Data Processing Agreement (DPA)

Pay Per Report Service

EUCompliance.support

Last updated: 8. January 2026


Purpose

This Data Processing Agreement (“DPA”) is entered into in accordance with Article 28 of the GDPR.

It governs the processing of personal data by EUCompliance.support on behalf of the Customer in connection with the whistleblower compliance service.


Roles of the Parties

  • The Customer acts as Data Controller

  • EUCompliance.support acts as Data Processor


Scope of Data Processing

Personal data is processed solely for the purpose of:

  • Receiving whistleblowing reports

  • Screening and classifying submissions

  • Maintaining case records

  • Communicating legally relevant reports to the Customer

Anonymous reporting is supported.


Categories of Personal Data

Personal data may include:

  • Information contained in whistleblowing reports

  • Optional contact details provided by the reporting person

  • Supporting documentation submitted with reports


Processing Activities

EUCompliance.support processes personal data only in accordance with:

  • This DPA

  • The Service Agreement

  • Documented instructions from the Customer


Use of Sub-processors

The Customer authorises EUCompliance.support to use third-party service providers (sub-processors) as necessary to deliver the service.

EUCompliance.support remains responsible for the performance of its sub-processors.


Data Security

EUCompliance.support implements appropriate organisational measures to protect personal data against unauthorised access, loss, or disclosure.


Data Breaches

In the event of a personal data breach affecting the service, EUCompliance.support will notify the Customer without undue delay.


Data Retention

Personal data is retained only for as long as necessary to:

  • Deliver the service

  • Fulfil legal and compliance obligations


Rights of Data Subjects

EUCompliance.support assists the Customer, where applicable, in responding to requests from data subjects in accordance with GDPR requirements.


Governing Law

This DPA is governed by Danish law, unless mandatory local law applies.


Acceptance

This Data Processing Agreement forms an integral part of the contractual relationship between EUCompliance.support and the Customer.