You asked
Usually, yes, when your organization has a lawful purpose for the screening and uses Norvext to carry out its documented instructions. For counterparty screening data, the customer normally decides why and how the check is run; Norvext processes that data to provide the service under the Data Processing Terms.
The roles follow the purpose
A controller decides why personal data is processed and the essential means of that processing. When your organization submits counterparties, people, cases or monitoring records for its own compliance work, it normally makes those decisions. Norvext acts as processor for that Customer Personal Data.
The same company can hold a different role for a different purpose. Norvext is a controller for website visits, account administration, billing, service security, support and its own customer due diligence. Calling Norvext a processor for screening data does not make it a processor for everything.
What the DPA changes
GDPR Article 28 requires the processor relationship to be written down. Our Data Processing Terms cover documented instructions, confidentiality, security, subprocessors, international transfers, assistance, deletion and audit information. Product use and configuration form part of the customer’s instructions.
The accurate promise is not ‘nothing else’ without qualification. The processor acts on documented instructions unless applicable law requires otherwise. The customer remains responsible for its legal basis, notices, data minimisation and the decision to perform the screening.
Before submitting a counterparty
Use only the information needed for the check. A company name and country may be enough for an initial screening; identity documents, dates of birth or other identifiers should be added only when they are relevant to resolving a match.
Confirm that the people using the workspace are authorised, that access and retention settings match your policy, and that your privacy information covers the screening activity. This publication explains our role allocation; it does not replace the customer’s own legal-basis assessment.
A defensible setup
- A documented compliance purpose and legal basis
- Accepted Data Processing Terms or a signed DPA
- Only the minimum data needed to resolve the check
- Controlled workspace access and an appropriate retention period
