
Operator and Data Processing Agreement
Last revision: 17 June 2026
This Operator and Data Processing Agreement ("DPA") forms part of the agreement between the client ("Client", "you") and La Bonne Vie Consulting (Pty) Ltd, a private company incorporated in South Africa under registration number 2006/004816/07, with its business address at 80 Strand St, Cape Town City Centre, Cape Town, 8000 ("LBVC", "we", "us"), for the provision of services (the "Agreement"). It sets out the terms on which LBVC processes personal information on the Client's behalf as an operator.
This DPA serves two regimes at once. It records LBVC's obligations as an operator under section 21 of South Africa's Protection of Personal Information Act, 2013 ("POPIA"), and, where the Client or the data subjects are in the European Union or United Kingdom, it records LBVC's obligations as a processor under Article 28 of the EU General Data Protection Regulation and the UK GDPR, together with the safeguards for international transfers.
Where this DPA conflicts with the rest of the Agreement on a question of data protection, this DPA prevails; on all other questions, the Agreement prevails.
1) Definitions
Terms used here have the meaning given in the applicable data protection law. In particular:
"Applicable Data Protection Law" means every law on the protection of personal information that applies to the processing under this DPA, including POPIA; the EU General Data Protection Regulation (Regulation 2016/679, "EU GDPR"); the UK GDPR and the Data Protection Act 2018 ("UK GDPR"); and any other such law that applies to a given engagement.
"Client Personal Information" means personal information that LBVC processes on the Client's behalf under the Agreement.
"Responsible Party", "Operator", "Data Subject", "Personal Information", "Processing", "Special Personal Information" and "Personal Information Breach" have the meanings given in POPIA. Where the EU GDPR or UK GDPR governs, "Responsible Party" includes "controller", "Operator" includes "processor", "Personal Information" includes "personal data", "Special Personal Information" includes "special category data", and "Personal Information Breach" includes "personal data breach".
"Standard Contractual Clauses" or "SCCs" means the clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
"Sub-operator" means any third party LBVC engages to process Client Personal Information. The term includes a "sub-processor" for the purposes of the EU GDPR and UK GDPR
2) Roles and parties
For Client Personal Information, the Client is the Responsible Party and LBVC is the Operator. The Client may itself be an operator acting for another responsible party; in that case the Client warrants that it has the authority to give the instructions in this DPA, and LBVC acts as a sub-operator on the same terms.
Each party complies with its own obligations under Applicable Data Protection Law. The Client is responsible for the lawfulness of the Client Personal Information it provides and for having a valid basis for the processing it instructs, including for obtaining any consent and giving any notice that data subjects are due. Where an engagement involves assessments, the Client is responsible for the matters that fall to it under LBVC's published consent arrangements, and LBVC is responsible for the engagement-specific informed consent it obtains from participants. LBVC is responsible for processing Client Personal Information only as this DPA and the Client's documented instructions allow
3) Scope and instructions
LBVC processes Client Personal Information only with the knowledge or authorisation of the Client and only on the Client's documented instructions, as section 21 of POPIA and Article 28 of the EU GDPR require, unless a law to which LBVC is subject requires otherwise; in that case LBVC informs the Client of the requirement before processing, unless that law prohibits it. The Agreement, this DPA, and the Client's use of LBVC's services to define the engagement are the Client's complete and final instructions. Additional instructions must be agreed in writing and may carry a charge if they call for work outside the agreed engagement.
The subject matter, duration, nature and purpose of the processing, the types of Client Personal Information, and the categories of Data Subjects are set out in Annexure I. LBVC tells the Client if, in its opinion, an instruction infringes Applicable Data Protection Law, and is not obliged to carry out an instruction it reasonably considers unlawful.
