Data Processing Agreement
| DAYONE CLEARANCE LTD DATA PROCESSING AGREEMENT Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 |
| ⚠️ ACTION REQUIRED BEFORE SENDING TO CLIENTS: Replace [CLIENT COMPANY NAME] and [CLIENT REGISTERED ADDRESS] on the parties page with each client’s details before sending. All Dayone Clearance details, including the ICO registration number, are already complete. |
PARTIES TO THIS AGREEMENT
| DATA CONTROLLER | [CLIENT COMPANY NAME] (“the Client” or “Controller”)Registered address: [CLIENT REGISTERED ADDRESS] |
| DATA PROCESSOR | Dayone Clearance Ltd (“Dayone” or “Processor”)Registered address: 61 Bridge Street, Kington, HR5 3DJCompany No. 17181162 | Registered in England & WalesICO Registration No. ZC155486 |
This Agreement is entered into on the date of last signature below and governs the processing of personal data by Dayone Clearance Ltd on behalf of the Client in connection with the provision of HR onboarding and pre-employment compliance services (“the Services”).
1. DEFINITIONS
In this Agreement, the following terms shall have the meanings set out below:
| “Applicable Data Protection Law” | means the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, the Data Protection Act 2018, and any other applicable UK data protection legislation. |
| “Controller” | means the Client, being the natural or legal person who determines the purposes and means of processing personal data. |
| “Processor” | means Dayone Clearance Ltd, being the natural or legal person who processes personal data on behalf of the Controller. |
| “Personal Data” | has the meaning given in Article 4 UK GDPR, any information relating to an identified or identifiable natural person. |
| “Special Category Data” | means personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, sexual orientation, or criminal convictions and offences data. |
| “Processing” | has the meaning given in Article 4 UK GDPR, any operation performed on personal data, including collection, recording, storage, use, disclosure, or erasure. |
| “Data Subject” | means any identified or identifiable natural person whose personal data is processed under this Agreement, principally job candidates and prospective employees of the Controller. |
| “Sub-Processor” | means any third party appointed by the Processor to process personal data on behalf of the Controller. |
| “Security Incident” | means any confirmed or suspected breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. |
2. SUBJECT MATTER AND DETAILS OF PROCESSING
2.1 Nature and Purpose of Processing
The Processor shall process personal data solely for the purpose of providing HR onboarding and pre-employment compliance services to the Controller, including:
- Conducting Digital Right to Work (IDVT) verification to establish a Statutory Excuse under the Immigration, Asylum and Nationality Act 2006
- Coordinating Baseline Personnel Security Standard (BPSS) screening including identity verification, employment history verification, criminal record checks, and right to work checks
- Coordinating Disclosure and Barring Service (DBS) checks at Basic, Standard, or Enhanced level as instructed by the Controller
- Collecting and processing new starter personal data for payroll set-up, including bank details, National Insurance numbers, and tax information
- Drafting and managing employment contracts and associated documentation
- Managing candidate communications throughout the onboarding process
- Producing Audit Evidence Packs documenting the completion of all compliance checks
2.2 Categories of Personal Data Processed
The Processor may process the following categories of personal data:
- Identity data: full legal name, date of birth, nationality
- Contact data: email address, telephone number, home address
- Identity document data: passport details, driving licence details, biometric residence permit details
- Employment history data: previous employer names, dates of employment, roles held, reasons for leaving
- Financial data: bank account details, National Insurance number, tax code, P45 information
- Criminal record data: DBS certificate results (where applicable and instructed by the Controller)
- Right to work documentation: copies of identity and immigration documents as required by UK law
2.3 Special Category and Criminal Convictions Data
The Processor may process criminal convictions and offences data where DBS checks are instructed by the Controller. The legal basis for this processing is the legitimate interests of the Controller in compliance with applicable employment law obligations, or as otherwise specified in the Controller’s instructions. The Processor shall process such data only to the extent strictly necessary for the performance of the Services.
2.4 Categories of Data Subjects
The personal data processed under this Agreement relates to the following categories of data subjects: prospective employees and job candidates of the Controller who have accepted a conditional or unconditional offer of employment.
3. OBLIGATIONS OF THE PROCESSOR
The Processor shall, in relation to all personal data processed under this Agreement:
- Process personal data only on the documented instructions of the Controller, and only for the purposes set out in Clause 2 of this Agreement, unless required to do so by applicable law
- Ensure that all persons authorised to process personal data have committed to appropriate confidentiality obligations
- Implement and maintain appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access
- Not engage any Sub-Processor without the prior written consent of the Controller, save as set out in Clause 6 of this Agreement
- Assist the Controller in responding to requests from data subjects exercising their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, and portability
- Assist the Controller in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with the ICO
- At the choice of the Controller, delete or return all personal data to the Controller at the termination of the Services, and delete existing copies unless applicable law requires retention
- Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this Agreement, and allow for and contribute to audits and inspections conducted by the Controller or its authorised auditor
- Notify the Controller promptly if, in the Processor’s opinion, any instruction from the Controller infringes Applicable Data Protection Law
4. OBLIGATIONS OF THE CONTROLLER
The Controller warrants and represents that:
- It has a lawful basis for the processing activities described in Clause 2 of this Agreement, including where applicable the explicit consent of the relevant data subjects or a legitimate interest assessment
- It has provided data subjects with appropriate privacy information in accordance with Articles 13 and 14 UK GDPR prior to their personal data being provided to the Processor
- The personal data provided to the Processor is accurate and, where applicable, up to date
- It shall promptly inform the Processor of any changes to its instructions regarding the processing of personal data
- It shall not instruct the Processor to process personal data in a manner that would cause the Processor to breach Applicable Data Protection Law
5. SECURITY MEASURES
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate:
- Storage of all personal data on European-owned, GDPR-sovereign infrastructure with no transfer to or processing by providers subject to US CLOUD Act jurisdiction or equivalent extra-territorial data access legislation
- Encryption of personal data in transit and at rest
- Ongoing confidentiality, integrity, availability, and resilience of processing systems
- The ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident
- A process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures
- Access controls ensuring that personal data is accessible only to authorised personnel on a need-to-know basis
6. SUB-PROCESSORS
6.1 The Controller hereby grants the Processor general written authorisation to engage the following categories of Sub-Processor for the purposes of delivering the Services:
| Sub-Processor Category | Purpose |
| Accredited background screening provider | Conducting BPSS screening, DBS checks, employment history verification, and criminal record checks on behalf of the Processor |
| Identity Document Validation Technology (IDVT) provider | Conducting certified Digital Right to Work verification |
| Electronic signature provider | Managing employment contract e-signature processes |
6.2 The Processor shall ensure that any Sub-Processor is bound by data protection obligations equivalent to those set out in this Agreement, and shall remain fully liable to the Controller for the performance of its Sub-Processors.
