Data Processing Agreement
Version dpa-2026-09, effective 15 September 2026. Between AOW Group Ltd trading as Daily DBS and each organisation that accepts it in the Daily DBS portal. Read with the Terms of Service and the privacy notice.
In summary
This agreement sets out how AOW Group Ltd, trading as Daily DBS, processes personal data on behalf of an organisation that uses the Daily DBS service. It is the written contract that Article 28 of the UK GDPR requires between a controller and its processor. It forms part of, and is read with, the Daily DBS Terms of Service.
In plain terms: your organisation decides who is monitored and why, and remains responsible for that decision. Daily DBS checks those people’s DBS certificate status on the DBS Update Service on your instructions, stores the results so you can evidence them, alerts you when a status changes, and does nothing else with the data.
You accept this agreement in the Daily DBS portal by confirming your name and role and ticking the acceptance box. Acceptance is recorded against your organisation with the version accepted, the time, and the account that accepted it, and a copy is emailed to you and to us. No signature is required: a contract in electronic form satisfies Article 28(9).
1. Parties and roles
This agreement is between the organisation that accepts it in the Daily DBS portal (the “Customer”) and AOW Group Ltd, company number 14089346, whose registered office is at 2nd Floor Sterling House, Langston Road, Loughton, Essex IG10 3TS, trading as Daily DBS (“Daily DBS”, “we”, “us”).
For the personal data described in Annex A, the Customer is the controller and Daily DBS is the processor.
Where the Customer is a partner that uses the service to monitor people on behalf of its own customers, the Customer acts as processor for those customers and Daily DBS acts as the Customer’s sub-processor. In that case the Customer warrants that its own contracts with its customers permit the appointment of Daily DBS on these terms, and references in this agreement to the Customer’s instructions include the instructions of the Customer’s own customers as relayed through the Customer.
The Disclosure and Barring Service is not a party to this agreement and is not a sub-processor. When the service queries the DBS Update Service it does so as the Customer’s agent under the Customer’s own authority to check status, and the DBS acts as an independent controller of the query it receives.
2. Definitions
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, and any legislation that replaces or supplements them in the United Kingdom.
“Customer Personal Data” means the personal data described in Annex A that Daily DBS processes on the Customer’s behalf in providing the service.
“Monitored Individual” means a person whose DBS certificate status the Customer asks Daily DBS to check.
“Sub-processor” means a third party engaged by Daily DBS to process Customer Personal Data.
“Service” means the Daily DBS monitoring service and portal described in the Terms of Service.
The terms controller, processor, data subject, personal data, personal data breach and processing have the meanings given in Data Protection Law.
3. Scope and duration
This agreement applies to all processing of Customer Personal Data by Daily DBS and lasts for as long as Daily DBS holds any Customer Personal Data. It continues after the Customer’s account closes until the data has been deleted or returned under clause 11.
The subject matter, nature, purpose and duration of the processing, the types of personal data and the categories of data subject are set out in Annex A.
4. The Customer’s obligations and instructions
The Customer instructs Daily DBS to process Customer Personal Data only for the purposes in Annex A. The Terms of Service, this agreement, and the actions the Customer’s authorised users take in the portal (adding, editing and removing people, assigning roles, exporting records, choosing who receives alerts) together form the Customer’s complete documented instructions. Any further instruction must be in writing and agreed by both parties.
The Customer is responsible for the lawfulness of the processing it instructs. In particular the Customer warrants that, for every Monitored Individual, it holds that person’s authority to check their DBS certificate status, it is entitled under the DBS Update Service conditions and the Police Act 1997 to receive information at the level of the certificate, it has given the person the information required by Articles 13 and 14 of the UK GDPR, and it will withdraw the person from monitoring when that authority ends.
The Customer is responsible for the accuracy of the details it supplies about each Monitored Individual and for keeping them up to date.
