DATA PROCESSING AGREEMENT
This Data Processing Agreement (“DPA”) forms part of and is incorporated by reference into the pay transparency analytics platform access and services agreement (in the form of a signed order form subject to terms of service) (the “Agreement”) between Skills Economy Insight Ltd. trading as SkillsTrust, a company registered in Ireland under company registration number 704253 and having its registered address at 77 Camden Street Lower, Dublin, (hereinafter referred as “SkillsTrust") and the customer entity entering into the Agreement having signed the order form (“Controller”).
This DPA applies automatically to the extent that SkillsTrust processes Personal Data on behalf of Controller in connection with the services provided under the Agreement. This DPA applies to the Processing of Personal Data subject to any applicable Data Protection Laws worldwide.
The terms used in this DPA shall have the meanings set forth herein. Terms not otherwise defined herein shall have the meaning given to them in the Agreement. Except as modified below, the terms of the Agreement shall remain in full force and effect.
By entering into the Agreement, Controller enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Affiliates for which SkillsTrust processes Personal Data as Processor.
In the event of conflict between this DPA and the Agreement, this DPA shall prevail with respect to the Processing of Personal Data.
Definitions
In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
"Authorised Sub-processors" means (a) those Sub-processors set out in Annex 2 (List of Authorised Sub-processors); and (b) any additional Sub-processors approved in writing by Controller in accordance with clause 6.
"Controller Personal Data" means the data described in Annex 1 and any other Personal Data processed by SkillsTrust on behalf of the Controller pursuant to or in connection with the Agreement.
“Data Protection Laws” means all applicable data protection and privacy laws, including without limitation the GDPR, UK GDPR, Data Protection Acts 1988–2018 (Ireland), and any applicable implementing or supplementary legislation.
“Erasure" means the removal or destruction of Personal Data such that it cannot be recovered or reconstructed.
"EEA" means the European Economic Area.
"Personal Data Breach" has the meaning given to 'personal data breach' in Article 4(12) of the GDPR, and for the purposes of this DPA means any such breach affecting Controller Personal Data.
“Process”, “Processing” and “Processed”, “Controller”, “Data Subject”, “Personal Data”, and “Special Categories of Personal Data” shall have the meanings given in the GDPR.
"Services" means the services to be supplied by SkillsTrust to the Controller pursuant to the Agreement.
"Standard Contractual Clauses" means the standard contractual clauses adopted by the European Commission Implementing Decision (EU) 2021/914, as amended, replaced or superseded from time to time.
"Sub-processor" means any third-party processor engaged by SkillsTrust to process Controller Personal Data on behalf of the Controller.
"Third Country" means any country outside EU/EEA, except where that country is the subject of a valid adequacy decision by the European Commission on the protection of Personal Data in Third Countries.
“UK GDPR” means the GDPR as incorporated into United Kingdom law pursuant to the European Union (Withdrawal) Act 2018.
Data Processing Terms
2.1 In the course of providing the Services to the Controller pursuant to the Agreement, SkillsTrust may process Controller Personal Data on behalf of the Controller as per the terms of this DPA. SkillsTrust agrees to comply with the following provisions with respect to any Controller Personal Data.
2.2 SkillsTrust shall comply with all applicable Data Protection Laws in connection with its processing of Controller Personal Data, including maintaining any records of processing activities required under Article 30 GDPR.
2.3 The parties acknowledge that the Controller determines the purposes and means of the Processing of Controller Personal Data and that SkillsTrust acts solely as a Processor. The Controller shall be responsible for the accuracy, quality and legality of the Controller Personal Data and for ensuring that it has a valid legal basis for the Processing of such Personal Data under applicable Data Protection Laws.
2.4 The Controller shall not instruct SkillsTrust to process Personal Data in a manner that would cause SkillsTrust to breach applicable Data Protection Laws. If SkillsTrust considers that any instruction from the Controller would constitute a breach of applicable Data Protection Laws, SkillsTrust shall immediately notify the Controller and shall be entitled to suspend processing pursuant to that instruction pending resolution, without liability to the Controller.
