---
title: "Third Party Data Processing Agreement (DPA)"
canonical: "https://wiki.patientsknowbest.com/space/IG/5196382241/Third%20Party%20Data%20Processing%20Agreement%20(DPA)"
format: markdown
---
Private and Confidential Third-Party-DPA v1.0 January 2026


### <u>PART 1 - DEFINITIONS AND CLAUSES</u>


1. **PARTIES**
2. Patients Know Best (“PKB”); and
3. [Third Party], with its registered office at [Address] (“Third Party”); each a “**Party**” and together the “**Parties**”.


2. **BACKGROUND**
3. This Agreement sets out the terms under which the Third Party may access PKB Data based on the Patient’s explicit instruction to share such data (“Patient Preference”).


2. PKB operates a patient-held record platform enabling patients to manage and share their health information.


3. Data received by PKB from the Third Party forms a category of data within the Patient Record (referred to herein as **Third Party Data**), for which PKB is a Processor.


4. Patient-entered data forms the **Patient Account**, for which PKB is a **Controller** with the Third Party.


5. When the Third Party accesses Patient Account data, PKB and the Third Party act as **Independent Controllers **in respect of those processing activities.


6. PKB may, under the Commercial Contract, present opportunities for patients to participate in Third Party services or activities.


3. **DEFINITIONS AND INTERPRETATION**


3.1 Unless specifically provided for in this Agreement, the following terms shall have the following meanings: 


|  |  |
| --- | --- |
| **“Agreed Purposes”** | has the meaning given in clause 6; |
| **“Commencement Date”** | has the meaning given in clause 4.1; |
| **“Controller”, “Joint Controllers”, “Personal Data”, “Personal Data Breach”, “Processing” (including “Process” and “Processed”), and “Special Categories of Personal Data” ** | have the meaning given in the DPA 2018; |
| **“Commercial Contract”** | means the commercial arrangement between the Parties under which the PKB Platform is made available to the Third Party; |
| **“Data Protection Law”** | means, for the periods in which they are in force in the United Kingdom, the DPA 2018, the GDPR, the Electronic Communications Data Protection Directive 2002/58/EC, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and all applicable laws and regulations relating to Processing of Personal Data and privacy; |
| **“Data Subject” or “Patient”** | means a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person in any PKB Data; |
| **“Data Subject Access Request”** | means a request from a Data Subject under Data Protection Law in respect of PKB Data; |
| **“DPA 2018”** | means the Data Protection Act 2018; |
| **“GDPR”, “UK GDPR”** | means the General Data Protection Regulation (Regulation (EU) 2016/679) and the GDPR as implemented into UK law by the DPA 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419); |
| **“Patient Account”** | means Personal Data entered by a patient into PKB; |
| **“Patient Preference”** | means the patient’s explicit instruction within PKB to allow the Third Party to access selected PKB Data; this is not UK GDPR consent. |
| **"Patient Record"** | means data received by PKB from the Third Party; |
| **  “PKB data”** | means all personal data held on the PKB platform, both patient Record and Patient Account; |
| **“Services”, “Platform”, “Solution”** | means the PKB software and architecture, infrastructure and operations; |
| **“Third Party Consent”:** | means consent collected by the Third Party directly from the patient for the Third Party’s own purposes; PKB has no role in this; |
| **“Third Party Communication”** | has the meaning given in clause 18.3; |

3.2 Interpretation:

1. Clause and Schedule headings do not affect interpretation.
2. Reference to a person includes natural and legal persons.
3. Schedules form part of this Agreement.
4. Singular includes plural and vice-versa.
5. References to statutes include amendments and re-enactments.
6. “Including” means “including without limitation.”


