Data processing agreements in place with all subprocessors
A current DPA is in place with every subprocessor that handles personal data. Agreements reflect GDPR Article 28 requirements including purpose limitation, security obligations, and audit rights.
DPAs cover: purpose limitation, data minimisation, security obligations, deletion timelines, audit rights, and breach notification requirements. Where subprocessors are outside the EEA, Standard Contractual Clauses or equivalent mechanisms are in place. The subprocessor list is reviewed annually and published on the EmpowerGPT trust page.