ArtAML™ Data Processing Agreement
Version 4.0 | Last updated 18th June 2026
1. Introduction
1.1. This Data Processing Agreement (‘DPA’ or ‘Agreement’) governs the terms on which ArtAML Limited processes personal data on behalf of its Clients in providing AML compliance services to Art Market Participants (AMPs). It forms part of the contract between ArtAML and each Client and should be read alongside the ArtAML Terms of Business and Privacy Policy, both available on our website.
1.2. This Agreement covers ArtAML’s role as Processor only — that is, processing carried out on the Client’s instructions in connection with CDD, KYC, sanctions screening and related compliance activities. Where ArtAML processes personal data for its own operational purposes, it does so as Controller; that processing is described in Appendix 3 of this Agreement and in ArtAML’s Privacy Policy.
1.3. This Agreement is designed to ensure compliance with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Clients based in the European Economic Area or other jurisdictions should satisfy themselves that this Agreement meets the requirements of their applicable data protection legislation. ArtAML will cooperate with Clients to address any jurisdiction-specific requirements on request.
1.4. Acceptance of the Terms of Business constitutes acceptance of this Agreement. This Agreement is incorporated into and forms part of the ArtAML Terms of Business.
2. Roles and Responsibilities
2.1. ArtAML acts as a Processor when handling CDD and KYC data uploaded by or collected on behalf of Clients. ArtAML acts as a Controller when handling data relating to platform accounts, billing, analytics and communications as further described in Appendix 3.
2.2. The Client acts as a Controller and is responsible for ensuring it has a lawful basis for processing and for issuing lawful instructions to ArtAML.
2.3. This Agreement applies solely to Personal Data processed on behalf of the named Client entity. Processing Personal Data on behalf of any other legal entity, including entities under common ownership or control, falls outside the scope of this Agreement and requires a separate Data Processing Agreement.
2.4. This Agreement governs ArtAML’s obligations as a Processor. Where ArtAML acts as a Controller in respect of its own operational data, it processes that data in accordance with its Privacy Policy.
3. Processing Particulars
3.1. ArtAML processes Personal Data on behalf of the Client in connection with the provision of AML compliance technology services, including Customer Due Diligence (CDD), Know Your Customer (KYC) processes, sanctions screening and related compliance activities.
3.2. Duration of processing: ArtAML shall process Personal Data for the duration of the Client’s use of the Services and thereafter for any period required by applicable AML legislation, regulatory obligations, or Documented Instructions relating to record-retention requirements.
3.3. Categories of data subjects: Clients, Clients’ staff, and Clients’ Customers.
3.4. Types of Personal Data: identification data, government-issued ID, proof of address, contact details, AML screening data, financial data, and technical data.
3.5. Nature and purpose of processing: to provide AML compliance technology services, conduct identity verification, perform sanctions and AML screening, store and manage compliance records, facilitate Customer Due Diligence (CDD) and Know Your Customer (KYC) processes, and fulfil applicable AML and regulatory obligations.
3.6. The Client, as Controller, is responsible for complying with applicable Data Protection Legislation in respect of Personal Data submitted to the platform, including any obligations arising under AML legislation applicable in the Client’s jurisdiction.
4. Obligations of ArtAML as Processor
4.1. ArtAML shall:
4.1.1. process Personal Data only on Documented Instructions from the Client;
4.1.2. promptly inform the Client if, in ArtAML’s opinion, any instruction received from the Client infringes applicable Data Protection Legislation;
4.1.3. ensure the confidentiality of persons authorised to process Personal Data;
4.1.4. implement appropriate technical and organisational measures to protect Personal Data, as further described in ArtAML’s Platform Security Policy (https://artaml.com/platform-security-and-compliance-policy/), incorporated into this Agreement by reference as updated from time to time;
4.1.5. ensure that the technical and organisational measures referred to in clause 4.1.4 include, at minimum, physical access controls, system access controls, data access controls, transmission controls, input controls, data backups, and data segregation;
4.1.6. assist the Client with data subject rights requests;
4.1.7. support the Client with data protection impact assessments; and
4.1.8. maintain records of processing activities where required under Article 30 UK GDPR.
5. Sub-processors
5.1. The Client hereby authorises ArtAML to engage the Sub-processors listed in Appendix 2 for the purposes of providing the Services.
5.2. ArtAML shall ensure that each Sub-processor is bound by written contractual obligations that provide a level of protection for Personal Data substantially equivalent to that required of ArtAML under this Agreement.
5.3. ArtAML shall remain responsible for the performance of its Sub-processors to the extent required by applicable Data Protection Legislation.
