Snapshot 78710
Normalized text
Scripts and page chrome removed; this is what change detection compares.
DATA PROCESSING AGREEMENT
(APRYSE ACTING AS PROCESSOR)
1. Scope
1.1 This Data Processing Agreement (within the meaning of Article 28.3 GDPR) (“DPA”) forms part
of the agreement(s) for the purchase, use and/or licensing of products or services of Apryse
(“Services”), together with its exhibits, statements of works or other incorporated or referenced
documents and any other agreement(s) governed by such agreement(s) (“Agreement”) between
Apryse and Customer.
1.2 In the course of providing the Services to Customer under the Agreement, Apryse may Process
Personal Data on behalf of the Customer in which case parties agree to comply with the provisions
of this DPA. The provisions of this DPA shall only apply to the extent that (and as the case may
be) Apryse (as the Processor) Processes Personal Data on behalf of the Customer (as the
Controller) under the Agreement.
1.3 In case of conflict between any provision of this DPA and any provision or another part of the
Agreement, this DPA shall prevail.
1.4 If at any time any provision of this DPA is or becomes illegal, invalid or unenforceable in any
respect under any law of any jurisdiction, in whole or in part neither the legality, validity or
enforceability of the remaining provisions of this DPA nor the legality, validity or enforceability of
such provisions under the laws of any other jurisdiction will in any way be affected or impaired.
Parties shall make all reasonable efforts and take all necessary actions to replace any illegal,
invalid or unenforceable provision of this DPA with a valid, legal and enforceable provision having
the same economic and legal effect for parties and reflecting to the fullest extent permitted by law
the provision to be replaced.
1.5 The DPA is entered into for the term of the Agreement and remains in full force until the
Processing of Personal Data is no longer required in the framework or pursuant to the Agreement
or longer, if required by law or Data Protection Legislation.
1.6 If the Customer has any questions regarding the Processing of Personal Data by Apryse,
Customer may send such questions to privacy@apryse.com.
2. Definitions
2.1. For the purpose of this DPA, the following terms shall have the following meaning. In case of any
doubt or differences with the terms defined in the Data Protection Legislation, the definitions
stipulated in the relevant Data Protection Legislation shall prevail.
1
“Controller” means the natural or legal person, public authority, agency or any other body which,
alone or jointly with others, determines the purposes and means of the Processing of Personal
Data carried out under its authority, for the purposes of the Consultancy Agreement and the DPA,
being the Customer.
“Data Protection Legislation” means the GDPR together with any other (data protection) laws
resulting from the GDPR and/or all other applicable laws of any country with regard to the
protection of Personal Data or privacy.
“Data Subject” means an identified or identifiable natural person to whom the Personal Data
relates. An identifiable person is one who can be identified, directly or indirectly, in particular by
reference to an identifier such as a name, an identification number, location data, online identifier
or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural
or social identity of that person. The relevant categories of Data Subjects are identified in this
DPA.
“GDPR” means the Regulation 2016/679 of the European Parliament and of the Council of 27
April 2016 on the protection of natural persons with regard to the processing of personal data and
on the free movement of such data.
“Apryse”: Apryse Group NV, with registered office at Kerkstraat 108, 9050 Gentbrugge (Belgium),
with company registration number 0895.263.973.
“Personal Data” means any information relating to a Data Subject within the meaning of Article 4,
1) GDPR. The relevant categories of Personal Data that are provided to Apryse by, or on behalf
of, the Customer, are identified in this DPA.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted,
stored or otherwise Processed in connection with the Agreement and the provision of the
Services.
“Processing”, “Process(es)” or “Processed” means any operation or set of operation which is
performed upon Personal Data or on sets of Personal Data, whether or not by automatic means,
such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval,
consultation, use, disclosure by transmission, dissemination or otherwise making available,
alignment or combination, restriction, erasure or destruction.
“Processor” means a natural or legal person, public authority, agency or any other body which is
authorised to process Personal Data on behalf of the Customer, being Apryse.
“Security Measures” means the technical and organizational measures within the meaning of
Article 32 GDPR aiming at protecting Personal Data against accidental or unlawful destruction or
loss, as well as against non-authorised access, alteration or transmission.
