Global Data Privacy Addendum - Mobileforce
Global Data Privacy Addendum
This Global Data Privacy Addendum (this “Privacy Addendum”) is attached and made part of the agreement that references these Global Data Privacy terms (the “Master Agreement”) between Customer (as identified on the Quote), including all affiliates, if any, and the Service Provider which processes Personal Data on behalf of Customer pursuant to the Master Agreement (as identified on the Quote).
The Privacy Addendum is divided into two separate addendums setting forth the privacy provisions applicable to the Master Agreement. Unless otherwise stated, the terms of this Privacy Addendum will apply to all processing of Personal Data in relation to the Services provided under the terms of the Master Agreement.
PART A: EU/UK GDPR and Swiss Addendum
1. DEFINITIONS
“Adequate Country” means a country or territory recognised as providing an adequate level of protection for Personal Data under an adequacy decision made, from time to time, by (as applicable) (i) the Information Commissioner’s Office and/or under applicable UK law (including the UK GDPR), or (ii) the European Commission under the GDPR, or (iii) the Swiss Federal Data Protection Authority under Swiss Data Protection Law.
“Data Subject Request” means a request from a Data Subject to exercise the Data Subject’s right of access, right to rectification, restriction of Processing, erasure, data portability, object to the processing, or its right not to be subject to an automated individual decision making.
“EEA” means the European Economic Area.
“EU Clauses” means the standard contractual clauses for international transfers of Personal Data to third countries set out in the European Commission’s Decision 2021/914 of 4 June 2021 incorporating Module Two for Controller to Processor transfers and Module Three for Processor to Processor transfers (as applicable).
“EU/UK Rules” means (a) in the European Union, the General Data Protection Regulation 2016/679 (the “GDPR“), (b) in the UK, the UK General Data Protection Regulation 2016/679, as implemented by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 and the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2020 (the “UK GDPR“) and the Data Protection Act 2018.
“Personal Data” means any information relating to an identified or identifiable natural person (‘Data Subject’) located in the EEA, United Kingdom (“UK”) or Switzerland; an identifiable natural person is one who can be identified, directly or indirectly in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; and is processed by Service Provider on behalf of the Customer within the scope of the Master Agreement.
“Services” means the services and other activities to be supplied to or carried out by or on behalf of Service Provider for the Customer pursuant to the Master Agreement.
“Standard Contractual Clauses” means the EU Clauses, the Swiss Addendum and/or the UK Approved.
“Supervisory Authority” means in the UK, the Information Commissioner’s Office (“ICO”) and in the EEA, an independent public authority established pursuant to the GDPR.
“Swiss Addendum” means the addendum set out in Schedule.
“Swiss Data Protection Law” means the Swiss Federal Data Protection Act of 19 June 1992 and, when in force, the Swiss Federal Data Protection Act of 25 September 2020 and its corresponding ordinances as amended, superseded or replaced from time to time.
“UK Approved Addendum” means the template Addendum B.1.0 issued by the UK’s Information Commissioner’s Office and laid before Parliament in accordance with s119A of the Data Protection Act 2018 of the UK on 2 February 2022, or its valid successor.
“UK Mandatory Clauses” means the Mandatory Clauses of the UK Approved Addendum, as updated from time to time and/or replaced by any final version published by the Information Commissioner’s Office.
2. APPLICABILITY; ROLES OF THE PARTIES
This Privacy Addendum amends and supplements the Master Agreement between the parties. This Privacy Addendum will not apply to the processing of Personal Data not regulated by the EU/UK Rules or Swiss Data Protection Law.
In the context of this Privacy Addendum, the Customer acts as a Data Controller or Data Processor (as applicable) and the Service Provider acts as a Data Processor with regard to the processing of Personal Data.
All Personal Data provided to Service Provider by the Customer or obtained by Service Provider in the course of its work should be protected. Service Provider agrees to comply with reasonable measures required by the Customer to ensure obligations under this Privacy Addendum are performed in accordance with applicable legislation.
3. DATA PROTECTION
Service Provider shall process the Personal Data only to the extent necessary to comply with obligations under the Master Agreement or as required by law including the EU/UK Rules and Swiss Data Protection Law.
Service Provider may retain sub-processors and shall ensure any third party to which it sub-contracts processing has enter into a written contract with similar provisions to those in this Privacy Addendum.
Service Provider agrees that upon notification by the Customer, it shall transfer a copy of all information held in relation to this Privacy Addendum to the Customer and/or, at the Customer’s request, destroy all such information using a secure method.
4. RIGHTS OF DATA SUBJECTS
- Service Provider shall promptly notify the Customer if it receives a Data Subject Request and assist the Customer by appropriate technical and organizational measures to the extent possible for the fulfillment of Customer’s obligation to respond to a Data Subject Request under applicable EU/UK Rules.
5. SECURITY
- Service Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data and comply with best industry practices to protect the Personal Data received from or processed on behalf of the Customer.
6. SECURITY BREACH MANAGEMENT AND NOTIFICATION
- Service Provider shall notify the Customer as soon as any Personal Data Breach occurs, but no later than 48 hours from the discovery of such a breach and will cooperate in investigations and analysis of the breach.
7. OBLIGATIONS OF THE CUSTOMER
- The Customer is responsible for complying with the EU/UK Rules with respect to the processing of Personal Data and ensuring that appropriate consents have been obtained from each individual to whom the Personal Data relates.
8. INTERNATIONAL DATA TRANSFERS
- Customer agrees to the transfer of Personal Data outside of the UK, Switzerland, or EEA for the provision of Services and the execution of the Master Agreement.
SCHEDULE 1
Data Processing Details
| Subject Matter of the Processing | Service Provider’s provision of the Services to Customer. |
| Nature and purpose of Processing | The collection and storage of Personal Data for the Services. |
| Types of Personal Data | Personal Data that Customer uploads or directs to be collected. |
| Categories of Data Subject | Data Subjects may include any end users or others about whom Personal Data is provided to Service Provider. |
| Duration of Processing | For the duration of the Agreement or until processing is no longer necessary. |
SCHEDULE 2
UK transfers
- The information required for Table 1 is contained in Schedule 1 and the start date shall be the same as the EU Clauses.
SCHEDULE 3
Swiss Addendum
- The FDPIC will be the competent supervisory authority;
- Data subjects may enforce their rights under Clause 18c of the EU Clauses.
SCHEDULE 4
EU Clauses
- For the purposes of this Schedule 4, the EU Clauses shall be incorporated by reference, and considered an integral part thereof.
ANNEX I to Schedule 4
A. LIST OF PARTIES
Data exporter(s): Name: Customer as specified on the Quote; Address: As specified on the Quote.
Data importer(s): Name: Service Provider as specified on the Quote.