DPA template (data processing agreement)

Based on SKR's Swedish standard contract. Print this page (Ctrl/Cmd+P) and fill in, or send completed details by email.

Operational details (data protection)

Data Processing Agreement

Agreement number: [completed by Skolkoll]
Agreement date: YYYY-MM-DD

1. Parties

1.1 Data Controller

Organisation: [Municipality name]
Organisation number: [XXXXXX-XXXX]
Address: [Postal address]
Contact person: [Name]
Email: [Email]
Data Protection Officer (DPO): [Name / email]

Hereinafter referred to as the "Data Controller".

1.2 Data Processor

Organisation: Skolspegeln AB
Organisation number: 559359-7288
Address: Ejdergatan 6, SE-619 32 Trosa, Sweden
Contact person: Markus Reimer
Email: info@skolspegeln.se

Hereinafter referred to as the "Data Processor".

2. Background and purpose

The Data Controller and the Data Processor have entered into a Skolkoll Municipal Licence agreement, whereby the Data Processor provides a web service that processes personal data on behalf of the Data Controller. This agreement governs the Data Processor's processing of personal data per article 28 of EU regulation 2016/679 (GDPR).

3. Subject of processing

3.1 Categories of personal data

Skolspegeln's own customer, billing and payment records, including Stripe data, are processed by Skolspegeln as controller and are not covered by this processor instruction. The same applies to public-source data, such as head-teacher names from official registers, where Skolspegeln itself determines the purposes and means.

3.2 Categories of data subjects

3.3 Purpose and duration of processing

The processing is performed to provide the Skolkoll service under the Municipal Licence agreement and the Data Controller's documented instructions. It continues during the agreement and thereafter only as long as needed for agreed return or verified deletion, unless Union or Swedish law requires the Data Processor to retain specific processor data. Skolspegeln's separate processing of its own customer, billing and payment records is outside this agreement.

3.4 Type of processing

Collection, storage, organisation, structuring, reading, modification, deletion. The Data Processor performs no profiling or automated decision-making with legal effect on data subjects.

4. Obligations of the Data Processor

The Data Processor shall:

  1. Only process personal data on documented instructions from the Data Controller, including for transfers to a third country. Where Union or Swedish law requires other processing, the Data Processor shall inform the Data Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
  2. Immediately inform the Data Controller if, in the Data Processor's opinion, an instruction infringes the GDPR or other applicable data-protection law.
  3. Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  4. Take appropriate technical and organisational security measures per GDPR article 32 (see annex A).
  5. Only engage other processors (subprocessors) under the conditions in section 5 below.
  6. Assist the Data Controller in fulfilling the obligation to respond to requests for the exercise of data subjects' rights (GDPR articles 12-22).
  7. Assist the Data Controller in fulfilling its obligations under GDPR articles 32-36 (security, breach notification, impact assessment).
  8. At the termination of the Municipal Licence agreement, at the Data Controller's choice, delete or return all personal data and delete existing copies, unless Union or Swedish law requires retention.
  9. Make available to the Data Controller all information necessary to demonstrate compliance with GDPR article 28, and allow for and contribute to audits, including inspections — see section 8 below.

5. Subprocessors

The Data Controller gives the Data Processor general prior authorisation to engage subprocessors under the following conditions:

  1. The subprocessor's processing is governed by a written agreement imposing the same data protection obligations as this agreement.
  2. If the subprocessor fails to fulfil its data-protection obligations, the Data Processor remains fully liable to the Data Controller for the subprocessor's performance.
  3. The Data Processor notifies the Data Controller of any planned changes (additions or replacements) of subprocessors at least 30 days before the change takes effect, by email to the agreed contact person, DPO and the organisation's administrators.
  4. The Data Controller has the right to object to changes. Objections are handled per the Municipal Licence agreement's termination clause, and the Data Processor shall not use the new subprocessor for the Data Controller's personal data before the objection has been handled or the termination period has expired.
  5. The current list of subprocessors is at https://skolkoll.se/en/privacy/data-protection/.

6. International transfer

The repository target configuration places Firestore, Cloud Functions and Cloud Storage in europe-west1 (Belgium), and an archived production readback dated 2026-09-05 establishes Firestore and all eight production buckets in the EU. The application-log surface was moved to europe-west1 the same day; the audit logs remain in global in a locked bucket. Firebase Hosting uses a global CDN. A transfer within the processor engagement may take place only on the Data Controller's documented instruction and with an applicable transfer mechanism. Stripe and providers used only in Skolspegeln's separate controller capacity do not become subprocessors through this template. For transfers to a third country, the following apply:

7. Personal data breach

The Data Processor shall, without undue delay and as a preliminary notice no later than within 24 hours of becoming aware of a personal data breach, notify the Data Controller. The Data Processor shall then provide ongoing updates as further information becomes available. The notification shall include:

8. Right to audit

The Data Controller has the right, at its own cost and with reasonable notice, to audit the Data Processor's compliance with this agreement. The audit may be conducted by the Data Controller or by an independent auditor appointed by the Data Controller and bound by appropriate confidentiality. The Data Processor has no approval veto but may require reasonable security, confidentiality and access rules. The Data Processor shall provide necessary information and allow for and contribute to audits, including inspections, in a manner that limits disruption and protects other customers' data.

Current SOC 2, ISO 27001 or equivalent reports from the Data Processor or relevant subprocessors may be used as supplementary evidence. They do not replace the Data Controller's audit right where the reports do not provide sufficient information for the processing concerned. (Skolkoll does not hold its own ISO 27001 certification as of 2026.)

9. Liability and limitations

The Data Processor's liability under this agreement is limited as set out in the Municipal Licence agreement's liability clause. The provisions of GDPR article 82 are however mandatory and not affected by limitations between the parties.

10. Term

This agreement enters into force on signing and remains in effect for the active lifetime of the Municipal Licence agreement. The Data Processor's obligations regarding deletion or return of personal data (section 4 item 8) survive termination.

11. Assignment

The Data Processor may assign this agreement to another company within the same group, without requiring the Data Controller's further approval, provided that the receiving party assumes the Data Processor's rights and obligations in writing before processing continues, that the security level, subprocessor terms and international transfer safeguards are not weakened, and that the Data Controller is notified in writing at least 30 days before the assignment where practically possible and otherwise in direct connection with the assignment.

This section constitutes the Data Controller's general written authorisation under GDPR article 28(2) for such an intra-group successor processor, subject to the right to object on objective GDPR grounds. If the Data Controller has an objective GDPR objection to the receiving party, the Data Controller may terminate the affected processing or the Municipal Licence agreement on 30 days' notice.

12. Amendments

Amendments to this agreement must be made in writing and signed by both parties.

13. Governing law and dispute resolution

This agreement is governed by Swedish law. Disputes shall be resolved primarily through negotiation; failing that, by the ordinary courts with competent jurisdiction.

Annex A — Technical and organisational security measures

The Data Processor takes the following measures:

For the Data Controller

Place and date: ___________________________

Signature: _______________________________
Name in print: [Name]
Position and authority: [Signatory rights or delegated decision]
For the Data Processor

Place and date: ___________________________

Signature: _______________________________
Name in print (Skolspegeln AB): Markus Reimer
Position and authority: Board member (styrelseledamot), authorised to sign for the company

This template is based on SKR's Swedish standard contract for data processors (public sector convention). For adjustments, contact info@skolspegeln.se. The template is a starting point; binding contract text is negotiated before signing.