Data protection
Data processing agreement
Published in full rather than sent on request, so your data protection officer can read it before anybody commits to anything.
How to use this page. Print it, or save it as a PDF from your browser's print dialogue. It is formatted to print cleanly. A signed copy on your own template is available instead if your organisation requires one — email contact@riseainternational.co.uk.
A note on what this is. This agreement was drafted against the requirements of Article 28(3) of the UK GDPR. It has not been reviewed by a solicitor. If your legal team wants changes, they will be accepted rather than argued about.
1. Parties and roles
This agreement is between your organisation (the Controller) and RISEA International, a sole trader business operated by Lynda Smart of Pontypridd, Wales (the Processor).
The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller's behalf.
2. Subject matter, duration, nature and purpose
Subject matter. Administration of a RISEA Canon Standard certification, including self-assessment, evidence review, audit and the issuing of a certificate.
Duration. The term of the certification licence, plus the retention period in clause 10.
Nature and purpose. Collection, storage, review, analysis and return or deletion of evidence submitted by the Controller for the purpose of assessing conformance against the standard.
3. Types of personal data and categories of data subject
Categories of data subject: the Controller's employees, volunteers and contractors.
Types of personal data: names, job roles, work email addresses, work telephone numbers, training completion records, and any personal data incidentally contained in evidence the Controller chooses to submit.
Not processed. The Processor does not require, request or accept personal data relating to the Controller's learners, service users, residents or clients. Evidence submitted for audit must be redacted or anonymised by the Controller before submission. If unredacted third-party personal data is received, the Processor will notify the Controller and securely delete it.
No special category data under Article 9 and no criminal offence data under Article 10 is requested or should be submitted.
4. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions, including on transfers to a third country, unless required to do otherwise by law. Where the Processor is required by law to process otherwise, it will inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so.
This agreement, together with the certification licence, constitutes the Controller's documented instructions. Further instructions may be given in writing at any time.
The Processor will inform the Controller immediately if, in its opinion, an instruction infringes the UK GDPR or other data protection law.
5. Confidentiality
The Processor ensures that any person authorised to process the personal data is subject to a binding duty of confidentiality. At present the only person with access is Lynda Smart. Should that change, no additional person will be given access until a written confidentiality undertaking is in place, and the Controller will be notified.
6. Security
The Processor implements appropriate technical and organisational measures under Article 32, appropriate to the risk. Current measures:
- Evidence is held in an access-controlled cloud store with multi-factor authentication.
- Devices used to access it use full-disk encryption and automatic screen locking.
- Data is encrypted in transit and at rest by the storage provider.
- Access is limited to the single named individual in clause 5.
- Evidence is not copied to removable media.
- The volume of personal data held is deliberately minimised, as set out in clause 3.
7. Sub-processors
The Processor will not engage another processor without the Controller's prior specific or general written authorisation. Where general authorisation is given, the Processor will inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object.
Where a sub-processor is engaged, the same data protection obligations set out in this agreement will be imposed on it by contract, and the Processor remains fully liable to the Controller for its performance.
Current sub-processors: the cloud storage and email provider used to receive and hold evidence. The current provider will be named in writing at the point of contract, and any change notified in advance.
8. Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III of the UK GDPR.
The Processor will notify the Controller without undue delay if it receives a request directly from a data subject, and will not respond to that request itself except on the Controller's documented instructions.
9. Assistance with security, breaches and impact assessments
The Processor assists the Controller in ensuring compliance with its obligations under Articles 32 to 36, taking into account the nature of processing and the information available to the Processor. This includes security of processing, notification of personal data breaches to the Information Commissioner and to data subjects, data protection impact assessments, and prior consultation.
The Processor will notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs in order to meet its own notification obligations.
10. Deletion or return of data
At the end of the provision of services, the Processor will, at the Controller's choice, delete or return all personal data to the Controller, and delete existing copies, unless law requires it to be stored.
Default position if the Controller expresses no choice: evidence submitted for audit is deleted 90 days after the certificate is issued. The certificate record itself — organisation name, tier, date of issue, date of expiry, and the name and role of the named internal lead — is retained for the life of the certification plus six years, because it is the record that makes the certification meaningful and auditable.
11. Audits and demonstrating compliance
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations in Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Audits will be conducted on reasonable notice and during normal working hours.
12. International transfers
Personal data is stored within the United Kingdom or the European Economic Area. No transfer to a third country will be made without the Controller's prior written authorisation and an appropriate transfer mechanism under Chapter V of the UK GDPR.
13. Precedence
Where this agreement conflicts with the certification licence, this agreement prevails in respect of data protection. Where the Controller has its own data processing agreement it requires suppliers to sign, the Controller's version may be used instead.
Last reviewed: August 2026. Questions to contact@riseainternational.co.uk.