Data Processing Agreement
Data processing terms for GP practices using Mjog messaging services.
DATA PROCESSING AGREEMENT
This data processing agreement (the "Data Processing Agreement" or "DPA") is between:
(1) Huma Therapeutics Limited, registration number 07725451, with registered office at 13th Floor Millbank Tower, 21-24 Millbank, London, England, SW1P 4QP ("Processor"); and
(2) the GP Practice that uses Processor's Services to process data pertaining to patients ("Controller").
1. Introduction
1.1 The parties have entered into a service agreement (the Main Agreement) under which Processor shall provide Controller with certain services for the purpose of supporting Controller's provision of healthcare (the "Services"). The Services include processing by Processor of personal data on behalf of the Controller. For any such processing, the parties agree that Controller shall be data controller and Processor shall be data processor.
1.2 This Data Processing Agreement regulates the provision and use of personal data and ensures both Processor and Controller meet their obligations under Applicable Law.
1.3 Terms used in this DPA which are defined by the UK GDPR (the "GDPR") shall have the same meaning when used herein, unless specifically defined in this DPA or the Main Agreement.
2. Processing of personal data
2.1 Processor shall process all personal data on behalf of the Controller in accordance with the (i) Main Agreement, (ii) any law, statute, regulation, subordinate law or similar, court orders, judgements or decrees, and directions, policies, rules or orders that are applicable to a party from time to time ("Applicable Law"), and (iii) Controller's documented instructions set out hereunder. Processor shall not take any measures in respect of personal data received from Controller or collected on behalf of Controller for purposes other than those set out in the instructions provided hereunder, unless required to do so by Applicable Law in which case it shall give Controller prior written notice thereof (unless prevented to do so by Applicable Law).
3. Processing instructions
3.1 Processor must only process personal data to the extent, and in such a manner, as is necessary for the purpose of providing the services under the Main Agreement and in accordance with Controller's instructions. Processor will not process the Personal Data in any other way or in a way that does not comply with this DPA or Applicable Law.
3.2 Processor must comply with any instruction from Controller to amend, transfer, delete or otherwise process personal data, or to stop, mitigate or remedy any unauthorised processing.
3.3 Processor must maintain the confidentiality of the personal data and not disclose the personal data to third parties, unless Controller or this DPA specifically authorises the disclosure, or as required by domestic law, court or regulator (including the Information Commissioner's Office). If a domestic law, court or regulator requires Processor to process or disclose the personal data to a third party, Processor must first inform Controller of such legal or regulatory requirement and give Controller an opportunity to object or challenge the requirement, unless the domestic law prohibits the giving of such notice.
3.4 Nothing in this DPA shall require Processor to check or verify Controller's use, accuracy or content of such personal data, and Processor shall have no liability or responsibility whatsoever to Controller for the accuracy, content, or Controller's use of such personal data.
3.5 Processor may refuse to adhere to the instructions provided by Controller if the instructions would entail that Processor processes personal data in conflict with Applicable Law, provided that Processor (where permitted under Applicable Law) promptly notifies Controller thereof.
4. Obligations of the Controller
4.1 Controller acknowledges that, for the purposes of Applicable Law, the Controller retains control of the personal data and remains responsible for its compliance obligations under Applicable Law, including but not limited to providing any required notices and obtaining required consents, and for instructions it gives to Processor.
4.2 Controller represents and warrants that Processor's processing of personal data as contemplated under this DPA will comply with Applicable Law including in terms of collection, storage and processing activities.
4.3 Controller acknowledges that it is responsible for ensuring its use of the Services is appropriate and complies with Applicable Law and that Sub-Appendix 1 has been reviewed and approved by the Controller.
5. Security measures
5.1 Processor shall take all appropriate technical and organisational measures to protect personal data which it processes, including but not limited to protecting it against destruction, modification, unauthorised dissemination, unauthorised access, and other types of unauthorised processing.
5.2 The measures shall be adapted to a level which is suitable, taking into consideration the degree of sensitivity of the personal data, risks, existing technical possibilities, and the costs for carrying out the measures. At a minimum, Processor shall maintain the same level of protection as imposed by Applicable Law.
5.3 Processor shall only allow access to the personal data to personnel on a need-to-know basis. Processor shall ensure that all personnel having access to the personal data are subject to adequate confidentiality obligations.
5.4 Taking into account the nature of the processing, Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller's obligation to respond to requests for exercising a data subject's rights laid down in Applicable Law.
5.5 Processor shall comply with any decisions from a competent authority with jurisdiction over Processor or Controller. Processor shall, to the extent strictly necessary, also allow any competent authority to conduct supervision of the processing under this DPA.
6. Personal data breach
6.1 In the event of a personal data breach Processor shall inform the Controller without undue delay and notify and assist Controller as reasonably requested in fulfilling its notification obligations. The notification must, where possible, include at least the following:
6.1.1 a description of the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
6.1.2 a description of the circumstances of the data breach, including the date and time of the incident;
6.1.3 a description of the likely consequences of the personal data breach; and
6.1.4 a description of the measures taken or proposed to be taken by the Processor to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
7. Records and risk assessments
7.1 Processor shall keep written records of the processing activities performed for the Controller, in accordance with Applicable Law.
7.2 Where a type of processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, Processor shall reasonably assist Controller, prior to the processing, in carrying out an assessment of the impact of the envisaged processing operations on the protection of personal data (including assisting Controller in consulting the supervisory authority) provided that Controller pays for Processor's reasonable costs as agreed between the parties from time to time.
8. Data subject rights
8.1 Processor shall without undue delay refer to Controller all requests from data subjects and notifications, inquiries and similar from supervisory authorities.