5.4. ArtAML may appoint additional Sub-processors or replace existing Sub-processors from time to time.
5.4.1. Where ArtAML appoints a new Sub-processor, that is, a provider performing a function not previously carried out by any Sub-processor listed in Appendix 2, ArtAML shall notify Clients by email no less than 30 days before the appointment takes effect.
5.4.2. Where ArtAML replaces an existing Sub-processor with another provider performing the same or substantially the same function with equivalent data protection protections, ArtAML shall update Appendix 2 of this Agreement and the corresponding appendix of its Privacy Policy to reflect the change, without email notification.
5.4.3. In all cases, Appendix 2 will reflect the current list of Sub-processors at all times. If a Client reasonably objects to a proposed new Sub-processor appointment on data protection grounds, it shall notify ArtAML in writing within 30 days of receiving notice. The parties shall work in good faith to resolve the objection. If no reasonable resolution can be reached, the Client may terminate the affected Services on written notice before the change takes effect, without penalty. Where a Client does not respond within 30 days of receiving notice, it shall be deemed to have accepted the appointment.
6. International Data Transfers
6.1. ArtAML is a UK-registered company and processes Personal Data under UK GDPR. ArtAML’s platform is hosted on servers located within the European Economic Area. Accordingly, Personal Data processed through the Services is stored within the EEA. Where Personal Data is transferred from the United Kingdom to the EEA for the purposes of hosting and storage, ArtAML shall rely on the UK Government’s adequacy regulations in respect of EEA states. Where the Client is based in the European Economic Area or another jurisdiction with its own restrictions on transfers of personal data to the United Kingdom, the Client is responsible for ensuring that appropriate transfer mechanisms are in place for the transfer of Personal Data to ArtAML. ArtAML shall cooperate with Clients to put in place any required transfer documentation on request.
6.2. Where Personal Data is processed or accessed in the United States or other jurisdictions not covered by UK adequacy regulations, ArtAML shall implement appropriate safeguards, such as the UK Addendum to the EU Standard Contractual Clauses or equivalent legally recognised mechanisms.
7. Data Retention and Deletion
7.1. The Client acknowledges that AML legislation applicable to the Client, including the MLRs where applicable, may require the Client to retain CDD records for a period of five years following the completion of an occasional transaction or the end of a business relationship. ArtAML processes and retains such records on the Client’s behalf in accordance with those obligations and the Client’s Documented Instructions.
7.2. Following termination or expiry of a subscription, ArtAML shall provide the Client with a secure export of its data. The Client shall have 30 days to download the exported data and confirm receipt. ArtAML may extend this period on request where reasonably necessary to support the Client’s compliance, regulatory or record-retention obligations.
7.3. Following confirmation of receipt, or after expiry of the applicable download period, ArtAML shall delete the Client’s Organisation and associated Personal Data from active platform systems except to the extent that continued retention is required by applicable law, regulatory obligation, or Documented Instructions relating to AML record-retention requirements. Upon expiry of any applicable retention period, ArtAML shall securely delete the retained data. Where deleted data remains within backup systems following deletion from active platform systems, ArtAML shall ensure that such backup copies are permanently deleted or rendered irrecoverable within 90 days of the deletion date.
7.4. Where a Prospective Client accesses the platform during a trial period and the trial does not convert to a paid subscription, the same data export and deletion process applies. ArtAML shall provide a secure export of any Personal Data uploaded during the trial period. The Prospective Client shall have 30 days to download the exported data and confirm receipt. ArtAML may extend this period on request. If no confirmation is received within 30 days, ArtAML shall proceed with deletion in any event.
7.5. Where a Client subscribes to the Services on a seasonal, periodic or pay-as-you-go basis and has indicated an intention to continue using the Services, ArtAML shall retain the Client’s data on the platform for the duration of the applicable MLR retention period, or until the Client confirms in writing that the data is no longer required, whichever is earlier. Such retention is carried out on the basis of Documented Instructions from the Client as Controller, reflecting the Client’s legitimate interests and ongoing record-keeping obligations as a regulated entity. The Client may withdraw this instruction at any time by notifying ArtAML in writing, in which case the data export and deletion process set out in clauses 7.2 and 7.3 shall apply.
8. Data Breach Notification
8.1. ArtAML shall notify the Client without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data breach affecting Personal Data processed under this Agreement. Where notification cannot be made within 72 hours, ArtAML shall provide an initial notification within that period and supply further details as they become available.
