LeadersSafeguardingCPDGovernorHubKeyGPT
Training Hub
Documents
  • The Key
  • GovernorHub
  • Robin

Data Processing Agreement

Effective from 1 October 2026

Contents
  1. 1.Definitions and Interpretation
  2. 2.Applicability and Roles
  3. 3.Processing of Personal Data
  4. 4.Customer Instructions
  5. 5.Assistance and Cooperation Obligations
  6. 6.Sub-Processing
  7. 7.Security and Confidentiality
  8. 8.Personal Data Breaches
  9. 9.Data Transfers
  10. 10.Audit
  11. 11.Deletion and Return of Customer Personal Data
  12. 12.Third Party Beneficiaries
  13. 13.Liability and Indemnity
  14. 14.Conflict
  15. 15.Dispute Resolution
  16. Appendix 1: Description of Services and Personal Data Processing
  17. Appendix 2: Security Schedule

Contents

  1. 1.Definitions and Interpretation
  2. 2.Applicability and Roles
  3. 3.Processing of Personal Data
  4. 4.Customer Instructions
  5. 5.Assistance and Cooperation Obligations
  6. 6.Sub-Processing
  7. 7.Security and Confidentiality
  8. 8.Personal Data Breaches
  9. 9.Data Transfers
  10. 10.Audit
  11. 11.Deletion and Return of Customer Personal Data
  12. 12.Third Party Beneficiaries
  13. 13.Liability and Indemnity
  14. 14.Conflict
  15. 15.Dispute Resolution
  16. Appendix 1: Description of Services and Personal Data Processing
  17. Appendix 2: Security Schedule

This Data Processing Agreement (DPA) supplements and forms part of the Customer Agreement available at thekeysupport.com/documents/customer-agreement/, or other agreement in place between Customer and TKG in respect of Customer’s use of TKG’s Services (Agreement). This DPA includes the terms that apply when Customer Personal Data is processed by TKG under the Agreement.

1. Definitions and Interpretation

1.1 Unless otherwise defined in this DPA, capitalised terms defined in the Customer Agreement will have the same meaning when used in this DPA.

1.2 In this DPA:

Customer means the legal entity that has entered into the Agreement with TKG.

Customer Data has the meaning given to it in the Customer Agreement.

Customer Personal Data means: (a) Customer Data which is personal data; and (b) all other personal data (which may include Service Data) that is processed by TKG (and/or its Sub-processors) on Customer’s behalf (including where Customer is itself acting on behalf of another controller).

Data Protection Legislation means applicable laws relating to privacy and data protection, including: (a) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) and any national implementing laws relating to the GDPR; (b) the UK General Data Protection Regulation (as defined in the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) (UK GDPR); (c) the UK Data Protection Act 2018; (d) the EU Privacy and Electronic Communications Directive 2002/58/EC, as implemented in each relevant jurisdiction; (e) the Privacy and Electronic Communications (EC Directive) Regulations 2003; and (f) any amending or replacement legislation of any of the above from time to time.

Permitted Region means the region comprising the UK and the European Economic Area Member States.

Service Data has the meaning given to it in the Customer Agreement.

Services shall mean the services provided by TKG to the Customer pursuant to and specified in the Agreement.

Sub-processor and New Sub-processor shall have the meanings given in Clause 6.1 (General Authorisation).

Supplier means the TKG entity that has entered into the Agreement with the Customer.

1.3 In this DPA, the terms controller, data subject, personal data, personal data breach, processing, processor, special categories of personal data and supervisory authority will have the meanings given to them in the Data Protection Legislation.

2. Applicability and Roles

2.1 Applicability. Under the Agreement, TKG has been appointed to provide the Services to Customer, on behalf of and for the benefit of Customer and/or its Authorised Institutions. This DPA will apply only to the extent that TKG processes Customer Personal Data to which Data Protection Legislation applies.

2.2 TKG as Processor. The parties agree that for the purposes of Data Protection Legislation:

2.2.1 Customer is either a controller of Customer Personal Data acting on behalf of itself and/or Authorised Institutions as applicable, or a processor of Customer Personal Data acting on another controller’s behalf (e.g. a member of Customer’s group); and

2.2.2 TKG is a processor (or respectively, a sub-processor) in respect of Customer Personal Data.

2.3 TKG as Controller. TKG is a controller of personal data as set out in The Key’s Privacy Statement, including with respect to processing activities of Service Data. This DPA shall not limit or prohibit Arbor from processing personal data in that capacity.

