SECURITY // LEVEL 4

Data Processing Addendum (DPA)

This Data Processing Addendum (DPA) sets out the terms governing the processing of personal data by Consent Shield as a Processor on behalf of our Clients.

Last Updated: August 7, 2026
Version: v2.0.4-RELEASE
Verification Hash: SHA-256//D1A7B4
GDPR Compliance: ARTICLE 28 COMPLIANT
[SEC_01]

1. Scope, Interpretation & Role Definitions

Within this Addendum, Client is identified as the "Data Controller" and Consent Shield is identified as the "Data Processor". Both parties agree to execute their respective duties in full compliance with the European Union General Data Protection Regulation (GDPR) and other globally active localized privacy frameworks.

Key Scope Parameters
  • Categories of Data: Browser telemetry, anonymized IP locations, consent choice indicators.
  • Target Subjects: Visitors browsing Client's active web properties.
  • Duration of Processing: Limited to active subscription services.
[SEC_02]

2. Processor Obligations & Telemetry Isolation

Consent Shield guarantees that it processes Personal Data solely on documented instructions from the Client, including with regard to transfers of Personal Data to third-country enclaves. All personnel handling processor operations are bound by strict NDA constraints.

[SEC_03]

3. Authorized Sub-Processors & Enclave Nodes

Client grants Consent Shield general authorization to engage sub-processors to maintain decentralized proxy hosting, database logs encryption, and analytics monitoring. A full, up-to-date registry of sub-processor nodes is available upon request.

Notification of Changes

Consent Shield commits to notifying the Client at least 30 days prior to onboarding any new infrastructural sub-processor, giving the Client a window to assert compliant objections.

Equivalency Guarantee

All active sub-processors are contractually bound to data protection requirements equivalent to those outlined in this Addendum.

[SEC_04]

4. Data Subject Rights & Autonomous Support

Consent Shield, taking into account the nature of the processing, will assist Client using appropriate technical and organizational measures to fulfill Client's obligation to respond to requests from Data Subjects seeking to exercise their rights under GDPR Chapter III.

[SEC_05]

5. Security Audits & Compliance Verification

Consent Shield will make available to the Client all information necessary to demonstrate compliance with Processor obligations under GDPR Article 28, and allow for and contribute to audits, including inspections, conducted by the Client or another auditor mandated by the Client.