Data Processing Agreement
1. Parties
This Data Processing Agreement (“Agreement”) forms part of the agreement for services (“Principal Agreement”) between:
Calibre Audio
New Road
Weston Turville
Aylesbury
Buckinghamshire
HP22 5XQ
United Kingdom
(“Calibre Audio”)
and
each school, academy, college or educational organisation using the Calibre Audio Learning service (the "Controller").
Calibre Audio and the Controller are together referred to as the "Parties".
1.1 Relationship of the Parties
The Parties acknowledge that their role under applicable data protection legislation may vary depending on the processing activity undertaken.
Where Calibre Audio processes personal data solely on behalf of the Controller and under documented instructions, Calibre Audio acts as a Processor.
Where Calibre Audio determines the purposes and means of processing for service administration, safeguarding obligations, legal obligations, regulatory compliance, organisational record keeping, or operational service delivery, Calibre Audio acts as an independent Controller.
Each Party shall comply with its respective obligations under applicable data protection legislation where acting as a Controller.
2. Definitions
For the purposes of this Agreement:
Controller means the organisation which determines the purposes and means of processing personal data.
Processor means an organisation processing personal data on behalf of a Controller.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on personal data including collection, storage, use, disclosure, deletion, retrieval, or destruction.
Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Sub-processor means any third party appointed to process personal data on behalf of the Processor.
3. Purpose
This Agreement governs the processing of personal data by Calibre Audio in accordance with:
• UK GDPR
• Data Protection Act 2018
• Applicable ICO guidance and codes of practice
• Other applicable legislation and regulatory requirements
4. Scope of Processing
4.1 Subject Matter and Duration
Processing relates to the provision of audiobook services and associated support services for the duration of the service agreement.
4.2 Nature and Purpose of Processing
Processing activities may include:
• Membership administration
• Provision of audiobook services
• Eligibility verification including print disability verification
• Communication with members, schools, parents and partner organisations
• User account administration
• Service support activities
• Safeguarding-related activities where required
• Service reporting and monitoring activities
• Operational service management activities
4.3 Types of Personal Data
Personal data processed may include:
• Names
• Contact details
• Dates of birth
• Membership records
• User account information
• Listening and usage information
• Educational setting information
• Eligibility information
• Disability or print disability information (special category data where applicable)
• Communication records
4.4 Categories of Data Subjects
Data subjects may include:
• Pupils/members
• School staff
• Parents or guardians
• Volunteers
• Partner organisation contacts
4.5 Lawful Basis and Data Minimisation
Each Party remains responsible for identifying and documenting its lawful basis for processing under applicable legislation.
Examples of lawful basis may include public task, legitimate interests, legal obligation, consent, or substantial public interest where applicable.
Where special category data is processed, each Party shall identify and document the relevant lawful condition relied upon.
The Parties shall ensure that only personal data necessary and proportionate for the agreed purpose is shared or processed.
When processing or sharing personal data relating to children, the Parties shall ensure that the best interests of the child are a primary consideration.
The Parties shall seek to minimise the sharing of children’s personal data and ensure information shared is necessary, proportionate, and relevant to the intended purpose.
5. Processor Obligations
5.1 Act on Instructions
Where acting as Processor, Calibre Audio shall process personal data only on documented instructions from the Controller unless otherwise required by law.
5.2 Confidentiality
Calibre Audio shall ensure personnel:
• Are subject to confidentiality obligations
• Receive appropriate training
• Access personal data only where necessary
• Follow organisational security procedures
Calibre Audio shall take reasonable steps to ensure the reliability of employees, contractors, volunteers, and agents with access to personal data.
5.3 Security Measures
Appropriate technical and organisational measures may include:
• Role-based access controls
• Authentication controls
• Encryption where appropriate
• Secure storage and transmission methods
• Monitoring and review processes
• Incident management procedures
• Staff training and awareness
• Access logging where appropriate
• Multi-factor authentication where available
• Regular review of permissions and access rights
5.4 Sub-processors
Calibre Audio may engage sub-processors to support service delivery.
