Data processing agreement
Anyone using a CMP has personal data of their visitors processed through us. That makes us a processor under Article 28 GDPR — and a processing agreement is mandatory, not an extra. It is concluded in electronic form on registration; Article 28(9) GDPR does not require a separate signature.
Version of 2026-08-19
This translation is provided for convenience only; the German version is authoritative.
Processor
LW IT Solutions Company Lukas Wójcik
LW IT Solutions Company Lukas Wójcik, al. Tadeusza Kościuszki, nr 80/82, lok. 301, 90-437 Łódź, Poland
Controller
The controller within the meaning of this agreement is the respective website operator who uses consented.eu on their website.
This agreement gives concrete form to the obligations under Article 28 GDPR for the processing the processor carries out for the controller. It forms part of the terms of use and is concluded on registration.
Contents
- Subject matter, nature and purpose of the processing
- Instructions of the controller
- Responsibility of the controller
- Confidentiality
- Technical and organisational measures
- Sub-processors
- Assistance with data subject rights
- Assistance with security, notification duties and impact assessment
- Personal data breaches
- Evidence and audits
- Deletion and return
- Record of processing activities
- Data protection contact
- Liability and indemnity
- Term and termination
- Final provisions
1. Subject matter, nature and purpose of the processing
Nature and purpose: Collection, storage and provision of the consent decisions made by the visitors of the controller, for the purpose of demonstrating consent under Art. 7 Abs. 1 DSGVO.
Categories of data subjects: Visitors to the websites of the controller.
Categories of data: Consent decision per category and service, timestamp, configuration version, language, domain, device family, hashed page URL, HMAC-pseudonymised IP address.
Duration: The agreement runs for as long as the controller uses the service and ends with the usage relationship. Processing of the consent records ends when the retention period configured by the controller expires, or on their instruction to delete.
Place of processing: exclusively within the European Union.
Excluded data: The service is not intended for processing special categories of data under Article 9 GDPR or data under Article 10 GDPR. The controller ensures that such data are not processed through the service.
2. Instructions of the controller
The processor processes personal data solely on documented instructions from the controller (Article 28(3)(a) GDPR). This also applies to any transfer to third countries.
The instructions follow exhaustively from this agreement, the terms of use and the configuration the controller makes in the dashboard. Every setting made there — services, categories, texts, languages, region rules, retention periods, templates and tests — is a documented individual instruction within the meaning of Article 28(3)(a) GDPR. It is recorded in the audit log with a timestamp and the person acting; that log is the documentation of the instructions in force.
Instructions outside the dashboard are given in text form to the address stated above. The controller confirms any instruction given orally in text form without delay. The persons entitled to give instructions are those recorded in the dashboard with the corresponding role; the controller keeps these details up to date.
If the processor considers an instruction to be manifestly unlawful, it says so without delay and may suspend execution until confirmation (Article 28(3), third sentence, GDPR). It owes no legal review of the instruction beyond that; it is not obliged to assess the lawfulness of the processing.
Where Union law or the law of a member state requires the processor to carry out processing, it informs the controller beforehand unless that law prohibits such notification.
Additional effort beyond the scope of functions owed may be refused by the processor, or made conditional on reimbursement, in the case of a service provided free of charge. Mandatory statutory duties to cooperate remain unaffected.
3. Responsibility of the controller
The controller is solely responsible for the lawfulness of the processing, in particular for
- the legal basis for each processing operation and the validity of the consent obtained,
- meeting the information duties under Articles 13 and 14 GDPR on its website,
- the accuracy and completeness of the details it enters on services, purposes, recipients and retention periods,
- assessing whether a data protection impact assessment under Article 35 GDPR is required,
- safeguarding the rights of data subjects, and
- the technical integration on its website, in particular ensuring that services requiring consent are not loaded there before consent is given. The processor has no access to the website of the controller and can neither check nor prevent this.
The processor does not decide on the purposes and means of the processing. Supplied categories, sample texts, catalogue entries and defaults are suggestions; they become an instruction only once the controller adopts them or leaves them in place.
4. Confidentiality
The processor uses only persons who are bound to confidentiality or subject to an appropriate statutory duty of secrecy (Article 28(3)(b) GDPR). The undertaking is given before the first activity and continues after it ends.
The persons involved process the data only on instructions, unless they are required to process under Union law or the law of a member state (Articles 29 and 32(4) GDPR). They are made familiar with the relevant data protection requirements.
Access is limited to what the respective task requires. Administrative access through the dashboard is recorded in the audit log.
