Third Party Index

Snapshot 16875

Document
Data processing addendum
URL
https://www.moodys.com/web/en/us/site-assets/coretermsdataprocessingschedule.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
133731 bytes
SHA-256 (raw)
c932aef2f64a957e849fbb0cd8c5c0dbe062f14a6b36f6485add36b100731b0d
SHA-256 (normalized text)
936f8237935b36ff4bbf5e1617f9d108d94ddadcbf113f7ba3ed4b9a35086c98

Normalized text

Scripts and page chrome removed; this is what change detection compares.

                                                    DATA PROCESSING SCHEDULE
                                                     Last updated October 1, 2025

This Data Processing Schedule (“DPS”) is made part of, and is hereby incorporated by reference into, the Agreement as defined
below.

1.      Definitions. For purposes of this DPS:

1.1.    “Agreement” means the document that references this DPS, which may include, as applicable, Moody’s Core Terms, the
        Master Subscription Services Agreement, the Master License and Services Agreement, the MSTTC, the Terms of Agreement,
        an Order Form, or other mutually executed writing between the parties referencing this DPS.

1.2.    “Content” either (a) has the meaning in the Core Terms, (b) is interchangeable with the term “Information” in the Terms of
        Agreement, or, if neither (a) nor (b) are applicable, means (c) information including but not limited to publications, reports, white
        papers, and all research, analysis, forecasts, ratings, opinions, models, security identifiers, methodologies and data, that
        Moody’s makes available under an Order Form, and includes any modifications, updates or derivations of the same. For
        purposes of this DPS, Content is not a Product.

1.3.    “Customer” means the party identified as such in the Agreement, which may also be referred to as “Client” or “Subscriber” in
        the Agreement.

1.4.    “Customer Personal Data” means Personal Data Moody’s Processes on behalf of Customer as Customer’s Data Processor or
        Sub-processor    in    relation    to    one      or     more     Product    or   Content    offering    listed   at
        https://www.moodys.com/web/en/us/legal/descriptions-of-processing-data.html.

1.5.    “Data Protection Legislation” means data privacy laws applicable to a party in its processing of Personal Data under this DPS,
        which may include, but is not limited to, the EU General Data Protection Regulation (2016/679).

1.6.    “Data Controller” means the party which determines the purposes and means of the Processing of Personal Data.

1.7.    “Data Processor” means a party which Processes Personal Data on behalf of a Data Controller.

1.8.    “Individual” means any natural person about whom Personal Data may be Processed under this DPS.

1.9.    “Personal Data” means any information that relates to an identified or identifiable natural person that may be Processed under
        this DPS.

1.10. “Process” means the collection, recording, organization, structuring, alteration, use, access, disclosure, copying, transfer,
      storage, deletion, combination, restriction, adaptation, retrieval, consultation, destruction, disposal, or other use of Personal
      Data under this DPS.

1.11. “Products” either (a) has the meaning in the Agreement, or (b) is interchangeable with the terms “Software Programs” or “SaaS
      Software Programs,” or “Hosted Services.”

1.12. “Relationship Management Data” means limited Personal Data Processed by a party about the other party’s employees or
      non-employees, including but not limited to name, job title, name of employer, business e-mail address, business postal
      address, business telephone number, internet protocol address, Product or Content usage tracking data.

1.13. “Security Incident” means any accidental or unauthorized access, acquisition, use, modification, disclosure, loss, destruction
      of, or damage to Customer Personal Data, or any other unauthorized Processing of Customer Personal Data.

1.14. “Sub-processor” means a party which Processes Personal Data as a Subcontractor of the Data Processor.

Other capitalized terms used but not defined in this DPS have the meaning given in the Agreement.

2.      Processing of Relationship Management Data.

2.1.    Where each party Processes Relationship Management Data in the capacity of an independent Data Controller, each party
        will comply with Data Protection Legislation. Information regarding how Moody’s Processes Relationship Management Data is
        available at https://www.moodys.com/web/en/us/legal/privacy-policy.html.

