DATA PROCESSING AGREEMENT
This data processing agreement (“DPA”) applies where it is expressly incorporated into or referenced by: (a) an Agreement; or (b) a Partner Agreement.
AGREED TERMS
1 Definitions, Interpretation, and Application
1.1 The definitions and rules of interpretation in this Clause 1 apply in this DPA (unless the context requires otherwise).
1.2 For the purposes of this DPA:
“Adequacy Decision” means a formal decision made by the European Commission, the United Kingdom (“UK”) government, or applicable government authority, which recognises that another country, territory, sector or international organisation provides an equivalent level of protection for personal data;
“Affiliate” means any entity that directly or indirectly, through one or more intermediaries, controls, or is controlled by, or is under common control by the Parties or their respective successors. Affiliates shall include such entities whether now existing or later established by investment, merger or otherwise, including the successors and assigns of such entities;
“Agreement” means a written agreement between VikingCloud and a Client for the provision of Services;
“ANPD” means the Brazilian National Data Protection Authority (the Autoridade Nacional de Proteção de Dados);
“APA” means the Australian Privacy Act 1988;
“APIPA” means the Albertan Personal Information Protection Act 2003;
“BCPIPA” means the British Columbian Personal Information Protection Act 2003;
“Brazilian LGPD” means Brazil Law No. 13,709, the General Law on Protection of Personal Data, as amended;
“CCPA” means the California Consumer Privacy Act 2018, as amended by the California Privacy Rights Act of 2020 or “CPRA”, along with all rules issued by the California Privacy Protection Agency;
“Client” means the party to whom VikingCloud provides the Services, being either: (a) a party subject to an agreement with VikingCloud in respect of the Services; or (b) a party subject to a Partner Agreement in respect of the Services.
“Controller to Controller Clauses” means the Standard Contractual Clauses that apply to Controller to Controller transfers and to which the Module One elements of the Standard Contractual Clauses apply;
“Controller to Processor Clauses” means the Standard Contractual Clauses that apply to Controller to Processor transfers and to which the Module Two elements of the Standard Contractual Clauses apply;
“Cross Border Transfer Restrictions” means the applicable Data Protection Legislation which restrict the cross border transfer of personal data, including, but not limited to, EU Data Protection Law, the Brazilian LGPD, and the South African POPIA, and which require an International Data Transfer Mechanism;
“Data Protection Legislation” means European Data Protection Law, APA, APIPA, BCPIPA, the Brazilian LGPD, CCPA, PIPEDA, QARPPIS, the South African POPIA and, any and all data protection and privacy laws applicable to the processing of personal data under or in connection with the Services;
“Effective Date” means: (a) the date of the Agreement, or (b) the date of the Partner Agreement; as applicable;
“European Data Protection Law” means all data protection laws and regulations applicable to Europe, including the GDPR, the UK GDPR and the Swiss FDPA;
“GDPR” means the General Data Protection Regulation (EU) 2016/679;
“International Data Transfer Addendum” means, in case of transfers outside the UK which require an International Data Transfer Mechanism, the international data transfer addendum to the Standard Contractual Clauses, as outlined in Schedule 3 to this DPA, for the transfer of personal data to controllers or processors established in third countries which do not ensure an adequate level of protection as set out by the UK’s ICO, in each case as updated, amended, replaced or superseded from time to time;
“International Data Transfer Mechanism” means a specific transfer mechanism required when transferring personal data to a recipient in another jurisdiction, where the law in that jurisdiction does not protect personal data in a manner equivalent to the transferring entity’s jurisdiction, for example, the Standard Contractual Clauses;
“Irish DPC” means the Irish Data Protection Commission;
“IRSA” means the Information Regulator (South Africa);
“Partner Agreement” means a written agreement between a VikingCloud Partner and the Client under which the Services are provided to the Client.
“Party” means each of VikingCloud and the Client, and “Parties” means both of them.
“PIPEDA” means the Canadian Personal Information Protection and Electronic Documents Act 2000;
“Processor to Processor Clauses” means the Standard Contractual Clauses that apply to Processor to Processor transfers and to which the Module Three elements of the Standard Contractual Clauses apply;
“Public Authority” means a government agency or law enforcement authority, including judicial authorities;
“QARPPIS” means the Quebecois Act Respecting the Protection of Personal Information in the Private Sector 1993 as amended;
“Security Breach” means the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to the Services Personal Data;
“Services” means the services provided by VikingCloud that are supplied to the Client under: (a) the Agreement; or (b) the Partner Agreement; as applicable;
“Services Personal Data” means the personal data processed by VikingCloud, in accordance with the Client’s instructions, in order to deliver the Services, including the personal data set out in Schedule 1;
“South African POPIA” means the Protection of Personal Information Act 2013 (South Africa);
“Standard Contractual Clauses” or “SCCs” means the Standard Contractual Clauses for the transfer of personal data from the European Economic Area (“EEA”) to third countries, pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.;
“Sub-Processor” means any processor engaged by VikingCloud, to provide some or all of the Services. Sub-Processors may include third parties or VikingCloud Affiliates;
“Supervisory Authority” means a regulator, government department of other judicial or regulatory body with powers under the Data Protection Legislation.
