
DORA Addendum for ICT Services
Last Updated: 20 April 2026
- ABOUT US
- GENERAL TERMS
- SERVICE SPECIFIC TERMS
- OPENPAYD PRIVACY NOTICE
- DATA PROCESSING AGREEMENT
- INFORMATION SECURITY STATEMENT
- DORA ADDENDUM FOR ICT SERVICES
The European Union’s Digital Operational Resilience Act (2022/2554) (“DORA”), which entered into force on 16 January 2023 and will apply from 17 January 2025, imposes obligations on EU-regulated entities regarding their management of ICT risk.
This DORA Addendum applies only to clients who are “financial entities”, as defined in DORA Article 2(1) points (a) to (t).
By providing payment-processing activities and/or operating payment infrastructures,OpenPayd may be considered as an ICT third-party service provider under DORA.
The purpose of this DORA Addendum is to ensure that the contractual provisions required by DORA are reflected in the agreement between OpenPayd and in-scope financial entities.
This DORA Addendum supplements and forms part of your agreement with OpenPayd (the “Agreement”), save to the extent that the provisions of the Agreement already comply withthe requirements of DORA. To the extent that there are provisions in the Agreement which comply with DORA in their entirety, or provide for rights and obligations which are more extensive than DORA, those provisions shall not be affected by this DORA Addendum.
To the extent that OpenPayd and (where relevant) OpenPayd’s Affiliates provide any services that are not in scope for DORA, this DORA Addendum shall not apply to the provision of such services.
| “Affiliate” | Means, whether in the case of Customer or OpenPayd, as applicable, with respect to a specified entity, any entity that controls, is controlled by, or is under common control with that entity, where the term “control” (including with correlative meanings, the terms “controlled by” and “under common control with”) means the possession directly or indirectly of the power to direct or cause the direction of the management and policies of an entity, whether through the ownership of more than 50% of voting securities or by contract. |
| “Applicable Law” | Means any law, rules, or regulation applicable to that OpenPayd or Customer (including rules of any Regulator), as amended from time to time. |
| “Confidential Information” | Means all information, data, materials, records, notes, drafts, and any other documents or materials disclosed by Customer and/or any of its Affiliates to OpenPayd, or which come to OpenPayd’s attention, or to the attention of any of OpenPayd’s Subcontractors, during the course of performing its obligations under the Agreement, regardless of whether such information is owned by Customer, its Affiliates, or third parties. |
| “Customer” | Means a customer of OpenPayd who is also a “financial entity,” as defined in DORA Article 2(1) points (a) to (t). |
| “Customer Data” | Means all data, information, text, drawings, and other materials supplied to OpenPayd by the Customer or that OpenPayd generates, collects, processes, stores, or transmits in connection with the Agreement. |
| “OpenPayd” | The OpenPayd entity that Customer contracts with, as set out in the Agreement. |
| “Regulator” | Means any governmental agency, authority, and/or regulator with jurisdiction over a party and its respective Affiliates. |
| “Services” | Means the ICT services provided by OpenPayd and/or its Affiliates to Customer under the Agreement. |
| “Subcontractor” | Means another supplier to whom OpenPayd may subcontract, outsource, or otherwise delegate in whole or in part its obligations under the Agreement. |
Regulatory Requirements
1 The Services [DORA Article 30(2)(a) & Article 30(2)(e)]
1.1 OpenPayd will provide Customer with the Services in accordance with the service description and performance standards set out in the Agreement.
2 Incident Management [DORA Article 30(2)(f)]
2.1 If Customer or OpenPayd confirm the existence of, or in goodfaith reasonably suspect there has been, a single event or series of linked events that have an adverse impact on the functioning or performance, or compromises the security, of any of Customer’s or OpenPayd’s equipment, software, network, information systems, or the availability, authenticity, integrity or confidentiality of data held or controlled by OpenPayd, such that the provision or receipt of the Services is impacted (an “ICT Incident”), OpenPayd shall:
2.1.1 (if OpenPayd is the party impacted by the event(s)), notify Customer of that fact without undue delay (and no later than 24 hours of its actual confirmation of theICT Incident or identification in goodfaith of a suspected ICT Incident), together with reasonable details of the ICT Incident and any steps required to be taken or that it is taking to mitigate the effects of the ICT Incident, including if relevant any steps necessary to reduce the risk of any future breach of security of that same nature;
2.1.2 provide reasonable assistance to Customer (at a cost agreed between the parties) to support Customer to recover from the ICT Incident and to comply with its obligations under Applicable Law including with regard to notifications to the Regulator; and
2.1.3 (if OpenPayd is the party impacted by the event(s)), promptly address and remediate the ICT Incident, and mitigate its effects.
