Introduction
Under each Contract, the Customer engages the Supplier to provide the Services and in providing the Services, the Supplier will or may be required to Process Personal Data on behalf of the Customer. To the extent of that Processing of Personal Data and for the purposes of these terms and conditions, the Customer is a ‘Controller’, and the Supplier is a ‘Processor’ for the purposes of the GDPR. As such, Article 28 of the GDPR requires that the details in this attachment are included in the contract between the Customer and the Supplier.
The parties must set out the subject matter and duration of the Processing, the nature and purpose of the Processing, the type of Personal Data and categories of data subjects – see appendix 1 to this attachment. If the Supplier determines the purposes and means of Processing, the Supplier is considered a ‘Controller’ in respect of that Processing in which case the Supplier needs to consider and address the different and additional provisions of the GDPR that apply.
The terms used in this attachment have the meanings given to them in the main definition section of these terms and conditions or in clause 13 of this attachment, or in the GDPR if not defined in these terms and conditions or in this attachment.