3.3 In the event of conflict:

1. The main body of this Agreement prevails over the Schedules unless expressly stated otherwise.


4. **SCOPE AND APPLICATION    **
  1. This Agreement governs the Processing of PKB Data on or through the PKB Platform.
  2. It prevails over the Commercial Contract and any previous agreements regarding PKB Data.
  3. When PKB Data is accessed by the Third Party, the Third Party acts as an independent Controller.
5. **COMMENCEMENT AND DURATION**
  1. This Agreement commences on the date stated at its head (“Commencement Date”).
  2. It continues for the duration of the Commercial Contract unless terminated earlier under clause 19.
  3. Clauses that must continue after termination (including clauses 13, 14, 18, 20, 21, 28 and Schedules 1 and 2) survive termination.
6. **TRANSPARENCY AND REGULATORY ENGAGEMENT**
  1. Each Party is responsible for regulatory compliance and transparency for the processing activities for which it is Controller.
  2. Each Party shall ensure its transparency information does not contradict or mislead patients and shall notify the other Party of material changes at least 14 days in advance.
  3. The Parties may cooperate on transparency materials relating to the Agreed Purposes but are not obliged to conduct wider engagement beyond legal requirements.
7. **AGREED PURPOSES**
  1. The Parties agree that PKB Data may be Processed for the following purposes:
    1. Facilitating patient access to, and addition of data into, their PKB record;
    2. Enabling patient choice over which organisations—including the Third Party—may access their PKB record;
    3. Displaying Third Party banners or opportunities to patients via PKB;
    4. Processing Third Party data incorporated into the Patient Record where PKB acts as Processor;
    5. Maintaining and securing the PKB Platform and all PKB Data.

_________________________________________________________________________________________________________________________________________________________________________________________________________


<u>**PART 2 – DATA PROCESSING SPECIFIC CLAUSES**</u>

8. **ROLES AND DATA FLOWS**
  1. PKB Processes PKB Data as:
    1. **Processor** for Third Party data;
    2. **Controller** for Patient Account data;
    3. **Independent Controller** for platform operations.
  2. Roles and data flows are detailed in **Schedule 1**.
9. **THIRD PARTY OBLIGATIONS**
  1. The Third Party shall access and use PKB Data strictly in accordance with the Patient’s Preference.
  2. The Third Party is solely responsible for obtaining and managing any Third Party Consent required for its own purposes; PKB has no responsibility for such consent.
  3. The Third Party shall:
    1. Provide transparency to patients consistent with Data Protection Law;
    2. Access only the minimum PKB Data necessary;
    3. Ensure security appropriate to the risks.
  4. The Third Party shall not subcontract access or use of PKB Data without PKB’s prior written consent.
  5. The Third Party shall not further disclose or onward share PKB Data unless required by law or where the patient has provided a valid UK GDPR‑compliant consent for such disclosure. The Third Party shall document and maintain evidence of any such consent.
10. **PKB RESPONSIBILITIES**
  1. PKB’s roles as Controller and Processor are those defined in clause 7 and **Schedule 1**.
  2. PKB shall maintain a designated Data Protection Officer.
  3. PKB shall comply with Data Protection Law in all Processing for which it is Controller or Processor.
11. **PROCESSOR TERMS**
  1. PKB shall Process Third Party-controlled Personal Data only on documented instructions from the Third Party unless legally required otherwise.
  2. PKB shall notify the Third Party if an instruction appears unlawful.
  3. PKB shall implement the Technical and Organisational Measures in **Schedule 2**.
  4. PKB shall assist the Third Party with:
    1. DPIAs;
    2. Data Subject rights;
    3. Breach Notifications.
  5. PKB shall make available to the Third Party all information necessary to demonstrate compliance with Article 28 of the UK GDPR and shall allow for and contribute to audits or inspections conducted by the Third Party or an auditor mandated by the Third Party, provided that such audits do not compromise PKB’s platform security, confidentiality of other customers’ data, or system integrity.
  6. PKB shall ensure that all staff, contractors, and persons authorised to process Third Party Personal Data are subject to enforceable confidentiality obligations under contract or statute.
  7. PKB shall not process Third Party Personal Data for any purpose other than the provision of PKB services to the Third Party and shall not determine purposes or means in respect of such data.
12. **OTHER CONTROLLING PROCESSING**
  1. PKB Processes certain PKB Data as an independent Controller for platform operations, including:
    1. Logging for security and audit;
    2. Pseudonymised feasibility and system performance analytics.


