Atlas Data Processing Agreement
The controller and the processor have entered into the following data processing agreement, in accordance with Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016:
1. Purpose of the Agreement
The processor provides the controller with hosting, storage, and operational services in the Atlas cloud in accordance with its general terms of service. This data processing agreement forms part of those terms of service. When using the Atlas service offering, personal data may be stored and processed on Atlas servers and within their systems. This agreement on the processing of personal data (the agreement) is intended to set out the terms that apply to the processing of personal data in connection with the provision of services under the licence agreement, in accordance with Article 28(3) of the Data Protection Act. The purpose of this data processing agreement is to specify the obligations of the processor and the controller, and to set out clearly the processor's processing of personal data on behalf of the controller, with the aim of ensuring the secure handling of personal data and legal compliance. This data processing agreement applies to services that Atlas provides under an agreement with the customer where the customer is either a controller or a processor and Atlas acts as a processor or sub-processor. Processing of personal data by Atlas where Atlas is the controller does not fall under this agreement; it is instead defined in the Atlas privacy policy. The parties to the agreement shall be bound by all applicable legal provisions concerning the processing of personal data by them, and in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the General Data Protection Regulation), which took effect on 25 May 2018. The terms "processing", "personal data", "data subject", "controller", and "processor" shall have the same meaning as given to them in the data protection legislation. The controller bears full responsibility for meeting the legal obligations incumbent upon it under the data protection legislation, including publishing notices to data subjects and obtaining lawful consent where applicable. The controller is likewise responsible for the instructions it gives the processor regarding the processing of the personal data.
2. Description of the Processing of Personal Data
The processor is permitted to process, on behalf of the controller, the personal data necessary for it to provide the following cloud and hosting services. Data concerned: Customer data Timing of the processing: processing and storage of this data shall be limited to the period during which the controller is in a business relationship with the processor, with the exception of cases where a judicial authority requires the data that is stored. The nature of the processing activity in question may be storage, computation, and/or other processing specified in the terms, depending on which Atlas services the customer uses. The limited and precise purpose of the processing under this data processing agreement is to provide the controller with first-class cloud and hosting services as requested and configured by the customer. Atlas will only process data as a processor on behalf of the customer and in order to provide the services specified in this agreement, or as processors are otherwise permitted under applicable data protection legislation. Atlas will not grant any third party access to any data, except in accordance with this data processing agreement or as required by law. The processor is permitted to process the following categories of personal data: The categories of personal data are determined and controlled by the controller alone. They include basic information, identification data, contact data (e.g. phone numbers and postal addresses), basic contract data, log data, and invoicing and billing data. Where other data is concerned, it shall be specified by the controller, who shall provide the processor with that information. The processor is permitted to process the following categories of data subjects: The categories of data subjects are determined and controlled by the controller alone. They include the controller's customers, employees, and stakeholders. Where other categories are concerned, they shall be specified by the controller, who shall provide the processor with information about those categories.
3. Term of the Agreement
This agreement applies alongside, and for as long as, the business relationship between the controller and the processor.
4. Obligations of the Processor
The processor shall:
process personal data solely in accordance with the purpose of the processing, pursuant to this agreement
process personal data solely on the controller's written instructions, which accompany this agreement. Where the processor considers that the controller's instructions are not compatible with the General Data Protection Regulation or other applicable legal provisions concerning the processing of personal data, it shall notify the controller without delay. The processor shall also inform the controller if it is required by law to transfer personal data to third countries or international organisations, unless the law prohibits disclosure of such a requirement.
handle requests from the controller for the modification, transfer, deletion, or other processing of personal data in accordance with the licence agreement. Instructions from the controller to halt processing or otherwise prevent damage arising from unauthorised processing shall be handled as quickly as possible.
ensure confidentiality regarding the processing of the personal data covered by this agreement, and ensure that employees who have access to personal data in connection with the performance of the agreement have signed a confidentiality declaration or are bound by a duty of confidentiality under law, and that they receive appropriate training in the protection of personal data. The duty of confidentiality survives the term of this agreement.
ensure that equipment and tools, products, applications, and services are designed with data protection by design and by default in mind.
to the extent reasonable, assist the controller in fulfilling the legal obligations incumbent upon it under the data protection legislation, having regard to the nature of the processing the processor carries out on the controller's behalf and the information available to the processor at any given time.
Use of Sub-processors:
If the processor engages a subcontractor to perform a particular service and that service requires the processing of personal data, that third party is considered a sub-processor within the meaning of the data protection legislation.
