1 DEFINITIONS AND INTERPRETATION
Company Personal Data
means any Personal Data Processed by a Processor or Subprocessor on behalf of Company pursuant to or in connection with the Agreement.
Controller
means the entity that determines the purposes and means of Processing Personal Data.
Data Protection Laws
means data protection or privacy laws and regulations directly applicable to Provider’s Processing of Company Personal Data under the Agreement, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and any national data protection laws, implementing regulations, or binding decisions made under the GDPR.
Data Subject
means the identified or identifiable natural person to whom Personal Data relate.
Data Subject Request
means a request from a Data Subject exercising his or her rights under Data Protection Laws that relates to Company Personal Data and identifies such Data Subject.
Personal Data
means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.
Personal Data Breach
means a breach of Provider’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Company Personal Data.
Process and Processing
mean any operation or set of operations which is performed on Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Processor
means the entity that Processes Personal Data on behalf of a Controller.
Subprocessor
means any Processor (including any third party and any Provider Affiliate, but excluding an employee of Provider or any employee of its Subcontractors) appointed by Provider or an Affiliate of Provider to Process Company Personal Data on Provider’s or its Affiliates’ behalf while providing the Cloud Services or Professional Services.
The terms “Data Subject”, “Personal Data”, “Processing”, and “Supervisory Authority”
shall have the meaning ascribed thereto in the GDPR, and their cognate terms shall be construed accordingly.
2 SCOPE AND ROLES
3 DUTIES OF THE PARTIES
4 SECURITY
5 SUBPROCESSING
6 OBLIGATION TO ASSIST
7 PERSONAL DATA BREACH
8 TRANSFERS OF PERSONAL DATA OUTSIDE THE EU/EEA
9 DELETION OR RETURN OF PERSONAL DATA
10 AUDIT RIGHTS
11 LIMITATION OF LIABILITY
Each Party’s liability taken together in the aggregate, arising out of or related to this DPA is subject to the limitation of liability provisions of the Master Agreement.
12 AMENDMENTS
13 GOVERNING LAW AND DISPUTES
This DPA shall be governed by the laws of the jurisdiction specified in the Master Agreement. The dispute resolution clause of the Master Agreement shall apply to this DPA.
14 SIGNATURE AND EFFECT
This DPA is deemed to be validly executed, effective and enforceable as of the Effective Date of the first Order Form jointly signed by the Parties.
15 ANNEXES
The following annexes form an integral part of this DPA:
a) Annex 1, Processing Specification Form (attached to the Order Form)