Data Processing Addendum
Version: 1.0
Effective Date: 20 August 2026
Last Updated: 20 August 2026
This Data Processing Addendum applies where Associate Enterprises Limited trading as Assent (“Processor”) processes Personal Data on behalf of a customer (“Controller”) in connection with the Services.
This DPA forms part of the agreement governing the Services and is incorporated by reference into the applicable Master Services Agreement, Statement of Work, Order Form or other services agreement.
1. Definitions
In this DPA, “Applicable Data Protection Law” means all applicable laws and regulations relating to the processing of Personal Data, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and where applicable Regulation (EU) 2016/679 (“EU GDPR”). Terms such as Controller, Processor, Personal Data, Processing, Data Subject and Personal Data Breach shall have the meanings given to them under Applicable Data Protection Law.
2. Scope and Duration
This DPA shall take effect on the Effective Date of the Agreement and shall remain in force for the duration of any Processing carried out by the Processor on behalf of the Controller. In the event of any conflict between this DPA and the Master Services Agreement concerning the Processing of Personal Data, the terms of this DPA shall prevail.
3. Nature of the Relationship
The parties acknowledge that, in respect of Personal Data processed under the Agreement, the Controller determines the purposes and means of Processing and the Processor processes Personal Data solely on behalf of the Controller. The Processor shall comply with all Applicable Data Protection Law applicable to processors and the Controller shall comply with all Applicable Data Protection Law applicable to controllers.
4. Processing Instructions
The Processor shall process Personal Data only on documented instructions from the Controller unless otherwise required by applicable law. Where the Processor considers that an instruction infringes Applicable Data Protection Law, it shall notify the Controller without undue delay.
5. Confidentiality
The Processor shall ensure that all persons authorised to process Personal Data are subject to an appropriate duty of confidentiality and shall process Personal Data only as necessary for the provision of the Services.
6. Security Measures
The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access. Such measures shall take account of the nature of the Personal Data processed, the associated risks and the current state of technological development.
7. Subprocessors
The Controller grants the Processor general authorisation to appoint subprocessors. The Processor shall inform the Controller of any intended addition or replacement of a subprocessor and provide the Controller with an opportunity to object on reasonable data protection grounds within thirty (30) days of notification.
The Processor shall ensure that each subprocessor is bound by written obligations that provide a level of protection substantially equivalent to those contained in this DPA. The Processor shall remain responsible for the performance of its subprocessors’ obligations relating to the Processing of Personal Data.
The Processor may utilise employees, contractors and consultants acting under its authority and subject to confidentiality obligations in connection with the delivery of the Services.
The Processor may also appoint subprocessors where reasonably required for the provision of the Services. Details of material third-party subprocessors are available at: https://www.clemarkgroup.com/trust/sub-processor-list/
8. Personal Data Breaches
The Processor shall notify the Controller without undue delay and, in any event, within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller. Such notification shall include all information reasonably available to the Processor regarding the nature of the breach, the categories of Personal Data affected, the likely consequences of the breach and the measures taken or proposed to address it.
9. Assistance to the Controller
Taking into account the nature of the Processing, the Processor shall provide reasonable assistance to the Controller in fulfilling its obligations under Applicable Data Protection Law, including responding to requests from Data Subjects and complying with obligations relating to security, breach notification, data protection impact assessments and consultations with supervisory authorities.
10. Compliance Information and Audit Rights
The Processor shall maintain records and information reasonably necessary to demonstrate compliance with this DPA and shall make such information available to the Controller upon reasonable written request. Any audit or inspection shall be conducted during normal business hours, on reasonable notice, and in a manner that does not unreasonably disrupt the Processor’s business operations.
11. International Transfers
The Processor shall not transfer Personal Data outside the United Kingdom, the European Economic Area, or a jurisdiction recognised by the relevant competent authority as providing an adequate level of protection, unless appropriate safeguards have been implemented in accordance with Applicable Data Protection Law.
12. Return and Deletion of Data
Upon termination or expiry of the Services, the Processor shall, at the Controller’s written request, return or securely delete Personal Data processed on behalf of the Controller unless retention is required by applicable law, regulatory obligations, insurance requirements or legitimate record-keeping obligations. Any retained Personal Data shall remain protected in accordance with the terms of this DPA until it is deleted.
13. Liability
The liability of the parties arising under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Master Services Agreement.
14. Changes
The Processor may update this DPA from time to time to reflect changes in law, services or processing activities. Material changes will be notified through the Trust Centre.
Schedule 1 – Processing Description
The subject matter of the Processing is the provision of consultancy, auditing, compliance, information security, governance, risk management and related professional services under the Master Services Agreement.
The duration of the Processing shall be the term of the Master Services Agreement together with any applicable retention period required by law or legitimate business need.
The nature and purpose of the Processing includes the provision of consulting services, audits, assessments, training, project management, customer support and administration of the Services.
The categories of Data Subjects may include the Controller’s employees, workers, contractors, representatives, suppliers and customers.
The categories of Personal Data may include names, business contact details, job titles, email addresses, telephone numbers, audit records, training records, compliance records and such other Personal Data as the Controller makes available to the Processor in connection with the Services.
Special Category Personal Data: None anticipated in the normal provision of the Services unless expressly provided by the Controller.
