Data Processing Agreement
Agreement number: [completed by Skolkoll]
Agreement date: YYYY-MM-DD
1. Parties
1.1 Data Controller
Organisation: [Municipality name]
Organisation number: [XXXXXX-XXXX]
Address: [Postal address]
Contact person: [Name]
Email: [Email]
Data Protection Officer (DPO): [Name / email]
Hereinafter referred to as the "Data Controller".
1.2 Data Processor
Organisation: Skolspegeln AB
Organisation number: 559359-7288
Address: Ejdergatan 6, SE-619 32 Trosa, Sweden
Contact person: Markus Reimer
Email: info@skolspegeln.se
Hereinafter referred to as the "Data Processor".
2. Background and purpose
The Data Controller and the Data Processor have entered into a Skolkoll Municipal Licence agreement, whereby the Data Processor provides a web service that processes personal data on behalf of the Data Controller. This agreement governs the Data Processor's processing of personal data per article 28 of EU regulation 2016/679 (GDPR).
3. Subject of processing
3.1 Categories of personal data
- P1 — customer users: email address, display name, organisation membership, role and login timestamps for persons to whom the Data Controller gives access to the Municipal Licence.
- P2 — customer-directed imports and watches: only the fields, persons, sources and purposes stated in the Data Controller's documented instruction.
- P3 — instruction-bound support and incident material: the contact, case and technical data needed to handle a matter on behalf of the Data Controller.
Skolspegeln's own customer, billing and payment records, including Stripe data, are processed by Skolspegeln as controller and are not covered by this processor instruction. The same applies to public-source data, such as head-teacher names from official registers, where Skolspegeln itself determines the purposes and means.
3.2 Categories of data subjects
- Employees of the Data Controller who have an account in the service.
- Persons appearing in a customer-directed import, watch or support/incident item, but only within the written instruction's scope.
3.3 Purpose and duration of processing
The processing is performed to provide the Skolkoll service under the Municipal Licence agreement and the Data Controller's documented instructions. It continues during the agreement and thereafter only as long as needed for agreed return or verified deletion, unless Union or Swedish law requires the Data Processor to retain specific processor data. Skolspegeln's separate processing of its own customer, billing and payment records is outside this agreement.
3.4 Type of processing
Collection, storage, organisation, structuring, reading, modification, deletion. The Data Processor performs no profiling or automated decision-making with legal effect on data subjects.
4. Obligations of the Data Processor
The Data Processor shall:
- Only process personal data on documented instructions from the Data Controller, including for transfers to a third country. Where Union or Swedish law requires other processing, the Data Processor shall inform the Data Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
- Immediately inform the Data Controller if, in the Data Processor's opinion, an instruction infringes the GDPR or other applicable data-protection law.
- Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Take appropriate technical and organisational security measures per GDPR article 32 (see annex A).
- Only engage other processors (subprocessors) under the conditions in section 5 below.
- Assist the Data Controller in fulfilling the obligation to respond to requests for the exercise of data subjects' rights (GDPR articles 12-22).
- Assist the Data Controller in fulfilling its obligations under GDPR articles 32-36 (security, breach notification, impact assessment).
- At the termination of the Municipal Licence agreement, at the Data Controller's choice, delete or return all personal data and delete existing copies, unless Union or Swedish law requires retention.
- Make available to the Data Controller all information necessary to demonstrate compliance with GDPR article 28, and allow for and contribute to audits, including inspections — see section 8 below.
5. Subprocessors
The Data Controller gives the Data Processor general prior authorisation to engage subprocessors under the following conditions:
- The subprocessor's processing is governed by a written agreement imposing the same data protection obligations as this agreement.
- If the subprocessor fails to fulfil its data-protection obligations, the Data Processor remains fully liable to the Data Controller for the subprocessor's performance.
- The Data Processor notifies the Data Controller of any planned changes (additions or replacements) of subprocessors at least 30 days before the change takes effect, by email to the agreed contact person, DPO and the organisation's administrators.
- The Data Controller has the right to object to changes. Objections are handled per the Municipal Licence agreement's termination clause, and the Data Processor shall not use the new subprocessor for the Data Controller's personal data before the objection has been handled or the termination period has expired.
- The current list of subprocessors is at https://skolkoll.se/en/privacy/data-protection/.
