Working template · grounded in primary law · not yet executed
Data-Processing Agreement
Between the client (Controller) and curator.consulting (Processor) · under GDPR Article 28 · last revised 24 July 2026
What this is. A ready-to-adapt Art 28(3) processing agreement for the content-review service. It sets, in writing, that the client is the controller (they own the data and the responsibility) and we are the processor (we act only on their instructions, and keep their content only while the engagement needs it — no longer, save the non-content tax record the law requires). The four points once flagged as “to be checked” are now resolved from the primary instruments and stated below. It is a working template, revisable as the law and the engagement require.
The parties
Controller
The client company, South Africa — the party whose marketing content is reviewed, and who determines why and how it is processed.
Processor
curator.consulting, a content-review practice established in Portugal [NIF / tax no.: to be inserted] — reviews the content on the controller's documented instructions and on the controller's behalf only. References to “curator.consulting” or “we” in this agreement mean this practice.
1 · Subject-matter & details (Art 28(3) chapeau)
Subject-matter
Review of the controller's social-media marketing content against applicable marketing/advertising and data-protection rules, and return of a written verdict.
Duration
The term of the engagement. We take in only the finished piece to be reviewed, and hold it only long enough to review it — by default inside a per-client encrypted container, cryptographically erased shortly after the finished review is delivered (see cl. 2(7)). We do not return content: the controller already holds the original. The sole exception is the non-content tax record at cl. 7.
Nature & purpose
Reading, analysis and quality/compliance review on-device; no profiling, no automated decisions about individuals, no re-use.
Type of personal data
Images and video of identifiable people appearing in the creatives; any names, contact details or personal data shown or spoken in the content.
Categories of data subjects
People depicted in the client's marketing content (models, staff, members of the public); named individuals in captions.
2 · The processor's obligations (Art 28(3)(a)–(h))
Documented instructions. We process the personal data only on the controller's documented instructions, including as to any transfer to a third country, unless required by EU or Member-State law (in which case we tell the controller first, unless the law forbids it). Art 28(3)(a)
Confidentiality. Everyone authorised to process the data is bound to confidentiality. Art 28(3)(b)
Security. We apply appropriate technical and organisational measures — sovereign-local, on-device processing; content held by default inside a per-client encrypted container whose key is destroyed on erasure, and otherwise on full-disk-encrypted storage; no cloud storage of client content. Art 28(3)(c) · Art 32
Sub-processors. We engage no sub-processors for the content. No third-party service receives the client's content. Any future sub-processor requires the controller's prior written authorisation and equivalent Art 28 terms. Art 28(2),(4)
Data-subject rights. We assist the controller, so far as possible, to answer requests from individuals exercising their rights. Art 28(3)(e)
Security, breach & DPIA support. We assist the controller with security, breach notification and any impact assessment, given the nature of the processing and the information available to us. Art 28(3)(f) · Arts 32–36
Deletion by default.Zero-retention is our default. The controller's content is held inside a per-client encrypted container and cryptographically erased on completion of the review — and no later than twenty-four hours after the finished review is retrieved. The per-client encryption key is destroyed, so the remaining ciphertext cannot be read, including by us, and a signed, time-stamped Certificate of Erasure is issued. The controller retains the statutory right under Art 28(3)(g) to instead elect return of the personal data; because the controller already holds the original content it supplied, return duplicates what the controller has and is available on request rather than as a standing step. The single exception, either way, is the retention required by law under cl. 7. Art 28(3)(g)
Demonstrate compliance. We make available the information reasonably needed to show compliance with this clause and allow for audits/inspections by the controller or its auditor. Art 28(3)(h)
3 · Roles & responsibility
The controller is responsible for, and determines, the lawful basis for the people shown in the content, the purposes of processing, and retention decisions, and is accountable under Art 5(2). The processor's responsibility is limited to processing on instruction and to its own Art 28/32/82 duties. Nothing here makes the processor a controller; if the processor ever processed the content for its own purposes it would become a controller under Art 28(10) — it will not.
4 · International transfer (EU → South Africa)
Because we do not return content by default, no transfer of content from us to South Africa arises in the ordinary course — the controller already holds the original there. Should the controller elect return under cl. 2(7), that return is a transfer to a third country not covered by an EU adequacy decision, and the parties will put the 2021 Standard Contractual Clauses (Module Four, processor-to-controller) in place, with the controller bearing primary responsibility for the transfer tool and any transfer-impact assessment. GDPR Chapter V · EDPB Guidelines 05/2021
5 · POPIA (the controller's own law)
The controller is a South African “responsible party” under POPIA (Act 4 of 2013). This agreement is intended to be consistent with POPIA's operator/processor requirements and its retention-limitation principle (s14): content is kept no longer than the review needs, and our zero-retention default meets both regimes' minimisation aims at once.
6 · Records & accountability
The processor keeps a lightweight Record of Processing Activities (Art 30(2)) — the parties' details, the categories of processing, transfers and safeguards, and a general description of the security measures. The Art 30(5) small-operator exemption is not relied upon.
7 · The one retention carve-out — 10 years, non-content
Portuguese tax law (Decreto-Lei 28/2019, with the Código do IVA Art 52) obliges the processor to keep invoices, books and supporting records for ten years. This is the sole exception to cl. 2(7): the retained material is invoice/accounting metadata only — never the reviewed content or the personal data of anyone shown in it. DL 28/2019 Art 19 · CIVA Art 52
Four points — resolved from primary law.
Transfer tool:SCC Module Four (Commission Implementing Decision (EU) 2021/914) — the EU-processor→third-country-controller module — governs any return the controller elects under cl. 2(7). We do not rely on the Art 49 derogations: EDPB Guidelines 2/2018 confine them to occasional, non-repetitive transfers, and a return within a standing engagement is not one we treat as occasional. Decision (EU) 2021/914 · EDPB 2/2018
Invoice residue is non-content: the mandatory fatura fields (supplier & customer name/NIF, date, sequential number, description of the service, taxable amount, VAT rate/reason) are administrative — none embeds reviewed content or a data subject's personal data. CIVA Art 36(5) & Art 40 · DL 28/2019 Art 19(1)
Nothing bites beyond 10 years: Código Comercial Art 40(1) mirrors the same 10-year keep of books/correspondence (non-content); Lei 58/2019 adds no fixed retention and no CNPD registration/notification duty on a solo operator (its Art 21 defers to whatever period other law sets — i.e. the tax/commercial 10 years). Código Comercial Art 40 · Lei 58/2019 Art 21
RoPA kept: a regular monthly review is “not occasional,” so the Art 30(5) under-250 exemption does not apply — a one-page Record of Processing is maintained regardless (cl. 6). GDPR Art 30(5) · EDPB position paper
Acceptance
This agreement is accepted electronically — there is no wet signature. Each acceptance is date-stamped and kept as part of the engagement record.
Controller
Open this agreement from your private link to accept it online.