Processing of Controller Personal Data
3.1 SkillsTrust shall only process Controller Personal Data for the purposes of the Agreement and in accordance with the Controller’s documented instructions as set out in the Agreement or otherwise agreed in writing, unless required to do otherwise by applicable law. Where SkillsTrust is required by applicable law to process Controller Personal Data otherwise than in accordance with the Controller's instructions, SkillsTrust shall, to the extent permitted by applicable law, inform the Controller of that legal requirement as soon as reasonably practicable and, where possible, prior to such processing. SkillsTrust shall promptly inform the Controller if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws
Access and Non–Disclosure
4.1 SkillsTrust shall ensure that access is strictly limited to personnel who require access to the relevant Controller Personal Data for the performance of the Services and that such personnel:
4.1.1 are informed of the confidential nature of the Controller Personal Data and are aware of SkillsTrust's obligations under this DPA and the Agreement in relation to the Controller Personal Data;
4.1.2 have undertaken appropriate data protection and security training consistent with industry standards;
4.1.3 are subject to confidentiality undertakings or professional or statutory obligations of confidentiality; and
4.1.4 are subject to user authentication and logon processes when accessing the Controller Personal Data consistent with the technical and organisational security measures required under Clause 5.
Personal Data Security
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, the SkillsTrust shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including but not limited to:
5.1.1 pseudonymisation and encryption;
5.1.2 the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
5.1.3 the ability to restore the availability and access to Controller Personal Data in a timely manner in the event of a physical or technical incident; and
5.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing.
5.2 In assessing the appropriate level of security, SkillsTrust shall take into account the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Controller Personal Data transmitted, stored or otherwise processed. SkillsTrust may update such measures from time to time provided that such updates do not materially reduce the level of protection.
Sub-Processing
6.1 As of this DPA’s Effective Date, the Controller hereby provides a general authorisation for SkillsTrust to engage the Authorised Sub-processors set out in Annex 2.
6.2 SkillsTrust shall inform the Controller of any intended addition or replacement of Sub-processors by providing at least thirty (30) days' prior written notice. The Controller may object to any such addition or replacement on reasonable grounds relating to data protection. Where the Controller objects, the parties shall work in good faith to resolve the objection. If no resolution is reached, the Controller may terminate the affected Services. If no written objections have been received within thirty (30) days of the date of notice, the proposed Sub-processor shall be deemed accepted.
6.3 With respect to each Sub-processor, SkillsTrust shall:
6.3.1 provide the Controller with details of the Processing to be undertaken by each Sub-processor;
6.3.2 carry out adequate due diligence on each Sub-processor to ensure that it can provide the level of protection for Controller Personal Data, including without limitation, sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the requirements of this DPA and the applicable Data Protection Laws;
6.3.3 include terms in the contract between SkillsTrust and each Sub-processor which are no less protective with respect to Processing of Personal Data compared to the provisions of this DPA. Upon request, SkillsTrust shall provide a copy of its agreements with Sub-processors to Controller for its review;
6.3.4 insofar as that contract involves the transfer of Controller Personal Data to a Third Country, ensure that an appropriate transfer mechanism is in place in accordance with applicable Data Protection Laws, which shall include (where applicable) the Standard Contractual Clauses or the UK International Data Transfer Addendum, or such other mechanism as may be agreed in writing with the Controller; and
6.3.5 remain fully liable to the Controller for any failure by each Sub-processor to fulfil its obligations in relation to the Processing of any Controller Personal Data.
Data Subject Rights
7.1 SkillsTrust shall promptly notify the Controller if it receives a request from a Data Subject, the Supervisory Authority and/or other competent authority under any applicable Data Protection Laws with respect to Controller Personal Data, and shall not respond except on the Controller’s instructions or as required by law.
