BUYER_DOCS / DATA_PROCESSING_AGREEMENT

A DPA is the document most likely to be scrutinised line by line by a counterparty's privacy team, and the one where a drafting error creates real regulatory exposure. This must be reviewed by a qualified lawyer before use. Points needing a lawyer's decision are marked [COUNSEL]. Fields to complete are […].

Scope note: Goldset's stated position is that client data is hosted in the UAE and accessed by screened contributors based in India. That is a cross-border access pattern and it is the single most important thing this document has to handle correctly.


Data Processing Agreement

Annex to, and forming part of, the Services Agreement dated [DATE]

Between

(1) [CLIENT LEGAL NAME] (the "Controller"); and

(2) PMCDXB Corporate Services Provider (CSP) L.L.C S.O.C, Dubai commercial licence 1638875, trading as Goldset (the "Processor").

1. Definitions

"Data Protection Law" means all laws applicable to the processing under this Agreement, including as applicable UAE Federal Decree-Law No. 45 of 2021 (PDPL), Regulation (EU) 2016/679 (GDPR) and the UK GDPR, and India's Digital Personal Data Protection Act 2023 (DPDP). "Personal Data", "processing", "data subject", "controller", "processor" and "personal data breach" have the meanings given in the applicable Data Protection Law.

2. Roles and scope

2.1 The Controller determines the purposes and means of processing. The Processor processes Personal Data only on the Controller's documented instructions, except where required by law (in which case it will inform the Controller unless legally prohibited).

2.2 The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex 1.

2.3 The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Law.

3. Confidentiality and personnel

3.1 The Processor ensures that persons authorised to process Personal Data are bound by confidentiality obligations and are subject to appropriate training.

3.2 Access is granted on a least-privilege, per-project, time-boxed basis to named individuals, and revoked on project close or role change.

4. Security

4.1 The Processor implements appropriate technical and organisational measures, described in Annex 2, including: encryption in transit and at rest; a named, access-controlled workspace; activity logging; and data minimisation and pseudonymisation before annotation where the task permits.

4.2 The Processor does not currently hold ISO 27001 or SOC 2 certification. These are on its roadmap. The Controller acknowledges this in entering the Agreement. [COUNSEL] Stating this expressly is deliberate — an implied certification is a misrepresentation risk far larger than the deal.

5. Sub-processing

5.1 Annotation work is not subcontracted. The Processor does not engage third-party vendors, crowd platforms or downstream labour pools to perform annotation on Controller data.

5.2 The Processor engages infrastructure sub-processors only (cloud hosting and workspace platform), listed in Annex 3. It will give the Controller [30] days' prior written notice of any intended change and the Controller may object on reasonable data-protection grounds.

5.3 The Processor remains fully liable for its sub-processors' performance.

6. International transfers and access — [COUNSEL: the critical clause]

6.1 Controller Personal Data is hosted in the United Arab Emirates.

6.2 Personnel located in India access that data remotely through the controlled workspace to perform the Services. This constitutes a cross-border access and, under several Data Protection Laws, a transfer.

6.3 The Parties shall put in place a lawful transfer mechanism appropriate to the Controller's jurisdiction before any processing begins, which may include Standard Contractual Clauses, an adequacy determination, or another mechanism permitted under the applicable law. [SPECIFY MECHANISM]

[COUNSEL] — do not ship this clause unreviewed. For an EU or UK controller, GDPR Chapter V applies and SCCs plus a transfer impact assessment will very likely be required. For a UAE controller, PDPL Article 22 et seq. governs transfers outside the UAE. The correct mechanism differs per client and must be settled per engagement.

7. Assistance to the Controller

The Processor shall, taking into account the nature of processing and the information available to it, provide reasonable assistance with: data subject requests (clause 8); security of processing; personal data breach notification; data protection impact assessments; and prior consultation with a supervisory authority.

8. Data subject requests

The Processor shall promptly notify the Controller of any request received directly from a data subject and shall not respond substantively unless instructed by the Controller, and shall provide reasonable assistance in responding.

9. Personal data breach

9.1 The Processor shall notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Controller Personal Data.

9.2 The notification shall include, to the extent known: the nature of the breach, categories and approximate number of data subjects and records, likely consequences, and measures taken or proposed. Information not yet known shall be provided as it becomes available; the Processor shall not delay the initial notification to complete its investigation.

10. Deletion and return

10.1 Default retention is zero beyond delivery. On completion of the Services the Processor shall delete Controller Personal Data from its working systems, unless the Controller has instructed retention in writing for a defined period.

10.2 On written request the Processor shall provide a certificate of deletion stating what was deleted, when and by whom.

10.3 The Processor may retain Personal Data to the extent required by law, and shall retain access and activity logs after deletion of the underlying data so that an access history can be produced. Log retention period: [12] months. [COUNSEL] Align this with the Controller's own retention policy; some will require shorter.

11. Audit

11.1 The Processor shall make available information reasonably necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Controller or an auditor it mandates, on [30] days' notice, no more than [once] per year (and additionally following a personal data breach).

11.2 Documentation ordinarily provided in satisfaction of clause 11.1 includes the Processor's data handling policy and QA methodology documents.

12. Liability, term and general

12.1 Liability under this Agreement is subject to the limitations in the Services Agreement. [COUNSEL] — check carefully. Data-protection liability is frequently carved out of the main cap by counterparties. Understand what you are agreeing to before signing, and consider whether professional indemnity / cyber cover should be in place first — it currently is not.

12.2 This Agreement takes effect on the Services Agreement date and continues for the duration of processing.

12.3 In the event of conflict between this Agreement and the Services Agreement in respect of data protection, this Agreement prevails.

12.4 Governing law and jurisdiction follow the Services Agreement. [COUNSEL]


Annex 1 — Details of processing

Subject matterHuman annotation, preference data, evaluation and red-teaming of Controller-supplied content
DurationTerm of the Services Agreement
Nature and purposeReview, labelling, ranking, rating and quality assurance of content to produce training and evaluation datasets
Categories of Personal Data[COMPLETE PER ENGAGEMENT — e.g. none intended; incidental personal data within prompts or documents; user-generated content]
Special category data[state expressly — and if none is permitted, say so]
Categories of data subject[COMPLETE PER ENGAGEMENT]

Practical note: the strongest position is that Annex 1 records no Personal Data is intentionally in scope, with any incidental personal data to be redacted or pseudonymised at intake. Propose that first at scoping — it simplifies clause 6 enormously.

Annex 2 — Technical and organisational measures

As set out in 03-data-handling-policy.md, which is incorporated by reference: encryption in transit and at rest · UAE-hosted, access-controlled workspace · named individual accounts, least privilege, time-boxed · activity logging retained post-deletion · no subcontracting of annotation · data minimisation and pseudonymisation before annotation where the task permits · deletion on delivery by default.

Annex 3 — Sub-processors

Sub-processorPurposeLocation
[CLOUD PROVIDER]Hosting of the controlled workspace[UAE REGION]
[WORKSPACE PLATFORM]Annotation tooling[LOCATION]
← All documents Start a pilot