The processor is permitted to contract with another party (a "sub-processor") to carry out specific processing operations. Before intended changes take effect, both when a sub-processor is added and when changes are made to sub-processors already in use, or where there are additions or changes to existing processing arrangements, the processor shall inform the controller in writing of the changes. This shall specifically state which processing operations the sub-processor intends to undertake, along with the sub-processor's name, contact details, and the date of the agreement. For the avoidance of doubt, colocation providers and telecommunications infrastructure companies are not considered sub-processors under this data processing agreement.
In order to offer outstanding cloud, backup, and hosting services, Atlas uses sub-processors. An up-to-date and current list of Atlas sub-processors is always available at https://trust.atlascloud.is/subprocessors
Those parties shall meet the same strict security and data protection requirements to ensure reliability and compliance. Beyond that, the customer grants Atlas general authorisation to add, change, or remove sub-processors from this list. The controller has 15 days from the date on which it receives information about a change in the use of a sub-processor to object to it. The use of a sub-processor is only permitted where the controller has not objected within that time limit.
The processor may not entrust a sub-processor with processing personal data on its behalf unless a written agreement exists between the sub-processor and the processor containing provisions that are comparable to and no weaker than those in this agreement, in particular provisions concerning the security of the personal data.
If a sub-processor fails to fulfil its obligations under such an agreement, the processor shall remain fully liable to the controller for the sub-processor's performance of its commitments.
To the extent possible, the processor shall assist the controller in fulfilling its obligation to respond to requests from data subjects concerning their rights, such as the right of access, the right to rectification and erasure of information, the right to object to or restrict processing, the right to data portability, and the right not to be subject to automated decision-making, including profiling. Where a data subject submits a request to exercise their rights to the processor, the processor shall forward such a request without delay to the controller, who shall be responsible for responding to it. Atlas will not handle such requests on its own initiative but will assist the controller as described above. The controller shall bear the cost incurred for work arising from enquiries from third parties or data subjects.
The processor must be given room to respond to requests received by the controller, at least 20 days from the point at which the controller requests the processor's assistance.
The processor may not provide data subjects or other third parties with information about the processing of personal data. The controller shall always handle requests received from data subjects.
Notification of Security Breaches
The processor shall notify the controller of any security breach as soon as possible
The notification shall be accompanied by any documents or data necessary for the controller to report the breach to the relevant supervisory authority. Such a notification shall describe the nature of the security breach, including the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned. It shall also describe the likely consequences of the breach and the measures taken or proposed to be taken in response to it. It shall likewise state the name and contact details of the data protection officer or other contact point from which further information can be obtained.
The above shall not, however, apply to emergencies and security breaches arising from the actions of the customer or its end users.
The parties agree that the controller alone is responsible for, and shall decide, whether data subjects, a supervisory authority, or others are notified of a personal data breach and how such notifications are sent. The processor shall assist the controller in carrying out data protection impact assessments. The processor shall assist the controller in complying with the Regulation's provisions on prior consultation with the supervisory authority (the Data Protection Authority).
Security Measures
The processor shall implement appropriate technical and organisational security measures to ensure the security of the personal data it processes on behalf of the controller. The security measures shall take account of the state of the art, the cost of implementation, the scope, context, and purposes of the processing, and the risk involved. This includes multi-factor system mirroring to ensure reliability and availability and the resilience of systems, and a procedure for regularly testing and evaluating the effectiveness of the technical and organisational measures taken to ensure security.
The processor undertakes to implement security measures in accordance with SOC 2 and ISO 27001 at the earliest opportunity.
When assessing security, regard shall be had to the risk that the processing entails, in particular the accidental or unlawful destruction of personal data that is transmitted, stored, or otherwise processed, or its loss, alteration, unauthorised disclosure of, or access to it.
The processor shall always inform the controller where personal data is hosted. Transferring personal data outside the European Economic Area is entirely prohibited except on the basis of instructions to that effect.
The processor undertakes to implement security measures in accordance with best possible practice.
This is set out in more detail in the Atlas summary of Security and Trust at https://trust.atlascloud.is/
When services end under this agreement, the processor agrees to delete all personally identifiable information. The processor shall, in consultation with the controller, deliver or delete all personal data, including copies, when it is no longer necessary for the purposes for which it was obtained, unless otherwise provided by law. Atlas has designated a data protection officer pursuant to Article 37 of the Regulation. Þórður Atlason, gdpr@atlascloud.is The processor shall provide the controller with access to all information necessary to demonstrate compliance with the obligations under the data protection legislation or the General Data Protection Regulation. The processor shall give the controller the opportunity to carry out, or to have a third party carry out on its behalf, audits of the processor's processing of personal data, and shall provide the controller with assistance for such audits. The processor's assistance with such audits shall be paid for in accordance with the parties' agreement or the processor's applicable price list. The processor shall assist the controller in complying with Article 30 of the Data Protection Act on prior consultation with the Data Protection Authority.