4) Confidentiality
LBVC treats all Client Personal Information that comes to its knowledge as confidential and does not disclose it, as section 21(2) of POPIA requires, unless required by law or in the course of the proper performance of the engagement. LBVC ensures that the people authorised to process Client Personal Information are bound by confidentiality, whether by contract or by a statutory or professional duty, and that they process the information only as instructed. For assessment engagements, access to identifiable results is limited to the registered professionals working on that engagement. Access generally is limited to those who need it to provide the services
5) Security
LBVC secures the integrity and confidentiality of Client Personal Information by taking appropriate, reasonable technical and organisational measures, as section 19 of POPIA and Article 32 of the EU GDPR require, to prevent its loss, damage or unauthorised destruction and unlawful access or processing. In doing so LBVC has regard to generally accepted information security practices and to the risk to data subjects. The measures in place at the date of this DPA are described in Annexure II. LBVC may update them as its services evolve, provided the level of protection is not reduced.
Where an engagement uses configured third-party artificial-intelligence tools to analyse data, the data passed to those tools is confined to what the analysis requires, within defined rules and rubrics, and identifying details are limited accordingly, as described in Annexure II and in LBVC's data policy.
6) Sub-operators
The Client gives LBVC general authorisation to engage Sub-operators to process Client Personal Information. LBVC maintains a current list of Sub-operators and makes it available to the Client. The list at the date of this DPA is in Annexure III.
Before adding or replacing a Sub-operator, LBVC gives the Client at least thirty days' notice, by updating the list and notifying the Client through the means the Client has registered for notices. Within that period the Client may object on reasonable data-protection grounds. The parties will then discuss the objection in good faith. If they cannot resolve it, the Client may, as its sole remedy, suspend or terminate the part of the services that requires the Sub-operator, without penalty for that termination.
LBVC imposes on each Sub-operator, by written contract, data-protection obligations no less protective than those in this DPA, and remains liable to the Client for a Sub-operator's performance of those obligations.
7) Assisting the Client
Taking into account the nature of the processing and the information available to it, LBVC assists the Client by:
-
Helping the Client respond to requests from data subjects who seek to exercise their rights, including by providing the relevant information or the means to act on the request. Where a data subject contacts LBVC directly about Client Personal Information, LBVC refers the request to the Client rather than answering it itself, unless the law requires otherwise.
-
Helping the Client meet its own obligations on security, breach notification, and any impact assessment or prior consultation with a regulator, to the extent those obligations relate to LBVC's processing and the Client cannot reasonably meet them without LBVC's help.
LBVC may charge a reasonable fee for assistance that goes beyond what the engagement includes or what the law requires of an operator, and will tell the Client before any such charge is incurred.
8) Personal information breach
If LBVC has reasonable grounds to believe that Client Personal Information has been accessed or acquired by an unauthorised person, or otherwise compromised, it notifies the Client without undue delay, and in any event within seventy-two hours after confirming that the breach has occurred, as the duty in section 22 of POPIA and Article 33 of the EU GDPR is given effect between operator and responsible party. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where LBVC cannot provide all of this at once, it may give the information in phases without undue further delay.
Notification to the Information Regulator, to an EU or UK supervisory authority, or to affected data subjects is the Responsible Party's duty, and LBVC does not make such notifications on the Client's behalf unless the Client instructs it to. The fact of a notice under this section is not an admission of fault.
9) Audits and information
LBVC makes available to the Client the information necessary to demonstrate compliance with this DPA and with its operator obligations under Applicable Data Protection Law. It satisfies this primarily by providing, on the Client's written request and no more than once a year, its then-current documentation: a description of its security measures, its Sub-operator list, and any audit reports, certifications or summaries it or its Sub-operators hold.
A more detailed audit is available only where this documentation does not reasonably resolve a specific, substantiated compliance concern, or where a regulator with jurisdiction requires it. Any such audit is conducted remotely; is carried out on at least thirty days' written notice; takes place no more than once in any twelve-month period, except where a regulator requires otherwise or a Personal Information Breach has occurred; is limited to information and systems within LBVC's control and may not extend to the internal environments of Sub-operators, for which LBVC's pass-through of the Sub-operator's own audit materials is the agreed means of assurance; is restricted to what is relevant to the processing under this DPA; respects the confidentiality and security of LBVC's other clients; and is at the Client's cost. LBVC operates substantially as a remote organisation, and audits are therefore document-based rather than conducted on site.
