Joint Controller Data Protection Addendum
THIS JOINT CONTROLLER DATA PROTECTION ADDENDUM supplements contracts between GroupNexus and its Clients for the provision of parking services and should be read in conjunction with the Master Services Agreement, also known as the GroupNexus Car Park Management Agreement, and the GroupNexus privacy policy.
Under the Master Services Agreements joint controller arrangements, processing of ANPR Data will be limited to the following purposes (the “Permitted Purposes”) and that data may be shared with third parties for processing which is limited to the Permitted Purposes.
(a) Car Park Management – to facilitate payment and validation of vehicles authorised to be parked or otherwise on or at a Site and enforcement for vehicles not authorised to be parked or otherwise on or at a Site;
(b) Prevention and Detection of Crime – which may involve sharing vehicle data with the police or other organisations; and
(c) Analysis of traffic flow, vehicle type, and footfall at the Sites to carry out demographic, geographic catchment and repeat visitor analysis.
(d) We may also share vehicle movement data with an organisation involved in traffic and vehicle analytics for the purposes of providing targeted advertising, but only where clients participate in that programme. Vehicle data will only be processed in this way if clients participate in that programme and data subjects using the car park of a participating client have not opted out of the use of their data for this purpose.
The Permitted Purposes may be reviewed from time to time by mutual agreement.
This addendum applies where GroupNexus and the Client:
A. Act as Joint Controllers for the purposes of the UK GDPR, therefore the processing of personal data by the Parties as such Joint Controllers requires that a transparent manner of determining their respective responsibilities be established as regards their compliance with their obligations as Joint Controllers under the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), and other generally applicable laws as well as relations between the Parties and the data subjects; and
B. On concluding this Agreement, the Parties seek to regulate the terms of processing of personal data in such a way that they meet the provisions of the UK GDPR,
the Parties enter into the following Agreement:
1. Definitions
For the purposes of this Agreement, the Parties agree that the following terms shall have the following meaning:
-
1.1 “Controller/Joint Controller” means any natural or legal person, public authority, agency or other body which, alone or (as appropriate) jointly with others, determines the purposes and means of the processing of personal data;
-
1.2 “Personal Data” or “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”);
-
1.3 “Third Country” means a country or territory outside the United Kingdom;
-
1.4 “Processor” means any natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller/Joint Controller;
-
1.5 “Data Protection Law” means the UK GDPR as well as other provisions of national law applicable to a relevant Party, passed in relation to personal data protection, including in particular the provisions of the given Controller’s/Joint Controller’s national law;
-
1.6 “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
-
1.7 “UK General Data Protection Regulation”, “UK GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act of 2018; wherever this Agreement refers to specific Articles of UK GDPR, it shall also apply to the corresponding provisions in national legislation guaranteeing a similar level of safety;
-
1.8 “Information System” means a group of cooperating devices, programs, information processing procedures and program tools used for the purpose of data processing;
-
1.9 “Cooperation” means the cooperation between the Parties described in Recitals A and B;
-
1.10 “Agreement” means this Joint Controller Data Protection Addendum, including the Appendices;
-
1.11 “Master Services Agreement” (MSA) means the commercial agreement referred to in Recital A, also referred to as the GroupNexus Car Park Management Agreement.
2. Subject-matter of the Agreement
2.1 This Agreement regulates mutual relations between the Parties as regards the joint control of Personal Data, and in particular it determines in a transparent manner the Parties’ responsibilities for compliance with the obligations under the GDPR; it also defines the representation of the Parties in contacts with the data subjects and their relations with those data subjects.
2.2 For the purpose of proper implementation of this Agreement, the Parties shall:
-
a. cooperate on performing the obligations of the Joint Controllers of Personal Data;
-
b. process the Personal Data with which they have been entrusted with regard to the Cooperation pursuant to this Agreement, UK GDPR, the MSA and other generally applicable laws; and
-
c. refrain from any legal or factual actions which might in any way undermine the security of Personal Data or might threaten the other Party with civil, administrative or criminal liability.
2.3 Categories of data subjects and personal data, the purposes and means of processing, including the participation of the Parties as Joint Controllers in those processes, as well as the categories of recipients of the Personal Data shall be defined in Appendix 1 to the Agreement.
3. Joint Controllers’ rights and obligations
3.1 The Parties declare that they have the means enabling them to process and protect Personal Data they are processing, including information systems meeting the requirements of the appropriate level of security, as stipulated by the UK GDPR. They will each fully adhere to the applicable Data Protection Law(s) with respect to obligations and responsibilities of Controllers.
3.2 In particular, the Parties shall:
-
a. exercise due diligence in processing Personal Data and process Personal Data pursuant to the Agreement, the UK GDPR and other provisions of Data Protection Law(s), including the appropriate provisions of each Party’s national law;
-
b. restrict access to Personal Data only to persons who need the access to Personal Data for the purposes of the Agreement and Cooperation, provide those persons with relevant authorisations, offer relevant training on personal data protection and ensure confidentiality of Personal Data processed thereby, both during and after their employment or other cooperation with a Party;
-
c. assist the other Party, where possible, in meeting its (i) obligation to respond to requests from data subjects and (ii) obligations laid down in Articles 32 through 36 of the UK GDPR.
