Draft for review — placeholder copy, not yet legally approved.
DPA
Data Processing Agreement.
For organisation customers whose staff use KurdCPD, this DPA forms part of your subscription terms and satisfies UK GDPR Article 28.
Last updated · May 2026
1. Roles
The organisation is the controller of its staff's CPD data. KurdCPD is the processor and processes data only on documented instructions.
2. Subject matter and duration
Processing is for the duration of the subscription and limited to delivering the KurdCPD service.
3. Categories of data and data subjects
- Data subjects: the organisation's clinical and CPD-bearing staff.
- Data: identity, contact, professional registration, CPD records and uploaded evidence.
4. Security
KurdCPD implements appropriate technical and organisational measures. See our Security Statement.
5. Sub-processors
The organisation authorises the sub-processors listed here. KurdCPD will give notice of changes and offer a right to object.
6. International transfers
Where transfers occur outside the UK, KurdCPD relies on UK adequacy regulations or the UK Addendum to the EU SCCs.
7. Personal data breaches
KurdCPD will notify the organisation without undue delay and in any event within 48 hours of becoming aware of a personal data breach.
8. Assistance and audit
KurdCPD will assist with DSARs, DPIAs and regulator queries. The organisation may audit compliance, on reasonable notice and at its cost.
9. Return or deletion
On termination, KurdCPD will return or delete personal data within 30 days, save where retention is required by law.