6. International transfer
The repository target configuration places Firestore, Cloud Functions and Cloud Storage in europe-west1 (Belgium), and an archived production readback dated 2026-09-05 establishes Firestore and all eight production buckets in the EU. The application-log surface was moved to europe-west1 the same day; the audit logs remain in global in a locked bucket. Firebase Hosting uses a global CDN. A transfer within the processor engagement may take place only on the Data Controller's documented instruction and with an applicable transfer mechanism. Stripe and providers used only in Skolspegeln's separate controller capacity do not become subprocessors through this template. For transfers to a third country, the following apply:
- The European Commission's Standard Contractual Clauses under Decision (EU) 2021/914, using the correct module and completed annexes, where an adequacy decision does not cover the transfer.
- A documented assessment of the destination country, recipient and supplementary technical, organisational or contractual measures where required.
- An applicable adequacy decision, including the EU–US Data Privacy Framework only where the recipient is certified and the certification scope covers the processing concerned.
7. Personal data breach
The Data Processor shall, without undue delay and as a preliminary notice no later than within 24 hours of becoming aware of a personal data breach, notify the Data Controller. The Data Processor shall then provide ongoing updates as further information becomes available. The notification shall include:
- A description of the nature of the breach, the number of data subjects affected and the categories of personal data concerned.
- Likely consequences of the breach.
- Measures taken or proposed to address the breach and limit its adverse effects.
- Contact details of the Data Processor's incident handler.
8. Right to audit
The Data Controller has the right, at its own cost and with reasonable notice, to audit the Data Processor's compliance with this agreement. The audit may be conducted by the Data Controller or by an independent auditor appointed by the Data Controller and bound by appropriate confidentiality. The Data Processor has no approval veto but may require reasonable security, confidentiality and access rules. The Data Processor shall provide necessary information and allow for and contribute to audits, including inspections, in a manner that limits disruption and protects other customers' data.
Current SOC 2, ISO 27001 or equivalent reports from the Data Processor or relevant subprocessors may be used as supplementary evidence. They do not replace the Data Controller's audit right where the reports do not provide sufficient information for the processing concerned. (Skolkoll does not hold its own ISO 27001 certification as of 2026.)
9. Liability and limitations
The Data Processor's liability under this agreement is limited as set out in the Municipal Licence agreement's liability clause. The provisions of GDPR article 82 are however mandatory and not affected by limitations between the parties.
10. Term
This agreement enters into force on signing and remains in effect for the active lifetime of the Municipal Licence agreement. The Data Processor's obligations regarding deletion or return of personal data (section 4 item 8) survive termination.
11. Assignment
The Data Processor may assign this agreement to another company within the same group, without requiring the Data Controller's further approval, provided that the receiving party assumes the Data Processor's rights and obligations in writing before processing continues, that the security level, subprocessor terms and international transfer safeguards are not weakened, and that the Data Controller is notified in writing at least 30 days before the assignment where practically possible and otherwise in direct connection with the assignment.
This section constitutes the Data Controller's general written authorisation under GDPR article 28(2) for such an intra-group successor processor, subject to the right to object on objective GDPR grounds. If the Data Controller has an objective GDPR objection to the receiving party, the Data Controller may terminate the affected processing or the Municipal Licence agreement on 30 days' notice.
12. Amendments
Amendments to this agreement must be made in writing and signed by both parties.
13. Governing law and dispute resolution
This agreement is governed by Swedish law. Disputes shall be resolved primarily through negotiation; failing that, by the ordinary courts with competent jurisdiction.
Annex A — Technical and organisational security measures
The Data Processor takes the following measures:
- Encryption in transit (TLS 1.2+, HSTS).
- Encryption at rest (Firestore Google-managed keys).
- Access control (role-based access, audit log for admin actions).
- Secrets management (Google Secret Manager).
- Rate limiting and input validation on all public endpoints.
- Error monitoring and alerts on scheduled-function failures.
- Firestore backup target: daily backups with seven-day retention. Production readback showing an active schedule and a tested restore has not yet been archived; the target must therefore not be read as a verified operational promise.
- Detailed disclosure: skolkoll.se/en/privacy/data-protection/ section 8.
Place and date: ___________________________
Signature: _______________________________
Name in print: [Name]
Position and authority: [Signatory rights or delegated decision]
Place and date: ___________________________
Signature: _______________________________
Name in print (Skolspegeln AB): Markus Reimer
Position and authority: Board member (styrelseledamot), authorised to sign for the company
This template is based on SKR's Swedish standard contract for data processors (public sector convention). For adjustments, contact info@skolspegeln.se. The template is a starting point; binding contract text is negotiated before signing.