5. Technical and organisational measures
The processor takes the measures required under Article 32 GDPR to ensure a level of protection appropriate to the risk. The overview below describes the position at the time the agreement is concluded and forms an annex to this agreement.
| Measure | Implementation |
|---|---|
| Physical access control | Servers operated in locked premises within the EU; physical access only for expressly authorised persons |
| Access control | Role model with four levels, every permission change in the audit log |
| Password security | Argon2id with a pepper held outside the database, minimum length 12 characters, progressive lockout, optional two-factor authentication (TOTP) |
| Encryption in transit | TLS enforced, HSTS active, HTTP redirects to HTTPS |
| Transfer control | Delivery exclusively over TLS; CORS only for verified domains of the property; no transfer to third parties and no third-country transfer |
| Pseudonymisation | IP addresses only as HMAC-SHA-256 with a rotating pepper; page URLs only as a SHA-256 hash |
| Data minimisation | No cross-site identifier, no profiling; user agent stored only as a coarse family |
| Separation control | Tenant separation by organisation and Property on every query |
| Application security | Prepared statements only, output escaping, CSP without unsafe-inline with a per-request nonce, CSRF tokens and origin checking |
| Input control | Append-only history: changes to a consent overwrite nothing |
| Logging | Audit log for sign-ins, permission changes and configuration changes with timestamp and acting person; passwords and tokens are masked |
| Instruction control | Processing solely on the basis of this agreement and the configuration in the dashboard; every configuration change is traceable in the audit log |
| Resilience | Rate limiting on sign-in, registration, password reset and the consent endpoint |
| Availability and recoverability | Full backup of database and file state before every deployment with a documented way back; backups are kept for a limited time and cleaned up automatically |
| Deletion | Automatic expiry after the configured period, 36 months by default; immediate deletion via the data subject interface |
| Review and evaluation | Security measures and known limitations are documented in the source code and carried forward with every change; the reporting channel for vulnerabilities is published |
The measures may be developed further as long as the agreed level of protection is not reduced; material changes are documented here. The full account of the measures implemented and of the known limitations is in docs/SECURITY.md in the source code.
6. Sub-processors
The controller gives general authorisation for engaging sub-processors under Article 28(2), second sentence, GDPR. The current list is set out at the bottom of this page.
Any intended addition or replacement is published here and announced in text form at least 30 days in advance. Within that period the controller may object on important grounds relating to data protection. If the ground cannot be resolved, the controller may terminate the usage relationship without notice; there is no further claim.
The processor binds every sub-processor to the same data protection obligations as this agreement provides and remains responsible to the controller for the sub-processors conduct (Article 28(4) GDPR). Engagement in a third country takes place only on a basis under Chapter V GDPR.
Ancillary services with no connection to the processing of the contract data — such as telecommunications, post, cleaning or maintenance of equipment without data access — are not sub-processing. Confidentiality is ensured there as well.
7. Assistance with data subject rights
Data subjects address their rights under Chapter III GDPR to the controller. If a data subject contacts the processor, the processor forwards the request without delay and does not answer on the substance.
The processor assists the controller by appropriate technical and organisational measures (Article 28(3)(e) GDPR). This assistance is provided primarily through the functions built into the service: the self-service lookup via the consent ID, the export of records and the immediate deletion of a record. Where those functions suffice, the duty to assist is met.
Linking a record to a particular person without the consent ID is technically impossible: IP addresses are stored solely as an HMAC with a rotating pepper, and there is no cross-site identifier. Article 11(2) GDPR applies to requests that would presuppose such a link.
Effort going beyond the functions provided is reimbursed on a time-spent basis to the extent legally permissible.
8. Assistance with security, notification duties and impact assessment
Taking into account the nature of the processing and the information available to it, the processor assists the controller in complying with the obligations under Articles 32 to 36 GDPR (Article 28(3)(f) GDPR).
For a data protection impact assessment, it provides the details of its processing, in particular a description of it, the categories of data and the measures taken. Carrying out and evaluating the impact assessment is a matter for the controller.
9. Personal data breaches
If the processor becomes aware of a personal data breach, it notifies the controller without delay at the address held in the account (Article 33(2) GDPR), together with the information available to it under Article 33(3) GDPR. Missing information is supplied as soon as it becomes available.
The processor takes the measures needed for containment and protection without delay and documents the incident.
Notification of the supervisory authority under Article 33(1) GDPR and communication to the data subjects under Article 34 GDPR are matters for the controller. A notification by the processor does not constitute an admission of fault or of a claim.
The controller likewise informs the processor where it identifies an incident affecting the data processed through the service.
