Data Processing Addendum
Controller-to-processor terms covering personal data we process on a client's behalf, including GDPR Article 28 obligations.
- Effective
- August 26, 2026
- Updated
- August 26, 2026
This Data Processing Addendum (“DPA”) forms part of the Engagement Agreement between NextEra Group(“Processor”) and the client (“Controller”) and applies whenever we process personal data on the Controller’s behalf. It is drafted to meet Article 28 of the EU and UK GDPR and the service-provider requirements of U.S. state privacy laws.
This page is the standard form we offer. Executing it requires a signed Engagement Agreement; contact info@nexteragp.com to put a countersigned copy in place.
1. Definitions
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given in the GDPR. “Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing, including the GDPR, UK GDPR, and U.S. state privacy laws.
2. Roles and scope
The Controller determines the purposes and means of processing. The Processor processes Personal Data only to provide the services described in the Engagement Agreement. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex A below or in the applicable statement of work.
3. Processing instructions
The Processor will process Personal Data only on documented instructions from the Controller, including regarding international transfers, unless required otherwise by law — in which case the Processor will inform the Controller before processing, unless the law prohibits it on important grounds of public interest.
The Processor will notify the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
The Processor will not sell or share Personal Data, will not retain, use, or disclose it for any purpose other than performing the services, and will not combine it with data from other sources except as permitted by Applicable Data Protection Law.
4. Confidentiality
The Processor ensures that personnel authorized to process Personal Data are bound by confidentiality obligations, receive appropriate data protection training, and access Personal Data only on a need-to-know basis.
5. Security measures
The Processor implements appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit and at rest, role-based access control with least privilege, multi-factor authentication on administrative access, logging and monitoring, secure development practices, regular patching, and periodic restoration testing of backups. Further detail is set out in our Security Overview.
6. Subprocessors
The Controller grants general authorization for the Processor to engage subprocessors, listed at nexteragp.com/legal/subprocessors. The Processor will give at least 30 days’ notice before adding or replacing a subprocessor, and the Controller may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected services without penalty.
The Processor imposes data protection obligations on each subprocessor no less protective than this DPA and remains fully liable for their performance.
7. Assistance to the Controller
- Data subject requests. Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organizational measures in responding to requests to exercise data subject rights. The Processor will promptly forward any request it receives directly and will not respond substantively itself unless instructed.
- DPIAs and consultation. The Processor will provide reasonable assistance with data protection impact assessments and prior consultation with Supervisory Authorities.
8. Personal data breach
The Processor will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting the Controller’s Personal Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where full information is not immediately available, it will be provided in phases without further undue delay.
9. Audits
The Processor will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor it mandates. Audits are limited to once per twelve-month period absent a breach or regulator requirement, require 30 days’ written notice, occur during business hours, and are subject to confidentiality. The Processor may satisfy an audit request by providing a current third-party assessment where one is available.
10. International transfers
Where processing involves transferring Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. In the event of a conflict, the Standard Contractual Clauses prevail.
11. Return and deletion
On termination of the services, the Processor will, at the Controller’s election, return or delete all Personal Data and existing copies within 60 days, unless law requires continued storage. Backup copies are deleted on the standard backup rotation cycle and remain protected by this DPA until deleted.
12. Liability
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Engagement Agreement.
Annex A — Details of processing
| Subject matter | Provision of technology consulting, software development, hosting, and support services. |
|---|---|
| Duration | The term of the Engagement Agreement, plus any agreed retention period. |
| Nature and purpose | Storage, hosting, transmission, analysis, migration, testing, debugging, and support as required to deliver the services. |
| Categories of data subjects | Controller’s employees, contractors, customers, and end users, as applicable to the engagement. |
| Categories of personal data | Identification and contact data, account and authentication data, transaction and billing data, usage and log data, and any other category the Controller elects to submit. |
| Special category data | Not processed unless expressly agreed in writing with documented additional safeguards. |