Schedule I — the processing instruction
Record the parties’ legal names, roles, addresses and authorised contacts; the Order and DPA versions; service identifier; processing subject matter, nature and purpose; duration; categories of data subjects; types of personal data; and the controller’s rights and obligations. Describe the operations, such as hosting, storage, administration, backup, support and deletion, rather than using “all processing”.
Record permitted and excluded data, the source of instructions, rights-request route, incident contacts and escalation, return/export method, retrieval period, deletion timing for live data and copies, and specific lawful retention. Where the customer is a processor, record the controller authority and instruction chain. Do not place real customer personal data in the schedule.
Schedule II — measures actually in place
Identify implemented measures and service boundaries for physical protection; access roles and least privilege; authentication and privileged access; encryption in transit and at rest where appropriate; key control; logging; vulnerability and patch management; segregation; backup, restoration and resilience; incident response; staff confidentiality; supplier oversight; and periodic review or testing. Describe exceptions and responsibility for customer-managed components.
Attach dated evidence references or an agreed confidential security annex. Distinguish an implemented control from a plan, supplier marketing statement or proposed certification. Record how changes are notified and reviewed.
Schedule III — the authorised processing chain
For each processor and subprocessor, record the full legal entity and contact, service and processing task, affected data, processing and storage countries, remote-access countries and entity, appointment basis, contract date, onward subprocessors, and the transfer-schedule reference. State whether authorisation is specific or general and how notice and objections work. A brand name or a list of data-centre countries is insufficient on its own.
The website and enquiry provider list concerns that service only. It must not be assumed to be the authorised list for a customer’s VPS.
Schedule IV — transfers outside the EEA
For each relevant flow, identify exporter and importer, legal roles, data, purpose, frequency, onward transfers, destination/access countries and the legal mechanism. Where adequacy is used, verify that the actual recipient falls within its scope. Where standard contractual clauses are used, identify the correct decision and module, complete the annexes, assess the destination circumstances and record necessary supplementary measures. Assess how rights and redress can be exercised.
Record separate-entity access and employment status accurately. An employee of the same entity accessing data abroad is not automatically a transfer to a separate importer, but still requires a risk and security assessment. A separate contractor or supplier may create a transfer. Medical-data exclusions do not remove the need to assess actual accidental processing.
Completion and access
The parties must agree the completed schedules before the relevant processing begins. Review them when the service, supplier, country, data or measures change. The customer must receive and be able to retain its completed set. This page is the schedule specification; it is not a completed schedule for a particular customer.
Published 4 October 2026 · Version processing-schedules-2026-10-04-v1.