2
“SSCs”: means the standard contractual clauses of which the European Commission on the basis
of Article 26 (4) of Directive 95/46/EC decided that these offer sufficient safeguards for transfers
of personal data to a third country, or the data protection clauses adopted by the European
Commission or by a supervisory authority and approved by the European Commission in
accordance with the examination procedure referred to in Article 93(2) of the GDPR. Data
protection clauses adopted in accordance with the GDPR shall replace and prevail over any
standard contractual clauses adopted on the basis of Directive 95/46/EC to the extent that they
intend to cover the same kind of data transfer relationship.
“Sub-processor” means any Processor engaged as a sub-processor or subcontractor by Apryse
and processes Personal Data for, on behalf of and in accordance with the instructions of Apryse.
“Supervisory Authority” means an independent public authority which is established by a Member
State pursuant to Article 51 GDPR.
“Third Party” means any party who is not a Data Subject, Controller, Processor or Sub-processor
under this DPA or a person who is authorised to process Personal Data under the direct authority
of the Customer or Apryse.
2.2. Any other terms used in this DPA but not defined will have the same meaning as in the Data
Protection Legislation or the Agreement.
3. Details of the Processing
3.1. Subject-nature: the Processing of Personal Data by Apryse (as Processor) on behalf of Customer
(as Controller) relates to the performance of the Services as described in the Agreement and/or
as further specified in the Services-related documentation, and/or as further instructed by the
Customer in its use of the Services of Apryse.
3.2. Means of the Processing: systems, software, products, Services, tools and/or servers of Apryse.
3.3. Categories of Personal Data: identification data (including contact details), financial data and
electronic / connection data (IP address, username, ID data for authentication purposes).
3.4. Categories of Data Subjects: customers and/or prospective customers, end-users (authorized by
the Customer to use the Services), partners, employees, agents or other service providers or
contractors of the Customer.
3.5. Purposes of the Processing: to perform the Services as described in the Agreement, CRM,
support desk and other customer management services or services related hereto and/or to
comply with other documented or written reasonable instructions provided by the Customer where
such instructions are consistent with the terms of the Agreement.
3
3.6. Retention period(s): Apryse will Process Personal Data for the term of the Agreement, unless
otherwise agreed upon in writing or as required by applicable law and no longer than is necessary
for the purposes for which the Personal Data are Processed, unless applicable law requires longer
storage of the Personal Data.
4. General
4.1. Apryse Processes the Personal Data only on behalf of the Customer and in accordance with the
documented or written instructions of the Customer, including with regard to transfers of Personal
Data to a third country or an international organization, unless required to do so by (Union or
Member State) law to which Apryse is subject; in such a case, Apryse shall inform the Customer
of that legal requirement before Processing, unless that law prohibits such information on
important grounds of public interest. The Agreement, including this DPA, is the Customer’s
complete instruction to Apryse with regard to the Processing of Personal Data. Any additional or
alternate instructions must be given in writing and agreed upon by the parties.
4.2. Apryse shall only Process Personal Data in accordance with the purposes specified in section 3.5
above.
4.3. Apryse shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR
or other Data Protection Legislation.
4.4. Any Processing of Personal Data by Apryse under the Agreement shall be performed in
accordance with the applicable Data Protecion Legislation, including the GDPR. Apryse is
however not responsible for compliance with any laws applicable to the Customer or the
Customer’s industry that are generally applicable to Apryse. The Customer shall comply with the
applicable Data Protection Legislation, including the GDPR, as well as any other laws applicable
to the Customer or the Customer’s industry. The Customer is solely responsible for the lawfulness
of the Personal Data. The Customer represents and warrants that, where it provides any Personal
Data to Apryse for Processing, it has duly informed the relevant Data Subject of their rights and
obligations, and in particular has informed them of the possibility of Apryse processing their
Personal Data on the Customer’s behalf and in accordance with its instructions. The Customer
represents and warrants that the Processing of the Personal Data under the DPA is lawful.
4.5. Apryse ensures that the Personal Data is only disclosed to the personnel or persons acting on
behalf of Apryse and that are authorized to Process the Personal Data and who need it to perform
the Services and/or tasks under the Agreement. Apryse ensures that persons authorized to
Process the Personal Data and/or its Sub-processors have committed themselves to
confidentiality or are under an appropriate statutory obligation of confidentiality.