10. Evidence and audits
The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allows for audits (Article 28(3)(h) GDPR).
Evidence is provided primarily through the documentation of the technical and organisational measures on this page, a self-declaration in text form, the security documentation published in the source code and, where available, attestations or certificates. Because the software is open source, the controller can additionally verify the measures implemented in the source code.
An on-site audit comes into consideration where that evidence is not sufficient in the individual case. It takes place on at least 20 working days notice, during normal business hours, without disrupting operations, and no more than once per calendar year; where there is specific cause, in particular after a personal data breach, also more often and at shorter notice.
Auditors must not be competitors of the processor and must be bound to secrecy beforehand. Access to the data of other controllers is excluded; tenant separation necessarily limits the scope of an audit. The controller bears the costs of the audit; for a service provided free of charge the processor may invoice its own effort, unless the audit was prompted by a breach for which it is responsible.
11. Deletion and return
After the end of the processing, the processor deletes the data or returns them, at the choice of the controller (Article 28(3)(g) GDPR). The controller communicates its choice before termination; without such communication the following paragraph applies.
Absent a differing instruction, the consent records expire with the configured retention period — the default is 36 months. The reason lies in the purpose of these data: they serve as evidence under Article 7(1) GDPR and are of use to the controller only for as long as they exist.
The controller may instruct immediate deletion at any time. The processor points out that the consent can no longer be demonstrated afterwards; it is not liable for the consequences of a deletion carried out on instruction.
The records can be exported through the dashboard until deletion. Backup copies are not cleaned up individually; they expire with the backup cycle and are not used for any other purpose in the meantime. Statutory retention duties remain unaffected; for as long as they apply, processing of the data concerned is restricted.
The processor issues confirmation of deletion in text form on request.
12. Record of processing activities
The processor maintains a record of all categories of processing activities carried out on behalf of the controller (Article 30(2) GDPR) and makes it available to the controller and to the supervisory authority on request.
13. Data protection contact
The controller addresses data protection enquiries to the address stated above. Where a data protection officer has been appointed, they are named in the privacy notice; where there is no duty to appoint one under Article 37 GDPR — Polish law sets no additional threshold — the operator is the contact.
The processor is established in the European Union; a representative under Article 27 GDPR therefore does not have to be designated. Its competent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).
14. Liability and indemnity
Liability towards data subjects is governed by Article 82 GDPR. It can neither be excluded nor limited by contract; the provisions below concern only the relationship between the contracting parties.
Under Article 82(2) GDPR, the processor is liable only where it has not complied with obligations specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the controller. Otherwise the liability provisions of the terms of use apply, unless mandatory law provides otherwise.
Where a claim is brought against the processor by a data subject, another third party or a supervisory authority on account of a circumstance for which the controller is responsible, the controller indemnifies the processor as between the parties. This applies in particular to claims resting on an instruction, on the configuration in the dashboard, on texts and details entered, on a missing or invalid legal basis, or on the integration of the script on the website of the controller. The indemnity covers the reasonable costs of legal defence.
Joint and several liability towards data subjects under Article 82(4) GDPR remains unaffected; recourse is governed by Article 82(5) GDPR. The indemnity does not apply to the extent the claim rests on a breach committed by the processor intentionally or through gross negligence.
15. Term and termination
This agreement is concluded in electronic form on registration (Article 28(9) GDPR) and runs for as long as the processor processes personal data for the controller.
Separate termination of this agreement while use continues is excluded — without a processing agreement the processing may not continue. This agreement ends together with the usage relationship; clause 11 continues to apply.
The controller may terminate this agreement for cause, in particular where the processor fails to meet a material obligation under Article 28 GDPR despite being given a deadline.
16. Final provisions
Precedence. In the event of conflict between this agreement and the terms of use, this agreement takes precedence for the processing. Deviating terms of the controller apply only where the processor has agreed to them in text form.
Form. The agreement and amendments to it require text form; this satisfies the requirement of Article 28(9) GDPR for an electronic format.
Amendments. Amendments are announced at least 30 days before they take effect; clause 16 of the terms of use applies accordingly. Adjustments required by mandatory statutory provisions, by case law of the highest courts or by an official order take effect on being announced.
Severability. If a provision is invalid, the remaining provisions stay in force (art. 58 § 3 k.c.). The statutory rule takes the place of the invalid provision, in particular the corresponding requirement of Article 28 GDPR.
Law and jurisdiction. Polish law applies. Clause 17 of the terms of use governs the place of jurisdiction.
Language. The German version of this agreement is authoritative.