top of page

Data Processing Agreement

ISL-LEG-F-A — the Article 28 processing agreement cited by B01 §8 and C01 cl.12.3. Sets out the controller/processor split per data set, the processing description, security measures, 48-hour breach notification, sub-processor groups and UK data residency, retention and deletion, and audit rights.

England & Wales

Data Processing Agreement

InSignLanguage Ltd · Document code ISL-LEG-F-A · Annex A to the Client / Approved Organisation Terms (ISL-LEG-B01) · Governing law: England & Wales · ICO registration ZC163713

Version 0.1 — DRAFT for external data-protection counsel review. Not yet binding.

1. What this agreement does

This agreement governs how InSignLanguage handles personal data when providing interpreting, translation and related services. It forms part of our Terms and Conditions of Service and satisfies Article 28 of the UK GDPR.

It applies automatically to every client engagement — you do not need to sign a separate document, though we are happy to execute a counterpart where your procurement process requires one. Where you have your own data processing agreement and we have signed it, that document takes precedence for your engagement.

2. Definitions

"UK GDPR", "controller", "processor", "personal data", "special category data", "processing", "data subject" and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Data Protection Law" means both, together with the Privacy and Electronic Communications Regulations 2003. "Client Personal Data" means personal data we process on your behalf in delivering the services.

3. Who is controller, and who is processor

This is the part most agreements leave vague, so we state it plainly. The roles differ by data set:

Data

Controller

Our role

Your staff and contacts (the person booking, the approver)

You

Processor

Your customers, patients, service users or employees for whom we interpret

You

Processor

The content of an interpreted session

You

Processor — and we do not record or retain it (section 7)

Our booking, scheduling and assignment records

InSignLanguage

Controller

Our invoicing and financial records

InSignLanguage

Controller

Aggregated management information and service reporting

InSignLanguage

Controller

Our interpreters' own personal data

InSignLanguage

Controller

This dual role is normal, and we document it rather than blur it. Where we act as controller we do so under our own Privacy Notice and lawful bases, not on your instructions.

4. The processing, described

Subject matter: provision of British Sign Language interpreting, translation and related accessibility services.

Duration: the term of our agreement with you, plus the retention periods in section 8.

Nature and purpose: receiving and validating booking requests; matching and assigning a suitably qualified interpreter; briefing that interpreter; delivering the assignment in person or remotely; recording completion; invoicing; and producing service reporting.

Types of personal data: names and contact details; appointment details including date, time, location and duration; the subject or context of the appointment; communication and access requirements; and any information you choose to include in booking notes.

Special category data: the service exists to support Deaf people, so data revealing disability is inherent to it. Depending on the setting, booking context may also reveal health, sexual orientation, religious belief or racial or ethnic origin. Healthcare, legal and social-care clients should assume special category data is in scope.

Criminal offence data: where an appointment concerns a police, court or safeguarding matter, booking context may amount to criminal offence data under Article 10. We handle this under section 10.

Categories of data subject: your staff; your customers, patients, service users or employees; and our interpreters.

5. Our obligations as your processor

  1. Process only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we tell you first unless the law prohibits it. Your booking requests, this agreement and our terms together constitute your documented instructions.

  2. Tell you if an instruction appears to breach Data Protection Law, and pause that processing until it is resolved.

  3. Ensure everyone authorised to process Client Personal Data is bound by confidentiality — our staff by contract, our interpreters by the Interpreter Supplier Terms and by their professional register's code of conduct, which imposes a confidentiality duty independent of ours.

  4. Apply appropriate technical and organisational measures (section 6).

  5. Assist you in responding to data subject rights requests, and with data protection impact assessments and prior consultations.

  6. Notify you of a personal data breach affecting Client Personal Data without undue delay and in any event within 48 hours of becoming aware, with the information available at that point and updates as we learn more.

  7. Delete or return Client Personal Data at the end of the engagement (section 8).

  8. Make available the information needed to demonstrate compliance, and submit to audits (section 12).

6. Security

We maintain an information security management system aligned to ISO/IEC 27001:2022, and hold ISO 9001:2015 and ISO 18841:2018 certification. Measures include:

  • Access control — Microsoft Entra ID with multi-factor authentication and conditional access; least-privilege roles; privileged access management; joiner-mover-leaver process with prompt deprovisioning and periodic access reviews.

