Audit Program 4.1 legal terms

AP4.1 Data Processing Agreement

This agreement sets out the data-processing responsibilities that apply if and to the extent EQC processes personal data on behalf of a CPA Practice Unit in connection with AP4.1.

Effective Date: 20 January 2025*Last Updated: 16 September 2026

1. Introduction and Applicability

This Data Processing Agreement (“DPA”) forms part of the applicable agreement between EQC Advisory Limited, trading as EQC Compliance Advisory (“EQC”, “we”, “us”, or “our”), and the CPA Practice Unit (“you”, “your”, or “Data User”) for Audit Program 4.1 (“AP4.1”). It applies only if and to the extent EQC processes Personal Data on behalf of the CPA Practice Unit under a separately agreed support, hosted, remote-access, or other service arrangement.

AP4.1 is described in EQC’s Privacy Policy as operating under a local-processing model. Where no EQC access to Personal Data occurs, this DPA does not create an obligation for EQC to process, host, retain, or access Personal Data. Where processing does occur, it is subject to this DPA, the CPA Practice Unit’s documented lawful instructions, and applicable law.

*The dates, parties, processing particulars, and any service model must be confirmed by EQC before publication or incorporation into customer agreements.

2. Definitions

  • “Personal Data” means data relating directly or indirectly to a living individual from which it is practicable for the identity of the individual to be directly or indirectly ascertained, within the meaning of the PDPO.
  • “Data User” means the CPA Practice Unit that controls the collection, holding, processing, or use of Personal Data.
  • “Data Processor” means EQC, only to the extent it processes Personal Data on behalf of and under the documented instructions of the Data User.
  • “Processing” means an operation performed on Personal Data, including collection, use, disclosure, storage, access, transmission, return, deletion, or destruction.
  • “Sensitive Personal Data” is used in this DPA descriptively for Personal Data that requires heightened care, including financial information. The term is not intended to alter the statutory definitions under the PDPO.

3. Roles and Processing Instructions

The CPA Practice Unit acts as Data User and remains responsible for determining the purposes and means of its professional-data handling, subject to applicable law. EQC acts as Data Processor only where and to the extent it processes Personal Data for the CPA Practice Unit under this DPA.

EQC will process Personal Data solely for the documented purposes and lawful instructions specified by the CPA Practice Unit, unless otherwise required by applicable law. If legally required to process Personal Data other than on the Data User’s instructions, EQC will notify the Data User before that processing where legally permitted to do so.

The applicable order form, support request, or written instruction should specify the processing purpose, duration, type of Personal Data, categories of data subjects, and authorised processing activities. EQC should not use Personal Data for marketing, profiling, product training, artificial-intelligence training, or another independent purpose unless such use is separately agreed and lawfully documented.

4. Responsibilities of the CPA Practice Unit

As Data User, the CPA Practice Unit agrees to:

  • comply with the PDPO and other applicable data-protection requirements when collecting, using, and disclosing Personal Data;
  • ensure that it has a lawful basis, authority, and any required notices or permissions to provide Personal Data for the instructed Processing;
  • provide EQC with clear, lawful, and documented Processing instructions;
  • ensure that Personal Data supplied to or made accessible to EQC is accurate, complete, and current where appropriate;
  • remain responsible for responding to data-subject requests and for the professional and regulatory obligations applicable to its audit-client data.

5. EQC Processing Obligations

Where EQC acts as Data Processor, EQC will:

  • process Personal Data only for the instructed purpose, except where required by applicable law;
  • ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations;
  • implement technical and organisational measures appropriate to the risks of the Processing, taking account of the actual service, systems, and access arrangements;
  • retain Personal Data only for the period necessary for the instructed Processing or as required by applicable law;
  • not sell or use Personal Data for unrelated purposes;
  • assist the CPA Practice Unit with privacy and security matters to the extent reasonably possible and appropriate to the service arrangement.

