10.1 Each party’s liability arising from this DPA is subject to the limitations in the Agreement.

10.2 Processor’s total liability for any breach of this DPA shall not exceed the greater of:

  • €1,000,000, or
  • 200% of fees paid by Controller in the 12 months preceding the claim

10.3 Processor shall indemnify Controller for:

  • Fines imposed by Supervisory Authorities directly on Controller due to Processor’s breach
  • Direct damages awarded to Data Subjects due to Processor’s breach

10.4 Indemnification is conditioned upon:

  • Controller providing prompt written notice of claim
  • Controller granting Processor sole control of defense
  • Controller providing reasonable assistance

11. TERM AND TERMINATION

11.1 This DPA becomes effective on the Effective Date and continues until termination of the Agreement.

11.2 Processor may terminate this DPA if:

  • Required to do so by law, or
  • Controller fails to cure a material breach within 30 days of notice

12. GOVERNING LAW AND JURISDICTION

12.1 This DPA shall be governed by:

  • For POPIA matters: Laws of South Africa
  • For GDPR matters: Laws of the Republic of Ireland
  • As specified in Standard Contractual Clauses where applicable

12.2 Any dispute arising from this DPA shall be resolved per the dispute resolution clause in the Agreement.


13. GENERAL PROVISIONS

13.1 Order of Precedence: In case of conflict:

  1. Standard Contractual Clauses (where applicable)
  2. This DPA
  3. The Agreement

13.2 Amendments: This DPA may be amended by Processor to comply with changes in law, with 30 days’ notice to Controller.

13.3 Severability: If any provision is invalid, the remainder remains in effect.

13.4 Notices: All notices shall be sent to the contact points specified in the Agreement.


APPENDIX 1: DETAILS OF PROCESSING

A. List of Parties

Controller:
Name: [Customer Name]
Address: [Customer Address]
Contact Person: [Data Protection Contact]
Email: [Data Protection Email]
Activities Relevant to Data Transferred: Use of WorkDuty Services

Processor:
Name: WorkDuty (Pty) Ltd
Address: The Workspace, 10 Fricker Road, Illovo, Johannesburg, 2196
Contact Person: Information Officer
Email: privacy@workduty.com
Activities Relevant to Data Transferred: Provision of WorkDuty Services

B. Description of Transfer

Categories of Data Subjects: As specified in Section 3.4
Categories of Personal Data: As specified in Section 3.5
Sensitive Data (if applicable): Only with explicit consent and additional safeguards
Frequency of Transfer: Continuous
Nature of Processing: As specified in Section 3.6
Purpose of Processing: Provision of WorkDuty Services
Retention Period: For duration of Agreement plus post-termination periods
Transfers to Third Countries: Yes, with appropriate safeguards as per Section 6

C. Competent Supervisory Authority

For GDPR: Data Protection Commission, Ireland
For POPIA: Information Regulator of South Africa


APPENDIX 2: TECHNICAL AND ORGANIZATIONAL MEASURES

A. Physical Access Control

  1. Data Center Security:
    • SOC 2 Type II certified facilities
    • Biometric access controls
    • 24/7 security personnel
    • Visitor logs and escort requirements
    • CCTV monitoring
  2. Environmental Controls:
    • Redundant power supplies (UPS, generators)
    • Climate control systems
    • Fire detection and suppression
    • Earthquake-resistant construction

B. System Access Control

  1. Authentication:
    • Multi-factor authentication for administrative access
    • Strong password policies
    • Regular credential rotation
    • Single Sign-On (SSO) support
  2. Authorization:
    • Role-Based Access Control (RBAC)
    • Principle of least privilege
    • Quarterly access reviews
    • Immediate deprovisioning upon termination
  3. Network Security:
    • Firewalls and intrusion prevention systems
    • Distributed Denial of Service (DDoS) protection
    • Network segmentation
    • Virtual Private Cloud (VPC) isolation
    • Regular vulnerability scans

C. Data Access Control

  1. Encryption:
    • At rest: AES-256 encryption
    • In transit: TLS 1.3 encryption
    • Key management: AWS KMS or equivalent
    • Key rotation every 90 days
  2. Data Classification:
    • Automated classification tools
    • Handling procedures per classification level
    • Data Loss Prevention (DLP) measures
  3. Access Logging:
    • Comprehensive audit logs
    • Immutable log storage
    • Real-time log analysis
    • 3-year log retention

D. Transmission Control

  1. Secure Transmission:
    • TLS 1.3 for all external communications
    • VPN for administrative access
    • Encrypted API communications
    • Certificate pinning
  2. Data Integrity:
    • Checksums for data transfer verification
    • End-to-end integrity checks
    • Regular data consistency validation

E. Input Control

  1. Data Validation:
    • Input sanitization
    • SQL injection prevention
    • Cross-Site Scripting (XSS) protection
    • File upload scanning
  2. Change Management:
    • Code review requirements
    • Security testing pre-deployment
    • Rollback capabilities
    • Change approval boards for major changes