4
5. Transfer of Personal Data
5.1. Apryse agrees to keep all Personal Data and its Processing strictly secret and shall not disclose
or reveal it, in whole or in part, directly or indirectly, to any Third Party, unless with prior written
consent by the Customer or required by law.
5.2. The Customer agrees to allow transfers of Personal Data outside the country from which it was
originally collected provided that such transfers are required in connection with the provision of
the Services under the Agreement and such transfers take place in accordance with Data
Protection Legislation, including, without limitation, completing any prior assessments required by
Data Protection Legislation.
5.3. Where Apryse transfers Personal Data collected in the European Economic Area to a country
outside the European Economic Area and without an adequacy decision under Article 45 of the
GDPR, Apryse shall transfer Personal Data pursuant to the European Commission’s decision
2010/87/EU on SSCs (for the transfer of personal data to processors established in third countries
under Directive 95/46/EC). These SSCs are attached hereto (Exhibit 1), are hereby incorporated
in their entirety into this DPA and, to the extent applicable, Apryse shall ensure that its
Subprocessors comply with the obligations of a data importer (as defined in the SSCs).
6. Security Measures
Apryse shall implement and maintain all appropriate Security Measures to ensure a level of
security to the risks in accordance with Article 32 GDPR. The Customer may request Apryse to
provide an updated description of the implemented Security Measures
7. Sub-processors
7.1. The Customer acknowledges and agrees that Apryse may engage Sub-processors for the
provision of the Services under the Agreement and that Apryse can transfer Personal Data to
these Subprocessors in this context. Apryse shall inform the Customer upon request about all
Sub-processors engaged and that Process Personal Data under the Agreement.
7.2. Apryse shall also inform the Customer of any intended changes concerning the addition or
replacement of Sub-processors, thereby giving the Customer the opportunity to object to such
changes. Customer may object by notifying Apryse in writing within ten (10) business days after
receipt of Apryse’s communication advising of the new Sub-processor or changes.
7.3. Apryse shall enter into a written agreement with any engaged Sub-processor that contains data
protection obligations no less protective than those contained in this DPA.
5
7.4. Where such Sub-processor fails to fulfil its Personal Data protection obligations in accordance
with this DPA and/or Data Protection Legislation, Apryse shall be liable for the performance of
that Sub-processor’s obligations.
8. Assistance and information obligations
8.1. Taking into account the nature of the Processing and the information available to Apryse, Apryse
shall assist the Customer (i) by appropriate technical and organization measures, insofar as this
is possible, for the fulfilment of the Customer’s obligation to respond to requests for exercising the
Data Subject’s rights laid down in Chapter III of the GDPR and (ii) in ensuring compliance with
the obligations pursuant to Article 32-36 GDPR. Apryse shall assist the Customer as it carries out
Data Protection Impact Assessments in accordance with Article 35 GDPR.
8.2. Apryse shall make available to the Customer all information necessary to demonstrate
compliance the GDPR and in particular with the obligations laid down in Article 28 GDPR.
8.3. Apryse shall be entitled to invoice the Customer on a time and material basis at the then-current
prices for any time expended for any such assistance within the meaning of this section 8.
9. Audits
9.1. The Customer is entitled to reasonably verify Apryse’s compliance with the DPA and the Data
Protection Legislation, provided that Apryse shall have no obligation to provide confidential and/or
proprietary information. To this extent, the Customer may, upon request in writing and with prior
notice of thirty (30) calendar days, at its own expense, instruct acknowledged audit professionals
to execute such audit or inspection: (i) once every twelve (12) months provided that such
additional audit inquiries take place during normal office hours and shall not unreasonably impact
in an adverse manner Apryse’s regular operations and do not prove to be incompatible with the
applicable legislation or with the instructions of a competent authority; (ii) where a competent data
protection authority requires this under Data Protection Legislation (including the GDPR); or (iii)
following a Personal Data Breach.
9.2. Before the commencement of any such audit inquiries, parties shall mutually agree upon the
scope, timing and duration of the audit, including conditions of confidentiality. During such audit,
Apryse shall provide reasonable cooperation and assistance to the auditors.
9.3. The Customer shall promptly notify Apryse with information regarding any non-compliance
discovered during the course of such audit. Audit reports, any other information to which the
Customer or the audit professionals have access pursuant to any audit activities, as well as an
attestation of the implementation of the Security Measures, will be considered confidential
information.