13. **INTERNATIONAL DATA TRANSFERS**
  1. PKB shall not transfer Personal Data outside the UK, EEA, or an adequate country except:
    1. Where expressly instructed by the Third Party; and
    2. where necessary for PKB to perform its Processor activities listed in **Schedule 1**.
  2. Where PKB is instructed to make such a transfer, the Third Party warrants that it has:
    1. Determined the appropriate transfer mechanism;
    2. Executed and maintains that mechanism;
    3. Conducted a documented Transfer Risk Assessment.
14. **DATA SUBJECTS RIGHTS AND WITHDRAWAL**
  1. The Third Party is responsible for managing withdrawals of Third Party Consent and informing PKB where this affects PKB’s Processing.
  2. Where a Party receives a Data Subject rights request relating to data for which the other Party is Controller it shall forward the request within two business days.
  3. Where a patient submits a request for data portability relating to processing activities for which the Parties act as independent Controllers, the Parties shall cooperate as necessary to ensure compliance with Article 20 UK GDPR, including the provision of structured, commonly used, machine‑readable data formats.


_________________________________________________________________________________________________________________________________________________________________________________________________________


<u>**PART 3 - FURTHER CONTRACTUAL CLAUSES**</u>

15. **RECORDS**

The Parties shall review this Agreement periodically to ensure compliance and maintain appropriate procedures for incident and breach management.

16. **WARRANTIES AND NOTIFICATIONS**
  1. Each Party warrants it has authority to enter into this Agreement and will comply with Data Protection Law.
  2. Each Party shall notify the other within five business days of any regulatory communication or third-party request relating to PKB Data.
17. **LIMITATION AND LIABILITY**
  1. Each Party is liable only for the Processing activities for which it is Controller or Processor under Data Protection Law.
  2. Liability is limited to direct losses arising from breaches of this Agreement or negligence.
18. **TERMINATION**
  1. Either Party may terminate this Agreement immediately upon:
    1. A material breach;
    2. Insolvency of the other Party;
    3. A change of control.
  2. This Agreement terminates automatically when the Commercial Contract terminates.
19. **CONSEQUENCES OF TERMINATION**
  1. For Processor data, PKB shall delete or return all Third Party Personal Data within 30 days unless legally required to retain it.
  2. PKB shall retain Patient Account data in accordance with PKB’s Controller obligations.
20. **FORCE MAJEURE**
  1. A Party is not liable for delays caused by events outside its reasonable control.
  2. If such an event continues for more than 90 days, either Party may terminate.
21. **ASSIGNMENT**

Neither Party may assign this Agreement without written consent except to affiliates or group companies under common control.

22. **VARIATION, NOTICES, SEVERANCE, RELATIONSHIP**
  1. Variations require a written agreement.
  2. Notices must be in writing and sent to the registered address.
  3. Invalid provisions are severed; the remainder stays in effect.
  4. The Parties are independent contractors.
23. **RIGHTS AND REMEDIES; WAIVER; COUNTERPARTS; THIRD PARTY RIGHTS**
  1. Rights are cumulative.
  2. Failure to enforce a right is not a waiver.
  3. This Agreement may be executed in counterparts.
  4. No third party has rights under the Contracts (Rights of Third Parties) Act 1999.
24. **FURTHER ASSURANCE AND COSTS**
  1. Each Party shall take necessary steps to give effect to this Agreement.
  2. Each Party bears its own costs.
25. **ENTIRE AGREEMENT**

This Agreement supersedes all prior agreements concerning the Processing of PKB Data.

26. **GOVERNING LAW AND DISPUTE RESOLUTION**
  1. This Agreement is governed by English law.
  2. Disputes are resolved per the escalation procedure in the Commercial Contract.
27. **SURVIVAL**

Clauses relating to confidentiality, liability, retention, audit, and Schedules 1 and 2 survive termination.