2.4 Duration

With respect to each Service, this DPA shall commence on the Service Start Date and shall continue in full force and effect until, and automatically expire when, TKG ceases to process Customer Personal Data in accordance with the terms of the Agreement (regardless of whether the applicable Licence Term has terminated or expired).

3. Processing of Personal Data

3.1 Scope and Purpose. The scope, nature and purpose of processing by TKG, the duration of the processing, the types of Customer Personal Data and categories of data subject are set out in Appendix 1 (Description of Services and Personal Data Processing) to this DPA.

3.2 Compliance with Data Protection Legislation. Each party shall comply with its obligations under the Data Protection Legislation in respect of Customer Personal Data. Without prejudice to the foregoing, neither party shall process Customer Personal Data in a manner that will, or is likely to, result in the other party breaching its obligations under the Data Protection Legislation.

4. Customer Instructions

4.1 Documented Instructions. Customer hereby instructs TKG to process Customer Personal Data on behalf of Customer and/or its Authorised Institutions in accordance with: (a) Customer’s instructions set out in the Agreement, including Appendix 1 of this DPA and Customer’s use of the Services (including relevant configurations and settings), and otherwise as TKG considers reasonably necessary to provide the Services to Customer in accordance with the terms of the Agreement; and (b) such other written instructions (which may include instructions given by or on behalf of Authorised Institutions, including with regard to transfers) as the Customer may issue to TKG from time to time (provided that such instructions do not result in processing that is outside the scope of the Services) (Documented Instructions).

4.2 TKG’s Compliance with Documented Instructions. Subject at all times to TKG's obligations under the Agreement, TKG undertakes to process Customer Personal Data only in accordance with the Customer’s Documented Instructions unless required to do otherwise by Applicable Law in which event, TKG shall, unless prohibited by law, inform the Customer of the applicable legal requirement before processing Customer Personal Data other than in accordance with the Customer's Documented Instructions.

4.3 Lawfulness of Instructions. Customer warrants that its disclosures of, and instructions to TKG in relation to, Customer Personal Data are lawful. TKG undertakes to notify the Customer as soon as practicable if in its reasonable opinion it has been given an instruction which doesn't comply with the Data Protection Legislation.

5. Assistance and Cooperation Obligations

Subject at all times to TKG's obligations under the Agreement, TKG undertakes to:

5.1 promptly refer to the Customer all requests, notices and other correspondence received from data subjects or supervisory authorities with regard to Customer Personal Data; and

5.2 provide reasonable and timely cooperation and assistance to the Customer, taking into account the nature of the Services and the information available to TKG, as the Customer may reasonably require to allow the Customer to comply with its obligations as a controller, including in relation to: (a) data security; (b) personal data breach notification; (c) data protection impact assessments; (d) prior consultation with supervisory authorities; (e) the fulfilment of data subject's rights; and (f) any enquiry, notice or investigation by a supervisory authority, in each case to the extent that Customer cannot reasonably fulfil such obligations independently with help of available Documentation.

6. Sub-Processing

6.1 General Authorisation. Subject to the requirements set out in this Clause 6 (Sub-Processing), Customer hereby expressly authorises TKG to:

6.1.1 appoint each of the third parties listed at Appendix 2 as at the date of the Agreement as further processors on behalf of TKG to process Customer Personal Data (each a Sub-processor); and

6.1.2 appoint new sub-processors as further processors on behalf of TKG to process Customer Personal Data (each a New Sub-processor) provided that TKG gives Customer at least thirty (30) days’ prior notice (Sub-processor Notice Period). TKG maintains an up-to-date list of its Sub-Processors on the webpage linked against the applicable Service in Appendix 2.

6.2 Objection to New Sub-processors. If, within the Sub-processor Notice Period, Customer notifies TKG in writing of any objections (on reasonable grounds relating to Data Protection Legislation) to the proposed appointment, if reasonably practicable taking into account TKG's commercial interests, including its provision of services to its other customers, TKG may at its sole discretion propose a reasonable change to the Services to accommodate (in whole or part) the Customer's objections to the proposed New Sub-processor. If TKG does not propose such a change within the Sub-processor Notice Period, or if the Customer reasonably refuses any such proposed change, the Customer may terminate the affected Services and TKG shall refund to Customer any prepaid, unused Fees relating to the period following termination, which shall be the Customer's sole and exclusive remedy for its objection to the proposed New Sub-processor.