6
9.4. Apryse shall be entitled to invoice the Customer on a time and material basis at the then-current
applicable prices for any time expended for any such audit inquiries. The Customer shall not be
entitled to claim compensation for any kind of audit expenses incurred by the Customer (unless
the audit has revealed any breach or any failure by Apryse in which case Apryse shall bear the
costs related to this breach or failure).
10. Personal Data Breaches
10.1. In the event of a Personal Data Breach, and irrespective of its cause, Apryse shall notify the
Customer without undue delay after having become aware of such Personal Data Breach,
specifying where known or readily identifiable: (i) the nature of the Personal Data Breach; (ii) the
categories and approximate number of Data Subjects and Personal Data records concerned; (iii)
as the case may be, any remedial actions taken or proposed to be taken to address the Personal
Data Breach, to mitigate its effects and to prevent re-occurrence and (iv) the identity and contact
details of any other contact person from whom more information can be obtained.
10.2. The Party responsible for the Personal Data Breach shall without undue delay further investigate
the Personal Data Breach and shall keep the other Party informed of the progress of the
investigation and take reasonable steps to further minimize the impact. Both parties agree to fully
cooperate with such investigation and to assist each other in complying with any notification
requirements and procedures.
11. Return and/or deletion of Personal Data
11.1. Upon termination of the DPA and/or the Agreement, Apryse shall delete or anonymize all Personal
Data on its systems (without prejudice to any backup archives) at the latest sixty (60) calendar
days after the last effective day of the DPA and/or the Agreement, unless otherwise instructed by
the Customer or unless applicable law requires longer storage of the Personal Data.
11.2. Upon written request of the Customer, Apryse will provide the Customer with a readable copy in
a standard format of the Personal Data on its systems. The costs related to such request / copy
are at the Customer’s expense.
12. Liability
12.1. Apryse is only liable for the damage caused by the Processing of Personal Data under the DPA
and/or the Agreement where it has not complied with the applicable Data Protection Legislation,
including the GDPR, specifically directed to Processors and/or where it has acted outside or
contrary to lawful instructions of the Customer.
12.2. The provisions of the Agreement on (limitation of) liability fully apply for the Processing of
Personal Data by Apryse under the DPA and/or the Agreement. In any event, Apryse’s
aggregate maximum liability under this DPA will be limited to the sum equal to the highest of the
following amounts: (i) the fees paid under the Agreement by the Customer to Apryse or (ii) the
7
amount of the insurance coverage offered by any of Apryse’s relevant insurance policies. The
right to claim damages attributable to Apryse will be forfeited irrevocably six (6) months after the
occurrence of the alleged error. The Customer must serve a notice of default within the
aforementioned term, providing a detailed description thereof.
8
Exhibit 1. EU Standard Contractual Clauses (2010/87/EU)
These SCCs are attached to and made part of this DPA. For the purposes of Article 26(2) of Directive
95/46/EC for the transfer of personal data to processors established in third countries which do not
ensure an adequate level of data protection. The data exporter and data importer are as described in
the DPA and HAVE AGREED on the following Contractual Clauses (the “Clauses”) in order to adduce
adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of
individuals for the transfer by the data exporter to the data importer of the personal data specified in
Appendix 1.
Clause 1
Definitions
For the purposes of the Clauses:
(a) ‘personal data’, ‘special categories of data’, ‘process/processing’, ‘controller’, ‘processor’, ‘data
subject’ and ‘supervisory authority’ shall have the same meaning as in Directive 95/46/EC of
the European Parliament and of the Council of 24 October 1995 on the protection of individuals
with regard to the processing of personal data and on the free movement of such data;
(b) ‘the data exporter’ means the controller who transfers the personal data;
(c) ‘the data importer’ means the processor who agrees to receive from the data exporter personal
data intended for processing on his behalf after the transfer in accordance with his instructions
and the terms of the Clauses and who is not subject to a third country’s system ensuring
adequate protection within the meaning of Article 25(1) of Directive 95/46/EC;
(d) ‘the sub-processor’ means any processor engaged by the data importer or by any other
subprocessor of the data importer who agrees to receive from the data importer or from any
other sub-processor of the data importer personal data exclusively intended for processing
activities to be carried out on behalf of the data exporter after the transfer in accordance with
his instructions, the terms of the Clauses and the terms of the written subcontract;
(e) ‘the applicable data protection law’ means the legislation protecting the fundamental rights and
freedoms of individuals and, in particular, their right to privacy with respect to the processing
of personal data applicable to a data controller in the Member State in which the data exporter
is established;
(f) ‘technical and organisational security measures’ means those measures aimed at protecting
personal data against accidental or unlawful destruction or accidental loss, alteration,
unauthorised disclosure or access, in particular where the processing involves the
transmission of data over a network, and against all other unlawful forms of processing.
