Data Processing Addendum for Processors and Subprocessors
Summary — Plain English
1. Processor Obligations
The processor must process personal data only on the documented instructions of MyChurch.Events. The processor must not process personal data for any purpose beyond the scope of the services provided under the principal agreement.
2. Confidentiality
The processor must ensure that all personnel authorised to process personal data have committed to confidentiality or are under appropriate statutory obligations of confidentiality.
3. Security Controls
The processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate: encryption of personal data, ability to ensure ongoing confidentiality and integrity of processing systems, ability to restore data after a technical incident, and regular testing and evaluation of security measures.
4. Subprocessor Approval
The processor must not engage a subprocessor without prior written authorisation from MyChurch.Events. Where authorisation is given, the processor must ensure that the subprocessor is bound by data protection obligations equivalent to those in this addendum.
5. International Transfer Safeguards
Personal data must not be transferred outside the UK or EEA without the prior written consent of MyChurch.Events and without appropriate safeguards in place (such as UK International Data Transfer Agreements or Standard Contractual Clauses).
6. Assistance with Data Subject Rights
The processor must assist MyChurch.Events in responding to data subject rights requests within the timescales required by applicable law.
7. Breach Notification
The processor must notify MyChurch.Events without undue delay (and in any event within 24 hours) of becoming aware of a personal data breach involving data processed under this addendum. The notification must include sufficient detail to enable MyChurch.Events to meet its own reporting obligations.
8. Deletion or Return of Data
Upon termination of the principal agreement or upon request by MyChurch.Events, the processor must securely delete or return all personal data processed under this addendum, and certify in writing that it has done so.
9. Audit Rights
MyChurch.Events may, upon reasonable notice, audit the processor's compliance with this addendum, or commission an independent audit. The processor must cooperate fully with all reasonable audit requests.
10. Records of Processing
The processor must maintain records of all processing activities carried out on behalf of MyChurch.Events as required by applicable data protection law.
11. Contact
For data protection enquiries, contact privacy@mychurch.events.
Contact us about this policy
If you have any questions, concerns or requests relating to this policy, please contact us:
