Data Processing Addendum
An overview of how Verdict processes personal data on behalf of its clients: the roles involved, how processing is scoped, and what the addendum covers.
What this page is
This is a summary of how Verdict handles personal data when we process it on a client’s behalf. It is not the data processing addendum itself, and it does not create obligations.
The executable addendum, with its annexes describing the processing and the safeguards around it, is provided during contracting and signed alongside the main agreement.
Roles
In a client engagement, the client is the controller of the personal data involved and Verdict acts as a processor. We process that data on documented instructions from the client and for the purposes of delivering the engagement.
Verdict is a controller in its own right for a narrow set of data, such as the contact details of the people who administer the relationship. That is covered by our privacy policy rather than by the addendum.
Scope of processing
Compliance work does not usually require broad access to personal data, and we scope it deliberately so that it does not.
The categories of data, the categories of data subject, the purpose, and the duration of processing are set out in the annexes to the addendum for each engagement, rather than described generically here.
Security measures
We apply technical and organizational measures appropriate to the data being processed, covering access control, encryption in transit and at rest, logging, segregation between clients, and personnel confidentiality obligations.
The specific measures in force for an engagement are described in the addendum, so that what you are agreeing to is a stated set of controls rather than a general assurance.
Sub-processors
Where we use a sub-processor, it is engaged under written terms no less protective than those we owe the client, and we remain responsible for its performance.
The current sub-processor list and the notice period for changes are provided with the addendum, so clients can see who is involved before they sign and are told when that changes.
International transfers
Where personal data moves across borders, the transfer is made under an appropriate legal mechanism, and the mechanism relied on is identified in the addendum for the engagement in question.
Assistance, deletion, and audit
The addendum sets out how we assist a client with data subject requests, security incidents, and any assessments the client has to carry out, and what happens to data at the end of an engagement.
It also sets out the client’s audit rights over our processing, and how they are exercised.
The operative addendum is contractual
Nothing on this page is an undertaking. The data processing addendum that governs an engagement, together with its annexes, the sub-processor list, and the applicable transfer mechanism, is provided and negotiated when we are in contact with a client and executed as part of the wider agreement. If you are evaluating Verdict and your privacy team needs to review it, ask us and we will provide it.
Questions: privacy@verdictcorp.com
For the terms that would apply to your engagement, talk to us and we will walk you through them.
Talk to a Consultant