3.      Moody’s Data Controller Product and Content Offerings.

Page 1 of 4                                                                                                                  v. October 1, 2025
3.1.    Where Moody’s acts as an independent Data Controller in relation to Processing Personal Data in Content it makes available
        to Customers, including Content delivered through Products, Moody’s will comply with Data Protection Legislation and the
        Agreement.    Information   regarding    how    Moody’s     Processes     such    Personal     Data   is    available   at
        https://www.moodys.com/web/en/us/about-us/trust-center/privacy-notices.html.

3.2.    Where Customer acts an independent Data Controller in relation to Processing Personal Data in its use of the Products and
        Content, it will comply with Data Protection Legislation and the Agreement.

3.3.    For the avoidance of doubt, the parties will not operate as joint Data Controllers.

4.      Moody’s as Customer’s Data Processor or Sub-processor. Where Moody’s Processes Customer Personal Data, the parties
        agree to the following:

4.1.    Moody’s will Process Customer Personal Data: (i) solely in accordance with the Agreement, (ii) according to other documented
        instructions of Customer (whether in written or electronic form), provided such instructions are consistent with the Agreement
        and applicable law, (iii) as necessary to deliver the Products, Content or related services, or (iv) as otherwise required by law
        applicable to Moody’s. Moody’s will inform Customer if, in its reasonable opinion, an instruction under section 4.1(ii) infringes
        applicable laws.

4.2.    Moody’s will hold Customer Personal Data in confidence pursuant to the confidentiality provisions of the Agreement and will
        require that Moody’s personnel granted access to Customer Personal Data are subject to confidentiality obligations.

4.3.    The subject matter, nature and purpose of the Processing is to provide the Products and Content. The duration of the
        Processing is until Moody’s returns or deletes the Customer Personal Data in accordance with the Agreement. The categories
        of Customer Personal Data and affected Individuals are described in the Description of Processing for the applicable Products
        or Content at https://www.moodys.com/web/en/us/legal/descriptions-of-processing-data.html.

4.4.    In connection with the performance of the Agreement, Moody’s may transfer Customer Personal Data outside the jurisdiction
        in which Customer is established. Moody’s will protect Customer Personal Data in accordance with this DPS regardless of the
        jurisdiction in which it is located. If required by Data Protection Legislation, the parties will enter into EU Standard Contractual
        Clauses or maintain another method of adequacy or implement other measures sufficient to allow Moody’s to receive Customer
        Personal Data in compliance with Data Protection Legislation, including entering into any similar data transfer agreements
        required by Data Protection Legislation in other countries. Moody’s will maintain a list of its processing locations and will provide
        this list to Customer upon Customer’s request or otherwise make this list available to Customer, which may include providing
        access to this list available at https://www.moodys.com/web/en/us/legal/descriptions-of-processing-data.html or on Moody’s
        Customer Portal; and at least thirty (30) days before adding any processing location to this list, Moody’s will provide Customer
        notice of such addition(s), which may include notice provided on the same page of Moody’s website that contains such list, so
        that Customer has the opportunity to object to such addition(s), subject to the remaining terms of this section. Any objections
        made by Customer pursuant to this section must be in writing, substantiated with a reasonable and valid explanation for the
        objection, and submitted to the Moody’s contact identified on the aforementioned website before the end of the stated thirty
        (30) day period. If Customer provides such a reasonable and substantiated objection to such addition(s) in accordance with
        this section, and Moody’s is unable to provide a suitable alternative, then Customer may elect to exercise its termination rights
        without any action, claim or proceedings for liability, costs, refunds or damages against Moody’s under the Agreement. Moody’s
        has entered into EU Standard Contractual Clauses (Module Three: Processor to Processor), and similar data transfer
        agreements required by Data Protection Legislation in other countries, to facilitate intragroup transfers of Customer Personal
        Data between Moody’s Affiliates.