8.2. Such notification shall, to the extent information is available at the time, describe:
8.2.1. the nature of the breach;
8.2.2. the categories and approximate number of affected data subjects and records;
8.2.3. the likely consequences of the breach; and
8.2.4. the measures taken or proposed to address and mitigate the breach.
8.3. ArtAML shall provide reasonable cooperation and assistance to enable the Client to comply with any applicable breach notification or reporting obligations under Data Protection Legislation.
9. Audit and Compliance
9.1. The Client may request information to demonstrate ArtAML’s compliance with this Agreement. ArtAML shall respond to reasonable information requests within 30 days.
9.2. The Client may conduct an audit or inspection of ArtAML’s compliance with this Agreement on not less than 30 days’ written notice and no more than once per calendar year, except where reasonably required following a Personal Data breach, regulatory inquiry, material security incident, or other reasonable compliance concern. Any audit shall be conducted during normal business hours, subject to reasonable confidentiality, security and operational requirements. The costs of any audit shall be borne by the Client unless the audit reveals a material breach by ArtAML.
10.Liability and Indemnities
10.1. ArtAML’s aggregate liability under this Agreement shall not exceed the greater of the total Fees paid by the Client in the 12 months preceding the event giving rise to the claim, or £10,000, as further set out in clause 12.3 of the Terms of Business. Nothing in this Agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded by law.
10.2. Each party shall indemnify the other against claims, losses, damages, costs and expenses (including reasonable legal costs) arising from its own failure to comply with applicable Data Protection Legislation.
10.3. The Client shall indemnify ArtAML against claims arising from unlawful processing instructions or the Client’s failure to establish a lawful basis for processing.
10.4. ArtAML shall indemnify the Client against claims arising directly from ArtAML’s failure to comply with its obligations as Processor under this Agreement.
11. Updates to this Agreement
11.1. ArtAML shall notify Clients of material changes to this Agreement by email to the account holder’s registered address no less than 30 days before the changes take effect. For the purposes of this clause, material changes include changes to data retention periods, international transfer mechanisms, or Client audit rights. Updates to Appendix 2 (Sub-processors) are governed exclusively by clause 5.4. Updates to Appendix 3 (Controller Processing Activities) reflecting new or modified platform features do not constitute material changes for the purposes of this clause, provided they do not alter the lawful basis for any existing processing activity.
11.2. Changes required by law or regulatory obligation may take effect on shorter notice where strictly necessary, in which case ArtAML shall notify Clients as soon as reasonably practicable.
11.3. Clients who object to a material change may terminate their subscription in accordance with the Terms of Business before the change takes effect. Continued use of the platform after the effective date of a change constitutes acceptance of the updated Agreement.
12. Governing Law and Jurisdiction
12.1. This Agreement is governed by the laws of England and Wales and is subject to the exclusive jurisdiction of the English courts.
13.Conflict and Precedence
13.1. In the event of any conflict between this Agreement and any other provision of the Terms of Business, this Agreement shall prevail in respect of the processing of Personal Data. In all other respects, the Terms of Business shall govern the relationship between the parties.
14. Third-Party Rights
14.1. No provision of this Agreement is intended to confer rights on any third party under the Contracts (Rights of Third Parties) Act 1999.
15.Contact Details
15.1. Any notices, queries or complaints relating to this Agreement should be directed to:
15.1.1. ArtAML Limited, 27 Old Gloucester Street, London WC1N 3AX
15.1.2. Data Protection Officer: Dr. Chris King E: [email protected]
15.1.3. T: +44 203 488 2966
15.1.4. General enquiries: [email protected]
15.2. The Client also has the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113, or with the supervisory authority in the EU member state of their establishment where applicable.
15.3. ArtAML Limited is registered with the Information Commissioner’s Office under registration reference ZA566966.
Appendix 1: Definitions
In this Agreement, the following terms have the meanings set out below. Where a term is also defined in the ArtAML Terms of Business, it has the same meaning in this Agreement unless the context requires otherwise. Defined terms are signalled by an initial capital letter.
