Mon – Fri: 9am – 5pm · UK-Wide Support

    Data Processing Agreement

    Last updated: August 2026

    Note: This Data Processing Agreement template outlines the general terms under which CM Debt Recovery processes personal data on behalf of clients. Specific terms may be agreed individually for each engagement.

    Parties

    • Data Controller: [Client Name] (the "Controller")
    • Data Processor: CM Debt Recovery, represented by Craig Martindale (the "Processor")

    1. Subject Matter and Duration

    This agreement governs the processing of personal data by the Processor on behalf of the Controller in connection with debt recovery and/or credit control services. The agreement commences on the date of acceptance and continues for the duration of services plus any required data retention period.

    2. Nature and Purpose of Processing

    The Processor will process personal data only as documented in the Controller's instructions, specifically for the purpose of providing debt recovery and credit control services as agreed between the parties.

    3. Types of Personal Data

    The categories of data processed include:

    • Contact details (names, addresses, email addresses, telephone numbers)
    • Financial information (invoice details, amounts owed, payment history)
    • Business information (company names, registration numbers where applicable)
    • Communications records between parties

    4. Data Subject Categories

    Data subjects may include:

    • Individuals who owe money to the Controller (debtors)
    • Representatives of business debtors
    • Contact persons at the Controller's organisation

    5. Obligations of the Processor

    1. Process data only in accordance with documented instructions from the Controller
    2. Ensure appropriate technical and organisational security measures
    3. Engage sub-processors only with prior authorisation or notification
    4. Assist the Controller in responding to data subject requests
    5. Notify the Controller promptly of any data breach
    6. Delete or return all data upon termination of services
    7. Make available information necessary to demonstrate compliance
    8. Allow for and contribute to audits by the Controller

    Security Measures

    The Processor implements measures including but not limited to:

    • Secure storage systems with access controls
    • Encrypted communications where appropriate
    • Staff training on data protection obligations
    • Physical security for any paper records held
    • Regular review of security arrangements

    7. Sub-processors

    The Processor will not engage sub-processors without prior written consent from the Controller, except for sub-processors listed in an appendix to this agreement which may be updated with reasonable notice.

    8. Data Breach Notification

    The Processor shall notify the Controller without undue delay upon becoming aware of a personal data breach, providing details of the nature of the breach, categories affected, likely consequences, and measures taken/proposed.

    9. Termination

    Upon termination of services, the Processor shall at the Controller's election either delete or return all copies of personal data, subject to any legal requirement for retention.

    Governing Law

    This agreement is governed by English law and subject to the exclusive jurisdiction of the courts of England and Wales.

    For specific enquiries about this agreement, please contact Craig Martindale at info@cmdebtrecovery.co.uk

    Chat with us on WhatsApp