Legal
Data Processing Agreement
The GAID Article 34(2) terms under which we process personal data on a firm’s instructions.
Between the Firm (data controller) and TKJ Global Media Ltd (data processor).
MERGED DOCUMENT, 13 August 2026. This supersedes and absorbs
docs/ndpa/02-processor-DPA-Article-34-DRAFT.md(12 Aug 2026), which is now a
pointer to this file. The base is02‘s letter-by-letter Article 34(2) mapping
— the right structure, because it lets counsel audit completeness at a glance.
Added from the later draft: populated Schedules A–D, the completion map,
and the insurance/indemnity flags. Nothing from02was dropped, including
its two load-bearing points: the CBDTI warning and the foreign-legal-process
safeguard.DRAFT for the pilot firms’ Nigerian counsel. Not legal advice, not fit to
sign.Two warnings that must survive editing
1. This DPA is not, by itself, a CBDTI. Where the data centre is outside
Nigeria, a transfer is lawful only on a Commission adequacy decision or a
Commission-approved CBDTI (GAID Schedule 5 para 1, read 12 Aug 2026). No
NDPC adequacy decision exists for the UK or South Africa — corroborated three
ways on file. This DPA is drafted to feed a CBDTI application by delivering the
Schedule 5 §4 objectives (monitoring and accountability, access to remedy, data
sovereignty); approval is the Commission’s, not ours.2. Cost is not a transfer basis. GAID Schedule 5 para 6, verbatim: “A
compelling legal right is different from a business interest. Profit and
personal business/organisational development considerations do not fall within
this category.” The derogations cannot be used to justify offshore hosting on
price.Current hosting position
DECISION-host-in-country.md(12 Aug 2026) recommends hosting the Nigeria
instance in Nigeria, retiring the Cape Town and DigitalOcean-London options.
The withdrawn Cape Town decision is recorded inGO-LIVE-NIGERIA.md§3. If
in-country is confirmed, clause (f) takes the in-country branch and Part VIII
never arises. The offshore branch is retained because the decision is
expressly reversible.Provenance: Article 34(2)(a)–(t) and 34(3) and Schedule 5 quoted from the
primary GAID (../../sources/NDPC-GAID-2025-full.pdf). NDPA section-level
references marked[verify]are memo-read pending pin-cite — TKJ has not read
the Act in primary form (G-NGDOC1).
How this maps to Article 34(2)
Each lettered clause answers the identically-lettered GAID Article 34(2)
requirement. The mapping is exact so counsel can audit completeness at a glance;
the completion map at the end is the checklist.
Parties. (b)(c) This Agreement is between [Firm] of [address]
(“the Firm”, data controller) and TKJ Global Media Ltd, registered in England
and Wales [[ G-EWDOC1 ]] under number 08272919, of 94 Queen Elizabeth
Road, Wakefield, WF1 4RJ, United Kingdom (“TKJ”, data processor).
TKJ has no Nigerian entity or office. See clause (m) on registration.
(a) Obligations under section 29. TKJ processes personal data only on the
Firm’s documented instructions; ensures persons authorised to process are bound
by confidentiality; implements section 39 security measures (clause (j));
assists the Firm with data-subject rights, breach notification and DPIAs;
engages no sub-processor without the Firm’s authorisation and notifies the Firm
of any intended new sub-processor [NDPA s 29(1)(e) — verify]; and, at the
Firm’s choice, deletes or returns personal data at the end of the engagement,
save where retention is required by law.
TKJ shall immediately inform the Firm if, in its opinion, an instruction
would breach the NDP Act.
(d) Recitals. This Agreement is entered under and subject to the [Principal
Subscription Agreement / Service Level Agreement] dated [ ] between the parties.
(e) Purpose of processing. Hosting and processing the Firm’s client and
matter records, client-account records, documents, billing, calendar and related
data, solely to provide the practice-management service. TKJ does not
determine the purposes or means, and acquires no independent basis.
(f) Location of data processing — cross-border. The personal data is
processed and stored at [data-centre location].