Because a status result may reveal that new information has been recorded against a person, the Customer acknowledges that it is processing criminal offence data within Article 10 of the UK GDPR and that it must hold an appropriate policy document under Schedule 1 of the Data Protection Act 2018 for that processing. Daily DBS processes such data only on the Customer’s instructions and under its own appropriate policy document.
The Customer will ensure that only people it has authorised have access to its portal account, will keep their credentials secure, and will remove users promptly when they leave or their role changes.
5. Daily DBS’s obligations
Daily DBS will:
- process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers outside the United Kingdom, unless required to do otherwise by law, in which case Daily DBS will inform the Customer of that legal requirement before processing unless the law prohibits it;
- tell the Customer immediately if, in its opinion, an instruction infringes Data Protection Law;
- ensure that every person it authorises to process Customer Personal Data is bound by a duty of confidentiality and has access only to the extent needed to provide the Service;
- implement and maintain the technical and organisational measures in Annex B, and keep them under review so they remain appropriate to the risk;
- not use Customer Personal Data for its own purposes, sell it, share it, or combine it with data from other customers, except that Daily DBS may derive aggregate, non-identifying statistics about use of the Service;
- assist the Customer in responding to requests from data subjects exercising their rights, by passing on any request received directly and by providing the data and tools needed to respond;
- assist the Customer in meeting its obligations on security, personal data breaches, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to Daily DBS;
- delete or return Customer Personal Data at the end of the Service in accordance with clause 11;
- make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits in accordance with clause 12.
6. Security
Daily DBS will protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, using the measures in Annex B as a minimum. Daily DBS may update those measures from time to time provided the overall level of protection is not reduced.
7. Sub-processors
The Customer gives Daily DBS general written authorisation to engage the Sub-processors listed in Annex C, and to replace them or add others, subject to this clause. The named list in Annex C is provided to the Customer in the copy of this agreement sent on acceptance, is available to the Customer’s admin users on request at any time, and is not published on the Daily DBS website.
Daily DBS will give the Customer at least 30 days’ notice by email to the Customer’s admin users, with the updated Annex C, before a new Sub-processor begins processing Customer Personal Data. If the Customer objects on reasonable data protection grounds within that period and the parties cannot resolve the objection, the Customer may end the Service on written notice without any early termination charge, and Daily DBS will delete or return the Customer Personal Data under clause 11.
Daily DBS will impose on each Sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this agreement, and remains fully liable to the Customer for the performance of each Sub-processor.
8. International transfers
Customer Personal Data is stored and processed in the United Kingdom. Daily DBS will not transfer Customer Personal Data outside the United Kingdom, or permit a Sub-processor to do so, unless the transfer is covered by adequacy regulations under section 17A of the Data Protection Act 2018, by the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner, or by another transfer mechanism valid under Data Protection Law. Where a Sub-processor in Annex C is established outside the United Kingdom, the mechanism relied on is stated there.
9. Data subject requests and assistance
If Daily DBS receives a request from a Monitored Individual or any other data subject relating to Customer Personal Data, it will not respond on the substance except to direct the person to the Customer, and will pass the request to the Customer within three working days.
The portal lets the Customer see, correct, export and delete the data held about each Monitored Individual. Daily DBS will provide any further reasonable assistance the Customer needs to respond to a request within the statutory time limit. Daily DBS may charge a reasonable fee for assistance that goes materially beyond what the portal already provides, and will agree that fee in advance.
10. Personal data breach
Daily DBS will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact for further information, and will be updated as more becomes known. Daily DBS will cooperate with the Customer and take reasonable steps to contain and remedy the breach. Daily DBS will not inform any third party of the breach in a way that identifies the Customer without the Customer’s agreement, except where required by law.
11. Deletion and return
The Customer may export its Customer Personal Data from the portal at any time as a CSV file, including the full history of checks.
When the Customer removes a Monitored Individual, or when the Service ends for any reason, Daily DBS will delete that person’s Customer Personal Data, or all Customer Personal Data as the case may be, within 90 days, and will delete it from backup copies within the backup retention cycle stated in Annex B, unless the law requires Daily DBS to keep it. On request made before deletion, Daily DBS will first return a copy in a commonly used electronic format.
