The Article 28 GDPR terms under which WEETRA processes personal and industrial data for clients.
Last updated: 22 July 2026
This Data Processing Agreement (DPA) fulfils the requirements of Article 28 of the GDPR and outlines the terms under which WEETRA processes personal and industrial data for Clients.
The Client acts as the Data Controller, determining the purposes and means of processing. WEETRA ORGANIZATION acts as the Data Processor, operating strictly on documented instructions from the Controller.
Processing involves ingestion, algorithmic structural assessment, and secure storage of industrial evidentiary files solely to generate independent regulatory Determinations.
WEETRA applies robust TOMs, including TLS 1.3 encryption in transit, AES-256 at rest, strict Role-Based Access Controls (RBAC), and continuous monitoring of processing systems.
WEETRA will promptly assist the Controller in fulfilling obligations to respond to data subject requests regarding access, rectification, erasure, and portability.
The Controller provides general authorization for WEETRA to engage infrastructure sub-processors (e.g., secure EU-based cloud hosting), provided they are bound by equivalent data protection obligations.
In the event of a security breach affecting personal data, WEETRA will notify the Controller without undue delay (within 48 hours of awareness) and assist in regulatory reporting.
WEETRA will make available all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Controller or a mandated auditor, subject to confidentiality constraints.
Upon termination of the Mandate, WEETRA will securely delete or return all personal data at the Controller’s choice, unless EU or Member State law mandates further retention.
For processing instructions or privacy inquiries, contact the Data Protection Officer at privacy@new-old.weetra.org.