9. Audit
9.1 Upon reasonable written notice, Controller may audit Processor's compliance with this DPA no more than once per calendar year, during normal business hours, and in a manner that does not unreasonably disrupt Processor's operations. The cost of the audit, including Processor's reasonable costs, shall be covered by the Controller.
9.2 The audit shall not grant the Controller access to trade secrets or proprietary information unless required to comply with Applicable Law. The Controller shall ensure its personnel conducting such audit are subject to adequate confidentiality obligations. The Processor shall upon request of the Controller provide all reasonable available information regarding the processing of personal data in order for the Controller to fulfil the obligations of a controller in accordance with Applicable Law. If the parties agree that an audit is to be performed by external auditors, such external auditor is to be appointed by the Controller but subject to approval of the Processor. Upon security audits performed by an external auditor, both parties shall be entitled to receive a copy of the audit report.
10. Sub-processors
10.1 Controller gives Processor a general written authorisation for the engagement of third party sub-processors for the processing of personal data and it may subcontract any of its processing operations under this DPA. The current list of sub-processors Processor is using is set out in Sub-Appendix 2. If Processor intends to engage additional sub-processors, Processor shall notify Controller thereof in writing (by email is sufficient) and must give Controller the possibility to object against the engagement of the sub-processor within 10 days of being notified. The objection must be based on reasonable grounds (e.g. if Controller proves that significant risks for the protection of its personal data exist). If the Processor and Controller are unable to resolve such objection, either party may terminate the Main Agreement by providing written notice to the other party.
10.2 Where Processor engages a sub-processor, it shall do so only by way of written agreement with the sub-processor which imposes adequate data protection obligations on the sub-processor that in all material respects are equivalent to those in this DPA. Processor remains responsible for the sub-processor's obligations under such agreement.
11. Liability
11.1 Nothing in this Data Processing Agreement limits any liability which cannot legally be limited.
11.2 Subject to clause 11.1, Processor's total liability to the Controller under this DPA shall not exceed £1,000,000 (one million pounds), provided that the aggregate liability of the parties under the Main Agreement (including this DPA) remains subject to the limitations set out in the Main Agreement where applicable.
12. International data transfers
12.1 The Processor may transfer personal data outside the UK and EU/EEA (or engage a sub-processor to process personal data outside of the UK and EU/EEA) provided (i) that the Processor ensures that at least one of the following prerequisites is fulfilled, and (ii) that the Processor can demonstrate the fulfilment of such prerequisite, and (iii) that the Processor obtains Controller's prior written approval for any such transfers / transfer mechanisms: (a) the receiving country has an adequate level of protection of personal data as decided by the European Commission; (b) the Controller confirms that the data subject has given his/her consent to the transfer; (c) the transfer is subject to the European Commission's standard contractual clauses for transfer of personal data to third countries; or (d) Processor is subject to Binding Corporate Rules and the receiving party in the third country is also subject to the Binding Corporate Rules.
13. Term and termination
13.1 This Data Processing Agreement shall terminate automatically once the Main Agreement has been terminated.
13.2 Upon termination, at Controller's written request, Processor shall either delete or return personal data processed on behalf of Controller hereunder. If Controller has not made such request within 30 days following the termination of the Main Agreement, Processor may destroy such personal data without notifying Controller thereof and without liability. Following termination of the Main Agreement, Processor shall not process any personal data for which Controller is the data controller in addition to the processing described in this clause 13, unless Processor is required to do so by Applicable Law and, if so, Processor shall inform Controller of any such obligations.
14. Governing law and jurisdiction
14.1 This DPA shall be governed by the same governing law, and be subject to the same dispute resolution mechanism, as set forth in the Main Agreement.
SUB-APPENDIX 1 - Details of processing
Subject matter of the processing: To provide the Services to the Controller.
Duration of the Processing: For so long as the Main Agreement and this DPA remain in effect.
Purposes and nature of the processing:
- Communication between patients, healthcare and/or social care professionals, via SMS, email, or other electronic communication, which may include images or documents.
- Video and audio communication for the purposes of video consultation.
- Hosting. Processor shall provide the Services and the technology, including infrastructure and applications supporting the functionality referred to above. This shall also include support and maintenance services to make sure the Services and technology meets acceptable standards on data availability, reliability, confidentiality and security, including but not limited to monitoring performance, troubleshooting, bug fixes, incident handling and management of capacity needs.
- Healthcare and/or social care professionals may disclose patient data when receiving technical support and from time-to-time Processor's technical team may have access to patient data when they are fixing a technical issue.
- Compilation of anonymised statistics about the use of Processor's services. These statistics may be used for Processor's own analytics and improvement purposes. Processor may also share these anonymised statistics publicly or with third parties. These third parties include: national bodies, including NHS Digital and NHS England; local NHS bodies, including ICBs, ICSs and Primary Care Networks; partners of Processor, including commercial organisations, charities and academic institutions.
Categories of personal data: Patient demographic details; NHS number; contact details; professional user details; and sensitive personal data including content of communications and health-related data required to provide the Services.
Categories of data subjects: Patients, Users/Employees of Controller.
Technical and organisational security measures: To ensure an appropriate level of protection of the personal data, Processor shall take all organisational and technical security measures that are identified in the Information Security and Data Protection policies that are applicable to the Huma group from time to time.
SUB-APPENDIX 2 - Current Sub-Processors
|
Name |
Services |
|
Amazon Web Services EMEA SARL |
Infrastructure |
|
Vonage (OpenTok) |
Video |
|
Looker Data Sciences, Inc. |
Analytics |
|
DataDog, Inc. |
Aggregation of metrics |
|
BT (EE) |
SMS |
|
NHS Digital |
App Messaging |
|
Exponential-E |
App Messaging |
