Data Processing Agreement — Recruiter Partner
Last updated: 28 August 2026
Between:
Controller: {{PARTNER_COMPANY_LEGAL_NAME}}, Org. nr.: {{PARTNER_ORG_NUMBER}}, registered at {{PARTNER_ADDRESS}} ("Controller" or "Recruiter Partner")
Processor: ArbeidMatch Norge AS, Org. nr.: {{PROCESSOR_ORG_NUMBER}}, registered at {{PROCESSOR_REGISTERED_ADDRESS}} ("Processor" or "ArbeidMatch")
Effective from: {{ACCEPTANCE_DATE}}
1. DEFINITIONS
Terms used herein shall have the meaning ascribed to them in Regulation (EU) 2016/679 ("GDPR") and the Norwegian Personal Data Act (Personopplysningsloven). "Personal Data," "Processing," "Data Subject," "Sub-Processor," and "Personal Data Breach" carry their GDPR meanings.
2. SUBJECT MATTER AND DURATION
The Processor processes Personal Data on behalf of the Controller for the sole purpose of operating the ArbeidMatch recruitment platform and facilitating placement of candidates introduced by the Controller with end-employers in Norway. This Agreement remains in effect for as long as the Controller maintains an active account on the ArbeidMatch platform and survives termination with respect to ongoing confidentiality and data return obligations.
3. NATURE AND PURPOSE OF PROCESSING
The Processor will process Personal Data exclusively to:
- Store candidate profiles introduced by the Controller
- Match candidates with employer requests within the platform
- Facilitate communication between the Controller, candidates, and end-employers
- Generate placement records and commission calculations
- Comply with the Controller's documented instructions
The Processor shall not process Personal Data for any other purpose, including marketing, profiling unrelated to recruitment, or sale to third parties.
4. CATEGORIES OF PERSONAL DATA
- Identification data: full name, date of birth, nationality
- Contact data: email, phone, address
- Professional data: CV content, employment history, qualifications, certifications, references
- Work eligibility data: work permits, residence status, D-number/personal number where applicable
- Communication data: messages exchanged via the platform
5. CATEGORIES OF DATA SUBJECTS
Job candidates introduced by the Controller through invitation links, manual upload, or platform-integrated channels.
6. CONTROLLER'S OBLIGATIONS
The Controller warrants that:
a) It has a valid legal basis under GDPR Article 6 for sharing each candidate's Personal Data with the Processor (typically consent or legitimate interest)
b) It has provided each candidate with a transparent privacy notice meeting GDPR Article 13/14 requirements
c) It will not introduce candidates whose Personal Data was obtained unlawfully
d) It will respond promptly to data subject requests forwarded by the Processor
7. PROCESSOR'S OBLIGATIONS
The Processor shall:
a) Process Personal Data only on documented instructions from the Controller
b) Ensure persons authorized to process Personal Data are bound by confidentiality
c) Implement appropriate technical and organizational measures (Section 9)
d) Assist the Controller in fulfilling data subject requests within 30 days
e) Assist the Controller with data protection impact assessments and consultations with supervisory authorities upon request
f) Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a Personal Data Breach
g) At the Controller's choice, delete or return all Personal Data after termination, save where Union or Member State law requires retention
8. SUB-PROCESSORS
The Controller grants general authorization for the Processor to engage Sub-Processors. Current Sub-Processors:
- Supabase Inc. - database hosting (EU/Frankfurt region)
- Vercel Inc. - application hosting (EU regions)
- One.com A/S - email infrastructure (EU/Denmark)
- Stripe Payments Europe Ltd. - payment processing (when commission payouts are activated)
The Processor shall maintain an updated list at https://arbeidmatch.no/subprocessors and notify the Controller of intended changes 30 days in advance via email. The Controller may object on reasonable data protection grounds; if no resolution is reached, the Controller may terminate this Agreement. The Processor remains fully liable for the acts and omissions of its Sub-Processors.
9. SECURITY MEASURES (GDPR ARTICLE 32)
The Processor implements:
- Encryption: TLS 1.3 in transit; AES-256 at rest
- Access control: role-based permissions, least-privilege principle, MFA for administrative accounts
- Audit logging: all access and modifications recorded with retention of 12 months
- Pseudonymization: applied upon erasure requests where full deletion is technically constrained
- Backup: encrypted daily backups, retention 30 days
- Incident response: documented procedure with 48-hour internal escalation
- Personnel: background checks for employees with production access; mandatory data protection training
10. PERSONAL DATA BREACH NOTIFICATION
In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay and in any case within 48 hours of becoming aware. The notification shall include:
a) Nature of the breach and categories/approximate number of data subjects and records affected
b) Likely consequences
c) Measures taken or proposed to address the breach and mitigate effects
d) Contact details of the data protection contact
The Controller is responsible for any onward notification to supervisory authorities (Datatilsynet) and data subjects under GDPR Articles 33-34.
11. AUDIT RIGHTS
The Controller may, no more than once per calendar year and with 30 days' written notice, request:
a) Written confirmation of the Processor's compliance with this Agreement
b) Copies of the Processor's most recent security audit reports (e.g., SOC 2, ISO 27001) where available
c) An on-site audit conducted at the Controller's expense, subject to reasonable confidentiality obligations and during business hours
In the event of a documented Personal Data Breach affecting the Controller's data, audit rights may be exercised more frequently.
12. INTERNATIONAL TRANSFERS
Personal Data is processed within the European Economic Area (EEA). The Processor shall not transfer Personal Data outside the EEA without ensuring adequate protection through Standard Contractual Clauses or another lawful transfer mechanism, and shall notify the Controller in advance.
13. DATA RETENTION AND RETURN
Upon termination of this Agreement or upon the Controller's written request:
- Active candidate data: returned in machine-readable format (JSON/CSV) within 30 days
- All copies (including backups): deleted within 90 days, except where legal retention applies (e.g., financial records under Norwegian Bookkeeping Act, retained for 5 years)
- Inactive candidates (no platform activity for 24 consecutive months): automatically anonymized
14. LIABILITY
Each party's liability under this Agreement is limited as set forth in the master ArbeidMatch Recruiter Partner Agreement. Notwithstanding any limitation, neither party may exclude liability for:
- Willful misconduct or gross negligence
- Breach of confidentiality obligations
- Fines imposed by supervisory authorities directly attributable to that party's breach
15. GOVERNING LAW AND JURISDICTION
This Agreement is governed by Norwegian law. Disputes shall be submitted exclusively to the courts of Trondheim (Sør-Trøndelag tingrett), Norway.
16. ELECTRONIC ACCEPTANCE
By clicking "I accept" within the ArbeidMatch onboarding flow, the Controller acknowledges having read, understood, and agreed to be legally bound by this Agreement. This electronic acceptance constitutes a binding agreement under Norwegian contract law (Avtaleloven). The Processor records the timestamp, IP address, and user agent for evidentiary purposes. This is not a Qualified Electronic Signature under eIDAS Regulation (EU) 910/2014. For high-formality agreements requiring QES, parties may execute a separate signed addendum.
17. SIGNATURES
Controller - {{PARTNER_COMPANY_LEGAL_NAME}}
Accepted electronically by: {{PARTNER_FULL_NAME}}
Title: {{PARTNER_TITLE}}
Date: {{ACCEPTANCE_DATE}}
IP: {{ACCEPTANCE_IP}}
Processor - ArbeidMatch Norge AS
{{PROCESSOR_SIGNATORY_LINE}}