4.5.    Moody’s will implement appropriate technical and organizational safeguards designed to protect Customer Personal Data,
        including Customer Personal Data provided as Business Data under the Agreement, against Security Incidents, which will
        include the measures listed in the Information Security Standards Schedule, available at www.moodys.com/coretermsinfosec.
        Moody’s may modify such safeguards from time to time, provided that such modifications will not materially reduce the overall
        level of protection for Customer Personal Data. At Customer’s request, Moody’s will provide reasonable assistance to
        Customer in meeting its obligations under Data Protection Legislation with respect to the security of the Processing of
        Customer Personal Data through the Products and Content, where Customer cannot meet its obligations without Moody’s
        assistance, and taking into account the nature of the Processing and the information available to Moody’s.

4.6.    Moody’s will promptly notify Customer, unless prohibited by applicable laws, if Moody’s receives: (i) any requests from an
        Individual with respect to Moody’s Processing of Customer Personal Data, including but not limited to opt-out requests,
        requests for access and/or rectification, blocking, erasure, requests for data portability, and all similar requests, and will not
        respond to any such requests unless expressly authorized to do so by Customer; or (ii) any complaint relating to Moody’s
        Processing of Customer Personal Data, including allegations that such Processing infringes on an Individual’s rights. Customer
        is responsible for ensuring the accuracy of any Customer Personal Data provided to Moody’s. At Customer’s request, Moody’s
        will provide reasonable assistance to Customer in meeting its obligations under Data Protection Legislation with respect to
        requests from Individuals where Customer cannot meet its obligations without Moody’s assistance. Customer agrees that

Page 2 of 4                                                                                                                  v. October 1, 2025
        Moody’s may disclose Customer Personal Data to Sub-processors for the purposes of providing Products and Content to
        Customer, provided that Moody’s will impose on its Sub-processors no less onerous obligations than as set forth in this DPS.
        Moody’s will maintain a list of its Sub-processors and will provide this list to Customer upon Customer’s request or otherwise
        make this list available to Customer, which may include providing access to this list available at
        https://www.moodys.com/web/en/us/legal/descriptions-of-processing-data.html or on Moody’s Customer Portal; and at least
        thirty (30) days before adding any Sub-processor to this list, Moody’s will provide Customer notice of such addition(s), which
        may include notice provided on the same page of Moody’s website that contains such list, so that Customer has the opportunity
        to object to such addition(s), subject to the remaining terms of this section. Any objections made by Customer pursuant to this
        section must be in writing and submitted to the Moody’s contact identified on the aforementioned website before the end of
        the stated thirty (30) day period. If Customer objects to such addition(s) in accordance with this section, and Moody’s is unable
        to provide a suitable alternative, then Customer may elect to exercise its termination rights without any action, claim or
        proceedings for liability, costs, refunds or damages against Moody’s under the Agreement. Moody’s will remain responsible for
        all actions by Sub-processors with respect to Customer’s Personal Data and for Moody’s compliance with its obligations under
        this DPS.

4.7.    In the event of a Security Incident, Moody’s will notify Customer promptly in accordance with the time frames prescribed by
        applicable laws, unless otherwise prohibited by law or otherwise instructed by a law enforcement or supervisory authority.
        Following such notification, Moody’s will provide reasonable assistance and cooperation requested by Customer in the
        furtherance of any correction or remediation of any Security Incident.

4.8.    Upon Customer’s request, Moody’s will provide reasonable assistance to Customer in the event of an investigation by a
        competent regulator, including a data protection regulator or similar authority, or the submission by Customer of a data
        protection impact assessment or prior consultation document, if required by the competent regulator, solely if and to the extent
        that such data protection impact assessment or prior consultation document relates to Moody’s Processing of Customer
        Personal Data pursuant to this DPS.

4.9.    Upon termination or expiration of the Agreement for any reason, Moody’s will return or destroy Customer Personal Data at
        Customer’s request, except as otherwise required by law applicable to Moody’s.