10) International transfers
LBVC may transfer Client Personal Information to, and process it in, countries other than the country of origin in order to provide the services, including by using the cloud and analysis providers listed in Annexure III.
Where Client Personal Information is transferred out of South Africa, LBVC relies on the conditions for lawful transfer in section 72 of POPIA: the recipient is subject to a law, binding corporate rules or binding agreement that upholds principles for the lawful processing of personal information that are substantially similar to those in POPIA, or the data subject has consented, or the transfer is necessary for the performance of the contract with or in the interest of the data subject, together with the protections in this DPA.
Where Client Personal Information protected by the EU GDPR or UK GDPR is transferred to a country that the European Commission or the United Kingdom has not found to provide an adequate level of protection, including South Africa, the transfer is made under the appropriate safeguard set out in this section. The parties agree that the Standard Contractual Clauses are incorporated into this DPA by reference and apply to such transfers from the European Economic Area, and that the UK Addendum is incorporated by reference and applies to such transfers from the United Kingdom. The following selections apply:
-
Module Two (Controller to Processor) applies, the Client being the data exporter and LBVC the data importer.
-
In Clause 7 (the docking clause), the option is included.
-
In Clause 9, Option 2 (general written authorisation) applies, with the notice period set at thirty days as provided in section 6 of this DPA.
-
In Clause 11, the optional redress wording is not included.
-
In Clause 17, the SCCs are governed by the law of the Republic of Ireland; in Clause 18, disputes under the SCCs are resolved by the courts of Ireland. For the UK Addendum, the governing law and forum are those of England and Wales.
-
Annexures I, II and III to this DPA populate the corresponding annexes of the SCCs, and the information in Tables 1 to 3 of the UK Addendum is taken from them; in Table 4 either party may end the Addendum as the ICO's published version allows.
The official texts of the SCCs and the UK Addendum are adopted as published by the European Commission and the UK Information Commissioner. If a transfer mechanism is invalidated or replaced, the parties will, without undue delay, put in place a valid replacement.
11) Deletion and return
At the Client's choice, LBVC deletes or returns all Client Personal Information after the end of the provision of the services, and deletes existing copies, unless a law to which LBVC is subject, or a professional record-keeping rule, requires the information to be kept. LBVC completes this within ninety days after the services end, save that:
-
where the engagement involves psychometric or other assessment data, identifiable assessment data is dealt with on the basis set out in LBVC's data policy, namely anonymised or deleted within twelve months of the final report or feedback, unless the record-keeping rules applicable to practitioners registered with the Health Professions Council of South Africa require a longer period, in which case it is kept for at least six years after the record becomes dormant and, in the case of a minor, until the person turns twenty-one, after which it is securely destroyed; and
-
copies held in routine backups are deleted on the normal backup cycle rather than individually, and remain protected by this DPA until they are.
De-identified or aggregated information that can no longer identify a data subject is not Client Personal Information and is not subject to this section.
12) Liability
Each party's liability arising out of or related to this DPA, whether in contract, delict or on any other basis, is subject to the limitations and exclusions of liability set out in the Agreement, and any aggregate cap in the Agreement applies to that party's combined liability under the Agreement and this DPA together; this DPA does not create a separate or additional cap. Without limiting the Agreement, the maximum liability of LBVC for claims arising out of the services is limited to an amount equal to the fees received in connection with the service in respect of which the claim arises, and LBVC is not liable for any punitive damages, or for any consequential or other loss or damage beyond that maximum, to the extent the exclusion is permissible in law. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law.