- In-country branch (the current recommendation). Where the location is in
Nigeria, the parties record that no cross-border transfer occurs and Part VIII
of the NDP Act is not engaged. TKJ shall not move, route or replicate the data
outside Nigeria — including for backup, logging, monitoring or support — without
the Firm’s prior written instruction and a transfer basis established under
the offshore branch below. - Offshore branch. Where the location is outside Nigeria, the parties record
that this is a cross-border transfer engaging Part VIII, which by section
63 is the overarching governing provision (GAID Art 45(1)); and the Firm relies
on [the Commission’s adequacy decision for [country] / Commission-approved
CBDTI ref [ ] / — none yet: see the transfer record,docs/ndpa/04].
In either case TKJ shall not change the processing location, or route or
replicate the data to any further country, without the Firm’s prior written
instruction and an updated transfer basis.
The in-country branch is not a convenience. It removes the Commission-approval
dependency entirely — seeDECISION-host-in-country.mdandNDPA-TRANSFER-BASIS.md.
(g) Scope. The categories of data subject and personal data (including
sensitive personal data and criminal-matter records) and the processing
operations set out in Schedule A.
(h) Lawful bases. The Firm’s lawful bases are set out in Schedule A; TKJ
does not determine purposes or means and acquires no independent basis.
(i) Responsibilities of the parties. As set out throughout, with the
allocation table at Schedule B (rights requests, breaches, DPIAs, audits and
registration evidence).
(j) Technical and organisational measures. Detailed at Schedule C, per
Article 34(2)(j). Without limitation:
- Host-side encryption with operator-held keys — backups and shipped logs are
encrypted before leaving the host, to a key the hosting provider cannot
access, so the provider holds only ciphertext. (This is the mitigation the NDPC
guidance and all counsel opinions identify for the foreign-legal-order risk.) - Encryption in transit (TLS); tenant isolation enforced by the database;
append-only client-account ledger; access control and authentication;
restoration testing; and periodic risk assessment[NDPA s 39(2) — verify]. - Foreign legal process: on any order, request or demand by a foreign
authority for the Firm’s data, TKJ shall (to the extent legally permitted)
notify the Firm without undue delay before disclosure, disclose no more than
legally compelled, and take reasonable steps to challenge or narrow the
demand.
(k) DPIA outcome. The outcome of the Firm’s Article 28 DPIA — which, for an
offshore destination, must include the destination human-rights assessment
required by GAID Schedule 4 — is recorded at Schedule D, and TKJ shall provide
the information the Firm reasonably needs to complete and file it.
(l) Potential risks. The risks identified in the DPIA — in particular
foreign public-authority access to privileged material — and the mitigations
at clause (j) are recorded at Schedule D.
(m) NDP Act compliance / registration evidence. Each party shall provide the
other, on request, evidence of its registration with the Commission (where it
is a controller or processor of major importance) and of its compliance posture;
TKJ shall furnish what the Firm needs for its Compliance Audit Return.
[[ ⚠ Q-NGDOC1 — GAID Art 8(2) treats a controller or processor who TARGETS data
subjects in Nigeria as "operating in Nigeria" even if not domiciled there. TKJ
markets to Nigerian firms. Whether TKJ must register as of major importance —
and in which class (UHL/EHL/OHL) — must be resolved BEFORE this Agreement is
offered to any Nigerian firm, because Art 34(2)(m) says evidence of registration
"should be ascertained" and the Firm's counsel will ask for it. ]]
(n) Confidentiality. TKJ and its personnel shall keep the personal data
confidential, without limit of time, in addition to any professional duty of
confidence owed by the Firm. Nothing in this Agreement waives privilege, and
TKJ asserts no right over privileged material.
(o) Tenure. This Agreement runs for the term of the [Principal Agreement] and
survives, as to confidentiality, deletion/return and audit, until those
obligations are discharged.
