|
295 | 295 | <li> |
296 | 296 | <p>Your organisation as a Data Controller is responsible for ensuring that:</p> |
297 | 297 |
|
298 | | - <ol class="govuk-list app-list--alpha"> |
| 298 | + <ol class="govuk-list app-list--lower-alpha"> |
299 | 299 | <li> |
300 | 300 | <p>it is permitted by Law to transfer Personal Data to GDS as its data processor;</p> |
301 | 301 | </li> |
|
342 | 342 | organisation, include: |
343 | 343 | </p> |
344 | 344 |
|
345 | | - <ol class="govuk-list app-list--alpha"> |
| 345 | + <ol class="govuk-list app-list--lower-alpha"> |
346 | 346 | <li> |
347 | 347 | <p>a systematic description of the envisaged Processing operations and the purpose of the Processing;</p> |
348 | 348 | </li> |
|
363 | 363 | <li> |
364 | 364 | <p>GDS shall, in relation to the GOV.UK Forms User Personal Data:</p> |
365 | 365 |
|
366 | | - <ol class="govuk-list app-list--alpha"> |
| 366 | + <ol class="govuk-list app-list--lower-alpha"> |
367 | 367 | <li> |
368 | 368 | <p> |
369 | 369 | process that Personal Data only in accordance with the Schedule of Processing, Personal Data and Data Subjects (Annex D) unless |
|
378 | 378 | Protective Measures), having taken account of the: |
379 | 379 | </p> |
380 | 380 |
|
381 | | - <ol class="govuk-list app-list--roman"> |
| 381 | + <ol class="govuk-list app-list--lower-roman"> |
382 | 382 | <li> |
383 | 383 | <p>nature of the data to be protected;</p> |
384 | 384 | </li> |
|
398 | 398 | <li> |
399 | 399 | <p>GDS shall ensure that:</p> |
400 | 400 |
|
401 | | - <ol class="govuk-list app-list--alpha"> |
| 401 | + <ol class="govuk-list app-list--lower-alpha"> |
402 | 402 | <li> |
403 | 403 | <p> |
404 | 404 | Processor Personnel do not Process Personal Data except in accordance with this MOU (and in particular the Schedule of Processing, |
|
411 | 411 | Data and ensure that they: |
412 | 412 | </p> |
413 | 413 |
|
414 | | - <ol class="govuk-list app-list--roman"> |
| 414 | + <ol class="govuk-list app-list--lower-roman"> |
415 | 415 | <li> |
416 | 416 | <p>are aware of and comply with the GDS duties under this paragraph;</p> |
417 | 417 | </li> |
|
435 | 435 | United Kingdom unless either: |
436 | 436 | </p> |
437 | 437 |
|
438 | | - <ol class="govuk-list app-list--roman"> |
| 438 | + <ol class="govuk-list app-list--lower-roman"> |
439 | 439 | <li> |
440 | 440 | <p>the transfer is in accordance with Article 45 of the UK GDPR or section 17A of DPA 2018; or</p> |
441 | 441 | </li> |
|
477 | 477 | either: |
478 | 478 | </p> |
479 | 479 |
|
480 | | - <ol class="govuk-list app-list--roman"> |
| 480 | + <ol class="govuk-list app-list--lower-roman"> |
481 | 481 | <li> |
482 | 482 | <p>the transfer is in accordance with Article 45 of the EU GDPR; or</p> |
483 | 483 | </li> |
|
503 | 503 | any Personal Data that is transferred; and |
504 | 504 | </p> |
505 | 505 |
|
506 | | - <ol class="govuk-list app-list--alpha"> |
| 506 | + <ol class="govuk-list app-list--lower-alpha"> |
507 | 507 | <li> |
508 | 508 | <p> |
509 | 509 | GDS complies with any reasonable instructions notified to it in advance by your organisation with respect to the |
|
530 | 530 | obligations under applicable Data Protection Legislation) if it: |
531 | 531 | </p> |
532 | 532 |
|
533 | | - <ol class="govuk-list app-list--alpha"> |
| 533 | + <ol class="govuk-list app-list--lower-alpha"> |
534 | 534 | <li> |
535 | 535 | <p>receives a Data Subject Request (or purported Data Subject Request);</p> |
536 | 536 | </li> |
|
567 | 567 | the timescales reasonably required by your organisation) including by promptly providing: |
568 | 568 | </p> |
569 | 569 |
|
570 | | - <ol class="govuk-list app-list--alpha"> |
| 570 | + <ol class="govuk-list app-list--lower-alpha"> |
571 | 571 | <li> |
572 | 572 | <p>your organisation with full details and copies of the complaint, communication or request;</p> |
573 | 573 | </li> |
|
611 | 611 | always that: |
612 | 612 | </p> |
613 | 613 |
|
614 | | - <ol class="govuk-list app-list--alpha"> |
| 614 | + <ol class="govuk-list app-list--lower-alpha"> |
615 | 615 | <li> |
616 | 616 | <p> |
617 | 617 | your organisation gives GDS a minimum of 30 calendar days’ written notice of its intention to audit (other than in the event of a |
|
666 | 666 | GDS must: |
667 | 667 | </p> |
668 | 668 |
|
669 | | - <ol class="govuk-list app-list--alpha"> |
| 669 | + <ol class="govuk-list app-list--lower-alpha"> |
670 | 670 | <li> |
671 | 671 | <p>have undertaken an information security assessment of the Sub-Processor to ensure compliance with all aspects of this MOU;</p> |
672 | 672 | </li> |
|
710 | 710 | particular GDS agrees that it shall: |
711 | 711 | </p> |
712 | 712 |
|
713 | | - <ol class="govuk-list app-list--alpha"> |
| 713 | + <ol class="govuk-list app-list--lower-alpha"> |
714 | 714 | <li> |
715 | 715 | <p>process the GOV.UK Forms User and Filler Personal Data only as set out in this MOU;</p> |
716 | 716 | </li> |
|
0 commit comments