This section forms the binding processing terms for personal data we handle on your behalf. No separate data-processing agreement is required. Applicable law includes the UK GDPR and Data Protection Act 2018, as amended, and the EU GDPR where applicable to the processing.
15.1. Processing description
- Subject matter
- Company register comparison; selected sanctions/AML screening; identity, address, liveness and face-matching checks; reminders, monitoring, assessment records, reports and associated support.
- Purpose and operations
- Receive submitted details; query sources; compare and present potential matches; arrange hosted verification and transmit request details; receive and retain selected assessments; support review, monitoring, alerts, permitted report downloads, return and deletion. Didit performs document and biometric analysis.
- Duration
- The service period and instructed read-only/restricted retention under section 7, subject to earlier lawful deletion and section 15.7.
- Individuals
- Customers, prospects, counterparties, directors, officers, owners and other selected people; authorised users and reviewers where their records are processed on your behalf.
- Data
- Names, aliases, relevant dates, nationality/country, address details, business links and identifiers, source records, candidate scores, instructions, reviewer notes, decisions and audit references. Identity checks also involve provider-held documents and facial captures, and selected extracted details, outcomes and warnings retained by RegScreen. Original document images, facial recordings and biometric templates are not retained in the assessment database.
- Sensitive information
- Screening material may include political affiliations, other special-category data, allegations, convictions, offences or related measures. Selected identity checks involve facial biometric processing by Didit. You must establish the applicable lawful basis and additional legal conditions. Processing follows lawful instructions, supplier permissions and safeguards; instructions cannot override legal or source restrictions.
- Roles
- You are normally controller. If you are a processor for another organisation, you must have authority to appoint us and pass through its instructions. We are processor or subprocessor for this activity; separate controller activities are covered by our privacy notice.
15.2. Standing instructions
Accepting these terms, selecting settings and submitting screening, monitoring or support requests provides your documented instructions for the corresponding processing, including transfers under section 15.5. Routine operations do not require separate instruction forms or approval requests.
We will process personal data only on those instructions unless UK law requires otherwise, or EU or Member State law where the EU GDPR applies. We will inform you beforehand unless the relevant law prohibits this. We will tell you immediately if we consider an instruction unlawful. We do not repurpose customer screening inputs, identity-verification data or review records for advertising, independent datasets or AI model training, and do not authorise our verification providers to do so. Automated matching and verification may be used to deliver the checks you request.
You determine the purposes and lawful basis for your checks, provide the necessary privacy information and meet any additional sensitive-data conditions, including obtaining and being able to demonstrate consent where required. Acceptance of these business terms or continued use does not substitute for an individual’s explicit consent where that is required. We remain responsible for obligations that apply directly to us.
15.3. Confidentiality and security
Personnel processing customer data must be subject to confidentiality duties and appropriate access controls. We will maintain technical and organisational measures meeting Article 32 of the UK GDPR, appropriate to the processing risks, including confidentiality, integrity, availability, recovery and regular assessment of security measures.
15.4. Subprocessors and notification
Acceptance of these terms gives general written authorisation to use subprocessors for the service. Separate approval for each appointment is not required. We make current provider identities, activities, relevant data, processing/access locations and transfer safeguards available before acceptance; updated details are available from contact@rrcompliance.com.
We give at least 30 days' written notice of intended additions or replacements, with relevant details. You may object on reasonable data-protection grounds during that period. We will address an objection before the change takes effect through a suitable alternative or cessation of the affected processing. If there is no objection, we may proceed after the notice period. Sections 7 and 8 govern resulting access and refund treatment.
Subprocessors must be bound by equivalent data-protection obligations, and we remain responsible to you for their performance of those obligations. Providers may support hosting, storage, screening queries, communications and support. A provider acting independently as controller is assessed according to that role.
15.5. UK hosting and international transfers
RegScreen's core application and system operations run on UK-hosted infrastructure. Its primary database of customer screening records, reports and decisions is stored in the UK. Service-provider processing, transfers and authorised access may occur outside the UK as described in this section.
The agreement gives standing instructions for transfers needed to provide, secure and support the service, including in both directions between the UK and the European Economic Area (EEA), which includes the EU. No separate customer approval is needed for each transfer. Section 15.4 continues to govern subprocessor changes.
We rely on applicable adequacy arrangements for UK–EEA transfers while they remain effective and cover the transfer. Other transfers must also meet applicable law. Where adequacy does not apply, we will put a lawful transfer mechanism, required assessment and necessary supplementary safeguards in place before transferring. Country and safeguard information is available from contact@rrcompliance.com.
15.6. Data-protection assistance
We will notify you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf. We will provide available information about its nature, affected data and people, likely effects, response and contact point, with updates as facts become available. You control notifications to individuals and regulators unless law independently requires us to act.
Taking account of the processing and information available, we will assist with individuals' rights, security, breach obligations, impact assessments and necessary regulatory consultation. Requests concerning your data will be referred to you promptly; we respond on your behalf only when instructed or required by law.
We will provide information needed to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, by you or your appointed auditor. Reasonable notice and confidentiality/security arrangements may protect the service and other customers, but must not obstruct legal rights or regulatory oversight.
15.7. Return, deletion and retained copies
At your choice, we will return or delete data processed on your behalf when that processing ends, and delete copies unless UK law requires retention. The access and restricted-retention periods in section 7 are standing instructions; earlier lawful deletion remains possible. At their end, we will delete the records after providing any return you have instructed before deletion.
Backup copies awaiting erasure will be protected, put beyond ordinary use and deleted as soon as possible through the backup-deletion cycle. Relevant deletion instructions will be reapplied if a backup is restored. Legally required retention is limited to the necessary data and purpose with restricted access. Separate controller records, including billing and legal records, follow our privacy notice.