Prepared for review: 30 September 2026. Status: draft, not effective.
1. Draft, parties and incorporation
This is a drafting framework for a customer agreement, not an executed data-processing addendum. It requires named legal parties, an effective service order, processing annexes and review against applicable laws. It must not be described as a signed DPA or transfer mechanism merely because it appears on the website.
2. Roles and instructions
For employee information managed on behalf of a customer, the customer is normally responsible for determining purposes and instructions. StaffWorkspace’s exact controller, processor or other role depends on the activity and applicable law. Website enquiries and the operator’s own billing administration must be analysed separately. Processing should follow documented, lawful customer instructions and the completed service agreement.
3. Processing description
Annex A must identify the service, processing purposes, duration, operations, data subjects and data categories. Typical workspace categories may include staff identifiers, contact details, contracts, attendance, leave, employer-published pay records, tasks and documents. Do not add health, biometric, identity-document or precise-location data by default. Each sensitive category requires an explicit assessment, instructions and safeguards.
4. Personnel and confidentiality
Access should be limited to authorised personnel who need it to deliver or support the agreed service and are subject to appropriate confidentiality duties. Joiner, role-change and leaver processes should remove unnecessary access. Support impersonation or access to employee documents should be controlled and auditable where implemented; it must not be assumed from marketing copy.
5. Security schedule
Annex B must describe verified measures rather than aspirational labels. Complete the actual authentication, authorisation, encryption, key management, tenant isolation, backup and restore, secure development, vulnerability management, access review, logging, incident response and physical hosting controls. Include evidence dates, responsible owners and any limitations. No certification, encryption standard or recovery target is asserted by this uncompleted schedule.
6. Subprocessors
Annex C must list each actual subprocessor’s legal identity, purpose, processing location and access. The agreement should establish the applicable authorisation model, notice of changes, a meaningful objection process and appropriate downstream obligations. A list of possible vendors is not a completed subprocessor register.
7. International transfers
The parties must identify exporting and importing entities, countries, onward access and the transfer rules applicable to each data flow. Execute an appropriate mechanism when required, complete necessary assessments and add supplementary measures where needed. An EU standard clause module, UK addendum or local equivalent must not be selected or incorporated without checking its applicability and annexes.
8. Rights requests and assistance
The service provider should assist the customer with applicable data-subject requests using secure, proportionate procedures and agreed timescales. The provider should not independently alter employment records or answer on the employer’s behalf unless authorised or legally required. The agreement should define request forwarding, identity verification, search and export capability, exemptions and evidence of completion.
9. Incidents
The agreement should require incident escalation without undue delay when applicable, identify a working security contact, and specify the facts to share as they become available, including affected systems, categories, scope, mitigation and contact points. Customer and provider duties to regulators or individuals must be allocated under applicable law. A universal breach-notification deadline is not assumed in this draft.
10. Impact assessments and consultation
Provide reasonable information and assistance for relevant risk assessments, sensitive processing and regulator consultation, within the actual service scope. The customer must evaluate whether attendance photography, location monitoring or other employee functions are necessary and proportionate, and whether a less intrusive option is required. Provider assistance does not transfer the employer’s decision-making responsibilities.
11. Audit and evidence
The final agreement should offer proportionate evidence and audit arrangements, protect other customers’ data and trade secrets, address confidentiality and notice, and preserve any mandatory audit rights. Evidence may include scoped independent reports where they genuinely exist. Do not imply an audit has occurred or a standard has been certified without a current report.
12. Return, deletion and retention
Specify an export format, an exit window, deletion steps and backup ageing after termination. Identify legal holds or mandatory retention separately and restrict continued use of retained records. The provider must be able to implement the agreed schedule before making a deletion guarantee. A marketing-site form is not a channel for exporting employee databases.
13. Liability, precedence and completion
Allocate contractual responsibility in the signed terms without overriding mandatory law or the rights of affected individuals. Clarify how this addendum, a transfer instrument and the main agreement interact. Do not release this draft as operative until Annex A, Annex B, Annex C, contacts, locations, governing terms and signature or incorporation process are complete.