Enterprise Service Level and Operational Continuity Framework
Public framework for service levels and support principles; binding commitments are those set out in the customer-specific signed SLA or order.
Regulatory and governance references
- Executed contract, order and SLA
- Applicable business-continuity and disaster-recovery plan
- Regulation (EU) 2023/2854 for applicable switching duties of data-processing services
- Customer sectoral resilience and security obligations
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Nature of the Framework and Priority of the Signed SLA
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Requests are prioritised by impact and urgency. Response time measures acknowledgement and engagement, not necessarily resolution; critical priorities require defined escalation channels, contacts and minimum diagnostic information.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. Measured Service Scope
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
The responsible legal entity must be unambiguously identifiable. Corporate details, contact channels and the relevant privacy role are kept separate from the commercial product name; a division or internal business unit does not change legal ownership unless expressly stated.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. Availability and Service Windows
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Availability is calculated using the formula, scope and measurement period defined in the SLA, excluding only agreed categories. Application outage, planned maintenance, third-party failure and degraded functionality must be distinguished; measurement should rely on verifiable sources.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. Scheduled Maintenance
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Emergency and Security Maintenance
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. Priority Classification
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Requests are prioritised by impact and urgency. Response time measures acknowledgement and engagement, not necessarily resolution; critical priorities require defined escalation channels, contacts and minimum diagnostic information.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. Acknowledgement and Response Times
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Requests are prioritised by impact and urgency. Response time measures acknowledgement and engagement, not necessarily resolution; critical priorities require defined escalation channels, contacts and minimum diagnostic information.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. Restoration Times and Operational Objectives
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
RTO and RPO, if offered, must be expressly stated in the SLA and aligned with the architecture. Without executed values they cannot be inferred from public material; disaster recovery and application restoration should be tested periodically where required by the continuity plan.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. External Dependencies and Third-Party Services
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. Backup, Restore and Disaster Recovery
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Application backups should be encrypted, tested and held separately from the primary environment. RPO and RTO are not implicit software characteristics but contractual objectives dependent on hosting and continuity architecture; restoration must include integrity and functional checks before reopening the service.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. Incident and Status Communications
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Exclusions and Customer Responsibilities
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Service Review, KPIs and Improvement
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
14. Service Credits and Contractual Remedies
Binding service levels are only those agreed in the executed customer SLA. This document defines the enterprise method for measuring availability, acknowledgement, restoration, incident communication and continuity while accounting for infrastructure and third-party dependencies and customer operational responsibilities.
Service credits, penalties or remedies apply only where expressly agreed. They do not replace non-excludable obligations or rights; calculation, claim window and exclusions should be defined in the governing contract.
Metrics must be calculable and verifiable. Exclusions should be limited to defined events and dependencies so that service levels remain meaningful; monitoring evidence should be retained for the agreed period.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.