Skip to content
All legal documents
Legal

Data Processing Addendum

An overview of how Verdict processes personal data on behalf of its clients: the roles involved, how processing is scoped, and what the addendum covers.

Last updated: August 10, 2026

What this page is

This is a summary of how Verdict handles personal data when we process it on a client’s behalf. It is not the data processing addendum itself, and it does not create obligations.

The executable addendum, with its annexes describing the processing and the safeguards around it, is provided during contracting and signed alongside the main agreement.

Roles

In a client engagement, the client is the controller of the personal data involved and Verdict acts as a processor. We process that data on documented instructions from the client and for the purposes of delivering the engagement.

Verdict is a controller in its own right for a narrow set of data, such as the contact details of the people who administer the relationship. That is covered by our privacy policy rather than by the addendum.

Scope of processing

Compliance work does not usually require broad access to personal data, and we scope it deliberately so that it does not.

The categories of data, the categories of data subject, the purpose, and the duration of processing are set out in the annexes to the addendum for each engagement, rather than described generically here.

Security measures

We apply technical and organizational measures appropriate to the data being processed, covering access control, encryption in transit and at rest, logging, segregation between clients, and personnel confidentiality obligations.

The specific measures in force for an engagement are described in the addendum, so that what you are agreeing to is a stated set of controls rather than a general assurance.

Sub-processors

Where we use a sub-processor, it is engaged under written terms no less protective than those we owe the client, and we remain responsible for its performance.

The current sub-processor list and the notice period for changes are provided with the addendum, so clients can see who is involved before they sign and are told when that changes.

International transfers

Where personal data moves across borders, the transfer is made under an appropriate legal mechanism, and the mechanism relied on is identified in the addendum for the engagement in question.

Assistance, deletion, and audit

The addendum sets out how we assist a client with data subject requests, security incidents, and any assessments the client has to carry out, and what happens to data at the end of an engagement.

It also sets out the client’s audit rights over our processing, and how they are exercised.

The operative addendum is contractual

Nothing on this page is an undertaking. The data processing addendum that governs an engagement, together with its annexes, the sub-processor list, and the applicable transfer mechanism, is provided and negotiated when we are in contact with a client and executed as part of the wider agreement. If you are evaluating Verdict and your privacy team needs to review it, ask us and we will provide it.

Questions: privacy@verdictcorp.com

For the terms that would apply to your engagement, talk to us and we will walk you through them.

Talk to a Consultant