_________________________________________________________________________________________________________________________________________________________________________________________________________

<u>**PART 4 - SCHEDULES**</u>

28. **SCHEDULE 1: DATA PROCESSING PARTICULARS**
  1. Personal Data to be Processed
    1. This Schedule describes the types of PKB Data that may be Processed under this Agreement. The Parties may agree to amend the descriptions in this clause at any time with the approval of the Parties.
    2. For clarity, PKB Data Processed under this Agreement shall be subject to the data minimisation measures described in clause 9.3.2,
  2. Providers applying data minimisation measures prior to sharing any data with PKB; and
  3. the Parties continuing to review the data minimisation measures to ensure the minimisation of Personal Data within PKB Data as may be required by Data Protection Law.
    1. PKB Data to be Processed under this Agreement may include data from the following sources:


|  |
| --- |
| Providers Electronic Patient Record (structured coded data only) |
| Patient Inputted Data |
| Third Party Partners and Integrations (for purposes of care provision) |


d. The inclusion of personal data of any natural person under the age of 13 should be considered on a case by case basis.  
  


29. **SCHEDULE 2A: PROCESSING OPERATION A**

**MAINTAINING THE PATIENT ACCOUNT**

<u>**Processing Operation: **</u>The storage, security, availability, and management of data entered directly by the Patient (Patient-Contributed Data) and PKB’s associated audit logs.

<u>**Performed by:**</u>** **PKB

<u>**Classification of Parties: **</u>PKB – Sole Controller

<u>**Lawful Bases for Processing:**</u>** **Article 6(1)(f) and Article 9(2)(h)

<u>**Data Subject Rights Fulfilment:**</u>


|  |  |
| --- | --- |
| **Right to be informed** | PKB provides transparency via its Privacy Notice and User Agreement. |
| **Right to Access/Portability** | PKB provides the platform for the individual to directly access and export this data in a readable and clear format (Access) and structure (Portability) via the PKB interface. |
| **Right to Correction** | PKB enables the individual to directly correct or update their Patient-Contributed Data via the PKB interface. |
| **Right to Restriction** | The right to request restriction of processing applies. PKB is responsible for implementing technical measures to restrict the processing of data upon instruction where legally required. |
| **Right to Erasure/Objection** | The right to erasure is restricted. PKB will honour deletion requests for data that has not been shared. Data that has been shared or is required for PKB's audit trails will be retained based on its necessary retention schedule. |
| **ADM/Profiling** | Automated Decision Making (ADM) and profiling resulting in legal or significant effect are not performed under this operation. |



**30. SCHEDULE 2B: PROCESSING OPERATION B**

**DISPLAYING THIRD PARTY OPPORTUNITIES (Screening/Banners)**


<u>**Processing Operation:**</u> Internal screening of PKB Data against Third Party inclusion/exclusion criteria for the purpose of displaying a specific opportunity/banner to a suitable data subject.

<u>**Performed by:**</u>** **PKB

<u>**Classification of Parties:**</u> PKB - Independent Controller

<u>**Lawful Bases for Processing:**</u> Article 6(1)(f) and Article 9(2)(h)

<u>**Data Subject Rights Fulfilment:**</u>


|  |  |
| --- | --- |
| **Right to be informed** | PKB provides transparency about this screening process within its Privacy Notice and via in-banner explanations. |
| **Right to Access/Portability** | The individual has the right to access the eligibility criteria applied to their record, which will be provided upon formal Subject Access Request (SAR). |
| **Right to Correction** | The right to correction applies to the source data (Operation 2A), not the resulting audit log. |
| **Right to Restriction** | The right to restriction applies and PKB is responsible for implementing technical controls to comply with a lawful restriction request. |
| **Right to Erasure/Objection** | The technical logs recording this processing are retained for a minimum of twenty (20) years for regulatory defense purposes overriding the right to erasure for the log data. |
| **ADM/Profiling** | Automated Decision Making (ADM) resulting in legal or significant effect is not performed. The screening only determines the content displayed. |


### **31. SCHEDULE 2C: PROCESSING OPERATION C**

**EXECUTING PATIENT-DIRECTED SHARING**

<u>**Processing Operation: **</u>The technical enablement for the execution of the Patient’s Preference to share their PKB Record with the Third Party following the patient’s decision to engage.


