<!-- Bizible Script --> <script type="text/javascript" class="optanon-category-C0004" src="//cdn.bizible.com/scripts/bizible.js" ></script> <!-- End Bizible Script -->

UK GDPR Data Processing Addendum 

The Data Processing Addendum that applies where Your Agreement is governed by the law of England and Wales, other than for AMS 

This UK GDPR Data Processing Addendum applies where the table at clause 2 of the Data Processor Terms identifies it as the Data Processing Addendum for Your Agreement (other than where AMS applies — see the UK GDPR AMS Data Processing Addendum instead). It forms part of the Data Processor Terms, and sets out the position specific to UK data protection law.

The terms that apply across every Data Processing Addendum are at www.theaccessgroup.com/en-gb/legal/documents/data-processor-terms — read this Addendum together with that page. 

1. Definitions 

Approved Jurisdiction — means the United Kingdom, as supplemented by any territory where a Sub-Processor is based in accordance with this Addendum. 

Data Protection Legislation — means the Data Protection Act 2018, the UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended), the Data (Use and Access) Act 2025, and any other law or regulation applicable in the United Kingdom concerning the processing of personal data, in each case as amended, replaced or repealed. “Personal data”, “data subject”, “controller”, “processor”, “process” and “supervisory authority” are interpreted in line with the UK GDPR. 

Your personal data — means the personal data that You submit to, or that is generated through Your use of, the Access Products and Services, and that We process on Your behalf under the Agreement. 

2. Our role 

  • 2.1 Except where clause 3.10 of the Data Processor Terms applies, We are the processor and You are the controller of Your personal data. The Product Fact Sheet sets out the subject-matter and duration of the processing, its nature and purpose, the types of personal data involved, and the categories of data subjects. 
  • 2.2 Each of us complies with our respective obligations under the Data Protection Legislation. You warrant that You will not instruct Us to process Your personal data in a way that would be unlawful. 

3. How We process Your personal data 

  • 3.1 We process Your personal data only on Your documented instructions, and We will not transfer it outside the Approved Jurisdiction without a documented instruction to do so — except as set out in clause 3.2 below or clause 3.4 of the Data Processor Terms (Sub-processing). Any configuration of the Access Products or Services by You, or by Us on Your instruction, counts as a written instruction for these purposes, including where that configuration results in a transfer; where it does, We will have put in place appropriate safeguards to protect Your personal data and to ensure data subjects have enforceable rights and effective remedies, as the Data Protection Legislation requires. 
  • 3.2 We may process Your personal data other than on Your documented instructions where required to do so by law. Unless that law prohibits it on important public interest grounds, We will tell You about the legal requirement before carrying out that processing. 

4. If We consider an instruction unlawful 

  • 4.1 If We consider that an instruction You give Us about processing Your personal data would infringe the Data Protection Legislation, We will tell You immediately, and You will reconsider the instruction in light of Our reasoning. We are not obliged to act on that instruction until You confirm it is non-infringing, or amend it so that it is. 

5. Your responsibilities 

  • 5.1 You are responsible, for the Licence Term, for having and maintaining the consents and/or lawful basis needed for the processing of the personal data of the data subjects affected by the Agreement. 
  • 5.2 We will use reasonable endeavours to help You meet Your own obligations under Articles 32 to 36 of the UK GDPR; clauses 3.3 (security), 3.5 (data breaches), 3.6 (individual rights requests) and 3.7 (impact assessments) of the Data Processor Terms set out how.