Any statement about encryption, access controls, monitoring, backups, security testing, service locations, or retention periods must reflect measures actually implemented by EQC and should be confirmed in the applicable service documentation rather than assumed from this DPA.

6. Incident Support

If EQC becomes aware of a Personal Data incident affecting Personal Data that it processes as Data Processor, EQC will notify the CPA Practice Unit without undue delay, subject to applicable law. EQC will provide available information appropriate to the incident, such as its nature and scope, categories of affected Personal Data or individuals where known, likely consequences, and containment or remedial measures taken or proposed.

EQC will take reasonable steps within its control to contain, investigate, and mitigate the incident and to assist the CPA Practice Unit with its assessment and communications as appropriate. The CPA Practice Unit remains responsible for deciding whether notification to individuals, the Privacy Commissioner for Personal Data, clients, regulators, or other parties is required.

7. Individual Requests and Audit

7.1 Requests

EQC will, to the extent reasonably practicable and appropriate to the Processing, assist the CPA Practice Unit in responding to valid requests for access to or correction of Personal Data. If EQC receives a request relating to Personal Data processed on behalf of the CPA Practice Unit, EQC will notify the CPA Practice Unit promptly and will not respond substantively unless required by applicable law or authorised by the CPA Practice Unit.

7.2 Compliance Information and Audit

EQC will make available information reasonably necessary to demonstrate compliance with this DPA, taking account of EQC’s confidentiality and security obligations. Any audit or inspection must be agreed in advance, limited to relevant Processing, conducted during normal business hours, and subject to reasonable confidentiality, security, and cost arrangements agreed by the parties.

8. Termination, Return, and Deletion

On termination of the relevant service, EQC will, at the CPA Practice Unit’s documented choice and to the extent EQC holds Personal Data as Data Processor, securely return or delete that Personal Data, unless retention is required by applicable law. Backup copies, logs, or records may remain for the period and in the manner actually required by EQC’s documented backup, legal-hold, or retention procedures; their further Processing must remain restricted.

The parties should confirm the actual return format, request process, deletion timing, backup rotation, and any deletion confirmation procedure in the applicable service documentation.

9. Subprocessors and Cross-Border Transfers

EQC will not appoint a Subprocessor that processes Personal Data on behalf of the CPA Practice Unit unless the appointment is authorised under the applicable written service arrangement and the Subprocessor is bound by data-protection obligations appropriate to the Processing. EQC remains responsible for its own obligations under this DPA.

EQC will not transfer Personal Data outside Hong Kong, or permit onward transfer, unless the transfer is authorised by the CPA Practice Unit in writing, the receiving party is subject to appropriate contractual or other safeguards, and the transfer is handled consistently with applicable law. The parties should confirm the actual processing locations, recipients, and transfer safeguards before any cross-border Processing begins.

10. Liability, Precedence, Changes, and Acceptance

EQC’s liability under this DPA is limited to the extent permitted by applicable law and the applicable written agreement. The CPA Practice Unit is responsible for claims, loss, damage, or expense arising from its own unlawful instructions, lack of authority, or non-compliance with applicable data-protection requirements, subject to applicable law.

If a conflict arises between this DPA and the applicable written commercial agreement on Personal Data processing, the parties should apply the document that expressly addresses the relevant Processing, except where applicable law requires otherwise. EQC may update this DPA from time to time; the current version will show its “Last Updated” date, and any material changes should be notified in a manner appropriate to the relevant service arrangement.

By installing or using AP4.1, and where this DPA applies to an actual EQC Processing arrangement, the CPA Practice Unit confirms that it has read and understood this DPA.

Related terms:

Publication note: This DPA is a structured draft. EQC should validate its actual architecture, support access, processing roles, security controls, subprocessors, locations, retention/deletion, incident processes, and incorporated agreement terms, then obtain qualified Hong Kong legal review before publication.

Scroll to Top