(p) Specific restrictions. TKJ shall not:
- process outside the location stated at (f);
- use the Firm’s data for its own purposes — including no training,
fine-tuning or improvement of any model, no benchmarking, no market insight —
and no AI or analytics on matter content without the Firm’s written
instruction; - respond directly to a data subject’s request about the Firm’s data — it shall
forward the request promptly and direct the data subject to the Firm; - delete the Firm’s data automatically. On termination the Firm may export for
[90] days, and deletion occurs only on the Firm’s written instruction,
because a legal practice’s retention duties may outlive its subscription.
(q) Indemnity. [To be negotiated — allocation of liability for breach of this
Agreement, cross-referenced to the Principal Agreement’s cap and to Article 34(3)
accountability below.]
[[ Settle (q), (r) and the Subscription Terms' liability cap TOGETHER. An
indemnity agreed in isolation can quietly defeat a negotiated cap. ]]
(r) Insurance. [TKJ to maintain [cyber / professional indemnity / technology
E&O] insurance of not less than [amount]; evidence on request.]
[[ ⚠ Q-EWDOC2 — BLOCKING, and required in two places: here by Art 34(2)(r), and
in the England & Wales liability cap where UCTA s 11(4) makes available cover
directly relevant to reasonableness. Confirm cover type, limit of indemnity, and
whether it responds to Nigerian operations and data-protection liabilities. This
clause cannot be completed by drafting. ]]
(s) Force majeure. [Standard, expressly excluding the parties’
data-protection and breach-notification duties from suspension.]
(t) Dispute resolution. [Governing law and forum — to be settled with the
Subscription Terms and Website Terms so all three agree.]
[[ Note, and it is not displaced by the forum chosen: GAID Art 47(2) records
that a data subject may seek redress at the closest Federal or State High Court
under s 46 of the 1999 Constitution and the Fundamental Rights Enforcement
Procedure Rules. The Firm's NDPA accountability is to the Commission regardless
of forum. ]]
Accountability for third parties (Article 34(2)/34(3)). Each party shall take
reasonable measures to ensure the other is NDPA-compliant and accountable to the
Commission or, for a foreign party, to a competent regulator outside Nigeria; and
each party is accountable for the acts and omissions of the third parties it
engages or permits to process data (GAID Art 34(3), quoted).
Breach notification. TKJ shall notify the Firm immediately on becoming
aware of a personal data breach, and shall provide the content required by GAID
Art 33(5)(a)–(h): the circumstances of the loss or unauthorised access or
disclosure; the date or time period; a description of the personal information
involved; an assessment of the risk of harm; an estimate of the number of
individuals at real risk of significant harm; steps taken to reduce harm; steps
taken to notify individuals; and a named contact who can answer the
Commission’s questions.
The parties record that the Firm must notify the Commission within 72 hours
of becoming aware of a breach likely to result in a risk to rights and freedoms
(NDP Act s 40(2), quoted at GAID Art 33(1)), and must notify affected data
subjects immediately (GAID Art 33(3)). TKJ’s notification is timed and
specified so that the Firm can do so.
Schedule A — Scope, data and lawful bases (clauses (g), (h))
| item | detail |
|---|---|
| Categories of data subject | The Firm’s clients; opposing parties and their representatives; witnesses and third parties named in matters; the Firm’s own personnel |
| Types of personal data | Identity and contact details; matter and case information; correspondence and documents; financial, billing and client-account data; user account data |
| Sensitive personal data | Anticipated — legal practice files routinely contain it |
| Criminal-matter records | Anticipated — contentious files |
| Privileged material | Yes — see clause (n) |
| Processing operations | Hosting, storage, organisation, retrieval, back-up, export and deletion |
| Duration | The term of the Principal Agreement, plus the export and deletion periods at (p) |