<u>**Performed by:**</u>** **PKB (under patient instruction)


<u>**Classification of Parties:**</u> Third Party: Independent Controller (of received data)


<u>**Lawful Bases for Processing:**</u>** **PKB: This is a patient-initiated disclosure


<u>**Principles and Roles**</u>


1. **Legal Basis for Access: **Access is enabled solely through Patient Preference, which is not UK GDPR consent; the Third Party must still have its own lawful basis.
2. **Data Protection Principles: **The Third Party is solely responsible for meeting all controller obligations (Articles 5, 6, 9, 12–22, 25, 30, 32, 33–34) for the received data.
3. **PKB Responsibilities: **PKB provides only the technical mechanism for access and does not determine purposes or means for the Third Party’s subsequent processing.


<u>**Data Subject Rights Fulfillment:**</u>

|  |  |
| --- | --- |
| **PKB Responsibilities** | PKB fulfills rights requests (Access, Correction, Restriction) relating only to the sharing transaction log and its execution of the transfer. |
| **Third Party Responsibilities** | The Third Party is responsible for all subsequent rights fulfillment (Access, Erasure, Correction, Restriction, Portability) for the data once it has been received, as they are the Controller of that data copy. |
| **ADM/Profiling** | ADM and profiling are not performed by PKB during the technical execution of the transfer. |


### **32. SCHEDULE 2D: PROCESSING OPERATION D**

**PROCESSING THIRD PARTY DATA IN THE PATIENT RECORD**

<u>**Processing Operation:**</u> Storage, display, and availability of data sent from the Third Party to PKB.


<u>**Performed by:**</u>** **PKB


<u>**Classification of Parties: **</u>Third Party: Controller; PKB: Processor


<u>**Lawful Bases for Processing:**</u>** **Determined by the Third Party (PKB as processor does not determine lawful basis).


<u>**Data Subject Rights Fulfillment:**</u>


|  |  |
| --- | --- |
| **Rights Fulfillment** | PKB shall provide full assistance to the Third Party to comply with all Data Subject rights requests (Access, Correction, Restriction, Portability, and Erasure) within required timescales. |
| **Right to Erasure** | PKB will only delete this data upon the documented instruction of the Third Party (the Controller). |
| **ADM/Profiling** | ADM and profiling are not performed by PKB in its capacity as Processor for this data. |


### **33. SCHEDULE 2E: PROCESSING OPERATION E**

**SERVICE EVALUATION AND IMPROVEMENT**

<u>**Processing Operation: **</u>Research and development using pseudonymised and aggregated PKB data to improve platform safety, reliability, and outcomes.


<u>**Performed by:**</u>** **PKB


<u>**Classification of Parties: **</u>PKB - Independent Controller


<u>**Lawful Bases for Processing:**</u>** **Article 6(1)(f) and Article 9(2)(h)


<u>**Data Subject Rights Fulfillment:**</u>



|  |  |
| --- | --- |
| **Right to be informed** | PKB provides transparency about this activity via the Privacy Notice. |
|  |  |
| **Right to Access/Correction** | Since the datasets are pseudonymised and aggregated, the rights of access and correction must be fulfilled at the source record (Processing Operation 2A), not the derived dataset. |
| **Right to Restriction** | The right to restriction applies. PKB is responsible for ensuring that restricted source data is not subsequently used in ongoing processes. |
| **Right to Erasure** | The processing is limited to necessity. Any Personal Data used for this specific purpose will be destroyed in line with PKB’s necessary retention schedules once no longer required. |
| **ADM/Profiling** | ADM and profiling are not performed using this dataset. |


_________________________________________________________________________________________________________________________________________________________________________________________________________