9
Clause 2
Details of the transfer
The details of the transfer and in particular the special categories of personal data where applicable are
specified in Appendix 1 which forms an integral part of the Clauses.
Clause 3
Third-party beneficiary clause
1. The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause
5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as
third-party beneficiary.
2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g),
Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has
factually disappeared or has ceased to exist in law unless any successor entity has assumed
the entire legal obligations of the data exporter by contract or by operation of law, as a result of
which it takes on the rights and obligations of the data exporter, in which case the data subject
can enforce them against such entity.
3. The data subject can enforce against the sub-processor this Clause, Clause 5(a) to (e) and (g),
Clause 6, Clause 7, Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter
and the data importer have factually disappeared or ceased to exist in law or have become
insolvent, unless any successor entity has assumed the entire legal obligations of the data
exporter by contract or by operation of law as a result of which it takes on the rights and
obligations of the data exporter, in which case the data subject can enforce them against such
entity. Such third-party liability of the sub-processor shall be limited to its own processing
operations under the Clauses.
4. The parties do not object to a data subject being represented by an association or other body if
the data subject so expressly wishes and if permitted by national law.
Clause 4
Obligations of the data exporter
The data exporter agrees and warrants:
(a) that the processing, including the transfer itself, of the personal data has been and will continue
to be carried out in accordance with the relevant provisions of the applicable data protection
law (and, where applicable, has been notified to the relevant authorities of the Member State
where the data exporter is established) and does not violate the relevant provisions of that
State;
(b) that it has instructed and throughout the duration of the personal data-processing services will
instruct the data importer to process the personal data transferred only on the data exporter’s
behalf and in accordance with the applicable data protection law and the Clauses;
10
(c) that the data importer will provide sufficient guarantees in respect of the technical and
organisational security measures specified in Appendix 2 to this contract;
(d) that after assessment of the requirements of the applicable data protection law, the security
measures are appropriate to protect personal data against accidental or unlawful destruction
or accidental loss, alteration, unauthorised disclosure or access, in particular where the
processing involves the transmission of data over a network, and against all other unlawful
forms of processing, and that these measures ensure a level of security appropriate to the risks
presented by the processing and the nature of the data to be protected having regard to the
state of the art and the cost of their implementation;
(e) that it will ensure compliance with the security measures;
(f) that, if the transfer involves special categories of data, the data subject has been informed or
will be informed before, or as soon as possible after, the transfer that its data could be
transmitted to a third country not providing adequate protection within the meaning of Directive
95/46/EC;
(g) to forward any notification received from the data importer or any sub-processor pursuant to
Clause 5(b) and Clause 8(3) to the data protection supervisory authority if the data exporter
decides to continue the transfer or to lift the suspension;
(h) to make available to the data subjects upon request a copy of the Clauses, with the exception
of Appendix 2, and a summary description of the security measures, as well as a copy of any
contract for sub-processing services which has to be made in accordance with the Clauses,
unless the Clauses or the contract contain commercial information, in which case it may
remove such commercial information;
(i) that, in the event of sub-processing, the processing activity is carried out in accordance with
Clause 11 by a sub-processor providing at least the same level of protection for the personal
data and the rights of data subject as the data importer under the Clauses; and (j) that it will
ensure compliance with Clause 4(a) to (i).