3 Permitted Locations [DORA Article 30(2)(b)]
3.1 OpenPayd will provide the Services from and will store and process Customer Data and Confidential Information in the UK and the EEA. OpenPayd’s subcontractors and banking partners involved in providing the Services may also transfer personal data outside of the UK and the EEA, as set out in our Privacy Notice. Further details regarding the service locations and storage of data are available upon request.
4 Termination [DORA Article 28(7) & Article 30(2)(h)]
4.1 Customer may terminate the Agreement:
4.1.1 immediately on the giving of notice to OpenPayd where OpenPayd is in breach of Applicable Laws;
4.1.2 immediately on the giving of notice to OpenPayd where OpenPayd commits a material breach of the Agreement which is incapable of remedy or, if capable of remedy, is not remedied within thirty (30) days after written notice to Customer of the occurrence of such event;
4.1.3 immediately on the giving of notice to OpenPayd where Customer identifies or becomes aware of circumstances or events which Customer reasonably considers are capable of altering the performance of the Services provided under the Agreement, including material changes that affect the Services or OpenPayd;
4.1.4 immediately on the giving of notice to OpenPayd where there is evidence of weaknesses in the ICT risk management of OpenPayd or any Subcontractor it relies on, including in respect of the security of any Customer Data; and
4.1.5 immediately on the giving of notice to OpenPayd upon request of a Regulator or where Customer is otherwise required to do so by Applicable Law.
5 Consequences of Termination [DORA Article 30(2)(d)]
5.1 If the Agreement is terminated or expires, or in the case of the insolvency, resolution or discontinuation of business operations of OpenPayd, OpenPayd shall ensure that any Regulator can access any data owned by Customer, Customer Data and Confidential Information, and that Customer can access, retrieve, store or otherwise deal with any data owned by Customer, Customer Data and Confidential Information.
6 Information Security [DORA Article 30(2)(c) and (d)]
6.1 OpenPayd shall ensure that its information security measures, and those of any Subcontractor(s) it uses to provide the Services, are appropriate in order to ensure at all times:
6.1.1 the security, availability, authenticity, integrity, confidentiality, and accuracy of Customer Data; and
6.1.2 that the Customer Data can be traced, recovered, disposed of or deleted as may be requested by Customer at any time.
6.2 OpenPayd shall ensure that Customer Data can be accessed, recovered and returned to Customer as needed and in an accessible format.
7 Awareness and Training [DORA Article 30(2)(i)]
7.1 On reasonable request from Customer, OpenPayd shall participate in Customer’s:
7.1.1 ICT security awareness programmes;
7.1.2 digital operational resilience training; and
7.1.3 other similar awareness and training initiatives.
7.2 Where such participation in awareness and training initiatives is requested by Customer, Customer and OpenPayd will agree, in good faith and acting reasonably, which of OpenPayd personnel should participate.
8 Regulatory Assistance [DORA Article 30(2)(g)]
8.1 OpenPayd shall fully cooperate with, and provide Customer with reasonable assistance in connection with, any investigation by or dealings with any Regulators relating to the Agreement, and/or Customer’s purchase or use of the Services. Such assistance shall include OpenPayd:
8.1.1 directing any and all queries from a Regulator relating to the Agreement or the Services to Customer; and
8.1.2 cooperating with and responding to any request for information, confirmations and/or assistance including replying to questions from a Regulator within a reasonable period of time and at the reasonable direction of and in consultation with Customerand/or a Regulator; and
8.1.3 granting each Regulator the right to give instructions in order to (i) prevent any breach of regulatory requirements (ii) remove any obstacles that hinder the Regulator’s audit rights and (iii) to remove any defects that impact the integrity of any entrusted assets or the due performance of the Services and/or financial services.
8.2 OpenPayd will further ensure that its Subcontractors fully cooperate with Customer and Regulators as is necessary for the discharge of Customer’s legal and regulatory obligations.