When this schedule applies
This schedule applies only where an identified customer is controller and LOOKPORT LTD processes personal data on that customer’s behalf. It must be incorporated into the signed service agreement. Lookport’s independent controller activities, such as handling its own business enquiries, are covered separately. The factual role takes precedence over a label in a contract.
Instructions and confidentiality
The processor will process the specified personal data only on documented controller instructions, including instructions about transfers, unless law requires otherwise. It will notify the controller of a legal requirement where permitted and alert the controller if an instruction appears to infringe applicable data protection law. Persons authorised to process the data must be bound by confidentiality.
Security, assistance and incidents
The parties must agree appropriate technical and organisational measures reflecting the risks, including access control, authentication, encryption where appropriate, backup and recovery, monitoring and regular review. The processor will assist with data rights requests and, taking account of the processing and information available, security, breach response, impact assessments and consultation duties.
The processor will notify the controller without undue delay after becoming aware of a personal data breach and provide available information and continuing assistance. This does not replace the controller’s own assessment of notification duties or deadlines.
Subprocessors and transfers
Subprocessors require the agreed specific or general written authorisation. Under general authorisation, the controller must receive notice of changes and a meaningful opportunity to object on data protection grounds. Equivalent data protection obligations must flow down to subprocessors, and the processor remains responsible for their performance as required by law. Restricted international transfers require a valid mechanism and any necessary supplementary safeguards.
Audit and end of service
The processor will make available information needed to demonstrate compliance and allow and contribute to appropriate audits and inspections. At the controller’s choice, it will return or delete the personal data at the end of service and delete existing copies unless retention is legally required. The parties must specify secure export, backup expiry and evidence of completion.
Annexes required before signature
Complete the subject matter, duration, purpose, processing activities, data types and categories of people. Record the controller’s rights and obligations, incident contacts, approved subprocessors, processing countries, transfer safeguards, actual security measures, retention and deletion periods. This schedule is incomplete without those annexes and must not be presented as an executed data processing agreement.
Contacts & official information
ICO registration reference: ZB682473
LOOKPORT LTD on Companies House ↗alex@lookport.co.uk — privacy & enquiriesContact the Information Commissioner ↗Ticket and project support