|
Term |
Meaning |
|
AML |
Anti-Money Laundering. |
|
CDD |
Customer Due Diligence, the process of verifying identity and assessing risk as required under the MLRs or equivalent AML legislation applicable to the Client in its jurisdiction. |
|
Client |
The business or organisation that enters into this Agreement with ArtAML as the Data Controller. The Client determines the purposes and means of processing Personal Data and instructs ArtAML in its role as Data Processor. ‘Client’ has the same meaning as in the ArtAML Terms of Business. |
|
Controller |
The entity that determines the purposes and means of processing Personal Data. |
|
Customer |
The Client’s own customers in the context of performing Customer Due Diligence (CDD). |
|
Data Protection Legislation |
UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Directive 2002/58/EC (as updated by Directive 2009/136/EC), the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426), and any other applicable legislation relating to the processing of Personal Data in force from time to time, including equivalent legislation applicable to the Client in its jurisdiction. |
|
Data Protection Officer (DPO) |
The person appointed to oversee data protection compliance. |
|
Documented Instructions |
A written instruction from the Client to ArtAML regarding the processing of Personal Data, including instructions given via the platform, by email, or as set out in this Agreement or the Terms of Business. |
|
DPA |
This Data Processing Agreement. |
|
ICO |
Information Commissioner’s Office, the UK supervisory authority for data protection. |
|
KYC |
Know Your Customer, part of the CDD process. |
|
MLRs |
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended), being the principal UK AML legislation applicable to Art Market Participants. References to the MLRs in this Agreement should be read, where applicable, as including equivalent AML legislation applicable to the Client in its own jurisdiction. |
|
Personal Data |
Any information relating to an identified or identifiable natural person, as defined in UK GDPR. |
|
Processing |
Any operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, or deletion. |
|
Processor |
The entity that processes Personal Data on behalf of a Controller. |
|
Prospective Client |
A person or business accessing the ArtAML platform during a trial period who has not yet converted to a paid subscription. |
|
Services |
The products and services provided by ArtAML, including SaaS subscriptions, Bundles, AML Training, AML Risk Assessment and Policy, ArtAML™ Protection, ArtAML™ Secure, add-ons, and associated support services, as further described in Appendix 2 of the ArtAML Terms of Business. |
|
Special Categories of Personal Data |
Information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, and data concerning a person’s sex life or sexual orientation, as defined in Article 9 UK GDPR or the equivalent provision of applicable data protection legislation. |
|
Sub-processor |
A third party engaged by ArtAML to process Personal Data in connection with the Services, including where ArtAML acts as Processor on behalf of a Controller. |
|
Terms of Business |
The ArtAML Terms of Business, available at https://artaml.com/terms-and-conditions-of-supply-main-agreement/, including Appendix 1 (Definitions) and Appendix 2 (Product and Service Terms). |
|
UK GDPR |
The United Kingdom General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. |
Appendix 2: Sub-processors
1. This appendix lists the third-party providers engaged by ArtAML to process personal data on behalf of Clients in ArtAML’s capacity as Processor. It covers providers who handle data uploaded by or collected on behalf of Clients, such as identity verification, screening, secure storage and platform hosting. It does not include tools used by ArtAML solely in connection with its own business operations; those are listed in Appendix 3 of the Privacy Policy. Changes to this list are governed by clause 5.4 of this Agreement.
2. ArtAML uses the following Sub-processors to deliver its Services:
2.1. Anthropic: AI-assisted analysis, drafting and software development support. Personal Data is processed only in accordance with ArtAML’s contractual arrangements with Anthropic and applicable Data Protection Legislation.
2.2. Auth0: secure login management
2.3. Backblaze: backup storage
2.4. ComplyAdvantage: PEP and sanctions screening
2.5. DigitalOcean: hosting
2.6. Google Workspace: business productivity and email
2.7. SendSafely: secure file transfer
2.8. Yoti: ID verification
Appendix 3: Controller Processing Activities
1. ArtAML’s processing activities as Processor on behalf of the Client are described in Section 3 of this Agreement. Where ArtAML acts as Controller in respect of its own operational data, it processes Personal Data for the purposes set out below and in accordance with its Privacy Policy:
1.1. The lawful bases set out above reflect ArtAML’s position under UK GDPR. Clients operating outside the United Kingdom should satisfy themselves that corresponding lawful bases under their own applicable data protection legislation apply.
| Purpose / Activity | Type of Data | Lawful Basis |
| Platform account creation and login | Name, email address, account credentials, authentication data, login history, IP address | Performance of contract; legitimate interests in platform security |
| Billing and payments | Name, contact details, billing address, payment records, transaction history | Performance of contract; legal obligation (accounting and tax compliance) |
| Support and service communications | Contact details, support requests, correspondence records | Performance of contract; legitimate interests in customer support and service continuity |
| Security monitoring and fraud prevention | IP addresses, device information, authentication logs, access logs, technical telemetry | Legitimate interests in maintaining platform security, preventing fraud and protecting Services |
| Analytics and service improvement | Usage data, feature interaction data, diagnostic information, error reports | Legitimate interests in improving platform performance, reliability and user experience |