Speech data · Data processing agreement

Executed before the first recording. The DPA, and what it puts on paper.

Roles, processing scope, consent and provenance, sub-processors, retention and audit access, fixed in the agreement before production collection begins. Draft terms come to your legal team during scoping.

Draft for legal review

Data Processing Agreement

Speech data collection and processing

Basis
GDPR Article 28
Processor
Your Personal AI AS, Oslo
Controller
the client, or YPAI as independent controller where agreed
Jurisdiction
Norwegian, EEA processing
  1. Roles and responsibilities
  2. Processing scope and data categories
  3. Consent, provenance and audit trail
  4. Sub-processors
  5. Retention and deletion
  6. Security, access and audit readiness

Executed before production collection begins

Clause · Roles controller · processor

Who is the controller is decided per engagement, and written down.

Role designation between Controller and Processor is determined per engagement based on the nature of the data processing activities and contractual requirements.

Processor engagements
YPAI processes personal data on behalf of the client organization according to documented instructions. The client remains the Controller.
Independent Controller engagements
In certain arrangements, YPAI acts as an Independent Controller for specific processing activities. This is documented in the engagement agreement.

Role definitions and responsibilities are specified in the DPA and reviewed during scoping. Specific obligations are defined contractually.

Clause · Scope five categories · one purpose

What is processed, and for which purposes.

Speech data collection workflows involve processing of audio recordings and associated metadata. The DPA Annex lists the categories and the purposes each one serves.

Data categoryHeld asPurpose
Voice recordings Audio files, per recording Collection, validation, quality assurance, delivery
Transcripts and annotations Text, linked to the recording Validation, quality assurance, delivery
Speaker metadata Anonymized identifiers, demographic categories as defined per project Quota reporting, delivery record
Consent records and provenance Consent id, timestamp, version, scope Lawful basis, audit trail
Technical metadata Sample rate, format, duration Validation, delivery record

Purpose limitation: Data is processed for the purposes of collection, validation, quality assurance, and delivery as defined in the engagement agreement. Specific data categories and processing purposes are documented in the DPA Annex and defined during scoping.

Clause · Sub-processors disclosed · governed · notified

Who else touches the data is in the agreement, with the change procedure.

Sub-processors engaged in data processing activities are disclosed as part of the DPA terms.

Clause · Retention and deletion windows · deletion · return

How long the data lives, and what happens when the engagement ends.

Retention periods and deletion procedures are defined contractually during scoping.

  1. During the engagement

    Retention windows vary by engagement and are specified in the DPA. Enterprise retention policies are supported as defined per project.

  2. Deletion

    Deletion procedures aligned with GDPR requirements, with timelines provided for internal review during scoping.

  3. After the engagement

    Return or deletion, as documented in the DPA. Post-engagement handling is written into the agreement before signature.

Clause · Security and audit access · documentation

Access is limited and documented. The documentation is yours to review.

Internal controls and security measures are implemented to protect data during collection, processing, and delivery.

Access control
Access to data is limited to authorized personnel. Access control policies are documented and available for review.
Audit readiness
Full audit documentation is available for legal and compliance review. Documentation of security practices is provided on request during scoping.

The review asks

Signing, roles and sub-processors

When is the DPA signed?

The DPA is executed before production collection begins. During scoping, we provide draft DPA terms for internal review. The signed agreement is finalized before any data processing activities commence.

Is YPAI a Controller or Processor?

Role designation depends on the engagement model. YPAI may act as Data Processor or Independent Controller depending on the contractual arrangement. Role definitions are specified in the DPA and reviewed during scoping.

Can we review sub-processors before signing?

Sub-processors are disclosed as part of the DPA terms. A list of sub-processors or categories of sub-processors is provided during scoping for internal review.

How is consent demonstrated?

Consent is obtained through our controlled platform and is verifiable. Provenance records are maintained for audit purposes. Details of consent mechanisms are documented in the DPA and available for compliance review.

What audit artifacts can you provide?

Full audit documentation is available for legal and compliance review. This includes provenance records, consent documentation, and processing logs. Specific audit requirements can be addressed during scoping.

What happens if requirements change after pilot?

Requirement changes are handled through contract amendment procedures defined in the engagement agreement. We work with your legal and procurement teams to document changes appropriately.

How do you handle deletion requests?

Deletion and retention terms are defined contractually during scoping. Procedures for handling deletion requests are documented in the DPA and aligned with GDPR requirements.

Do you support regulated environments?

Yes. Our approach is designed for organizations in regulated environments including healthcare, finance, and automotive. Specific regulatory requirements are addressed during technical and compliance scoping.

Can we use our own DPA template?

We are able to review and work with client-provided DPA templates. Template review and negotiation occur during the scoping phase.

How are sub-processor changes communicated?

Sub-processor update procedures are defined in the DPA. Notification mechanisms and approval workflows are agreed upon during contract negotiation.

Bring the requirement. The draft DPA comes back with the scoping brief.

A formal appendix for internal review is part of scoping. Your own DPA template is reviewed in the same step.