Tru Data Protection
AboutDPO ServicePortal
PricingContactSign in →

Data Processing Agreement

Status: Ready for review

Version: 1.1

Effective date: July 2026

Audience: Customer controllers using Tru Data Protection services

Between Tru-Digital Services Ltd (Processor) and the Customer (Controller)

Agreement summary

The Customer is the Controller and agrees to appoint Tru-Digital Services Ltd (trading as Tru Data Protection), 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, as Processor to process Personal Data on the terms set out in this Agreement.

The Processor agrees to process Personal Data on the terms set out in this Agreement and in accordance with the Controller's documented instructions.


1. Interpretation

The following definitions apply in this Agreement.

Agreed Purpose: The purposes for which Personal Data is processed, as set out in this Agreement and the Services Agreement.

Agreement: This Data Processing Agreement, which forms part of the Services Agreement between the parties.

Business Day: A day other than Saturday, Sunday or UK bank holiday when banks in London are open for business.

Data Protection Authority: The Information Commissioner's Office (ICO).

Data Security Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.

Personal Data: Has the meaning given in UK GDPR and includes all personal data processed by the Processor on behalf of the Controller.

Portal: The customer-facing online portal used to provide access to evidence, cases, service records, outputs, support information and collaboration workspaces.

Privacy and Data Protection Legislation: UK GDPR, the Data Protection Act 2018, PECR and all applicable laws relating to privacy and processing of personal data.

Services Agreement: The contract between the parties for the provision of services, including the Quote, Terms and Conditions and this Agreement.

TruCredits: Usage credits that may be used for eligible one-off processing, redaction, export or policy-pack tasks.

Terms such as Controller, Processor, Data Subject, Personal Data, Special Category Data and Processing have the meanings given in UK GDPR.


2. Compliance with data protection legislation

Both parties shall comply with all applicable requirements of Privacy and Data Protection Legislation during the term.

The Controller is responsible for ensuring it has a lawful basis for processing Personal Data and is entitled to transfer Personal Data to the Processor.

The Processor shall process Personal Data only on documented instructions from the Controller unless required by law.


3. Processing instructions

The Processor shall process Personal Data only:

  • for the Agreed Purpose;
  • in accordance with the Controller's documented instructions;
  • as described in the Services Agreement; and
  • in accordance with this Agreement.

If the Processor believes an instruction infringes applicable law, it shall notify the Controller.


4. Purpose of processing

The Processor processes Personal Data to deliver contracted data protection, governance, Portal and related managed services.

This may include:

  • Outsourced DPO support;
  • SAR and FOI support;
  • breach and incident support;
  • ROPA, DPIA and supplier governance support;
  • policy pack production and export;
  • evidence processing;
  • directory-assisted redaction;
  • Portal access and service records;
  • training, advice and document review;
  • credit-based tasks purchased using TruCredits;
  • related support and administration.

5. Personal data categories

Personal Data may relate to:

  • pupils and students;
  • parents and guardians;
  • staff and governors;
  • trustees;
  • volunteers and contractors;
  • external professionals;
  • complainants and correspondents;
  • suppliers and service providers;
  • Portal users and customer contacts.

Categories may include:

  • identifiers and contact details;
  • education and training data;
  • employment data;
  • safeguarding data;
  • SEND or health-related data;
  • financial data;
  • digital and technical data;
  • case, incident, complaint, SAR, FOI or governance records;
  • evidence and redaction material supplied for processing.

Special Category Data may include health information, racial or ethnic origin, religious or philosophical beliefs, safeguarding-related information, biometric data or other sensitive information where relevant.


6. Fair and lawful processing

The Controller warrants that:

  • it has identified appropriate lawful bases for processing;
  • it has appropriate conditions for processing Special Category Data and criminal offence data;
  • privacy notices and fair processing information are in place;
  • it is entitled to transfer Personal Data to the Processor;
  • instructions given to the Processor are lawful.

7. Data subject rights

The Processor shall notify the Controller where it receives a request from a data subject or regulator relating to Personal Data processed under this Agreement.

The Processor shall provide reasonable assistance to the Controller in responding to data subject rights requests.


8. Data retention, deletion and return

The Processor shall retain Personal Data only for as long as necessary for the Agreed Purpose, as instructed by the Controller or as required by law.

On termination, completion of a task or expiry of an agreed retention period, the Processor shall return, delete or anonymise Personal Data in accordance with the Controller's instructions, the Services Agreement and applicable legal requirements.

Service-specific deletion arrangements may apply, for example where evidence processing, redaction or export tasks create temporary working material and a clean output pack.


9. Sub-processors and third parties

The Controller authorises the Processor to engage sub-processors necessary to deliver the services.

The Processor remains responsible for sub-processor compliance and shall ensure appropriate data processing terms are in place.

Where international transfers occur, the Processor shall use appropriate safeguards.

Current categories of sub-processors may include hosting, storage, security, communication, payment, form, workflow and productivity providers.


10. Security and confidentiality

The Processor shall implement appropriate technical and organisational measures to protect Personal Data.

Measures may include:

  • encryption in transit and at rest;
  • multi-factor authentication;
  • role-based access controls;
  • audit logging;
  • secure backups;
  • staff confidentiality obligations;
  • staff training;
  • incident response procedures;
  • secure deletion and disposal;
  • least-privilege access;
  • supplier review and vendor management.