Daily DBS may keep a minimal record that the Customer was a customer, the agreements it accepted, and the invoices issued, for as long as the law and its legitimate interests in defending claims require. That record does not include data about Monitored Individuals.
12. Audit and information
On written request, no more than once in any 12 months unless a personal data breach or a regulator requires otherwise, Daily DBS will provide the Customer with the information reasonably needed to demonstrate its compliance with this agreement, which may include its current security measures, its sub-processor contracts in summary form, and any independent assurance reports it holds for its infrastructure providers.
Where that information is not sufficient to demonstrate compliance, the Customer or an independent auditor bound by confidentiality and appointed by the Customer may audit Daily DBS’s relevant processing on at least 30 days’ written notice, during normal working hours, without unreasonably disrupting the Service, and at the Customer’s cost. Audit of infrastructure operated by a Sub-processor is satisfied by that Sub-processor’s published certifications and assurance reports.
13. Liability
Each party’s liability under this agreement is subject to the limitations and exclusions in the Terms of Service, save that nothing limits either party’s liability to the extent it cannot be limited under Data Protection Law or other applicable law. Each party remains responsible under Article 82 of the UK GDPR for its own compliance.
14. General
If this agreement conflicts with the Terms of Service on a matter of data protection, this agreement prevails. If it conflicts with a transfer mechanism referred to in clause 8, the transfer mechanism prevails to the extent of the conflict.
Daily DBS may update this agreement to reflect changes in Data Protection Law, regulatory guidance or the Service, by publishing a new version on its website with a new version identifier and notifying the Customer’s admin users by email at least 30 days before it takes effect. Changes that materially reduce the Customer’s protection take effect only when the Customer accepts the new version in the portal. The version the Customer accepted continues to apply until then.
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.
Questions about this agreement, and notices under it, go to privacy@dailydbs.co.uk. Notices to the Customer go to the email addresses of its admin users as held in the portal.
Annex A — Details of the processing
Subject matter. Daily monitoring of the status of DBS certificates held by people the Customer engages, using the DBS Update Service status check, and the keeping of records that evidence that monitoring.
Nature of the processing. Storing the details needed to run a status check; submitting those details to the DBS Update Service each day; storing the result returned; comparing it with the previous result; sending alerts and reminders by email; displaying records and history to the Customer’s authorised users; exporting records on request; deleting records on instruction or at the end of the Service.
Purpose. To enable the Customer to know, on the day it happens, when a DBS certificate it relies on is no longer current or has new information recorded against it, so that the Customer can meet its safeguarding and vetting obligations; and to give the Customer an audit trail of the checks made.
Duration. For as long as the Customer keeps each Monitored Individual on its list, and then for the deletion period in clause 11.
Categories of data subject. Employees, workers, volunteers, contractors, trustees, governors and self-employed people engaged by the Customer or by the Customer’s own customers; the Customer’s authorised portal users; where the Customer chooses, the people who receive alert emails.
Types of personal data. For each Monitored Individual: forename and surname as shown on the DBS certificate; date of birth; DBS certificate number; the level of check and workforce and whether it was issued for voluntary work, where the Customer records them; the role the Customer assigns and the Customer’s eligibility determination for that role; the record that the Customer holds the person’s authority to check; the result of each status check (whether the certificate is current, whether new information is recorded, and the certificate issue date), with the date and time of each check and who ran it; an email address if the Customer asks Daily DBS to send Update Service renewal reminders. For the Customer’s users: name, email address, role, sign-in records, and the actions they take in the portal.
Special category and criminal offence data. Daily DBS never receives the content of a DBS certificate. A status result indicating that new information has been recorded is personal data relating to criminal convictions and offences within Article 10 of the UK GDPR and is processed solely on the Customer’s instructions for the purpose above.
