Overall HighGDPR

Report rpt_cloudledger_dpa

CloudLedger DPA v3.2

Completed Jul 28, 2026, 3:02 PM · 2/2 pages scanned

High risk

3

Review

4

OK

0

Findings

8

High riskArticle 6 GDPR

Unclear or incomplete lawful basis for processing

1 source · 0 clauses

Finding

No clear lawful basis (contract, legal obligation, legitimate interests, or consent) is stated for core processing.

Recommendation

Map each processing purpose to an Article 6 basis and state it in the DPA or privacy notice.

Regulation

Article 6 GDPR

Processing is lawful only if and to the extent a legal basis applies.

Source document

“No matching protective language found in the submitted text.”

High riskArticle 9 GDPR

Special category data handled without Article 9 condition

1 source · 1 clause

Finding

Special category or sensitive data is contemplated without a documented Article 9 condition or prohibition.

Recommendation

Either prohibit special category data or document the Article 9 condition, safeguards, and retention limits.

Regulation

Article 9 GDPR

Processing of special categories of personal data is prohibited unless an Article 9 condition applies.

Source document · Approx. p. 4

“…ess, device identifiers, payment metadata, IP address, and transaction history. Special category data may be processed when customers supply it without restriction. 4. Purpose of processing To provide the CloudLedge…”

High riskArticle 28(2) GDPR

Sub-processor changes without prior notice

1 source · 1 clause

Finding

The processor may add sub-processors without prior written notice or authorisation from the controller.

Recommendation

Require prior written authorisation or general authorisation with advance notice and a meaningful objection right.

Regulation

Article 28(2) GDPR

The processor shall not engage another processor without prior specific or general written authorisation of the controller.

Source document · Approx. p. 6

“…roduct improvement. 5. Sub-processors The Processor may appoint sub-processors without prior written notice. A current list is available on request. 6. International transfers Personal data may be transferred to the United Sta…”

ReviewArticles 44–46 GDPR

International transfers lack documented safeguards

1 source · 1 clause

Finding

Cross-border transfers are contemplated; confirm SCCs/IDTA and transfer risk assessment are explicit and current.

Recommendation

Name the transfer mechanism (SCCs/IDTA), commit to a transfer impact assessment, and list destination countries.

Regulation

Articles 44–46 GDPR

Transfers to third countries require an adequacy decision or appropriate safeguards such as SCCs plus transfer risk assessment.

Source document · Approx. p. 6

“…on request. 6. International transfers Personal data may be transferred to the United States and other third countries. The Processor relies on standard contractual clauses where available. 7. Security The Proce…”

ReviewArticle 33 GDPR

Breach notification window is conditional or weak

1 source · 1 clause

Finding

Breach notification language exists but may dilute the controller's ability to meet the 72-hour regulatory clock.

Recommendation

Require processor notice to the controller without undue delay and no later than 24–48 hours after awareness, with fixed content requirements.

Regulation

Article 33 GDPR

Personal data breaches must be notified to the supervisory authority without undue delay and, where feasible, not later than 72 hours.

Source document · Approx. p. 9

“…the Customer without undue delay and in any event within seventy-two (72) hours where feasible. 9. Data subject rights The Processor will provide reasonable assistance with data subject requests when requested in…”

ReviewArticle 28(3)(h) GDPR

Audit rights limited to summary reports only

1 source · 1 clause

Finding

Customer audit rights appear limited to third-party report summaries, which may be insufficient for bank-partner or regulator diligence.

Recommendation

Allow audits (including via independent auditor) on reasonable notice, with SOC 2/ISO reports as a first step rather than the sole remedy.

Regulation

Article 28(3)(h) GDPR

The processor must make available all information necessary to demonstrate compliance and allow for and contribute to audits.

Source document · Approx. p. 11

“…The Customer may request a summary of the Processor's most recent SOC 2 report. On-site audits are not permitted. 12. Liability Except for wilful misconduct, the Processor's aggregate liability under this DPA is limited to fees pai…”

ReviewArticle 28(3)(g) GDPR

Deletion/return timeline is open-ended

1 source · 1 clause

Finding

Post-termination deletion or return is promised only within a commercially reasonable period, not a fixed deadline.

Recommendation

Set a fixed deletion/return deadline (for example 30 days) and require written certification of destruction.

Regulation

Article 28(3)(g) GDPR

At the end of services the processor must delete or return personal data at the choice of the controller.

Source document · Approx. p. 10

“…on Upon termination, the Processor will delete or return personal data within a commercially reasonable period, unless retention is required by law. 11. Audit The Customer may request a summary of the Processor's most recent SOC…”

InformationalArticle 82 GDPR

Liability cap may undermine GDPR indemnity posture

1 source · 1 clause

Finding

A tight liability cap is present. Not automatically unlawful, but often flagged in fintech vendor diligence.

Recommendation

Carve out data protection breaches, confidentiality, and wilful misconduct from low fee-based caps where commercially possible.

Regulation

Article 82 GDPR

Any person who has suffered damage as a result of an infringement has the right to receive compensation.

Source document · Approx. p. 12

“…are not permitted. 12. Liability Except for wilful misconduct, the Processor's aggregate liability under this DPA is limited to fees paid in the prior three months.”