Snapshot 65025
Normalized text
Scripts and page chrome removed; this is what change detection compares.
ITCI Data Processing Terms & Conditions
In the provision of certain services under the terms of the Principal Agreement(s) as defined below, Customer,
as controller will require ITCI to process certain personal data received from Customer.
The parties agree that these terms and conditions shall apply to all such processing undertaken by ITCI on
behalf of Customer and shall be supplemental to the terms of the Principal Agreement.
1. Appointment that has executed standard contractual
Customer as controller of certain personal data clauses adopted or approved by the European
appoints ITCI as processor to process the Commission.
personal data listed in Schedule 1 (the “Data")
for the purposes also described in the 4. Confidentiality of processing
Schedule1 (or as otherwise agreed in writing by ITCI shall ensure that any person it authorizes to
the parties) (the "Permitted Purpose"). Each process the personal data (an "Authorized
party shall comply with the obligations that Person") have committed themselves to
apply to it under Applicable Data Protection preserve the confidentiality of such personal
Law. data.
2. Definitions 5. Security
In these terms and conditions, the following ITCI shall implement the technical and
terms shall have the following meanings: organizational measures as set out in the
(a) “Principal Agreements”: Any agreement Schedule 1 to protect the personal data (i) from
between ITCI and Customer under the accidental or unlawful destruction, and (ii) loss,
terms of which ITCI provides services alteration, unauthorized disclosure of, or access
Customer; to the personal data.
(b) "controller", "processor", "data subject", 6. Subcontracting
"personal data", “personal data breach” Customer as controller consents to ITCI
"processing" (and "process") and "special engaging third party subprocessors mentioned
categories of personal data" and in Schedule 2 to process the Data for the
“supervisory authority” shall have the Permitted Purpose. The list of subprocessors
meanings given in Applicable Data mentioned in Schedule 2 shall be updated with
Protection Law; and details of any change in subprocessors at least
10 days' prior to any such change taking effect;
(c) "Applicable Data Protection Law" (ii) ITCI imposes data protection terms on any
shall mean, where personal data of EU subprocessor it appoints that require it to
residents is processed (i) prior to 25 May protect the personal data to the standard
2018, the EU Data Protection Directive required by Applicable Data Protection Law;
(Directive 95/46/EC); (ii) on and after 25 and (iii) ITCI remains liable for any breach of this
May 2018, the EU General Data Protection Clause that is caused by an act, error or
Regulation (Regulation 2016/679), and (iii) omission of its subprocessor. Customer may
where personal data of non-EU residents is object to ITCI’s appointment or replacement of
processed any applicable privacy law in a subprocessor prior to its appointment or
the relevant jurisdiction. replacement, provided such objection is based
on reasonable grounds relating to data
All other terms shall be as defined in the protection. In such event, Customer may
applicable Principal Agreement. require ITCI to suspend or terminate all
3. International transfers processing activities (without prejudice to any
As a global company ITCI may need to transfer fees incurred by or committed to by Customer
personal data out of the country that the under the terms of the Principal Agreement
Customer or the data subjects are located. All prior to suspension or termination).
such transfers shall be in accordance with
measures that permit the lawful transfer of 7. Cooperation and data subjects' rights
personal data out of the EEA such as ITCI shall provide reasonable and timely
transferring the personal data to a recipient assistance to Customer (at Customer's
Page 1 of 5
expense) to enable Customer to respond to: (i) any further processing except to the extent
any request from a data subject to exercise any required by such law.
of its rights under Applicable Data Protection
Law (including its rights of access, correction, 10. Audit
objection, erasure and data portability, as Customer acknowledges that ITCI is regularly
applicable); and (ii) any other audited for compliance with various
correspondence, enquiry or complaint internationally recognized standards as more
received from a data subject, regulator or specifically detailed in the Schedule(s) by
other third party in connection with the independent third party auditors. Upon
processing of the Data. In the event that any request, ITCI shall supply a summary / redacted
such request, correspondence, enquiry or copy of its audit report(s) to Customer, which
complaint is made directly to ITCI, ITCI shall reports shall be subject to the confidentiality
promptly inform Customer providing full details provisions these terms and conditions. ITCI shall
of the same. also respond to any written audit questions
submitted to it by Customer, provided that
8. Personal Data Breach Customer shall not exercise this right more than
If it becomes aware of a confirmed personal once per year. Notwithstanding the foregoing,
data breach, ITCI shall inform Customer without in the event of an audit request directly from a
undue delay and shall provide reasonable Supervisory Authority, ITCI shall always assist
information and cooperation to Customer so Customer in answering the request and
that Customer can fulfil any data breach organizing an audit.