Annex B — Technical and organisational security measures
- Hosting. The database and authentication service run in a data centre in London, United Kingdom. The application and its server-side functions run in a London region. Both infrastructure providers hold SOC 2 Type II attestation and ISO 27001 certification.
- Encryption. All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Emails are sent over TLS where the receiving server supports it.
- Isolation between customers. Every record carries the identifier of the organisation it belongs to, and the database itself enforces row-level security so that a user can only read or change records belonging to organisations they are a member of. This isolation is enforced in the database, not in the application, and is covered by automated tests.
- Access control. Users sign in with a verified email address using one-time links or codes; multi-factor authentication is available. Access to records is limited by membership and role within each organisation. Daily DBS staff access to production data is limited to the minimum needed to operate the Service, is individually authenticated, and is logged.
- Least privilege in the application. The browser application has no ability to insert or delete monitored people directly; those actions go through server-side functions that enforce the Customer’s agreements, declarations and person limits regardless of what the interface does.
- Logging and audit trail. Every status check, its result and who ran it, every import, every acceptance of an agreement, and every change to a role determination is recorded with a timestamp. Records of attested role determinations are immutable once made; a change creates a new version.
- Secrets. Credentials for the database, the email service and the DBS Update Service are held as encrypted environment secrets on the hosting platform, are never present in the browser application or in source control, and are rotated if exposure is suspected.
- Backups. The database is backed up automatically by the hosting provider on a daily cycle; backups are encrypted and retained for no more than 30 days, after which deleted data no longer exists in any backup.
- Availability and monitoring. Daily checks run on a schedule and the portal shows when a day’s checks could not be completed. Failed or incomplete runs are alerted to Daily DBS.
- Email. Alert and reminder emails identify the person and the change but never include certificate content. Sending is authenticated with SPF, DKIM and DMARC on the sending domain.
- Development practice. Changes are made through version control with a build step; database changes are made through reviewed migration scripts; security-relevant behaviour (row-level security, immutability of attestations, agreement gates) is covered by automated tests run before deployment.
- Personnel. Everyone with access to Customer Personal Data is bound by written confidentiality obligations and has received data protection training appropriate to their role.
- Breach handling. A written incident procedure covers detection, containment, assessment, notification to customers within the period in clause 10, and notification to the Information Commissioner where required.
Annex C — Sub-processors
Daily DBS uses a small number of sub-processors, each bound by a written data processing agreement that offers at least the protection this agreement does. They fall into these categories:
- A database, authentication and storage provider, hosted in London, United Kingdom (SOC 2 Type II, ISO 27001).
- An application hosting provider running the portal and its server-side functions in a London, United Kingdom region (SOC 2 Type II, ISO 27001).
- A transactional email provider, European Union region, for alerts, reminders, sign-in messages and agreement copies (SOC 2 Type II).
- A UK payment processor, which receives billing contact and payment details only and never data about Monitored Individuals.
- Where a provider’s parent company is established outside the United Kingdom, the transfer mechanism relied on is the UK Addendum to the EU Standard Contractual Clauses incorporated in that provider’s data processing addendum.
The named list, with each provider’s legal entity, data location and transfer mechanism, is given to every customer in the copy of this agreement emailed on acceptance, and is available to a customer’s admin users at any time from privacy@dailydbs.co.uk. It is not published here so that the detail of how the service is built is not.
The Disclosure and Barring Service receives, for each check, the surname, date of birth and certificate number of the Monitored Individual, the Customer’s organisation name and the name of the person running the check, under the DBS Update Service conditions. It is an independent controller of that data and is not a sub-processor of Daily DBS.
Accepting this agreement
An admin of your organisation accepts this agreement in the portal the first time people are added, by confirming their name and role and ticking the acceptance box. We record the version, the time, the account used and the network address it came from, and email a PDF of the accepted version, including the named sub-processor list, to the person who accepted it and to us. You can ask for another copy at any time from privacy@dailydbs.co.uk.
If your organisation needs this agreement on its own paper, or needs a signed copy for its records, send it to the same address and we will arrange it.