13) Governing law and jurisdiction
This DPA is governed by the law of the Republic of South Africa, and the parties submit to the exclusive jurisdiction of the courts of South Africa, to the extent that choice of law and jurisdiction is permissible. Where an international client engages LBVC, any dispute arising out of or in connection with this DPA is likewise settled in and under South African law before the courts of South Africa, save where a provision of Applicable Data Protection Law, or the Standard Contractual Clauses or UK Addendum, requires a different governing law or forum for a particular matter; in that case the required law or forum applies to that matter only, and South African law and jurisdiction continue to apply to the remainder.
14) Term, and general
This DPA takes effect when the Agreement does and continues for as long as LBVC processes Client Personal Information, after which the deletion and return obligations in section 11 apply. If a provision of this DPA is held invalid, the rest continues in effect. This DPA may be updated where Applicable Data Protection Law changes or a transfer mechanism requires it; LBVC will give the Client notice of a material change. LBVC's Information Officer, and its EU representative for clients and data subjects in the European Union, are identified in LBVC's data policy and are the contacts for matters arising under this DPA.
Annexure I: Description of the processing
Parties: The data exporter is the Client identified in the Agreement, acting as Responsible Party. The data importer is LBVC, acting as Operator.
Subject matter: Processing of Client Personal Information so that LBVC can provide the agreed consulting, advisory or assessment services to the Client.
Duration: For the term of the Agreement, followed by deletion or return under section 11.
Nature and purpose: Collection, recording, organisation, storage, analysis (including, where agreed, by configured third-party AI tools within defined rules and rubrics), aggregation, de-identification and, at the end, deletion or return, for the purpose of delivering the engagement the Client has commissioned.
Categories of Data Subjects: The Client's employees, candidates, and other individuals whose information the Client provides or who take part in the engagement. Where the engagement is of a kind that involves minors, the additional protections in LBVC's data policy apply, including consent from both a parent or guardian and the minor.
Categories of Client Personal Information: Contact and professional details; survey, interview and assessment responses; and, where the engagement requires it, biographic particulars and psychometric results. Where the engagement involves Special Personal Information, the Client is responsible for the lawful basis and LBVC processes it only on instruction and under heightened safeguards.
Frequency: For the duration of the engagement.
Retention: As set out in section 11 of this DPA and LBVC's data policy.
Competent supervisory authority: For transfers under the SCCs, the supervisory authority of the EU member state determined in accordance with Clause 13 of the SCCs.
Annexure II: Technical and organisational measures
LBVC maintains measures that include:
-
Use of reputable cloud providers (principally Microsoft and Google) that maintain recognised security standards, with encryption of Client Personal Information in transit and, where supported, at rest.
-
Where configured third-party AI tools are used for analysis, confinement of the data passed to those tools to what the analysis requires, within defined rules and rubrics, with identifying details limited accordingly.
-
Role-based access control, so that personnel can access only the Client Personal Information they need for their role; for assessment engagements, access to identifiable results is limited to the registered professionals working on the engagement.
-
Strong authentication for access to systems holding Client Personal Information, including multi-factor authentication wherever possible.
-
Confidentiality obligations on all personnel, by contract and, for registered professionals, by professional duty.
-
Encryption and password protection of devices, secure handling of any physical records, and a substantially remote operating model in which physical-environment risk is addressed through device security rather than office controls.
-
Logging and monitoring for security purposes, periodic review of foreseeable risks and safeguards, and an incident-response process aligned with the breach obligations in section 8.
-
Secure deletion or irreversible anonymisation of Client Personal Information at the end of the applicable retention period, including the overwriting of backups on their normal cycle.
Annexure III: Sub-operators
The current list of Sub-operators is maintained separately and available to the Client here. At the date of this DPA it includes the cloud and productivity providers (Microsoft and Google), the website host (Wix), the invoicing provider (Zoho), and the AI model providers (Anthropic and Google), each engaged under a written contract with data-protection terms and, where relevant, a commitment not to use the data LBVC sends to train their models.