34. **SCHEDULE 3 - TECHNICAL AND ORGANISATIONAL MEASURES**


35. **INFORMATION SECURITY MANAGEMENT**
  1. PKB shall maintain an information security management framework that is consistent with the NHS Data Security and Protection Toolkit (DSPT), ISO 27002, and any successor standards or equivalent recognised security controls. PKB shall ensure that technical and organisational measures are appropriate to the risks associated with the processing of PKB Data and Third Party Data.
  2. PKB shall implement a structured programme of risk assessment, mitigation, monitoring, and continuous improvement. This shall include:
    1. Routine assessment of threats, vulnerabilities, and control effectiveness;
    2. Documented risk treatment plans;
    3. Ongoing verification that security controls remain effective and proportionate; and
    4. Regular internal reviews of access controls, logging, encryption, and system hardening.
  3. PKB shall maintain, review, and update its information security policies, standards, and procedures as necessary to reflect changes in technology, legal requirements, or identified risks. PKB shall notify the Third Party of any material changes that may reasonably impact the Third Party’s compliance, risk posture, or integration with PKB systems.
  4. PKB shall ensure that staff, contractors, and authorised personnel with access to PKB Data or Third Party Data receive appropriate security and data protection training, and that such access is based on the principle of least privilege and controlled via role-based access mechanisms.
  5. PKB shall maintain appropriate monitoring, audit logging, intrusion detection, and incident detection mechanisms to ensure timely identification of security events affecting PKB Data or Third Party Data.
  6. PKB shall cooperate with reasonable Third Party security enquiries, including providing summaries of relevant certifications, audit results and responses to security questionnaires, provided such disclosures do not compromise PKB’s security posture.
  7. PKB shall ensure that any subcontractors or sub-processors engaged in delivering related services implement security measures no less protective than those required of PKB under this Agreement.
36. **TECHNICAL SECURITY MEASURES**
  1. PKB shall implement role-based access control (RBAC) aligned with least-privilege and need-to-know principles. Access rights shall be reviewed regularly and revoked promptly when no longer required. Administrative access shall be restricted to authorised personnel only.
  2. Mandatory multi-factor authentication (MFA) shall be enforced for all administrative users and any user accessing systems containing PKB Data or Third Party Data. Authentication mechanisms shall follow current industry best practice and avoid outdated or weak factors.
  3. All data in transit shall be encrypted using TLS 1.2 or higher (or its successor standards). PKB shall prohibit insecure protocols and ciphers and shall maintain current configurations aligned with recognised security benchmarks.
  4. Data at rest shall be encrypted using AES-256 or an equivalent internationally recognised encryption standard. Encryption keys shall be managed securely using appropriate key-management controls, including segregation of duties and periodic rotation.
  5. PKB shall maintain appropriately configured firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and secure baseline configurations across relevant systems. Network segmentation shall be implemented to separate public-facing, internal, and high-risk systems.
  6. PKB shall apply system hardening standards, disable unnecessary services, and maintain a documented patching process to ensure timely application of security patches and updates to operating systems, infrastructure, and applications.
  7. PKB shall log and monitor access, authentication, administrative actions, and security-relevant events. Logs shall be protected from alteration and retained for a period consistent with PKB’s security policies and legal requirements.
  8. PKB shall conduct regular vulnerability scanning, follow up with remediation on a risk-based schedule, and commission independent penetration testing at appropriate intervals.
  9. PKB shall maintain encrypted backups, test restoration procedures regularly, and implement measures for high availability, disaster recovery, and business continuity consistent with service requirements.
  10. PKB shall deploy modern malware protection, endpoint detection and response tools (EDR), and secure configuration baselines for client and server endpoints.
37. **PHYSICAL SECURITY**
  1. PKB hosts its systems and data within Google Cloud Platform (GCP). Physical security for all data-centre facilities where PKB Data and Third Party Data are stored is provided and managed exclusively by GCP. This includes layered physical access controls such as biometric authentication, card access, 24/7 on-site security, CCTV monitoring, and environmental protection systems. PKB shall ensure that GCP maintains certifications and security standards appropriate for such facilities.
