Data Processing Agreement
Version 1.0 · Effective 01 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer (the operator, "Controller") and Fleeta Limited trading as OperatorCompliance ("Processor") and applies to personal data processed by the Processor on the Controller's behalf under UK GDPR and the Data Protection Act 2018.
1. Subject matter, duration, nature and purpose
Processing of vehicle, driver and tachograph data to provide compliance monitoring, licence-check recording, tachograph analysis, electronic signature of reports, alerts and reporting, for the term of the Customer's subscription and the 90-day export period after it.
2. Categories of data subjects and data
Drivers, transport managers and other staff of the Controller. Identification and contact data; driving-licence data (number, status, entitlements, endorsements/points, photocard expiry, images); Driver CPC data; tachograph card data and activity records; infringement reports and e-signature metadata; user account and audit data.
3. Processor obligations
The Processor shall: (a) process personal data only on the Controller's documented instructions, which include these Terms and the Controller's use of the Service; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement appropriate technical and organisational measures (encryption in transit and at rest, field-level encryption of licence numbers, role-based access, two-factor authentication, audit logging, daily backups, UK hosting, access reviews); (d) assist the Controller with data-subject requests and with Articles 32–36 obligations; (e) delete or return personal data at the end of the service, except where law requires retention (signed DVLA mandates - 7 years; invoices); (f) make available information necessary to demonstrate compliance and allow audits on reasonable notice, no more than annually unless required by a supervisory authority; (g) notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Controller data.
4. Sub-processors
The Controller gives general authorisation to the sub-processors listed at operatorcompliance.co.uk/legal/subprocessors. The Processor will give at least 14 days' notice of additions by email, during which the Controller may object on reasonable grounds; if unresolved, the Controller may terminate the affected service. The Processor remains liable for its sub-processors.
5. International transfers
Data is stored in the United Kingdom. Transfers to sub-processors outside the UK occur only under the UK International Data Transfer Addendum, adequacy regulations or another lawful mechanism.
6. Controller obligations
The Controller warrants it has a lawful basis for the data it provides, has issued appropriate privacy information to drivers (it may use our Driver Privacy Notice), and has obtained each driver's signed consent and mandate through the Service before requesting any DVLA licence enquiry for that driver.
7. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except that nothing limits liability for breaches of data-protection law that cannot be limited.
8. Precedence
In case of conflict between this DPA and the Terms regarding personal data, this DPA prevails.