Data Processing Agreement
Last updated:
On this page
- 1. Introduction and scope
- 2. Roles and scope of processing
- 3. Controller instructions
- 4. Processor obligations
- 5. Sub-processors
- 6. Data subject rights
- 7. Security measures
- 8. International transfers
- 9. Personal data breach
- 10. Data retention and deletion
- 11. Audits and inspections
- 12. Term and termination
- 13. Contact
1. Introduction and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Verify Recruits Ltd ("Verify Recruits", "Processor", or "we") and the employer client ("Client", "Controller", or "you") that uses our verification platform.
It reflects the parties' obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This DPA applies to all processing of personal data carried out by Verify Recruits on behalf of the Client in providing the Services.
2. Roles and scope of processing
The Client is the data controller and determines the purposes and means of processing candidate personal data. Verify Recruits is the data processor and processes personal data only on the Client's documented instructions.
The scope of processing includes:
- Identity verification and right-to-work checks;
- Employment history verification, including contact with previous employers;
- Education and professional credential verification;
- Reference collection from referees nominated by the candidate;
- HMRC income and employment history checks, where authorised by the candidate;
- Storage of verification results and supporting documents for the Client's records.
3. Controller instructions
The Client instructs Verify Recruits to process personal data for the following purposes:
- To perform verification checks requested through the platform;
- To store and transmit verification results to the Client;
- To provide audit trails and compliance reports; and
- To operate and maintain the platform infrastructure.
The Client warrants that its instructions comply with applicable data protection law and that it has obtained all necessary consents and lawful bases for the processing. Verify Recruits will not process personal data for any purpose other than as instructed, except where required by law, in which case we will inform the Client unless that law prohibits it.
4. Processor obligations
Verify Recruits shall:
- Process personal data only on the Client's documented instructions;
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations;
- Implement appropriate technical and organisational security measures as set out in Section 7;
- Assist the Client in responding to data subject rights requests;
- Assist the Client with data protection impact assessments where required;
- Notify the Client without undue delay (and in any event within 48 hours) of any personal data breach;
- Make available all information necessary to demonstrate compliance with this DPA and allow audits by the Client or its auditor.
5. Sub-processors
Verify Recruits engages the following categories of sub-processor to deliver the Services:
- Cloud hosting — infrastructure providers hosting the platform and stored data.
- Email delivery — services sending verification invitations and notifications.
- Identity verification — providers of document checking and biometric verification.
- HMRC — for income and employment history checks authorised by the candidate.
- Analytics — privacy-preserving analytics on aggregated, anonymised data.
A current list of named sub-processors is available on request from dpo@[verify-recruits].com. We will give the Client at least 30 days' notice of any change to sub-processors, during which the Client may object. We remain liable for the acts of our sub-processors to the same extent as if we performed the services ourselves.
6. Data subject rights
Verify Recruits will assist the Client in fulfilling its obligations to respond to data subject rights requests. Where a candidate or User contacts Verify Recruits directly to exercise a right, we will forward the request to the Client without undue delay and will not respond to the request ourselves unless instructed by the Client or required by law.
7. Security measures
Verify Recruits implements the following technical and organisational measures:
- Encryption — TLS 1.2+ in transit and AES-256 at rest.
- Access control — role-based permissions, least-privilege access, and multi-factor authentication for administrative accounts.
- Network security — firewalls, intrusion detection, and regular vulnerability scanning.
- Personnel security — background checks for staff with access to personal data and ongoing security training.
- Incident management — documented incident response procedures with breach notification to the Client and the ICO where required.
- Business continuity — regular backups and disaster recovery testing.
8. International transfers
Personal data is primarily stored and processed within the United Kingdom. Where data is transferred outside the UK, Verify Recruits ensures an adequate level of protection through UK government adequacy decisions, Standard Contractual Clauses, or International Data Transfer Agreements approved by the ICO. A copy of the safeguards is available on request.
9. Personal data breach
Verify Recruits will notify the Client without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Client's data. The notification will describe the nature of the breach, the categories and approximate number of records and individuals concerned, the likely consequences, and the measures taken or proposed to address it.
The Client is responsible for assessing whether the breach requires notification to the ICO or to affected data subjects. Verify Recruits will provide reasonable assistance to the Client in meeting its notification obligations.
10. Data retention and deletion
Verify Recruits retains personal data for the duration of the Client's contract and for the retention period set out in our Privacy Policy, unless the Client instructs otherwise in writing. On termination, Verify Recruits will, at the Client's choice, return or delete all personal data and existing copies, unless retention is required by law.
11. Audits and inspections
The Client may audit Verify Recruits' compliance with this DPA, subject to reasonable notice (at least 14 days) and no more than once per calendar year. Audits will be conducted during business hours, with minimal disruption to our operations, and may be carried out by the Client or an independent auditor bound by confidentiality. Verify Recruits will provide reasonable cooperation and access to relevant records.
12. Term and termination
This DPA takes effect on the date the Client accepts the Terms of Service and remains in force for the duration of the agreement between the parties. On termination, the obligations of confidentiality and security survive indefinitely.
13. Contact
For questions about this DPA or to request a signed copy, contact our Data Protection Officer:
- Verify Recruits Ltd — Data Protection Officer
- Email: dpo@[verify-recruits].com
- Address: [Registered office address, United Kingdom]