7.2 SkillsTrust shall cooperate as requested by the Controller to enable the Controller to comply with any exercise of rights by a Data Subject under any Data Protection Laws with respect to Controller Personal Data and comply with any assessment, enquiry, notice or investigation under any Data Protection Laws with respect to Controller Personal Data or this DPA. SkillsTrust shall provide reasonable and proportionate assistance, taking into account the nature of the processing and the information available to SkillsTrust.
Personal Data Breach
8.1 SkillsTrust shall notify the Controller without undue delay and, in any case, within forty eight (48) hours upon becoming aware of a Personal Data Breach affecting Controller Personal Data. SkillsTrust will provide the Controller with sufficient information to allow the Controller to meet any obligations to report a Personal Data Breach under the Data Protection Laws. Such notification shall as a minimum:
8.1.1 describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned;
8.1.2 communicate the name and contact details of SkillsTrust's Data Protection Officer, Privacy Officer or other relevant contact from whom more information may be obtained;
8.1.3 describe the estimated risk and the likely consequences of the Personal Data Breach; and
8.1.4 describe the measures taken or proposed to be taken to address the Personal Data Breach.
8.2 SkillsTrust shall co-operate with the Controller and take such reasonable commercial steps to investigate, mitigate and remediate the breach.
8.3 SkillsTrust shall not notify any third party (other than Authorised Sub-processors engaged to assist in remediation) of a Personal Data Breach without the Controller's prior written consent, except where required to do so by applicable law or by a Supervisory Authority or other competent regulatory authority acting within its powers.
Data Protection Impact Assessment and Prior Consultation
SkillsTrust shall provide reasonable assistance to the Controller with any data protection impact assessments which are required under Article 35 of GDPR and with any prior consultations to any supervisory authority of the Controller which are required under Article 36 of GDPR, in each case solely in relation to Processing of Controller Personal Data by SkillsTrust on behalf of the Controller and considering the nature of the processing and information available to SkillsTrust.
. Erasure or return of Controller Personal Data
10.1 SkillsTrust shall promptly and, in any event, within 90 (ninety) calendar days of the earlier of:
(i) cessation of Processing of Controller Personal Data by SkillsTrust; or (ii) termination of the Agreement, at the choice of Controller (such choice to be notified to SkillsTrust in writing) either:
10.1.1 return a complete copy of all Controller Personal Data to the Controller by secure file transfer in such format as notified by the Controller to SkillsTrust and securely erase all other copies of Controller Personal Data Processed by SkillsTrust or any Authorised Sub-processor; or
10.1.2 securely wipe all copies of Controller Personal Data Processed by SkillsTrust or any Authorised Sub-processor, and in each case, provide a written certification to the Controller that it has complied fully with the requirements of this clause 10.
10.2 SkillsTrust may retain Controller Personal Data to the extent required by Data Protection Laws, and only to the extent and for such period as required by Data Protection Laws, and always provided that SkillsTrust shall ensure the confidentiality of all such Controller Personal Data and shall ensure that such Controller Personal Data is only Processed as necessary for the purpose(s) specified in the Data Protection Laws requiring its storage and for no other purpose.
. Audit Rights
11.1 SkillsTrust shall make available to the Controller, upon request, information reasonably necessary to demonstrate compliance with this DPA. The Controller may, no more than once per year and on at least thirty (30) days’ prior written notice, conduct an audit of SkillsTrust’s compliance with this DPA, subject to the following conditions:
11.1.1 audits shall be limited in scope to matters relevant to data protection compliance;
11.1.2 audits shall be conducted during normal business hours and in a manner that minimises disruption to SkillsTrust;
11.1.3 audits shall be conducted by an independent third-party auditor subject to confidentiality obligations; and
11.1.4Controller shall bear all costs of the audit unless a material breach is identified.
