Snapshot 78713
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Personal Data
Protection Addendum
March 2025
Personal Data Protection Addendum
This Personal Data Protection Addendum (the “Addendum”) defines the roles of responsibilities of the Parties for their respec-
tive processing of Personal Data and is an integral part of the Business Terms agreed between you and Banking Circle.
This Addendum shall override other terms in the Business Terms and any deviation thereof agreed between you and Banking
Circle if and to the extent there is any conflict or inconsistency and shall survive the termination of the business relationship.
1. Definitions 2. General obligations under Data Protection Law
1.1 In this Addendum the terminology below shall have 2.1 Each Party acts as separate and independent (but not
the following meanings: joint) data controller in respect of the Personal Data
processed pursuant to the Services which Banking
Circle provides and shall independently determine the
i. “Banking Circle” means Banking Circle S.A.; purposes and means of such processing.
2.2 Each Party acknowledges and confirms that they will
ii. “Data Protection Laws” shall have the meaning
observe all applicable requirements of Data Protection
ascribed to such terms in Banking Circle Busi-
Laws and these terms in relation to its processing of
ness Terms.;
the Personal Data as independent controller and rep-
resents for its own part that all instructions given in
iii. “Personal Data” means any personal data (in-
respect of the Personal Data shall be in accordance
cluding any sensitive or special categories of
with Data Protection Laws.
data) that is processed under or in connection
with the Agreement;
2.3 Banking Circle understands that you shall share Per-
sonal Data solely for the performance of the Services.
iv. “Supervisory Authorities” means any local, na- Banking Circle does not use or otherwise process any
tional or multinational agency, department, offi- such Personal Data, without any lawful ground, nor for
cial, parliament, public or statutory person or any any purpose other than facilitating and performing the
government or professional body, regulatory or Services. In particular without limitation, Banking Cir-
supervisory authority, board or other body re- cle shall not use any such personal data shared by the
sponsible for administering Data Protection Client for marketing, analysis, model building or
Laws. providing any other services to the relevant data sub-
ject(s) except to evaluate and further develop our
v. "EU Standard Contractual Clauses" means ei- transaction monitoring tools to provide assurance that
ther (i) the standard contractual clauses for the Banking Circle has effective processes to identify,
transfer of personal data to controllers estab- manage, monitor and report fraud, money laundering
lished in third countries which do not ensure an and terrorism financing risks it is or might be exposed
adequate level of protection as set out in Com- to.
mission Decision 2021/914; or (ii) the standard
contractual clauses for the transfer of personal 2.4 You acknowledge and understand that Banking Circle
data to processors established in third countries processes Personal Data (i) before and in conjunction
which do not ensure an adequate level of protec- with the commencement of a business relationship; (ii)
tion as set out in Commission Decision 2021/914, throughout the business relationship for the manage-
in each case as updated, amended, replaced or ment of such relationship, including the marketing of
superseded from time to time by the European products or services to you which may be of interest
Commission; for you, invoicing, the settlement of disputes and as-
sociated business administration; (iii) to enable Bank-
1.2 The terms "data controller", "data subject", "per- ing Circle to perform its regulatory and statutory obli-
sonal data" and "processing” shall have the same gations, as part of its Financial Crime Management Ac-
meanings ascribed to them under Data Protection tivity; and (iv) to enable Banking Circle to provide the
Laws as applicable. Services, e.g. suppliers incl. in particular IT suppliers
or correspondent institutions.
1.3 Capitalised terms not defined in Clause 1 (Definitions)
shall have the meaning ascribed to them elsewhere
in the Business Terms.
Banking Circle 2025.03
2
2.5 Each Party shall implement its own measures de- Party and provide the other Party with reasonable co-
signed to ensure performance of and compliance with operation and assistance in relation to the same.
its own obligations under Data Protection Laws.
5. Requests from Data Subjects
2.6 Each Party shall (without prejudice to the generality of
the foregoing), be responsible for complying with its
own security obligations taking into account the state If a data subject makes a written request to a Party to
of the art, the costs of implementation and the nature, exercise their rights in relation to the Personal Data
scope, context and purposes of the Personal Data pro- that concerns processing in respect of which another
cessing, and for implementing its own appropriate Party is the controller, that Party shall forward the re-
technical and organisational measures to protect such quest to the other Party promptly and in any event
Personal Data against unauthorised or unlawful loss, within eight (8) Business Days from the date on which
alteration, unauthorised disclosure or other unauthor- it received the request and, upon the other Party’s rea-
ised or unlawful processing and against accidental or sonable written request, provide that other Party with
unlawful destruction or loss. reasonable co-operation and assistance in relation to
that request to enable the other to respond to such re-
quest and meet applicable timescales set out under
3. Notice to Data Subject
Data Protection Laws.
3.1 You acknowledge that Banking Circle as a data con- 6. Notification of Breach
troller is obligated to provide the information listed in
GDPR Article 14 to the relevant data subjects. You will
assist Banking Circle in ensuring that data subjects If either Party becomes aware of a Personal Data
are informed of Banking Circle’s role as Data Control- breach involving Personal Data that concerns pro-
ler, in compliance with GDPR article 14. cessing in respect of which another Party is the con-
troller, it shall notify the other Party without undue de-
3.2 Banking Circle’s privacy notice for data subjects can lay, and each Party shall co-operate with the other, to
be found here: the extent reasonably requested, in relation to any no-
https://www.bankingcircle.com/privacy-notice tifications to the Supervisory Authorities or to data
subjects which either Party is required to make under
Data Protection Laws.
4. Complaints
7. Third Country Transfers
If either Party (the "Data Receiving Party") receives
any complaint, notice or communication from a data You acknowledge that Banking Circle may transfer
subject or a supervisory authority which relates di- and otherwise process or have transferred or other-
rectly or indirectly to the other Party’s: (i) processing wise processed Personal Data outside the EEA pro-
of the Personal Data; or (ii) a potential failure to com- vided that such transfer is made in compliance with
ply with Data Protection Laws, the Data Receiving applicable Data Protection Laws, including, if applica-
Party shall, to the extent permitted by law, promptly ble, EU Standard Contractual Clauses or such other in-
and in any event within five (5) Business Days forward ternational transfer mechanism approved under ap-
the complaint, notice or communication to the other plicable Data Protection Law.
Banking Circle 2025.03
3