11. Data security breaches

The Processor shall notify the Controller without undue delay after becoming aware of a Data Security Breach affecting the Controller's Personal Data.

The Processor shall assist the Controller with investigation, containment, notification and remediation where required.


12. Audits and inspections

The Processor shall provide information reasonably necessary to demonstrate compliance with this Agreement.

Any audit or inspection should be proportionate, reasonable, scheduled in advance where possible and subject to appropriate confidentiality and security controls.


13. Data Protection Impact Assessments

Where the Controller is required to conduct a DPIA, the Processor shall provide reasonable assistance and information relevant to the services.


14. AI-assisted and automated support

Where AI-assisted or automation-supported features are used, they support processing, drafting, matching, classification or review. They do not replace the Controller's decision-making responsibility and do not make legal or similarly significant decisions about individuals on behalf of the Controller.

The Controller remains responsible for deciding whether the output is appropriate for its intended purpose.


15. Termination

On termination or expiry of the Services Agreement, the Processor shall cease processing Personal Data except where required by law or agreed in writing.

The Processor shall support orderly transition to the Controller or successor provider where reasonable.


16. Liability

Liability under this Agreement is subject to the limitations and exclusions set out in the Services Agreement, except where liability cannot be limited by law.


17. General provisions

This Agreement forms part of and is incorporated into the Services Agreement.

If this Agreement conflicts with the Terms and Conditions, this Agreement prevails in relation to processing of Personal Data.

This Agreement is governed by the law of England and Wales.


Schedule 1: Data processing details

Controller

An educational establishment, school, academy, trust, multi-academy trust or other customer using Tru Data Protection services.

Processor

Tru-Digital Services Ltd, trading as Tru Data Protection.

Address: 3rd Floor, 86-90 Paul Street, London, EC2A 4NE

ICO Registration: ZB887707

Company Number: 16210598

Data subjects

  • pupils and students;
  • parents and guardians;
  • staff;
  • governors and trustees;
  • volunteers;
  • contractors;
  • external professionals;
  • complainants and correspondents;
  • suppliers and service providers;
  • Portal users and customer contacts.

Categories of personal data

  • identifiers and contact details;
  • education and training data;
  • employment data;
  • safeguarding data;
  • SEND or health-related data;
  • financial data;
  • digital and technical data;
  • SAR, FOI, complaint, incident and governance records;
  • evidence, redaction and export material supplied for processing.

Special category data

May include health information, safeguarding-related information, biometric data, racial or ethnic origin, religious or philosophical beliefs or other sensitive data where relevant.

Processing operations

Processing may include collection, receipt, storage, organisation, review, analysis, matching, redaction, structuring, export, disclosure, updating, protection, restriction, deletion and return of data.

Duration of processing

For the term of the Services Agreement plus applicable retention periods, or as otherwise instructed by the Controller.


Schedule 2: Services and data handling

Services may include:

  • Outsourced DPO support;
  • Portal access;
  • ICO liaison support;
  • DPIA and ROPA support;
  • SAR and FOI support;
  • breach and incident support;
  • evidence processing;
  • directory-assisted redaction;
  • policy pack production and export;
  • training and advice;
  • supplier governance support;
  • credit-based tasks purchased using TruCredits.

Personal Data should be transferred through secure channels and handled in line with this Agreement.


Schedule 3: Technical and organisational measures

The Processor implements measures including:

  • access controls;
  • multi-factor authentication;
  • encryption;
  • network security;
  • backup and disaster recovery;
  • secure disposal;
  • personnel security;
  • vendor management;
  • software and patch management;
  • audit and compliance controls;
  • testing and assurance.

End of Data Processing Agreement

Document reference: TDP-DPA-v1.1

Last updated: July 2026

Next review: July 2027

On this page

  • Agreement summary
  • 1. Interpretation
  • 2. Compliance with data protection legislation
  • 3. Processing instructions
  • 4. Purpose of processing
  • 5. Personal data categories
  • 6. Fair and lawful processing
  • 7. Data subject rights
  • 8. Data retention, deletion and return
  • 9. Sub-processors and third parties
  • 10. Security and confidentiality
  • 11. Data security breaches
  • 12. Audits and inspections
  • 13. Data Protection Impact Assessments
  • 14. AI-assisted and automated support
  • 15. Termination
  • 16. Liability
  • 17. General provisions
  • Schedule 1: Data processing details
  • Schedule 2: Services and data handling
  • Schedule 3: Technical and organisational measures

Get started

Ready to get started?

See pricing, or get in touch for a quick conversation and a clear plan.

See pricing →Get in touch →
Tru Data Protection

Hosted in the UK (AWS London)

ISO 9001/27001-aligned (certification planned)

Products

  • DPO Service
  • Portal
  • Evidence Processing
  • Redaction
  • Policy Packs & Exports

Company

  • About
  • Founder
  • Contact
  • Pricing
  • Tru-Digital Services

Support

  • Guidance
  • Blog

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions
  • Data Processing Agreement
© 2026 Tru Data Protection is a trading name of Tru-Digital Services Limited, company number 16210598. ICO registration: ZB887707.