Report rpt_cloudledger_dpa
CloudLedger DPA v3.2
Completed Jul 28, 2026, 3:02 PM · 2/2 pages scanned
High risk
3
Review
4
OK
0
Findings
8
Unclear or incomplete lawful basis for processing
1 source · 0 clauses
Finding
No clear lawful basis (contract, legal obligation, legitimate interests, or consent) is stated for core processing.
Recommendation
Map each processing purpose to an Article 6 basis and state it in the DPA or privacy notice.
Regulation
Article 6 GDPR
Processing is lawful only if and to the extent a legal basis applies.
Source document
“No matching protective language found in the submitted text.”
Special category data handled without Article 9 condition
1 source · 1 clause
Finding
Special category or sensitive data is contemplated without a documented Article 9 condition or prohibition.
Recommendation
Either prohibit special category data or document the Article 9 condition, safeguards, and retention limits.
Regulation
Article 9 GDPR
Processing of special categories of personal data is prohibited unless an Article 9 condition applies.
Source document · Approx. p. 4
“…ess, device identifiers, payment metadata, IP address, and transaction history. Special category data may be processed when customers supply it without restriction. 4. Purpose of processing To provide the CloudLedge…”
Sub-processor changes without prior notice
1 source · 1 clause
Finding
The processor may add sub-processors without prior written notice or authorisation from the controller.
Recommendation
Require prior written authorisation or general authorisation with advance notice and a meaningful objection right.
Regulation
Article 28(2) GDPR
The processor shall not engage another processor without prior specific or general written authorisation of the controller.
Source document · Approx. p. 6
“…roduct improvement. 5. Sub-processors The Processor may appoint sub-processors without prior written notice. A current list is available on request. 6. International transfers Personal data may be transferred to the United Sta…”
International transfers lack documented safeguards
1 source · 1 clause
Finding
Cross-border transfers are contemplated; confirm SCCs/IDTA and transfer risk assessment are explicit and current.
Recommendation
Name the transfer mechanism (SCCs/IDTA), commit to a transfer impact assessment, and list destination countries.
Regulation
Articles 44–46 GDPR
Transfers to third countries require an adequacy decision or appropriate safeguards such as SCCs plus transfer risk assessment.
Source document · Approx. p. 6
“…on request. 6. International transfers Personal data may be transferred to the United States and other third countries. The Processor relies on standard contractual clauses where available. 7. Security The Proce…”
Breach notification window is conditional or weak
1 source · 1 clause
Finding
Breach notification language exists but may dilute the controller's ability to meet the 72-hour regulatory clock.
Recommendation
Require processor notice to the controller without undue delay and no later than 24–48 hours after awareness, with fixed content requirements.
Regulation
Article 33 GDPR
Personal data breaches must be notified to the supervisory authority without undue delay and, where feasible, not later than 72 hours.
Source document · Approx. p. 9
“…the Customer without undue delay and in any event within seventy-two (72) hours where feasible. 9. Data subject rights The Processor will provide reasonable assistance with data subject requests when requested in…”
Audit rights limited to summary reports only
1 source · 1 clause
Finding
Customer audit rights appear limited to third-party report summaries, which may be insufficient for bank-partner or regulator diligence.
Recommendation
Allow audits (including via independent auditor) on reasonable notice, with SOC 2/ISO reports as a first step rather than the sole remedy.
Regulation
Article 28(3)(h) GDPR
The processor must make available all information necessary to demonstrate compliance and allow for and contribute to audits.
Source document · Approx. p. 11
“…The Customer may request a summary of the Processor's most recent SOC 2 report. On-site audits are not permitted. 12. Liability Except for wilful misconduct, the Processor's aggregate liability under this DPA is limited to fees pai…”
Deletion/return timeline is open-ended
1 source · 1 clause
Finding
Post-termination deletion or return is promised only within a commercially reasonable period, not a fixed deadline.
Recommendation
Set a fixed deletion/return deadline (for example 30 days) and require written certification of destruction.
Regulation
Article 28(3)(g) GDPR
At the end of services the processor must delete or return personal data at the choice of the controller.
Source document · Approx. p. 10
“…on Upon termination, the Processor will delete or return personal data within a commercially reasonable period, unless retention is required by law. 11. Audit The Customer may request a summary of the Processor's most recent SOC…”
Liability cap may undermine GDPR indemnity posture
1 source · 1 clause
Finding
A tight liability cap is present. Not automatically unlawful, but often flagged in fintech vendor diligence.
Recommendation
Carve out data protection breaches, confidentiality, and wilful misconduct from low fee-based caps where commercially possible.
Regulation
Article 82 GDPR
Any person who has suffered damage as a result of an infringement has the right to receive compensation.
Source document · Approx. p. 12
“…are not permitted. 12. Liability Except for wilful misconduct, the Processor's aggregate liability under this DPA is limited to fees paid in the prior three months.”