6.3 TKG’s Responsibility for Sub-Processors. TKG shall: (a) engage all Sub-processors and New Sub-processors on written contractual terms that provide substantially the same level of protections as those set out in this DPA; and (b) be responsible for the acts, omissions and defaults of any Sub-processor or New-Sub-processor as if they were TKG's own acts, omissions or defaults.

7. Security and Confidentiality

7.1 Technical and Organisational Measures. TKG undertakes to implement technical and organisational measures to protect Customer Personal Data processed by it against unauthorised and unlawful processing and against accidental loss, destruction, disclosure, damage or alteration.

7.2 Security Measures. TKG’s current technical and organisational measures are described in Appendix 2. Customer acknowledges that the security measures are subject to technical progress and development and that TKG may update or modify the security measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Services during a Licence Term.

7.3 Confidentiality. Subject at all times to TKG's obligations under the Agreement, TKG undertakes to ensure that its personnel who have access to Customer Personal Data are bound by appropriate obligations of confidentiality.

8. Personal Data Breaches

TKG shall notify the Customer without undue delay on becoming aware of any personal data breach in relation to the Customer Personal Data. TKG shall also provide the Customer with a description of the personal data breach, including, to the extent known to TKG, the categories of data and of data subject affected by the breach, as soon as reasonably practicable after such information becomes available, as well as any other information and co-operation which the Customer may reasonably request relating to the personal data breach.

9. Data Transfers

9.1 TKG shall not transfer Customer Personal Data outside of the Permitted Region without obtaining the Customer's prior written consent unless:

9.1.1 the transfer is to a territory which is subject to a current finding by a regulatory authority under the Data Protection Legislation, that the territory provides adequate protection for the privacy rights of individuals; or

9.1.2 the transfer is effected by way of a legally enforceable safeguarding mechanism that is permitted under the Data Protection Legislation.

10. Audit

10.1 Upon written request and at no additional cost to Customer, TKG shall provide Customer and/or its appropriately qualified third-party representative access to such information as is reasonably requested to evidence TKG’s compliance with this DPA in the form of relevant audits or certifications. Where Customer, acting reasonably, has grounds to seek further evidence of TKG’s compliance with this DPA, TKG shall permit Customer or its appropriately qualified third party representative (bound by appropriate obligations of confidentiality) to conduct an audit, including a physical inspection, provided that such audits are carried out:

10.1.1 during TKG's normal business hours and on reasonable, prior notice to TKG;

10.1.2 in a manner that causes minimal disruption to TKG's business and excludes from its scope any internal pricing information, information relating to other customers of TKG or TKG's own internal reports;

10.1.3 no more that once per year, except to the extent that the Data Protection Legislation requires more frequent audits; and

10.1.4 at the Customer's own cost.

10.2 If a third party is to conduct an audit under Clause 10.1, the third party must be mutually agreed to by the Customer and TKG (except if such third party is a supervisory authority).

11. Deletion and Return of Customer Personal Data

11.1 Save where the Agreement expressly provides that TKG shall retain Customer Personal Data for a specified period of time following termination of the Agreement (the Retention Period):

11.1.1 upon expiry or termination of the Agreement and at the option and request of the Customer, TKG undertakes to either return to the Customer or destroy all Customer Personal Data in the possession or control of TKG as at the termination or expiry date; and

11.1.2 if Customer does not request deletion of Customer Personal Data, TKG will automatically delete it on the date which is either thirty (30) days after the termination or expiration of this Agreement, or on the expiry of the Retention Period, whichever is the later.

11.2 Notwithstanding the foregoing, TKG may retain Customer Personal Data to the extent required by Applicable Laws, including Data Protection Legislation, provided that TKG will maintain the confidentiality of retained Customer Personal Data and not further process it except as required by Applicable Laws.

12. Third Party Beneficiaries

TKG acknowledges that Customer Personal Data may include personal data in respect of which one or more Authorised Institutions are the controller and that Customer may be issuing processing instructions on their behalf. Notwithstanding any other provisions of this DPA, such Authorised Institutions shall not be entitled to enforce this DPA as third party beneficiaries.

