Deskpro Vendor Data Protection Requirements
Last Updated: 4 March 2026
These Vendor Data Protection Requirements (“Data Protection Requirements”) apply only where incorporated by reference into a written agreement between Deskpro and a supplier, vendor, subcontractor, or other third party (“Vendor”).
1. Introduction
Deskpro requires Vendors to protect Deskpro information and personal data processed in connection with services provided to Deskpro.
Vendor must comply with all applicable data protection and privacy laws and regulations in any jurisdiction relevant to the services, including (without limitation and where applicable) UK GDPR, EU GDPR, US federal and state privacy laws, healthcare privacy requirements (including HIPAA where applicable), and any other applicable data protection, confidentiality, or information security laws.
These requirements are intended to support Deskpro’s global compliance obligations to customers, regulators, and data subjects.
2. Processing on Instructions
Vendor must process personal data only:
- for the purposes of providing the services to Deskpro; and
- in accordance with Deskpro’s documented instructions.
Vendor must not use Deskpro personal data for its own purposes, including marketing, analytics unrelated to the services, profiling, training artificial intelligence or machine learning models, or product improvement, unless explicitly authorised in writing by Deskpro.
3. Confidentiality and Ownership
All Deskpro information (including personal data, customer data, and system data) remains the property of Deskpro or Deskpro’s customers, as applicable.
Vendor must ensure:
- Deskpro information is treated as strictly confidential;
- access is limited to authorised personnel on a need-to-know basis;
- confidentiality obligations apply to all Vendor Personnel; and
- confidentiality obligations survive termination of the services.
4. Security Measures
Vendor must implement appropriate technical and organisational measures to protect personal data and Deskpro information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Vendor must comply with the Deskpro Vendor Security Requirements, available at:
www.Deskpro.com/vendorsecurity
Security measures must be proportionate to the nature of the services, the sensitivity of the data, and the risk profile. These obligations survive termination of the Vendor’s relationship with Deskpro.
5. Personal Data Breach Notification
Vendor must notify Deskpro without undue delay and in any event within 24 hours after becoming aware of any actual or suspected personal data breach or security incident involving Deskpro data.
Such notification must include, to the extent known at the time:
- a description of the nature of the incident;
- the categories and approximate volume of data affected;
- the likely impact on Deskpro or affected individuals;
- containment and mitigation measures taken or proposed; and
- contact details for the incident lead.
Vendor must provide ongoing updates as further information becomes available and must cooperate fully with Deskpro in investigation, containment, remediation, regulatory notification, and customer communications.
Notifications must be sent to: security@deskpro.com
6. Subprocessors
Vendor must not appoint any subprocessor or subcontractor to process Deskpro personal data unless authorised under the parties’ agreement.
Vendor must ensure that any approved subprocessors are bound by written obligations that impose, for the relevant scope, the same data protection, confidentiality, and security obligations that apply to Vendor under these Requirements and the parties’ agreement. Vendor remains fully responsible for their subprocessors’ acts and omissions.
Vendor must provide at least 30 days’ prior written notice before engaging any new subcontractor or third party that will access, process, store, or support Deskpro systems or Deskpro information.
Deskpro may object to the appointment of a proposed subcontractor where Deskpro determines that the subcontractor presents a material security, privacy, regulatory, or compliance risk.
Where Deskpro must flow down customer or regulatory requirements, Deskpro may require an extended review period of up to 60 days prior to engagement.
If Deskpro objects, Vendor must not engage the subcontractor for Deskpro-related services unless and until the concern has been resolved.
7. Cross-Border Transfers
Where Vendor transfers personal data across international borders, Vendor must ensure appropriate safeguards are in place as required by applicable law, including (where relevant) Standard Contractual Clauses or equivalent mechanisms.
8. Data Retention, Return, and Deletion
Vendor must retain Deskpro information and personal data only for as long as necessary to provide the services, unless retention is required by applicable law.
Upon termination of services or upon Deskpro’s written request, Vendor must promptly:
- return Deskpro data; or
- securely delete Deskpro data,
in accordance with Deskpro’s instructions.
Upon request, Vendor must certify in writing that such return or deletion has been completed.
Vendor must not retain copies, extracts, backups, or derivative data except where legally required, and any permitted retention remains subject to these Data Protection Requirements.
9. Data Subject Rights and Regulatory Support
Vendor must provide timely assistance and cooperation required for Deskpro to meet its obligations in relation to:
- data subjects (including rights of access, rectification, deletion, restriction, portability, objection, and opt-out, where applicable);
- Deskpro customers; and
- regulators or supervisory authorities.
Vendor must:
- notify Deskpro promptly upon receipt of any data subject request relating to Deskpro data;
- not respond directly to a data subject request unless Deskpro has provided written authorisation;
- provide Deskpro with the information and support required for Deskpro to respond within legally required timeframes; and
- cooperate with Deskpro in responding to regulatory inquiries, investigations, examinations, or supervisory requests relating to personal data processed on Deskpro’s behalf.
10. Legal Requests
Vendor must promptly notify Deskpro of any legally binding request, order, subpoena, or demand for disclosure of Deskpro information or personal data, unless prohibited by law.
Where permitted, Vendor must cooperate with Deskpro to challenge, limit, or otherwise appropriately respond to such requests. Vendor must not voluntarily disclose Deskpro data to any third party without prior written authorisation from Deskpro unless legally required.
11. Evidence and Compliance
Upon request, Vendor must provide evidence demonstrating compliance with these Data Protection Requirements, including as applicable:
- relevant privacy and security policies and procedures;
- records of processing activities for Deskpro personal data (where required by law);
- incident response procedures and breach notification procedures;
- security assurance evidence (for example: ISO/IEC 27001 certificate, SOC 2 Type II report, independent audit report, penetration testing summary, or equivalent evidence);
- completed privacy/security questionnaires and written attestations; and
- documentation required to support cross-border transfer safeguards where applicable.
Where Vendor processes, stores, transmits, or otherwise has access to Deskpro personal data or Deskpro information outside Deskpro-controlled environments (including via hosted services, SaaS, cloud infrastructure, managed services, or third-party platforms used to deliver the services), Vendor must maintain independent third-party security assurance at least annually for the systems, environments, and locations in-scope for the services, consisting of one of the following:
- a SOC 2 Type II report; or
- an ISO/IEC 27001 certification (including the current certificate and the most recent surveillance/recertification audit report summary); or
- another industry-recognised independent assessment report that Deskpro confirms in writing is acceptable for the relevant scope.
Vendor must make available to Deskpro the relevant sections or an executive summary of such reports sufficient to demonstrate the scope and results for the services, subject to appropriate confidentiality protections.
Where Vendor does not have the required independent assurance, Vendor must promptly notify Deskpro. Deskpro may (at its discretion) permit an alternative assurance approach for a limited period, which may include an independent assessment commissioned by Vendor, or additional evidence and testing agreed in writing.
Vendor must provide the cooperation and documentation required for Deskpro to respond to privacy, data protection, audit, and regulatory requests from Deskpro customers and regulators relating to Vendor’s processing of Deskpro personal data.
Vendor must ensure that approved subprocessors provide equivalent evidence and cooperation for the relevant scope.
Failure to provide required evidence or cooperation may constitute a material breach of the parties’ agreement.
12. Updates to These Requirements
Deskpro may update these Data Protection Requirements from time to time by publishing an updated version at this URL.
13. Enforcement
Failure to comply with these Data Protection Requirements may constitute a material breach of the parties’ agreement and may result in remediation requirements, suspension of access, or termination.