3.3 Each Party shall provide the other with the necessary assistance in carrying out the obligations referred to in section 3.2(c) above, in particular in the notification of a personal data breach, by:
-
a. providing, at the request of the other Party, information concerning the processing of personal data immediately upon receipt of such request as soon as possible;
-
b. notifying the other Party of any breach as soon as possible but not later than 48 hours of its discovery. The notification should include all the information referred to in Article 33.3 of the UK GDPR. If—and to the extent that—the information cannot be provided at the same time, they can be given successively without undue delay;
-
c. providing to the other Party all information necessary for the communication of a personal data breach to the data subject;
-
d. informing the other Party of inquiries, requests or demands from data subjects and other individuals, national or European Union public administrations, including relevant data protection authorities and courts, as well as any controls or inspections by such authorities in connection with the joint controllership of Personal Data; information shall be provided promptly and in such a way as to enable the other Party to comply with the obligations set out in sections 2 and 3, without undue delay but not later than 7 calendar days after receipt of an inquiry, request or demand or after the start of a control or inspection.
4. Data subjects’ rights
4.1 The Parties shall inform, in any way they deem appropriate, the data subjects of the essence of this Agreement and shall provide them the information referred to in Appendices 1 and 2 in accordance with Article 26 of the UK GDPR.
4.2 The information referred to in section 4.1 shall be primarily provided to the data subjects by the Party which collects the personal data.
4.3 Data subjects may contact either of the Parties about the rights granted to them by Articles 15 – 22 of the GDPR. The contacted Party shall identify the Party which is the responsible Joint Controller and forward the request internally to this Party. The originally contacted Party shall carry out all necessary communication with the data subject.
4.4 The responsible Joint Controller shall be determined as follows: If the data of the data subject is part of a set of data which can be attributed to a Party, this Party shall be the responsible Joint Controller. In all other cases the Party contacted by the data subject shall be the responsible Joint Controller.
4.5 The Parties undertake to comply with the data subjects’ rights and shall assist one another with the execution of data subjects’ requests.
5. Transfers of Personal Data to third countries
A Party and/or its Processor(s) that transfer(s) personal data in the scope of the execution of the Agreement to the other Party and/or its Processor and/or other entity situated in the third country that does not present adequate safeguards under the UK GDPR shall ensure that such transfer is possible and that it complies with the UK GDPR (e.g. pursuant to Article 45 of the UK GDPR on the basis of an adequacy decision; or Article 46.2(d) on the basis of standard data protection clauses adopted by the UK Information Commissioner) or pursuant to Article 49 of the UK GDPR. A copy of standard data protection clauses referred to in the preceding sentence shall be provided when so requested by a data subject.
6. Entrusting Processors with processing of Personal Data
6.1 The Parties jointly consent to each of them entrusting Processors with processing of Personal Data subject to this Agreement on terms and to the degree defined by this Agreement and Article 28 of the UK GDPR.
6.2 Each Party may entrust Processors with processing of Personal Data under this Agreement only for the purposes of this Agreement, the Master Services Agreement and the Cooperation.
6.3 Processors can only carry out specific Personal Data processing activities on behalf of a Party once the Party has entered into a contract with such a Processor laying down the obligations of the latter related to Personal Data protection in a manner ensuring sufficient guarantees of technical and organisational measures for the processing to meet the requirements of the UK GDPR.
6.4 A Processor may carry out specific Personal Data processing activities on behalf of a Party without entering into the contract referred to in section 6.3 as long as it is possible pursuant to another legal instrument under Data Protection Law or other national law, which binds the Processor and the Controller.
6.5 This Paragraph 6 shall apply in the case of any intended modifications regarding adding Processors or replacing Processors with other Processors.
6.6 Categories of Processors are listed in Appendix 1. Each Party shall provide detailed information on its Processors on request to the data subject.
7. Controllers’ liability
The liability of the Parties is governed by the Data Protection Law, in particular Article 82 of the UK GDPR with regard to the Processing activities that they are in charge of as defined in regard to each Joint Controller’s role in the collaboration and as stated in paragraph 8 below and Appendix 1.
8. Collaboration of the Parties
8.1 The Parties shall collaborate in supervising the implementation of this Agreement.
8.2 The Parties agree that at the time of the implementation of the Agreement they shall collaborate closely, informing one another of any circumstances that have or may have effect on Processing of Personal Data. Each Party shall designate a contact point to coordinate the collaboration of the Parties in connection with the implementation of the Agreement, disclosing their names and contact details in point 1 of Appendix 2.
9. Term and termination of the Agreement
The Agreement will take effect as of the Effective Date. The Agreement shall be concluded for the period of implementation of the Cooperation and as long as and until, after the termination of the Cooperation, obligations still have to be fulfilled.
10. Final provisions
10.1 The Parties hereby agree that they shall process Personal Data pursuant to this Agreement free of charge (except for any fees for services agreed in the MSA), and neither the conclusion of this Agreement nor the processing of data pursuant thereto shall entitle any Party to seek, on whatever legal basis:
-
a. remuneration,
-
b. reimbursement of any costs or expenses incurred for the purpose of due performance of the Agreement,
-
c. exemption from any obligations contracted to that end or advances on such costs or expenses,
additional to that specified in the MSA, even if at the time of entering into Cooperation or concluding this Agreement, despite exercising due care, the Party was unable to foresee the circumstances justifying such rises, costs, expenses or obligations.
10.2 Should any provision hereof become invalid or ineffective, the Parties shall adopt all measures possible to replace it with a valid and effective provision reflecting the goal and meaning of the invalid or ineffective provision to the extent of applicable law. Should any provision hereof be or become invalid or ineffective at any time, it shall not restrict the validity or effectiveness of the remaining provisions of the Agreement. In the event of any discrepancies between the provisions of the Agreement and the terms of Cooperation agreed by the Parties, the provisions of this Agreement shall prevail.
10.3 Any amendments hereto must be in writing on sanction of invalidity.
10.4 This Agreement shall be governed by the same laws and the Parties shall be subject to the jurisdiction of the same courts as those specified in the Master Services Agreement.
Name: Elli Morris
Appointment: CEO
Date: 01.05.26
Version: 1.2