. International Transfers of Controller Personal Data
12.1 To the extent that SkillsTrust Processes Controller Personal Data in a Third Country, SkillsTrust shall ensure that such Processing is carried out in compliance with applicable Data Protection Laws. Where Controller Personal Data is transferred to a Third Country which is not subject to an adequacy decision by the European Commission or relevant competent authority, the parties agree that such transfer shall, where required, be governed by the Standard Contractual Clauses which are hereby incorporated into and form part of this DPA by reference.
12.2 For the purposes of the Standard Contractual Clauses:
12.2.1 the Controller shall act as “data exporter” and SkillsTrust shall act as “data importer”;
12.2.2 Annex 1 of this DPA shall be deemed to constitute Annex I of the Standard Contractual Clauses;
12.2.3 the technical and organisational measures implemented by SkillsTrust as described in this DPA shall be deemed to satisfy the requirements of Annex II of the Standard Contractual Clauses;
12.2.4 Clause 9(a) (Use of Sub-processors) shall apply with Option 2 (general written authorisation), and the time period for prior notice of Sub-processor changes shall be thirty (30) days;
12.2.5 the optional provisions relating to independent dispute resolution shall not apply; and
12.2.6 the governing law for the purposes of Clause 17 of the Standard Contractual Clauses shall be Ireland, and the courts of Ireland shall have jurisdiction for the purposes of Clause 18.
12.3 To the extent that Controller Personal Data originating from the United Kingdom is transferred to a Third Country, the parties agree that the UK International Data Transfer Addendum shall be deemed incorporated into and form part of this DPA. The parties shall complete and execute the mandatory Tables in Part 1 of the UK IDTA and attach these as an annex to this DPA.
12.4 SkillsTrust may also Process Controller Personal Data in a Third Country where such Processing is based on an adequacy decision or any other valid transfer mechanism recognised under applicable Data Protection Laws.
12.5 The Controller hereby authorises SkillsTrust to make such transfers, including onward transfers to Sub-processors, provided that appropriate safeguards are implemented in accordance with this clause.
. General Terms
13.1 This DPA shall terminate automatically upon termination or expiry of the Agreement, or upon cessation of all processing of Controller Personal Data by SkillsTrust, whichever is later. The Standard Contractual Clauses shall remain in force for so long as SkillsTrust holds or processes any Controller Personal Data originating from the EEA or UK, notwithstanding termination of this DPA or the Agreement.
13.2 Any obligation imposed on SkillsTrust under this DPA in relation to the Processing of Personal Data shall survive any termination or expiration of this DPA.
13.3 This DPA, excluding the Standard Contractual Clauses, shall be governed by the governing law of the Agreement for so long as that governing law is the law of a Member State of the European Union. If the governing law of the Agreement is not the law of an EU Member State, this DPA shall be governed by the laws of Ireland. To the extent that this DPA applies in respect of UK GDPR obligations, it shall additionally be subject to English law and the non-exclusive jurisdiction of the courts of England and Wales in relation to those UK GDPR obligations.
13.4 Any breach of this DPA shall constitute a material breach of the Agreement.
13.5 The liability of each party under this DPA shall be subject to the limitations of liability set out in the Agreement.
ANNEX 1: DETAILS OF PROCESSING OF CONTROLLER PERSONAL DATA
This Annex 1 includes certain details of the Processing of Controller Personal Data as required by Article 28(3) GDPR.
Subject matter and duration of the Processing of Controller Personal Data
Subject Matter: Processing of Controller Personal Data by SkillsTrust in connection with the provision of pay transparency analytics services as described in the Agreement, including the analysis of pay data to identify gender pay gaps and support compliance with the EU Pay Transparency Directive (Directive 2023/970/EU).
Duration: Processing shall continue for the duration of the Agreement and any applicable renewal period. Following termination or expiry of the Agreement, SkillsTrust shall retain Controller Personal Data only for the period necessary to perform its obligations under Clause 10 of this DPA (Erasure or Return), being a maximum of 90 days following termination, unless a longer retention period is required by applicable law.