5. Obligations of the Controller
The controller is responsible for providing data subjects with information about the processing activity before or at the same time as processing begins, in accordance with the provisions of the General Data Protection Regulation on information to be provided to the data subject, cf. Articles 13 and 14 thereof.
The customer is solely responsible for the accuracy, quality, and lawfulness of content data, as well as for the means by which the customer obtained the data. This includes obtaining all necessary consents and rights required for Atlas to process the content data in accordance with applicable data protection legislation and this data processing agreement. The customer specifically confirms that its use of the service will not infringe the rights of any data subject and/or end user who has opted out of the sale or other disclosure of personal data, to the extent that this applies under applicable data protection legislation.
The customer is solely responsible for the personal data processed through the Atlas service. The customer specifically acknowledges that Atlas performs no monitoring of the content of such data and cannot be responsible if the data is unlawful or impermissible. Whether the customer acts as a controller or a processor, it shall bear sole and unqualified responsibility for any collection, processing, disclosure, distribution, or publication of information or data that it carries out through the service. Such activity shall always be in strict accordance with applicable data protection legislation.
The customer specifically undertakes: To provide the data subjects covered by the processing with the necessary information when data is collected, and to enable them to exercise their rights. To provide Atlas with instructions on the processing of personal data and to keep account data up to date. To maintain a record of processing activities in which Atlas is identified as the processor or sub-processor for the relevant processing operations. To carry out, or have carried out under its responsibility, a data protection impact assessment where needed, and, where applicable, to consult the relevant supervisory authority (the Data Protection Authority) when intended processing is likely to result in a high risk to the rights and freedoms of data subjects. To define retention periods and terms for the storage and deletion of the personal data processed. To implement technical and organisational measures concerning the protection, security, and confidentiality of the personal data processed that fall outside the scope of the services Atlas provides or that are based on the customer's choices. To establish internal procedures to identify and respond to personal data breaches that must be reported to the relevant supervisory authority and/or to data subjects.
6. Location
Atlas hardware is hosted in data centres within Iceland. Personally identifiable data will not be transferred outside the EEA. Backups may be stored in countries outside Iceland but within the EEA. The processor (and, where applicable, other sub-processors) may not transfer or otherwise process personal data outside the European Economic Area (EEA) unless it has obtained the controller's written consent. Where the controller has given such consent, the processor shall only process or permit the processing of personal data outside the EEA in the following cases: the processor processes personal data where the European Commission has decided that the third country, a territory, or one or more specified sectors within the third country in question, or the international organisation concerned, ensures an adequate level of protection. the processor has put in place appropriate safeguards, and on the condition that enforceable rights and effective legal remedies are available for data subjects in accordance with the conditions of Article 46 of the Data Protection Act. The transfer of the personal data is otherwise compatible with the data protection legislation.
7. Damages
The processor's liability for damages towards data subjects shall be governed by the data protection legislation. The processor's liability for damages towards the controller is limited to all direct loss suffered by the controller that is attributable to the processor's failure to fulfil its obligations under this data processing agreement, including where it has not followed the controller's lawful instructions on the processing of personal data Indirect loss will not be compensated by the processor, nor will loss that is not attributable to gross negligence or intent on the part of the processor. Indirect loss is considered to be loss attributable to a reduction in or stoppage of production, services, or business generally, and loss attributable to lost profit where a contract with a third party lapses or is not properly performed. The processor's liability towards the controller is further limited to an amount equal to the consideration the controller has paid the processor for services under the agreement during the six months preceding the loss. The processor shall compensate the controller for loss that the controller demonstrably suffers as a result of the processor's handling of information contrary to applicable laws and rules, the controller's instructions, or the data processing agreement.
8. Jurisdiction
Each party shall send the other information on the name and contact details of its data protection officer, if one has been designated. Should a dispute arise regarding the substance of this agreement and its interpretation, the parties shall endeavour to resolve that dispute through conciliation. If a settlement is not reached, a party may bring the matter before the District Court of Reykjavík. By signing this data processing agreement, the processor and joint controller confirm that they have the capacity and competence to fulfil the obligations set out in this agreement.
Last updated: 14 July 2026