Legal
Data Processing Agreement
GDPR Article 28 DPA governing Arbiter's processing of personal data on your behalf.
Coming soon. Our Data Processing Agreement is being drafted. It will be available here before Arbiter opens to the public and will be executable on request for customers subject to GDPR. Contact us if you need it earlier.
What the DPA will cover
- Subject matter and duration of processing
- Nature and purpose of processing (RADIUS authentication, device profiling)
- Categories of personal data processed (MAC addresses, usernames, certificate subject names, authentication logs)
- Categories of data subjects (employees, contractors and devices of the controller)
- Obligations and rights of the controller
- Sub-processor list and change notification process
- Standard Contractual Clauses (SCCs) where applicable
- Technical and organisational security measures
Key data facts
- All personal data processed by Arbiter is stored in the EU (Ireland).
- Arbiter acts as data processor; the customer (tenant) is the data controller.
- Tenant data is strictly isolated. No cross-tenant processing.
- Sub-processors limited to EU-resident infrastructure providers.
Last updated May 2026. For questions about this page, contact privacy@arbiter.ie.