reporting obligations it may have under (and in
accordance with the timescales required by) 11. Liability
Applicable Data Protection Law. ITCI shall Each party's liability to the other in respect of
further take such any reasonably necessary any individual claim for breach of contract,
measures and actions to remedy or mitigate negligence, breach of statutory duty or
the effects of the personal data breach and otherwise in relation to these terms and
shall keep Customer informed of all material conditions will be limited in accordance with
developments in connection with the personal the terms of the Principal Agreement.
data breach.
9. Deletion or return of Personal Data 12. General
Upon termination or expiry of the Principal The laws governing the Principal Agreement
Agreement, ITCI shall (at Customer's election) shall apply to these terms and conditions
destroy or return to Customer all personal data except in the case where personal data of EU
in its possession or control. This requirement shall citizens is being processed and the jurisdiction
not apply to the extent that ITCI is required by of the Principal Agreement is not that of a
applicable law to retain some or all of the member state of the EU, in which case the laws
personal data, or to personal data it has of the Republic of Ireland shall apply in default.
archived on backup systems, which personal These terms and conditions and the terms of the
data ITCI shall securely isolate and protect from Principal Agreement referred to herein
embody the whole agreement of the parties
with respect to its subject matter.
Page 2 of 5
Schedule 1
Security Measures
Description of the technical and organizational security measures implemented by ITCI as processor:
1. Secure user authentication protocols including:
• Control user IDs and other identifiers
• Provide a reasonably secure method of assigning and selecting passwords (or use an
alternative authentication technology such as biometrics or Multifactor authentication)
• Control data security passwords to ensure that such passwords are kept in a location
and/or format that does not compromise the security of the data they protect
• Restrict access to active users and active user accounts only
• Block access to user identification after multiple unsuccessful attempts to gain access
or the limitation placed on access for the particular system
• Restrict access to records and files containing personal information to those who need
such information to perform their job duties
• Assign unique identifications plus passwords, which are not vendor supplied default
passwords, to each person with customer access, that are reasonably designed to
maintain the integrity of the security of the access controls
2. Encrypt (to the extent technically feasible) all transmitted records and files containing personal
information that will travel across public networks, and encryption of all data to be transmitted
wirelessly
3. Implement reasonable monitoring of systems, for unauthorized use of or access to personal
information
4. Encrypt all personal information stored on laptops or other portable devices
5. Provide reasonably up-to-date operating system security patches for files containing personal
information on a system that is connected to the Internet, designed to maintain the integrity of
the personal information
6. Provide reasonably up-to-date versions of endpoint detection and response agent software for
malware protection and reasonably up-to-date sensor versions, or a version of such a software
that can still be supported with up-to-date sensor versions, and is set to receive the most current
sensor updates on a regular basis
7. Educate and train employees on the proper use of the computer security system and the
importance of personal information security
8. Ensure that any third party that may have access to the systems by way of providing services to
ITCI, but which are not providing data processing services, guarantee an equivalent level of
security.
Security Certifications:
ISO 27001:2013
Page 3 of 5
DATA:
Data subjects
The Personal Data relating to the following categories of data subjects:
• Individuals who are authorized by Customer to use access ITCI services being Customer’s
employees, consultants, subcontractors, suppliers, business partners and customers.
• Other individuals whose personal data may be uploaded by Customer to ITCI services.
Personal Data Categories
Name, Company, organization, business contact details, interactions with ITCI’s services such as logfiles
and incident reports, training records and other personal data that an individual may share with ITCI.
IP addresses, cookie data, device identifiers and similar device-related information.
Permitted Purpose:
To DELIVER ITCI SERVICES to Customer in accordance with the terms of the Principal Agreement and
Customer’s instructions.
Page 4 of 5
Schedule 2
ITC Infotech India Ltd. group entities/affiliates may also act as sub‐processors.
Refer to ITCI affiliates list at www.itcinfotech.com/dxp-services/resources/legal-documents
Page 5 of 5