| The Firm’s lawful bases | [[ TO COMPLETE BY THE FIRM — NDPA s 25 has NOT been read (G-NGDOC1). GAID Arts 16–26 elaborate the bases; Art 26 and Schedule 8 govern legitimate interest and provide a Legitimate Interest Assessment template. ]] |
Schedule B — Responsibility allocation (clause (i))
| activity | the Firm (controller) | TKJ (processor) |
|---|---|---|
| Determining purposes and lawful basis | ✔ | — |
| Responding to data subject rights requests (GAID Arts 36–40) | ✔ | assists; forwards; never answers directly |
| Notifying the Commission of a breach (72h) | ✔ | supplies Art 33(5) content immediately |
| Notifying data subjects of a breach (immediately) | ✔ | supplies content and assistance |
| DPIA (GAID Art 28, Schedule 4) | ✔ | supplies information |
| Registration of major importance + CAR (Arts 9, 10) | ✔ for itself | ✔ for itself — see (m), Q-NGDOC1 |
| DPO designation (Arts 11–14) | ✔ for itself | ✔ for itself if designated |
| Security measures | oversight | ✔ implements Schedule C |
| Establishing a transfer basis, if offshore | ✔ (with counsel) | supplies evidence; does not move data unilaterally |
| Retention decisions and deletion instruction | ✔ | acts only on written instruction |
Schedule C — Technical and organisational measures (clause (j))
- Isolation between firms enforced at the database level, not by application
logic alone. - Encryption in transit (TLS); backups encrypted before leaving the host,
to a key the hosting environment does not hold. - Access control limited to personnel who require it, with authentication, and
logging of access to Firm data by TKJ personnel. - Append-only client-account and billing ledgers — history cannot be rewritten;
corrections are new entries. - Backups held separately from the primary environment and periodically tested by
restoration; off-host decryption drills performed and recorded. - The service refuses to start on a configuration that would disable isolation.
- Automated evaluation suites run against the platform before changes ship.
- Periodic compliance audit of processing activities on a risk-based approach
(GAID Art 10). - Foreign legal process: notify-and-challenge, per clause (j).
Schedule D — DPIA outcome, risks and mitigations (clauses (k), (l))
DPIA outcome: [[ TO COMPLETE — the Firm's DPIA under GAID Art 28 / Schedule 4.
For an offshore destination this MUST include the destination human-rights
assessment. ]]
| risk | mitigation |
|---|---|
| Foreign public-authority access to privileged material | Host-side encryption to an operator-held key; notify-and-challenge on foreign legal process; in-country hosting removes the exposure altogether |
| Unauthorised access to another firm’s data | Database-level isolation, enforced by the database |
| Loss of data | Encrypted daily backups, held separately, restoration tested |
| Exposure of backups at rest | Encrypted before leaving the host; provider holds ciphertext only |
| Alteration of financial records | Append-only ledgers |
| Unsafe configuration reaching production | Service refuses to start rather than run degraded |
| Insider access | Access restricted, authenticated and logged |
| Transfer without a lawful basis | Clause (f); no relocation without written instruction |
Completion map — check before execution
| Art 34(2) | requirement | where | state |
|---|---|---|---|
| (a) | s 29 obligations | (a) | ⚠ s 29 memo-read, not pin-cited |
| (b)(c) | Names, addresses | Parties | ✔ |
| (d) | Recitals / principal agreement | (d) | ⚠ identify the agreement |
| (e) | Purpose | (e) | ✔ |
| (f) | Location, incl. cross-border | (f) | ⚠ hosting decision + basis |
| (g) | Scope | Schedule A | ✔ |
| (h) | Lawful bases | Schedule A | ⚠ s 25 unread; Firm to complete |
| (i) | Responsibilities | Schedule B | ✔ |
| (j) | Technical/organisational measures | Schedule C | ✔ |
| (k) | DPIA outcome | Schedule D | ⚠ open |
| (l) | Potential risks | Schedule D | ✔ (review) |
| (m) | NDP Act compliance / registration | (m) | ⚠ Q-NGDOC1 |
| (n) | Confidentiality | (n) | ✔ |
| (o) | Tenure | (o) | ✔ |
| (p) | Specific restrictions | (p) | ✔ |
| (q) | Indemnity | (q) | ⚠ commercial |
| (r) | Insurance | (r) | ⚠ Q-EWDOC2 blocking |
| (s) | Force majeure | (s) | ⚠ standard wording to settle |
| (t) | Dispute resolution | (t) | ⚠ decision |
Not legal advice. Settle with the Firm’s Nigerian counsel / DPCO.