Data processing agreement
Concluded where Lodline acts as processor on a client's instruction. Where we act as controller — enquiries, our own compliance, factual reports commissioned by the client — this template does not apply and the privacy policy governs.
1. Subject matter and duration
Processing is carried out solely for the performance of the engagement described in the engagement letter, and for its duration.
2. Instructions
We process only on documented instruction from the controller. Where an instruction appears to infringe applicable data protection law, we say so before acting.
3. Confidentiality
Everyone with access is bound by confidentiality. This is contractual: Lodline is not an advokatbyrå and advokatsekretess does not apply. Where privilege matters to the matter, an external advokat is engaged as co-adviser and that is stated before the engagement begins.
4. Security
Access on a need-to-know basis · encryption in transit and at rest · logging of access to matter files · segregation of client data · annual review.
5. Subprocessors
General authorisation, with the published list and notice of changes before they take effect. The controller may object; if the objection cannot be resolved, either party may terminate the affected part of the engagement.
6. Data subject rights
We assist the controller in responding, within the time available to the controller.
7. Breach notification
Without undue delay and in any event within 24 hours of becoming aware, with the facts known at that point rather than a completed investigation.
8. Deletion and return
On termination, at the controller's choice: return or deletion, save where retention is required by law. What is retained, and on what basis, is stated in writing.
9. Audit
The controller may audit compliance once per calendar year on reasonable notice, or more often following a breach.
10. Transfers
None outside the EEA without prior written agreement identifying the mechanism relied on.