F. Availability Control

  1. Redundancy:
    • Multi-zone deployment
    • Load balancing
    • Auto-scaling capabilities
    • Geographic redundancy
  2. Backup and Recovery:
    • Daily encrypted backups
    • 30-day backup retention
    • Regular recovery testing
    • Business Continuity Plan
    • Disaster Recovery Plan tested semi-annually
  3. Monitoring:
    • 24/7 system monitoring
    • Automated alerting
    • Performance monitoring
    • Capacity planning

G. Separation Control

  1. Data Segregation:
    • Logical separation per customer
    • Tenant isolation
    • Database segmentation
    • Resource allocation controls
  2. Development/Production Separation:
    • Separate environments
    • No production data in development
    • Controlled promotion procedures

H. Personnel Security

  1. Employee Screening:
    • Background checks for relevant roles
    • Reference verification
    • Employment history validation
  2. Training:
    • Annual security awareness training
    • Role-specific security training
    • Phishing simulation exercises
    • Data protection training
  3. Policies:
    • Acceptable Use Policy
    • Information Security Policy
    • Data Protection Policy
    • Incident Response Policy

I. Incident Response

  1. Response Plan:
    • Documented incident response procedures
    • Designated response team
    • Communication protocols
    • Escalation procedures
  2. Testing:
    • Annual tabletop exercises
    • Quarterly response drills
    • Post-incident reviews

J. Subprocessor Management

  1. Due Diligence:
    • Security questionnaire
    • Third-party audit review
    • Contractual requirements
    • Regular reassessment
  2. Ongoing Monitoring:
    • Quarterly compliance checks
    • Security score monitoring
    • Breach notification monitoring

K. Compliance and Certification

  1. Certifications:
    • SOC 2 Type II (annual)
    • ISO 27001 (planned Q3 2024)
    • Regular penetration testing
  2. Compliance Monitoring:
    • Automated compliance checks
    • Regular gap assessments
    • Legal and regulatory monitoring

L. Data Subject Rights

  1. Request Handling:
    • Automated request intake
    • Identity verification procedures
    • Response tracking
    • Audit trail maintenance
  2. Technical Measures:
    • Data portability tools
    • Deletion automation
    • Access control for rectification
    • Processing restriction capabilities

APPENDIX 3: STANDARD CONTRACTUAL CLAUSES

Module Two: Controller to Processor transfers

Clause 1 – Purpose and Scope: As per EU Commission Implementing Decision

Clause 2 – Effect and Invariability: SCCs prevail over contradictory provisions

Clause 3 – Third-Party Beneficiaries: Data Subjects may enforce certain clauses

Clause 4 – Interpretation: Definitions as per GDPR

Clause 5 – Hierarchy: In case of conflict with other agreements

Clause 6 – Description of Transfer: As per Appendix 1

Clause 7 – Docking Clause: Allows additional parties

Clause 8 – Data Protection Safeguards: As per Sections II and III of SCCs

Clause 9 – Use of Subprocessors: As per Section 5.4 of this DPA

Clause 10 – Data Subject Rights: As per Section 5.5 of this DPA

Clause 11 – Redress: Data Subject may lodge complaint with Supervisory Authority

Clause 12 – Liability: As per Section 10 of this DPA

Clause 13 – Supervision: Competent Supervisory Authority as per Appendix 1

Clause 14 – Local Laws Affecting Compliance: Processor shall notify Controller of inability to comply

Clause 15 – Obligations After Termination: As per Section 8 of this DPA

Clause 16 – Governing Law and Forum: As per Section 12 of this DPA

Clause 17 – Choice of Forum and Jurisdiction: Courts of Ireland for GDPR, South Africa for POPIA


APPENDIX 4: UK INTERNATIONAL DATA TRANSFER ADDENDUM

Part 1: Tables

Table 1: Parties as per Appendix 1
Table 2: Selected SCCs, Modules and Selected Clauses as per Appendix 3
Table 3: Appendix Information as per Appendices 1-3
Table 4: Ending this Addendum when the Approved Addendum changes

Part 2: Mandatory Clauses of the Approved Addendum


SIGNATURES

IN WITNESS WHEREOF, the parties have executed this DPA by their authorized representatives:

FOR WORKDUTY (PTY) LTD:


Name: Bruno Mpako
Title: Chief Executive Officer
Date: 25 Decenmber 2024

FOR CUSTOMER:


Name: Lesedi Moesha
Title: Systems Administrator
Date: 14th Octomber 2025


EXECUTION INSTRUCTIONS

  1. This DPA is incorporated by reference into the Agreement
  2. No separate signature required if Customer has accepted the Agreement
  3. To request a countersigned copy, email legal@workduty.com
  4. Controller specific details to be completed in Appendix 1

Document Control:
Version: 3.1
Approval: Legal & Compliance Committee
Next Review: July 1, 2024
Applicability: All Customer agreements globally

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare