Legal · draft template, have it reviewed by counsel

Data Protection & Processing Terms

Controller–processor model, Article 28 processing terms, sub-processors and technical and organisational measures for EDD.

Roles

The customer organisation is controller for all investigation data. EDD processes it only on documented instructions, under a Data Processing Agreement (Art. 28 GDPR) that forms part of the service terms.

Article 28 commitments

Confidentiality of personnel; security measures under Art. 32; sub-processors engaged only with prior notice and equivalent obligations; help with data-subject requests, DPIAs and breach notification (without undue delay); deletion or return of data at the end of the engagement; audit cooperation.

Criminal-offence data (Art. 10)

Adverse media and conviction data are processed only where the customer is authorised by Union or Member State AML law. Findings carry their legal stage (allegation, charge, conviction, acquittal and so on) and are never shown as proven wrongdoing.

Technical & organisational measures

Encryption in transit; temporary session-only case storage with automatic deletion; minimal data collection; methodology version control; deterministic, explainable scoring; and audit trails in reports.

Sub-processors

Hosting and data-intelligence providers are listed in the Sub-processor Register supplied with the DPA. In the demo build, no investigation data is sent to third-party data sources.

Automated decision-making (Art. 22)

The platform gives risk recommendations only. A human at your organisation always makes the final decision, and any override is recorded with a rationale.

DPIA

Customers should complete a Data Protection Impact Assessment before using the platform in production. EDD provides supporting documentation on request.