Clause 5
Obligations of the data importer
The data importer agrees and warrants:
(a) to process the personal data only on behalf of the data exporter and in compliance with its
instructions and the Clauses; if it cannot provide such compliance for whatever reasons, it
agrees to inform promptly the data exporter of its inability to comply, in which case the data
exporter is entitled to suspend the transfer of data and/or terminate the contract;
(b) that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the
instructions received from the data exporter and its obligations under the contract and that in
the event of a change in this legislation which is likely to have a substantial adverse effect on
the warranties and obligations provided by the Clauses, it will promptly notify the change to the
data exporter as soon as it is aware, in which case the data exporter is entitled to suspend the
transfer of data and/or terminate the contract;
11
(c) that it has implemented the technical and organisational security measures specified in
Appendix 2 before processing the personal data transferred;
(d) that it will promptly notify the data exporter about:
(i) any legally binding request for disclosure of the personal data by a law enforcement authority
unless otherwise prohibited, such as a prohibition under criminal law to preserve the
confidentiality of a law enforcement investigation;
(ii) any accidental or unauthorised access; and
(iii) any request received directly from the data subjects without responding to that request,
unless it has been otherwise authorised to do so;
(e) to deal promptly and properly with all inquiries from the data exporter relating to its processing
of the personal data subject to the transfer and to abide by the advice of the supervisory
authority with regard to the processing of the data transferred;
(f) at the request of the data exporter to submit its data-processing facilities for audit of the
processing activities covered by the Clauses which shall be carried out by the data exporter or
an inspection body composed of independent members and in possession of the required
professional qualifications bound by a duty of confidentiality, selected by the data exporter,
where applicable, in agreement with the supervisory authority;
(g) to make available to the data subject upon request a copy of the Clauses, or any existing
contract for sub-processing, unless the Clauses or contract contain commercial information, in
which case it may remove such commercial information, with the exception of Appendix 2 which
shall be replaced by a summary description of the security measures in those cases where the
data subject is unable to obtain a copy from the data exporter;
(h) that, in the event of sub-processing, it has previously informed the data exporter and obtained
its prior written consent;
(i) that the processing services by the sub-processor will be carried out in accordance with Clause
11;
(j) to send promptly a copy of any sub-processor agreement it concludes under the Clauses to
the data exporter.
Clause 6
Liability
1. The parties agree that any data subject, who has suffered damage as a result of any breach of
the obligations referred to in Clause 3 or in Clause 11 by any party or sub-processor is entitled
to receive compensation from the data exporter for the damage suffered.
2. If a data subject is not able to bring a claim for compensation in accordance with paragraph 1
against the data exporter, arising out of a breach by the data importer or his sub-processor of
any of their obligations referred to in Clause 3 or in Clause 11, because the data exporter has
factually disappeared or ceased to exist in law or has become insolvent, the data importer
agrees that the data subject may issue a claim against the data importer as if it were the data
exporter, unless any successor entity has assumed the entire legal obligations of the data
12
exporter by contract of by operation of law, in which case the data subject can enforce its rights
against such entity.
The data importer may not rely on a breach by a sub-processor of its obligations in order to
avoid its own liabilities.
3. If a data subject is not able to bring a claim against the data exporter or the data importer referred
to in paragraphs 1 and 2, arising out of a breach by the sub-processor of any of their obligations
referred to in Clause 3 or in Clause 11 because both the data exporter and the data importer
have factually disappeared or ceased to exist in law or have become insolvent, the sub-
processor agrees that the data subject may issue a claim against the data sub-processor with
regard to its own processing operations under the Clauses as if it were the data exporter or the
data importer, unless any successor entity has assumed the entire legal obligations of the data
exporter or data importer by contract or by operation of law, in which case the data subject can
enforce its rights against such entity. The liability of the sub-processor shall be limited to its own
processing operations under the Clauses.
Clause 7
Mediation and jurisdiction
1. The data importer agrees that if the data subject invokes against it third-party beneficiary rights
and/or claims compensation for damages under the Clauses, the data importer will accept the
decision of the data subject:
(a) to refer the dispute to mediation, by an independent person or, where applicable, by the
supervisory authority;
(b) to refer the dispute to the courts in the Member State in which the data exporter is
established.
2. The parties agree that the choice made by the data subject will not prejudice its substantive or
procedural rights to seek remedies in accordance with other provisions of national or
international law.
Clause 8
Cooperation with supervisory authorities
1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if it so
requests or if such deposit is required under the applicable data protection law.
2. The parties agree that the supervisory authority has the right to conduct an audit of the data
importer, and of any sub-processor, which has the same scope and is subject to the same
conditions as would apply to an audit of the data exporter under the applicable data protection
law.
3. The data importer shall promptly inform the data exporter about the existence of legislation
applicable to it or any sub-processor preventing the conduct of an audit of the data importer, or
any sub-processor, pursuant to paragraph 2. In such a case the data exporter shall be entitled
to take the measures foreseen in Clause 5(b).