  2. Server racks, equipment rooms and physical infrastructure containing PKB Data or Third Party Data are secured and controlled by GCP. Physical access is limited to authorised GCP personnel in accordance with GCP’s security protocols, and PKB does not provide or manage direct physical access to these environments.
  3. PKB shall review and assess GCP’s published physical security controls, audit reports, and certifications (e.g., ISO 27001, SOC 2), and conduct periodic risk assessments to confirm that GCP’s measures remain appropriate. PKB shall address any residual risks within its area of responsibility.
  4. Where PKB controls any office or operational facilities (not including GCP data centres), PKB shall maintain appropriate physical security measures such as controlled entry, visitor logging, secure areas for staff devices, and protection of any equipment used to administer its cloud environment.
  5. Where PKB handles any physical devices that could store or access PKB Data or Third Party Data (e.g., staff laptops, removable media), PKB shall ensure secure storage, transport, and disposal. GCP is responsible for secure destruction of media within its own infrastructure in accordance with its published standards.
38. **INCIDENT MANAGEMENT AND BREACH REPORTING**
  1. PKB shall maintain, update, and regularly test an incident response plan appropriate to the nature of the processing and the risks to data subjects.
  2. PKB shall notify the Third Party **without undue delay and in any event within 72 hours **of becoming aware of any Personal Data Breach that is likely to affect the Third Party or Third Party Data.
  3. The Third Party shall notify PKB within 72 hours of becoming aware of any Personal Data Breach affecting PKB Data or any processing carried out under this Agreement.
  4. PKB shall conduct root-cause analyses for Personal Data Breaches occurring within its environment and implement appropriate remedial and preventative actions, and shall share a summary of these findings with the Third Party where the breach impacts the Third Party.
39. **AUDIT AND MONITORING**
  1. PKB shall maintain comprehensive and tamper-resistant audit trails for all relevant systems and applications processing PKB Data or Third Party Data. Audit logs shall record, at minimum, authentication events, administrative actions, data access, configuration changes, and security-relevant activities. Logs shall be retained in accordance with PKB’s security and compliance policies.
  2. PKB shall perform routine reviews of audit logs to detect unauthorised access, anomalous activity, policy violations, or indicators of compromise. Log reviews shall be risk-based, documented, and completed by appropriately trained personnel. Any identified issues shall be escalated, investigated, and remediated promptly.
  3. PKB shall maintain continuous security monitoring across relevant systems, including automated mechanisms for threat detection, alerting, and correlation of events. Alerts relating to high-risk or suspicious activities shall be prioritised and acted upon without undue delay.
  4. PKB shall implement appropriate safeguards to ensure audit logs are protected against alteration, unauthorised access, and deletion. Access to logging infrastructure shall be strictly limited to authorised personnel with a genuine operational need.
  5. PKB’s monitoring processes shall support timely investigation of security incidents by enabling event correlation, reconstruction of activity, and provision of relevant audit information to support forensic analysis.
  6. PKB shall provide summaries of relevant monitoring findings to the Third Party upon reasonable request where such findings relate to systems or processing activities under this Agreement and do not compromise PKB’s overall security posture. PKB shall cooperate with Third Party audits relating to shared obligations, in accordance with any audit rights provided elsewhere in this Agreement.
40. **DATA RETENTION AND SECURE DISPOSAL**
  1. PKB shall maintain and adhere to documented data retention schedules specifying how long PKB Data and Third Party Data are retained in accordance with applicable legal, regulatory, clinical, and contractual requirements. Retention periods shall reflect the minimum necessary to fulfil the purposes of processing and shall be reviewed periodically for continued appropriateness.
  2. PKB shall ensure that data is retained only for as long as required to provide the PKB service, meet statutory health and records obligations, or comply with applicable laws. Where retention periods differ by data category, PKB shall apply category-specific rules and ensure clear traceability.
  3. At the expiry of the relevant retention period, or upon validated deletion request where applicable, PKB shall securely delete or irreversibly anonymise data using industry-standard methods that prevent recovery. Deletion shall include data stored in all active systems and storage media under PKB’s control.
