Data Protection & Processing Terms
Controller–processor model, Article 28 processing terms, sub-processors and technical and organisational measures for EDD.
Roles
The customer organisation is controller for all investigation data. EDD processes it only on documented instructions, under a Data Processing Agreement (Art. 28 GDPR) that forms part of the service terms.
Article 28 commitments
Confidentiality of personnel; security measures under Art. 32; sub-processors engaged only with prior notice and equivalent obligations; help with data-subject requests, DPIAs and breach notification (without undue delay); deletion or return of data at the end of the engagement; audit cooperation.
Criminal-offence data (Art. 10)
Adverse media and conviction data are processed only where the customer is authorised by Union or Member State AML law. Findings carry their legal stage (allegation, charge, conviction, acquittal and so on) and are never shown as proven wrongdoing.
Technical & organisational measures
Encryption in transit; temporary session-only case storage with automatic deletion; minimal data collection; methodology version control; deterministic, explainable scoring; and audit trails in reports.
Sub-processors
Hosting and data-intelligence providers are listed in the Sub-processor Register supplied with the DPA. In the demo build, no investigation data is sent to third-party data sources.
Automated decision-making (Art. 22)
The platform gives risk recommendations only. A human at your organisation always makes the final decision, and any override is recorded with a rationale.
DPIA
Customers should complete a Data Protection Impact Assessment before using the platform in production. EDD provides supporting documentation on request.