4.10. Customer acknowledges that Moody’s is regularly audited by independent third-party and Moody’s internal auditors.

        (a) In order to establish Moody’s compliance with this DPS, Moody’s will provide to Customer, upon Customer’s written
            request, copy third-party assessments such as a SSAE 18 SOC report or comparable report (“Third-Party Report”) where
            Moody’s has obtained such a Third-Party Report for the applicable Products and Content, and written responses to all
            reasonable requests for information related to the applicable Products and Content, including responses to information
            security and audit questionnaires.

        (b) Only to the extent that information provided under (i) is insufficient to reasonably establish Moody’s compliance with this
            DPS, or where required by a competent regulator, Customer and its authorized representatives may conduct an audit of
            Moody’s books and records as necessary to establish Moody’s compliance with this DPS during the term of the relevant
            Order Form. Any audit must be conducted not more than once per year, during Moody’s regular business hours, with
            reasonable advance notice of not less than forty-five (45) days, conducted in good faith, and subject to reasonable
            confidentiality procedures. Such audit must not require Moody’s to disclose to Customer or its authorized representatives
            any information of other Moody’s Customers, internal accounting or financial information, trade secrets, or information
            that, in Moody’s reasonable opinion, could compromise the security of Moody’s systems or premises or cause Moody’s to
            breach its obligations under applicable Data Protection Legislation or privacy obligations to third parties. Customer must
            promptly provide Moody’s with information regarding any non-compliance discovered during the course of an audit.

        (c) Any information provided to Customer pursuant to this section will be considered Moody’s Confidential Information under
            the confidentiality provisions of the Agreement and will be handled accordingly.

4.11. In the event of any direct conflict between the Agreement and this DPS, this DPS shall govern.

4.12. If applicable, the following California Consumer Privacy Act Addendum (“CCPA Addendum”) is made part of and hereby
      incorporated by reference into this DPS.

Page 3 of 4                                                                                                              v. October 1, 2025
                                                          CCPA ADDENDUM

If applicable, the following terms of this CCPA Addendum govern how Moody’s will treat all personal information subject to the
California Consumer Privacy Act, as amended by California Privacy Rights Act (collectively, “CCPA”) that Moody’s collects pursuant
to Moody’s Agreement with Customer. In the event of a conflict, this CCPA Addendum shall govern and control with respect to
personal information subject to CCPA that Moody’s collects pursuant to the Agreement. Terms used herein have the same definitions
set forth in CCPA when explicitly defined in CCPA.

1.      Moody’s shall not sell or share personal information it collects pursuant to the Agreement with Customer.

2.      The Customer is only disclosing the personal information to Moody’s for the limited business purpose specified in the
        Agreement.

3.      Moody’s shall not retain, use, or disclose the personal information that it collected pursuant to the Agreement with Customer
        for any purposes other than those specified in the Agreement or as otherwise permitted by the CCPA and its regulations.

4.      Moody’s shall not retain, use, or disclose personal information it collected pursuant to the Agreement with Customer for any
        commercial purpose other than those specified in the Agreement unless expressly permitted by the CCPA or its regulations.

5.      Moody’s shall not retain, use, or disclose the personal information it collected pursuant to the Agreement with Customer outside
        the direct business relationship between Moody’s and Customer, unless expressly permitted by the CCPA or its regulations.

6.      Moody’s shall comply with all applicable sections of the CCPA and its regulations, including—with respect to the personal
        information that it collected pursuant to the written contract with Customer—providing the same level of privacy protection as
        required of businesses by the CCPA and its regulations.

7.      Customer has the right to take reasonable and appropriate steps to ensure that Moody’s uses the personal information it
        collected pursuant to the Agreement with Customer in a manner consistent with Customer’s obligations under the CCPA and
        its regulations.

8.      Moody’s shall notify Customer after it makes a determination that it can no longer meet its obligations under the CCPA and its
        regulations.

9.      Customer has the right, upon notice, to take reasonable and appropriate steps to stop and remediate Moody’s unauthorized
        use of personal information.

10.     Moody’s must enable the Customer to comply with consumer requests made pursuant to the CCPA.

Page 4 of 4                                                                                                             v. October 1, 2025