6.3 The Processor shall notify the Controller of any intended changes to the Sub-Processors listed above and the Controller shall have the right to object to such changes on reasonable grounds within 14 days of notification.
7. INTERNATIONAL TRANSFERS OF PERSONAL DATA
The Processor shall not transfer personal data outside the United Kingdom or the European Economic Area without the prior written consent of the Controller. The Processor confirms that all data processing and storage under this Agreement takes place on European-owned infrastructure located within the EEA, ensuring full compliance with UK GDPR transfer restrictions.
8. SECURITY INCIDENTS AND BREACH NOTIFICATION
8.1 In the event of a confirmed or suspected Security Incident, the Processor shall notify the Controller without undue delay and, where feasible, no later than 48 hours after becoming aware of the incident.
8.2 Such notification shall include, to the extent then known:
- A description of the nature of the Security Incident, including the categories and approximate number of data subjects and personal data records affected
- The name and contact details of the Processor’s data protection contact
- A description of the likely consequences of the Security Incident
- A description of the measures taken or proposed to address the Security Incident and to mitigate its possible adverse effects
8.3 The Processor shall cooperate fully with the Controller in any investigation, regulatory notification, or remediation activity arising from a Security Incident.
9. DATA SUBJECT RIGHTS
The Processor shall provide reasonable assistance to the Controller in responding to requests from data subjects exercising their rights under Applicable Data Protection Law. Where a data subject contacts the Processor directly, the Processor shall promptly redirect the request to the Controller and shall not respond to the data subject directly unless instructed to do so by the Controller.
10. RETENTION AND DELETION OF PERSONAL DATA
10.1 The Processor shall retain personal data only for as long as is necessary to fulfil the purposes for which it was collected and to comply with applicable legal obligations.
10.2 Unless otherwise agreed in writing, personal data shall be retained for a period of 12 months following the completion of the relevant engagement, after which it shall be securely deleted or returned to the Controller at the Controller’s election.
10.3 Notwithstanding the above, the Processor may retain Audit Evidence Pack documentation for a period of 3 years to comply with UK Statutory Excuse requirements under the Immigration, Asylum and Nationality Act 2006.
11. AUDIT AND INSPECTION RIGHTS
The Processor shall, upon reasonable written notice of not less than 14 days, make available to the Controller all information reasonably necessary to demonstrate compliance with this Agreement and shall permit the Controller or its authorised representative to conduct audits or inspections of the Processor’s data processing activities, provided that such audits are conducted during normal business hours and at the Controller’s expense.
12. TERM AND TERMINATION
12.1 This Agreement shall come into force on the date of last signature and shall continue until the termination of the Services Agreement between the parties.
12.2 Upon termination, the Processor shall, at the election of the Controller, securely delete or return all personal data processed under this Agreement, subject to Clause 10.3 above.
13. GOVERNING LAW AND JURISDICTION
This Agreement shall be governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute arising under or in connection with this Agreement.
14. ENTIRE AGREEMENT
This Agreement constitutes the entire agreement between the parties in relation to data processing and supersedes all prior agreements, representations, and understandings in respect of the same subject matter. In the event of any conflict between this Agreement and any other agreement between the parties, this Agreement shall prevail in respect of data protection matters.
| EXECUTION — SIGNATURES |
This Agreement is entered into by the parties as of the date of last signature below. Each party confirms that it has read and understood this Agreement and has authority to enter into it on behalf of the organisation named above.
| FOR AND ON BEHALF OF THE DATA CONTROLLER: | FOR AND ON BEHALF OF THE DATA PROCESSOR: |
| Signature | Signature |
| Full name | Abu-Bakarr Kamara |
| Title / Position | Director |
| Company | Dayone Clearance Ltd |
| Date | Date |
| DATA PROCESSOR | Dayone Clearance Ltd | Company No. 17181162Signed by: Abu-Bakarr Kamara, Director |
| Signature of Data Controller | Signature of Abu-Bakarr Kamara, Dayone Clearance Ltd |
| Date | Date |
Dayone Clearance Ltd | Company No. 17181162 | Registered in England & Wales | ICO Registration No. ZC155486 | dayoneclearance.com