  • Encryption — in transit and at rest across our Microsoft 365, Dataverse and Azure estate.

  • Data minimisation in practice — interpreters receive only the booking detail needed to prepare and attend, never the full record.

  • Segregation — client data is held in structured CRM records with role-based and record-level security, not in shared mailboxes or loose files.

  • Logging and monitoring — Dataverse auditing, Azure Monitor and Defender, with alerting on anomalous access.

  • Vetting — enhanced DBS or equivalent for interpreters working with children or adults at risk; right-to-work and identity verification for all.

  • Training — role-based data protection training with annual refresh.

  • Business continuity — documented disaster recovery, with data held in Microsoft's certified datacentres.

We review these measures at least annually and after any material change or incident.

7. Recording

We do not record interpreted sessions by default. Recording happens only where it has been enabled in writing for a specific assignment, with the lawful basis, purpose, retention and distribution agreed in advance, and with the informed consent of everyone taking part — confirmed accessibly, in British Sign Language, where a participant is Deaf.

Where recording is enabled, the interpreter retains no copy. Any retained recording is held by us as controller for quality assurance, complaint handling or safeguarding, for the minimum period in our retention schedule, and then deleted.

8. Retention, return and deletion

We keep Client Personal Data for the duration of the engagement plus a defined audit period, after which it is securely deleted. Aggregated management information — which contains no personal data — may be retained indefinitely.

On termination, at your choice, we will return Client Personal Data in a commonly used format or delete it, and certify deletion, except where we must retain it: to evidence an Access to Work claim to the DWP; to meet statutory accounting or limitation-period requirements; or to defend a legal claim. Retained data stays subject to this agreement's confidentiality and security terms and is not otherwise processed.

9. Sub-processors and international transfers

You give general written authorisation for us to appoint sub-processors. We maintain the current list and will give at least 30 days' notice before adding or replacing one, so you can object on reasonable data protection grounds. Every sub-processor is engaged under written terms imposing obligations no less protective than these, and we remain fully liable to you for their performance.

Our sub-processors fall into four groups: cloud and productivity infrastructure (Microsoft — Microsoft 365, Dataverse, SharePoint, Azure Communication Services); website and booking platform (Wix); finance (Xero); and interpreters — self-employed professionals engaged under the Interpreter Supplier Terms, who receive only the minimum booking detail and are bound by confidentiality and their register's code.

Processing takes place in the United Kingdom; our Dataverse environment is UK-region. Where a sub-processor transfers personal data outside the UK, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.

10. Special category and criminal offence data

Processing disability data is inherent to what we do. Where we act as your processor, you are responsible for the Article 9 condition; where we act as controller, we rely on the conditions set out in our Privacy Notice.

For criminal offence data — principally the DBS, PVG or AccessNI information we hold for interpreters — we process under the safeguarding condition in Schedule 1 of the Data Protection Act 2018, and maintain the Appropriate Policy Document that condition requires.

11. Liability

Each party's liability under this agreement is subject to the limitations in our Terms and Conditions of Service, except that nothing limits either party's liability for death or personal injury caused by negligence, for fraud, or to the extent liability cannot lawfully be limited — including a data subject's rights to compensation under Article 82.

12. Audit

We will make available the information reasonably needed to demonstrate compliance with Article 28, including our certifications, policies and the results of relevant assessments.

You may audit our processing once in any twelve-month period on 30 days' written notice, or sooner following a personal data breach affecting your data or where a regulator requires it. Audits take place during business hours, must not unreasonably disrupt the service, and are subject to confidentiality. Where an independent certification or audit report already answers the question, we will provide it in the first instance.

13. General

This agreement takes effect with the Terms and Conditions of Service and ends when they do, save for provisions that by nature survive. If any provision conflicts with Data Protection Law, the law prevails and the provision is read down to the minimum extent necessary. Governed by the laws of England and Wales.

Data protection contact: John Hood, Data Protection Lead — john@insignlanguage.co.uk · support@insignlanguage.co.uk

InSignLanguage Ltd · 26 Domum Road, Portsmouth PO2 0QZ · Company number 10943637 · ICO registration ZC163713

bottom of page