  4. Where data persists in backups or replicated systems, PKB shall ensure that such copies are subject to the same retention periods and are securely deleted or overwritten in accordance with PKB’s backup lifecycle processes. Backup deletion shall occur as part of routine backup rotation and cannot be expedited outside these cycles.
  5. PKB shall maintain evidence of deletion processes, including audit trails or system logs confirming that secure disposal has occurred. PKB shall make available, upon reasonable request, summaries of its retention and deletion practices to the Third Party.
  6. Any PKB-controlled devices or media that may store PKB Data or Third Party Data shall be securely wiped or physically destroyed using recognised industry standards before disposal or reuse.
  7. Upon termination or expiry of this Agreement, PKB shall securely delete or return Third Party Data in accordance with the Third Party’s written instructions, except where PKB is required to retain certain data to comply with legal obligations. Deletion or return shall be completed within a mutually agreed timeframe.
41. **TRAINING AND AWARENESS**
  1. PKB shall ensure that all staff, contractors, and authorised users with access to PKB Data or Third Party Data complete mandatory privacy, data protection, and information security training upon hire, prior to being granted access to relevant systems, and at least annually thereafter. Training shall be role-specific and tailored to the individual’s level of access and responsibilities.
  2. All PKB personnel shall be bound by appropriate confidentiality obligations, either contractually or under statutory professional duties. PKB shall ensure that staff are assessed for competency to perform their roles safely and securely, and shall provide additional or corrective training where necessary.
  3. PKB shall maintain an ongoing security awareness programme covering emerging threats, secure working practices, phishing prevention, incident reporting, and responsibilities under data protection legislation. Periodic reminders and scenario-based exercises shall be used to reinforce good practice.
  4. Access to PKB systems containing PKB Data or Third Party Data shall only be granted once required training has been completed. PKB shall remove or suspend access for individuals who fail to complete mandatory refresher training within required timescales.
  5. PKB shall maintain auditable records of training completion, competency checks, and awareness activities. These records shall be retained in accordance with PKB’s training governance processes and shall be made available to the Third Party upon reasonable request.
  6. PKB shall ensure that contractors and service providers working under PKB’s direction receive equivalent training or can evidence training that meets the same standards before accessing PKB systems or data.
42. **SUB-PROCESSOR MANAGEMENT**
  1. PKB shall conduct appropriate due diligence on all sub-processors prior to engagement. This due diligence shall include assessment of the sub-processor’s security controls, data protection practices, regulatory compliance, and ability to meet PKB’s obligations under this Agreement. Documentation of such assessments shall be maintained by PKB.
  2. PKB shall maintain an up-to-date list of all sub-processors used to process PKB Data or Third Party Data. PKB shall provide the Third Party with at least 30 days’ prior written notice before engaging a new sub-processor or making material changes to the scope of an existing sub-processor’s processing.
  3. PKB shall ensure that each sub-processor is contractually bound to:
    1. Implement technical and organisational measures (TOMs) equivalent to those required of PKB under this Agreement;
    2. Comply with applicable data protection laws, including UK GDPR;
    3. Cooperate with PKB and the Third Party in relation to audits, inspections, investigations, or data subject requests;
    4. Notify PKB promptly of any personal data breaches or security incidents affecting PKB Data or Third Party Data.
  4. PKB shall maintain oversight of sub-processor activities to ensure continued compliance with contractual and regulatory obligations. PKB shall periodically review sub-processor performance, security, and data protection compliance, and take corrective action if deficiencies are identified.
  5. PKB remains fully responsible for the acts and omissions of its sub-processors to the same extent as if the processing were carried out by PKB itself. PKB shall ensure that sub-processor agreements contain terms enabling PKB to enforce compliance and to terminate or replace sub-processors if necessary.
  6. PKB shall ensure that sub-processors allow audits or provide certification/attestation evidence (e.g., ISO 27001, SOC 2) upon request, to verify compliance with security and data protection obligations