processes personal data on behalf of the Controller.
11.2 On termination, the Processor will delete or return personal data per Section 4.8, subject to legally required retention. Specific retention periods and disposal methods per data category are in the Retention Schedule.
Annex I — Description of Processing
A. Categories of Data Subjects
- Workers checking in to sites (including subcontractor workers and returning workers).
- Site staff and on-site issuers/team members.
- Administrative users (e.g., OrganisationAdministrator, SafetyAdministrator, PermitIssuer, SiteTeam, Receiver).
B. Categories of Personal Data
- Identity data — names, role, employer/subcontractor, worker identifiers.
- Contact data — email address, phone number.
- Pre-work questionnaire answers — including free-text responses that may contain health-related information (e.g., fitness-to-work, medical declarations). Where this constitutes special-category data under Article 9, the Controller is responsible for establishing an appropriate condition for processing.
- Selfies / checkout photos — facial images captured at check-in/checkout. These are biometric-adjacent; if used for unique identification they may constitute biometric data under Article 9. Current use is for visual verification/audit, not automated biometric matching.
- Technical/device data — IP addresses, device push tokens (APNs), request logs, rate-limit records, and authentication artefacts (magic-link/password-reset challenges, refresh tokens).
- Communications metadata and content — email/SMS notification bodies and audit logs.
C. Nature & Purpose
As set out in Section 3 of this DPA.
D. Duration
As set out in Section 3.2 and the Retention Schedule.
Annex II — Technical & Organisational Security Measures
[PLACEHOLDER — confirm and expand with security/DPO. The following reflects engineering's current understanding.]
- Multi-tenant isolation — tenant-scoped data access controls and tenant-scoped routing as defence against cross-tenant access ("tenant creep").
- Access control — role-based access; least-privilege administrative roles; authentication via password and magic-link flows; security-stamp validation for prompt revocation of stale sessions.
- Encryption — TLS in transit; encryption at rest provided by Azure SQL and Azure Blob Storage; encrypted returning-worker/identity cookies.
- Network & infrastructure — hosting on Microsoft Azure App Service with managed SQL and Blob Storage; staging/UAT/production separation.
- Logging & monitoring — request logging, communication audit logging, permit audit logging, rate-limiting.
- Data minimisation & retention — automated purge of expired transient secrets (magic-login codes, password-reset tokens) and time-boxed operational logs per the Retention Schedule. Safety/permit records are retained, not anonymised.
- Secret management — connection strings and credentials managed via environment configuration [SECRET-MANAGEMENT DETAIL TO CONFIRM].
- Backup & recovery — [BACKUP/DR DETAIL TO CONFIRM].
Annex III — Authorised Sub-processors
The current list of authorised sub-processors, with purpose, region, and transfer mechanism, is maintained in the Sub-processor List and forms part of this DPA. The Controller's general authorisation under Section 7 extends to the sub-processors listed there, as updated in accordance with Section 7.3.
DPA v1.0-draft — engineering-prepared draft, pending legal review.