Calibre Audio shall:
• Maintain a list of approved sub-processors
• Make this available upon request
• Ensure equivalent contractual obligations are imposed on sub-processors
• Remain responsible for sub-processor performance
• Ensure appropriate safeguards are implemented where required
5.5 Data Subject Rights
Calibre Audio shall reasonably assist the Controller with:
• Subject Access Requests
• Rectification requests
• Erasure requests
• Restriction requests
• Objections
• Data portability requests
Where Calibre Audio receives a request directly relating to Controller data, it shall notify the Controller promptly.
5.6 Personal Data Breaches
Calibre Audio shall:
• Notify the Controller without undue delay and normally within 48 hours of becoming aware of a breach affecting Controller data
• Provide sufficient information to support investigation and reporting
• Assist with mitigation activities
• Maintain records relating to breaches
5.7 DPIAs and Compliance
Calibre Audio shall reasonably assist with:
• Data Protection Impact Assessments
• Regulatory consultations
• Compliance activities
5.8 Unlawful Instructions
Calibre Audio shall notify the Controller if an instruction appears to breach applicable law.
6. Retention, Deletion and Disposal
6.1 Retention
Calibre Audio retains personal data in accordance with published policies including:
Data Retention & Disposal Policy:
https://www.calibreaudio.org.uk/legal/data-retention-disposal-policy
Privacy Policy:
https://www.calibreaudio.org.uk/legal/privacy
6.2 Deletion or Return
At the end of services:
• Personal data shall be deleted or returned where appropriate
• Retention may continue where required for safeguarding, legal, regulatory, statutory, or operational purposes
• Deletion includes live systems and normal backup cycles where reasonably possible
Written confirmation of deletion may be provided upon request.
6.3 Secure Disposal
Calibre Audio shall ensure:
• Electronic records are securely deleted
• Paper records are securely destroyed
• Disposal activities are documented where appropriate
6.4 Safeguarding and Children’s Data
Where processing relates to children or safeguarding matters, Calibre Audio shall apply additional consideration to:
• The best interests of the child
• Data minimisation principles
• Appropriate access controls
• The sensitivity of disability, safeguarding, or special category data
• The need for proportionate information sharing to protect children or vulnerable individuals
Nothing within this Agreement prevents appropriate information sharing where necessary to safeguard a child or vulnerable person.
Where safeguarding concerns arise, information sharing decisions shall be made in accordance with applicable legislation, safeguarding guidance, and organisational policies.
7. Audit and Assurance
Calibre Audio shall:
• Provide information demonstrating compliance
• Permit reasonable audits or inspections
• Provide alternative assurance documentation where appropriate
8. International Transfers
Where personal data is transferred outside the United Kingdom:
• Transfers shall comply with UK GDPR requirements
• Appropriate safeguards shall be implemented
• Safeguards may include adequacy regulations, IDTAs, or UK Addendum arrangements
9. Data Protection Contact Information
Data Protection enquiries should be directed to:
Data Protection Lead
Calibre Audio
New Road
Weston Turville
Aylesbury
Buckinghamshire
HP22 5XQ
Email: dataprotection@calibre.org.uk
10. Confidentiality
Each Party shall keep confidential information received under this Agreement confidential except where disclosure is required by law.
11. Liability
Each Party remains responsible for complying with its own obligations under applicable data protection legislation.
Where Calibre Audio appoints sub-processors, Calibre Audio remains responsible for ensuring equivalent contractual obligations are maintained.
12. Data Protection Complaints
You can complain to us as well as the Information Commissioner’s Office (ICO) if you consider that we have infringed data protection legislation because of the way we have handled your personal data. More information can be found in our separate policy on Data Protection Complaints.
13. Review
This Agreement shall be reviewed periodically and updated where there are material changes to services, suppliers, systems, legal requirements, or operational arrangements.
14. Governing Law
This Agreement is governed by the laws of England and Wales.