The nature and purpose of the Processing of Controller Personal Data
The EU Directive on Pay Transparency (EUPTD) requires that employers report gender pay gaps for categories of workers that perform work of equal value. SkillsTrust helps companies define these categories and helps compute pay gaps for each category.
In order to define categories of workers based on the work they do, SkillsTrust requires Jobs Data, i.e., data that describes the work performed by client employees.
In order to subsequently compute pay gaps, SkillsTrust needs individual pay data that is linked to the jobs data in order to assign each employee to a category of workers.
Clients may optionally share names or ID numbers of employees. This data is used by clients to improve the quality of the analysis. For example, when one employee has unusually high/low pay for their category, the link to the individual helps clients diagnose if pay was correctly provided or categories were correctly assigned.
The types of Controller Personal Data to be Processed
SkillsTrust processes three categories of data:
Jobs data: Job titles and descriptions. It is the responsibility of the user/client to ensure that these do not contain personally identifiable information.
Pay data: A breakdown of employee compensation by base, variable, and benefits. This data is pseudonymised (unless client chooses to provide names) but will be treated as sensitive personally identifiable information.
Additional data: Org-charts, compensation frameworks, etc. Typically does not contain PII but is treated as confidential.
The following is a more detailed outline of the data inputs that will be requested for an EU pay transparency readiness project.
Jobs Data:
A list of all job titles in the company
Job descriptions for all of jobs (or as many as you have on file)
Pay Data:
An pseudo-anonymised compensation report for all employees, including for each employee:
Unique anonymous ID number
Job title
Department
Contract type
Hours worked over the reporting period
Gender
Base compensation amount
Bonus participation and amount
Variable compensation amount
Amount of benefits in kind received
(optional) Employee names may be shared to facilitate analysis of anomalies.
Note:
The report should cover a full 12-month period (not necessarily calendar year).
Clients may opt to use the dataset used for Irish Gender Pay Gap reporting.
Pay gap audit may be run using either contractual pay or historic earnings, as agreed during the initial planning call.
Additional Data Inputs: Additional useful data includes org charts, compensation philosophy, leveling guides, salary band definitions or competency frameworks as available. While these data do not typically contain PII, they may contain confidential information and will be treated as such.
The categories of Data Subject to whom the Controller Personal Data relates
Current and former employees of the Controller, including workers and contractors whose pay data is included within the scope of the Controller's gender pay gap reporting obligations, and such other categories of Data Subjects as may be agreed in writing between the parties.
ANNEX 2: LIST OF APPROVED SUB-PROCESSORS
List of Approved Sub-processors as at the DPA Effective Date
Amazon Web Services
Types of processing:
Approved for all processing of confidential information to include Controller Personal Data subject to security policy.
Google Workspace
Types of processing:
Gmail, Sheets, Slides, and Docs are approved for all processing of confidential information to include Controller Personal Data subject to security policy.
Microsoft OneDrive / Microsoft 365
Types of processing:
Microsoft OneDrive is approved for storage and processing of confidential information to include Personal Data, subject to SkillsTrust’s security policy.
Microsoft Word, Excel and PowerPoint are approved for all processing of confidential information to include Controller Personal Data subject to security policy.
Personal Data shall not be processed using artificial intelligence or machine learning services unless such data is anonymised or aggregated such that it no longer constitutes Personal Data. SkillsTrust shall ensure that no Personal Data is used for training or improving any third-party AI models.
Contractors
SkillsTrust engages HR consultants, IT consultants, Rewards consultants and other service providers on a contract basis in connection with the provision of the Services. Each such contractor who has access to Controller Personal Data:
is subject to a written data processing agreement containing terms no less protective than this DPA, or is incorporated within SkillsTrust's internal data processing framework which is subject to equivalent terms;
is subject to confidentiality and non-disclosure obligations; and
is subject to the same data security controls as SkillsTrust employees, including access controls and security training as described in Clauses 4 and 5 of this DPA
Last Updated: 14th April 2026