13
Clause 9
Governing law
The Clauses shall be governed by the law of the Member State in which the data exporter is established.
Clause 10
Variation of the contract
The parties undertake not to vary or modify the Clauses. This does not preclude the parties from adding
clauses on business related issues where required as long as they do not contradict the Clause.
Clause 11
Sub-processing
1. The data importer shall not subcontract any of its processing operations performed on behalf of
the data exporter under the Clauses without the prior written consent of the data exporter. Where
the data importer subcontracts its obligations under the Clauses, with the consent of the data
exporter, it shall do so only by way of a written agreement with the sub-processor which imposes
the same obligations on the sub-processor as are imposed on the data importer under the
Clauses. Where the sub-processor fails to fulfil its data protection obligations under such written
agreement the data importer shall remain fully liable to the data exporter for the performance of
the sub-processor’s obligations under such agreement.
2. The prior written contract between the data importer and the sub-processor shall also provide
for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject is
not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against the
data exporter or the data importer because they have factually disappeared or have ceased to
exist in law or have become insolvent and no successor entity has assumed the entire legal
obligations of the data exporter or data importer by contract or by operation of law. Such
thirdparty liability of the sub-processor shall be limited to its own processing operations under
the Clauses.
3. The provisions relating to data protection aspects for sub-processing of the contract referred to
in paragraph 1 shall be governed by the law of the Member State in which the data exporter is
established, namely …
4. The data exporter shall keep a list of sub-processing agreements concluded under the Clauses
and notified by the data importer pursuant to Clause 5(j), which shall be updated at least once
a year. The list shall be available to the data exporter’s data protection supervisory authority.
Clause 12
Obligation after the termination of personal data processing services
1. The parties agree that on the termination of the provision of data-processing services, the data
importer and the sub-processor shall, at the choice of the data exporter, return all the personal
14
data transferred and the copies thereof to the data exporter or shall destroy all the personal data
and certify to the data exporter that it has done so, unless legislation imposed upon the data
importer prevents it from returning or destroying all or part of the personal data transferred. In
that case, the data importer warrants that it will guarantee the confidentiality of the personal
data transferred and will not actively process the personal data transferred anymore.
2. The data importer and the sub-processor warrant that upon request of the data exporter and/or
of the supervisory authority, it will submit its data-processing facilities for an audit of the
measures referred to in paragraph 1.
Appendix 1 to the Standard Contractual Clauses
This Appendix forms part of the Clauses and has been agreed by the parties by virtue of their signing
the DPA.
The Member States may complete or specify, according to their national procedures, any additional
necessary information to be contained in this Appendix.
Data exporter
The data exporter is the legal entity that has executed the DPA and as a result has accepted the Clauses.
Data importer
The data importer is Apryse.
Data subjects
The personal data transferred concern the categories of data subjects specified under section 3.4 of the
DPA.
Categories of data
The personal data transferred concern the categories of data specified under section 3.3 of the DPA.
Processing operations
The personal data transferred will be subject to the following basic processing activities (please specify):
the performance of the Services under the Agreement.
15
Appendix 2 to the Standard Contractual Clauses
This Appendix forms part of the Clauses and has been agreed by the parties by virtue of their signing
the DPA.
Description of the technical and organisational security measures implemented by the data
importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached):
Use of Multi Factor Authentication for accounts that have access to Personal Data.
Use of industry standard anti-virus and malware protection on clients, servers and other
endpoints.
All media (fixed or removable) should have strong encryption in place in order to prevent
data loss when devices get lost or stolen.
All databases or systems holding critical Personal Data should have encryption-at-rest and
auditing enabled.
All endpoints that have access to Personal Data that should be operated without local
administrator rights.
All network traffic, both internal and external, should be protected with SSL encryption.
SHA-Z (Secure Hash Algorithms) will have to be the minimum cryptographic hash and the
key length has to be 2048 at minimum, 4096 is preferred.
Systems that hold, or have access to Personal Data, should be at an adequate patch level.
Updates should be installed not later than 3 months after release by the vendor.
A well-documented and audited incident response process should be in place and known
by all staff working with Personal Data.
Physical access to the datacenters should be registered and detailed information should
be retained for auditing purposes.
16