Sanction List Check
How it works Sample report Pricing FAQ See pricing

← Sanction List Check home

Legal

Data Processing Agreement

Last updated: 2026-08-25 · Sanction List Check (sanctionlistcheck.com)

1. Purpose and Scope of this DPA

This Data Processing Agreement ("DPA") governs the processing of Personal Data by Miguel Casares Robles, sole trader (autonomo), operating sanctionlistcheck.com, with registered address Horno de Haza, 34 2A, 18002 Granada, Spain (the "Processor"), on behalf of the customer ("Controller"). This DPA forms an integral part of the Terms of Service agreed between the Controller and the Processor for the use of sanctionlistcheck.com's services, and applies where the Processor processes Personal Data as a processor on behalf of the Controller, pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any applicable national implementing laws.

The purpose of this DPA is to ensure compliance with the requirements of applicable data protection laws, including the GDPR, in relation to the processing of Personal Data.

2. Subject Matter, Duration, and Nature of Processing

The Subject Matter of the processing under this DPA is the screening of Controller-submitted name lists (including company or individual names, and optionally country and date-of-birth context fields) against public, official sanctions and denied-party lists (such as OFAC SDN, US Consolidated Screening List, EU Consolidated Sanctions List, UK Sanctions List, and UN Security Council Consolidated List).

The Nature of the processing involves the Controller uploading a CSV or XLSX file, or typing one name for a free single-name check. The sanctionlistcheck.com service normalizes and fuzzy-matches each name against snapshots of official sanctions lists. A PDF and CSV report is then generated based on the screening results.

The Duration of processing for any specific screening job is limited to the length of that job. Uploaded files and generated reports are stored temporarily in Cloudflare R2, within the EU region only, and are automatically deleted no later than 24 hours after upload. No customer data is used to train any Artificial Intelligence (AI) model, and no AI or Large Language Model (LLM) is used to process, read, or make judgments about the Controller's uploaded data at any point.

3. Categories of Data Subjects and Personal Data

The Categories of Data Subjects whose Personal Data may be processed under this DPA are typically the individuals or company representatives named in the Controller's uploaded list. These individuals are generally the Controller's own counterparties, such as suppliers, customers, or business partners.

The Categories of Personal Data processed are: name, and optionally country and date of birth, as submitted by the Controller. The Processor does not knowingly process any special categories of data, as defined in Article 9 of the GDPR.

4. Processor Obligations

The Processor shall:

  • Process the Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  • Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
    • Encryption: Data in transit is encrypted using Transport Layer Security (TLS).
    • Data Storage: Stored data, including uploaded files and generated reports, is kept within the EU region only.
    • Retention Policy: Data is subject to automatic deletion no later than 24 hours after upload.
    • Advertising/Tracking: No third-party advertising or tracking cookies are used within the product.
  • Take all measures required pursuant to Article 32 of the GDPR.
  • Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor.
  • At the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data. (Note: for job-specific data, automatic deletion occurs within 24 hours as described in Section 7).
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Processor shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

5. Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of other sub-processors, thereby giving the Controller the opportunity to object to such changes.

The Processor currently engages the following sub-processors:

  • Cloudflare: Provides hosting, storage (R2), and compute services. All Cloudflare services used for processing Personal Data under this DPA are configured to operate within the EU region.
  • Paddle.com: Acts as the Merchant of Record for paid purchases, handling payment processing and billing for the services.
  • Resend: Used for transactional email delivery, such as magic-link authentication emails and notifications when reports are ready.

Where a sub-processor carries out specific processing activities on behalf of the Processor, the Processor shall ensure that the same data protection obligations as set out in this DPA shall be imposed on that sub-processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR.

6. Data Subject Rights Assistance

Taking into account the nature of the processing, the Processor will reasonably assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR (including rights of access, rectification, erasure, restriction of processing, data portability, and objection). The Processor shall notify the Controller without undue delay if it receives a request from a data subject concerning the Personal Data processed on the Controller's behalf.

7. Data Deletion and Retention

Upon the termination of the Controller's use of the services, all customer data covered by this DPA (specifically, uploaded files and generated reports related to screening jobs) is deleted automatically as per the 24-hour retention policy described in Section 2. No separate manual deletion request is required or performed for job data specifically. The Controller may still contact support for account-level deletion requests if needed.

8. International Transfers

The Processor does not intend to transfer Personal Data outside the European Union. All processing activities described in this DPA, including data storage and computing, are configured to remain within the EU region.

9. Liability

Liability under this DPA shall be subject to the same caps and limitations as stated in the Terms of Service between the Controller and the Processor. In no event shall the Processor's total aggregate liability under this DPA exceed the fees actually paid by the Controller to the Processor during the preceding twelve (12) months.

The Controller acknowledges that sanctionlistcheck.com is provided as a due-diligence aid, and is never intended to be a compliance certification or legal advice. The product does not, at any point, state that a match is 'safe' or 'clear', nor does it provide legal opinions on screening results.

10. Governing Law

This DPA shall be governed by and construed in accordance with the laws of Spain.

11. Contact

For any matters related to privacy, data protection, or this Data Processing Agreement, the Controller may contact the Processor at: [email protected].

Home · Terms of Service · Privacy Policy

Sanction List Check

Sanction List Check screens names against 5 official sanctions lists for due diligence. One-time purchase, EU-processed.

Product

  • How it works
  • Sample report
  • Pricing
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement

Company

  • Contact
  • Refund policy

Guides

  • OFAC screening tool
  • Sanctions screening tool
  • Denied party screening
  • Bulk sanctions check
  • Sanctions screening API
  • Deutsch
© 2026 Sanction List Check. This tool is a due-diligence aid, not a legal compliance determination. Customers are responsible for their own compliance decisions. EU processing · GDPR · Paddle (Merchant of Record)