13. Liability and Indemnity

The liability of each party to the other in relation to all and any claims, losses, proceedings, actions or regulatory penalties arising under or in connection with this DPA shall be governed by the provisions relating to exclusion and limitation of liability in the Agreement.

14. Conflict

To the extent of any conflict between this DPA and the Agreement, this DPA will prevail.

15. Dispute Resolution

The provisions of the Customer Agreement relating to governing law and dispute resolution apply to this DPA and to any dispute or claim arising out of or in connection with it (including its subject matter or formation, and including non-contractual disputes or claims).

Appendix 1: Description of Services and Personal Data Processing

The data processing activities carried out by TKG under this DPA are as follows:

Description of ServicesThe Services provided by TKG to the Customer pursuant to the Agreement.
Subject-matter of ProcessingThe performance of the Services pursuant to the Agreement.
Duration of ProcessingSubject to any subsequent deletion or return of Customer Personal Data in accordance with this DPA, TKG will Process Customer Personal Data for the duration of the Agreement (unless otherwise agreed in writing), which shall include receiving it continuously from Authorised Users.
Processing operations TKG is instructed to performCustomer instructs TKG to perform the following processing operations in respect of Customer Personal Data: collection, storage, organisation, structuring, displaying, adaption or alteration, retrieval, anonymisation, de-identification and aggregation, display, dissemination or otherwise making available, disclosure, consultation, use, combination, restriction and erasure or destruction.
Nature and purpose of Processing

TKG will process Customer Personal Data as is reasonably necessary to provide, maintain, secure, support and improve the Services to Customer pursuant to the Agreement, and as may be further instructed by the Customer in its use of the Services.

TKG may anonymise, de-identify and/or aggregate Customer Personal Data so that it cannot be used to identify, infer information about, or otherwise be linked to an individual person.

Categories of Data subjects whose Personal Data is Processed

Customer, Authorised Users and any other individuals in respect of which Customer Personal Data is provided to TKG by or at the direction of Customer or its Authorised Users via the Services, including from Third-Party Services. This may include Customer Personal Data relating to Customer’s and its Authorised Institutions’:

  • pupils and parents and guardians of pupils;
  • employees, contractors, governors and members of the governing body, or other staff members;
  • suppliers or other service providers to Customer or of any of Customer’s Authorised Institutions (including any Third Party Services) that need to access the Services for the purposes of fulfilling their obligations to Customer or its Authorised Institutions.
Categories of Personal Data Processed
  • Customer Personal Data as determined and controlled by Customer and its Authorised Users.
  • Personal data collected in the context of the provision of Customer support by TKG.
Categories of Special Category Data Processed

Customer Personal Data to the extent that it includes Special Category Data, which shall be determined and controlled solely by Customer and its Authorised Users, and may include:

  • health data, including special educational needs data;
  • personal data revealing racial or ethnic origin, religious or philosophical beliefs, or data concerning a natural person’s sex life or sexual orientation.

Appendix 2: Security Schedule

Name of ServiceSecurity MeasuresList of Sub-Processors
The Keyhttps://thekeysupport.com/trust-and-safety-program/ https://thekeysupport.com/sub-processors/
GovernorHubhelp.governorhub.com/en/articles/5302916-governorhub-technical-organisational-measureshttps://help.governorhub.com/en/articles/5165444-governorhub-sub-processors
Robinhttps://thekeysupport.com/trust-and-safety-program/ https://www.robin.education/subprocessors/
The KeyHomeWhy choose us?TrustsPricingStart your free trialJoin The Key
ExploreLeadersSafeguardingCPDGovernorHubKeyGPT
CompanyAboutCareersBlogThe Key Group
ContactGet in touch0800 061 4500Help centre

© The Key | Company: 08268303 | 0800 061 4500 | Customer AgreementPrivacyAccessibilityCookies

Why choose us?AboutPricing
Log inRegisterStart your free trial
Return to homepage
LeadersSafeguardingCPDGovernorHubKeyGPT
Training Hub
  • Staffing
  • Curriculum
  • School improvement & inspection
  • Admin & finance
  • Pupils & parents
  • MAT leadership
  • Policies
  • Safeguarding
  • CPD
  • Governance