This Data Processing Agreement ("DPA") forms part of the membership agreement between Super Save Protocol Ltd ("Processor") and the Member institution ("Controller"). It applies where the Processor processes personal data on the Controller's behalf and is intended to satisfy Article 28 of the UK and EU GDPR.
A countersigned copy is available on request from legal@supersaveprotocol.com.
01 Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the SSP anti-duplicate finance registry |
| Duration | The term of the membership agreement, plus the retention periods that survive it |
| Nature and purpose | Collection, storage, normalisation, hashing, matching, scoring, disclosure to other Members, alerting, audit logging, reporting and deletion |
| Types of personal data | Business contact details of authorised users; names and identifiers of individuals appearing in commercial documents (for example a sole trader exporter, a cheque drawer, an authorised signatory); technical and audit data |
| Categories of data subject | Controller's employees and authorised users; the Controller's customers and their counterparties, where they are individuals or sole traders |
| Special category data | None. The Controller must not submit special category or criminal offence data |
02 Processor obligations
The Processor will:
- process personal data only on the Controller's documented instructions, including on transfers, unless required by law — in which case it informs the Controller first unless the law forbids it;
- ensure personnel authorised to process are bound by confidentiality;
- implement the technical and organisational measures set out in Annex A;
- respect the conditions on sub-processors set out below;
- assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to data subject rights requests;
- assist the Controller with security, breach notification, impact assessments and prior consultation under Articles 32 to 36;
- at the Controller's election, delete or return personal data at the end of the service, subject to the retention carve-out below;
- make available information necessary to demonstrate compliance and allow for audits as described below;
- immediately inform the Controller if, in its opinion, an instruction infringes data protection law.
03 Controller obligations
The Controller warrants that:
- it has a lawful basis for the processing it instructs, including for the disclosure of registry records to other Members;
- it has given the required transparency information to its data subjects, including that records may be checked against and disclosed to a shared industry registry;
- the personal data it submits is accurate and lawfully obtained;
- it will not submit special category data, criminal offence data, or data of children;
- its instructions comply with applicable data protection law.
04 The registry carve-out
The Controller acknowledges and instructs that, notwithstanding any deletion request:
- registry records already submitted and the fingerprints derived from them are retained for their stated retention period, because other Members have relied and will rely on them to detect duplicate financing;
- audit log entries are append-only and are retained for their stated retention period as an integrity and compliance control.
This is a condition of membership and is disclosed before any record is submitted. It reflects Article 17(3)(b) and (e), and the legitimate interests of the Member community in the integrity of a shared fraud-prevention record.
05 Sub-processors
The Controller gives general written authorisation for the Processor to engage sub-processors. The current list is published at Sub-processors.
The Processor will give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Controller may terminate the affected service without penalty for the unused portion of any prepaid fees.
The Processor imposes on each sub-processor obligations no less protective than this DPA, and remains fully liable for its sub-processors' performance.
06 International transfers
Where processing involves a transfer of personal data outside the UK or EEA, the parties rely on an adequacy decision or enter into the European Commission's Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail in the event of conflict.
07 Security measures (Annex A)
- Encryption — TLS 1.2 or above in transit; encryption at rest for databases and backups.
- Access control — role-based access with twelve defined institutional roles, organisation scoping, least-privilege defaults, quarterly access reviews.
- Authentication — two-factor authentication, password hashing with a modern algorithm, enforced rotation, lockout after repeated failures, idle session timeout.
- Logging — append-only audit log capturing actor, organisation, action, timestamp and IP for every registry action.
- Application security — CSRF protection, parameterised queries, output encoding, security headers, dependency patching.
- Resilience — regular backups with tested restores, documented recovery objectives.
- Personnel — background checks proportionate to role, confidentiality undertakings, annual security and data protection training.
- Vendor management — due diligence and written terms before any sub-processor handles personal data.
08 Breach notification
The Processor notifies the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data. The notification includes, so far as known: the nature of the breach, categories and approximate numbers affected, likely consequences, measures taken or proposed, and a contact point. The Processor provides further information as the investigation progresses.
09 Audit
The Processor makes available to the Controller its current security documentation and, where available, third-party assurance reports. Where those do not reasonably satisfy the Controller, the Controller may audit once in any 12-month period on 30 days' written notice, during business hours, subject to confidentiality, at its own cost, and without accessing other Members' data. A regulator with jurisdiction may audit at any time as the law requires.
10 Liability and term
Liability under this DPA is subject to the limitations in the membership agreement and the Terms and Conditions, except to the extent those limitations are prohibited by data protection law.
This DPA takes effect on the effective date of the membership agreement and continues until the Processor has ceased all processing, including at the end of the surviving retention periods.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.