A DPA applies only where processing on behalf of a customer actually takes place.
Not every IT service automatically constitutes processing on behalf of a customer. The actual role depends on whether HTS Europa processes personal data for the specific engagement on documented customer instructions.
What the engagement-specific DPA governs.
The contractual version sets out the data protection obligations for the actual engagement rather than applying a generic model to every service.
Subject, duration & purpose
The concrete processing is described for the commissioned service.
Data & data subjects
Relevant data categories and data subject groups are documented only where they apply.
Instructions & confidentiality
Processing remains within the agreed scope and documented instructions, except where law requires otherwise.
Assistance & termination
Support with data subject rights or incidents, plus return, deletion and legal retention, are addressed contractually.
The public overview is not the individual DPA.
The website is provided for advance information. The DPA governing an engagement is identified during contracting and completed with the required engagement-specific schedules.
Versioned reference
The offer or service agreement can reference a clearly identified DPA version.
Engagement schedule
Purpose, data types, data subject categories, processing locations and retention belong in confidential contractual documentation.
Customer identities, concrete processing locations, internal reporting paths, authorised instruction contacts, security-sensitive operational information and customer-specific schedules are not published.
More public information
The overview brings together information about data processing, TOMs, subprocessors, retention and deletion.
