Rowville Consulting

DATA PROCESSING AGREEMENT TEMPLATE

Between Client (Controller) and Rowville Consulting (Processor)

For engagements subject to Article 28 of the UK GDPR or EU GDPR

Public template: The execution copy is completed for the specific engagement, including the service scope, transfer mechanism and authorised subprocessors.

Template version 2.1 • Published 21 July 2026

Template Version 2.1 (UK & Ireland Focus)
Template Published 21 July 2026
Governing Law England and Wales
Legal Review Recommended for Controller's counsel

Note: The effective date and governing law of the execution copy will be as recorded by the parties.

PARTIES TO THIS AGREEMENT

1.1

CONTROLLER: The Client engaging Rowville Consulting for accounting services, as detailed in the Master Services Agreement (the "Client").

1.2

PROCESSOR: Rowville Consulting (Pty) Ltd, a company registered in Botswana with its principal place of business at Gaborone, Botswana, operating through its website at https://rowvilleconsulting.co.bw (the "Processor").

1.3

This DPA is incorporated into and forms part of the Master Services Agreement between the Parties. In case of conflict, this DPA prevails regarding data protection matters.

DEFINITIONS

Term Definition
UK GDPR The General Data Protection Regulation as incorporated into UK law by the Data Protection Act 2018.
EU GDPR Regulation (EU) 2016/679 as applicable in Ireland, alongside the Irish Data Protection Act 2018.
Personal Data Any information relating to an identified or identifiable natural person processed under the Agreement.
Processing Any operation performed on Personal Data (collection, recording, storage, etc.).
Sub-processor A third party engaged by Processor to process Personal Data.
Data Subject An individual whose Personal Data is processed (employees, customers, etc. of Controller).
Security Incident Breach of security leading to accidental or unlawful destruction, loss, alteration, or access to Personal Data.

DETAILS OF PROCESSING

3.1

Subject Matter & Duration

Processing of Personal Data necessary to provide the accounting and finance services described in the Master Services Agreement. Duration matches the term of the Agreement plus applicable statutory retention periods.

3.2

Nature & Purpose

Processing includes: preparation of management accounts, financial statements, tax computations, payroll processing, bookkeeping, and related finance-support activities expressly described in the service schedule.

3.3

Types of Personal Data

May include: Employee details (name, salary, contact info), customer/vendor information, financial transaction data, and any other data provided by Controller for accounting purposes.

3.4

Categories of Data Subjects

Controller's employees, directors, shareholders, customers, suppliers, and other individuals whose data is included in financial records provided to Processor.

PROCESSOR OBLIGATIONS

4.1

Instructions & Compliance

Processor shall only process Personal Data on documented instructions from Controller, unless required by applicable law. Processor shall immediately inform Controller if, in its opinion, an instruction infringes applicable UK or EEA data-protection law.

4.2

Confidentiality

Processor ensures persons authorised to process Personal Data are subject to confidentiality obligations (contractual or statutory) that survive termination of their engagement.

4.3

Security Measures

Processor implements and maintains technical and organisational measures described in Appendix 1.

4.4

Sub-processing

Controller grants general authorisation for Processor to engage Sub-processors listed in the execution copy. Processor shall provide 30 days' notice of intended changes, giving Controller opportunity to object.

4.5

Data Subject Rights

Processor shall assist Controller in responding to Data Subject requests by appropriate technical and organisational measures.

4.6

Security Incident Notification

Processor shall notify Controller without undue delay (and in any event within 48 hours) upon becoming aware of a Security Incident. Notifications shall include available details and proposed mitigation steps.

4.7

Deletion/Return of Data

At Controller's choice, Processor shall delete or return all Personal Data after termination of services, and delete existing copies unless applicable law requires storage.

4.8

Audit Rights

Upon reasonable notice, Processor shall make available to Controller (or its independent auditor) information necessary to demonstrate compliance. Audits shall be conducted at Controller's expense, no more than annually, subject to confidentiality agreements, and with the following exceptions:

  • Material security incidents requiring follow-up verification
  • Regulator requirements or orders
  • Evidence of serious non-compliance identified through other means

CONTROLLER OBLIGATIONS

5.1

Controller warrants that it has lawful basis for processing and necessary notices/consents for Processor to process Personal Data as described herein.

5.2

Controller shall provide clear instructions and any necessary cooperation for Processor to perform its obligations.

5.3

Controller is responsible for responding to Data Subject requests regarding data processed by Processor.

INTERNATIONAL TRANSFERS

6.1

Controller acknowledges that Processor's primary processing operations are in Botswana.

6.2

Where UK or EEA Personal Data is transferred to Botswana, such transfer shall be governed by an appropriate transfer mechanism.

UK transfers: The UK International Data Transfer Agreement or EU Standard Contractual Clauses with the UK Addendum may be used, subject to completion of the relevant annexes and a transfer risk assessment.

EEA transfers: EU Standard Contractual Clauses may be used, subject to completion of the relevant annexes and a transfer impact assessment.

Implementation: The execution copy of this DPA will specify the transfer mechanism(s) selected for the engagement and shall incorporate the completed clauses or refer to them as an appendix.

6.3

Processor shall not transfer Personal Data to any third country not covered by adequacy regulations without Controller's prior written consent and the appropriate safeguard.

APPENDICES

APPENDIX 1: TECHNICAL AND ORGANISATIONAL MEASURES

The measures set out below are maintained by Rowville in respect of its own systems and personnel. Additional measures may be agreed for specific engagements.

Security Area Rowville Baseline Measures
Access Control Role-based access, Multi-factor authentication, Unique user IDs, Regular access reviews, Principle of least privilege
Encryption Encryption at rest (AES-256 equivalent) and in transit (TLS 1.3) where supported by the systems used; encrypted backups where applicable
Physical Security Managed through secure cloud providers with industry-standard access controls; measures described during due diligence
Network Security Firewalls, secure access controls and VPN for remote access; managed via approved platforms and providers
Incident Response Documented response plan, escalation procedures, breach notification within 48 hours of awareness
Business Continuity Backup and recovery procedures appropriate to the service scope, reviewed and tested periodically
Personnel Security Confidentiality agreements, role-appropriate training and access removal on departure or reassignment

Client-approved subprocessors and cloud platforms may operate additional controls, which are disclosed during onboarding.

APPENDIX 2: SUBPROCESSORS (EXECUTION COPY)

The execution copy of this DPA will list each subprocessor that will process Client Personal Data in connection with the services.

Controller will be notified 30 days before Rowville engages a new Subprocessor for Client Personal Data.

AGREED AND ACCEPTED

FOR AND ON BEHALF OF CONTROLLER

Company Name: ________________________________

Signature: ____________________________________

Name (Print): _______________________________

Title: _______________________________________

Date: ________________________________________

FOR AND ON BEHALF OF PROCESSOR

Rowville Consulting (Pty) Ltd

Gaborone, Botswana

Registration number and tax details supplied in the execution copy

Signature: ____________________________________

Name (Print): _______________________________

Title: _______________________________________

Date: ________________________________________

Request Execution Copy View Compliance Policy