“Swiss FDPA” means the Federal Act on Data Protection of 25 September 2020 (Switzerland);
“Third Party / Third Parties” means any third party to whom personal data is disclosed, under or in connection with the Services;
“UK GDPR” means the GDPR as amended and incorporated into UK law under the UK European Union (Withdrawal) Act 2018 and all associated laws, including applicable secondary legislation made under that Act and the UK Data Protection Act 2018;
“UK ICO” means the UK Information Commissioner’s Office;
“VikingCloud Partner” means a third party that has entered into an agreement with VikingCloud authorising such third party to resell, supply, or otherwise make available the Services to its own customers.
1.3 “controller”, “data subject”, “personal data”, “processing”, “processor” and “supervisory authority” shall have the meanings given to those terms in the GDPR, and where applicable, terms which are broadly equivalent to these as provided for by any other applicable Data Protection Legislation (for example, where CCPA is applicable, ‘controller’ shall be interpreted as ‘business’, ‘processor’ as ‘service provider’, ‘data subject’ as ‘consumer’ and 'personal data’ as ‘personal information’).
1.4 A reference to this DPA includes its schedules.
1.5 Words in the singular include the plural and vice versa.
1.6 Any words that follow ‘include’, ‘includes’, ‘including’, ‘in particular’ or any similar words and expressions shall be construed without limitation.
1.7 Clause, schedule or other headings in this DPA are included for convenience only and shall have no effect on the interpretation of this DPA.
1.8 A reference to any statute, statutory provision, rule, regulation or any requirement shall be construed as including references to it as modified, consolidated, re-enacted or superseded from time to time and shall include all subordinate legislation made from time to time under that statute or statutory provision.
1.9 A reference to any regulator or regulatory board shall include a reference to any replacement or successor bodies from time to time.
1.10 Where the Services are provided under an Agreement, this DPA supplements and forms part of the Agreement, and all of the terms and conditions of the Agreement apply to this DPA, provided that in the case of conflict or ambiguity between: (a) the terms of this DPA and the terms of the Agreement relating to data processing, the terms of this DPA shall prevail; (b) the terms of any provision contained in the main body of this DPA and, to the extent applicable, the terms of any Standard Contractual Clauses entered into between the Parties, the provisions of the Standard Contractual Clauses shall prevail.
1.11 Where the Services are supplied under a Partner Agreement, this DPA takes effect as a separate agreement between VikingCloud and the Client, accepted by the Client on the earlier of: (a) the date the Client enters into a Partner Agreement that incorporates or references this DPA; and (b) the date the Client first receives or uses the Services. VikingCloud Partner is not a party to this DPA, and no term of a Partner Agreement varies this DPA or imposes any obligation on VikingCloud.
1.12 Where the Services are provided to the Client under more than one Agreement (or Partner Agreement, as applicable), this DPA applies separately in respect of each, and references to the Agreement (or the Partner Agreement, as applicable) are to the one under which the processing in question is carried out.
2 Roles and Responsibilities
2.1 Controllers. The Parties accept that both Parties will, at times, act as independent controllers. The controller is responsible for the accuracy of personal data and the legality of the means by which it acquires personal data.
(a) VikingCloud as Controller. In certain situations, VikingCloud may act as a controller in respect of personal data processed in connection with the Services. This includes, but is not limited to, administration or billing purposes, and purposes incidental to the provision of the Services.
(b) Client as Controller.
(i) The Client shall be the controller (or processor where the Client processes personal data on behalf of its own customers) in respect of Services Personal Data processed by VikingCloud under this DPA. The Client will ensure that its instructions to process personal data comply with all applicable Data Protection Legislation and is responsible for the accuracy and quality of the Services Personal Data provided to VikingCloud.
(ii) The Client may also act as controller when processing personal data provided by VikingCloud’s representatives to facilitate the Services, this includes screening / vetting information relating to VikingCloud personnel, where the Client has an agreed requirement for, and / or a legal basis to conduct screening (in addition to the screening VikingCloud already conducts). VikingCloud consultant’s personal data will not be held for more than three (3) months after each consultant’s direct involvement with a Client has ceased, unless the Client informs VikingCloud of any legal obligations which require the retention of this personal data. The client agrees that this data will not be used for any other purposes and that the data will only be shared with relevant colleagues and third parties on a strict need to know basis and ensure such parties are party to confidentiality obligations in respect of the personal data.
(c) Responsibilities of the Parties as Controllers.
Each Party shall:
(i) determine the lawful basis(es) along with the purpose for and the means by which personal data is processed and / or transferred; and
(ii) ensure that it has in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
(d) Cooperation and assistance.
Each Party shall cooperate and provide assistance to the other Party in order to comply with all applicable requirements of the Data Protection Legislation. In particular, each Party shall, as relevant:
(i) promptly inform the other upon receipt of any data subject rights requests;
(ii) provide the other with reasonable assistance in complying with any data subject rights requests; and
(iii) at the cost of the requesting Party, provide any other assistance to facilitate compliance with the Data Protection Legislation with respect to security, personal data breach notifications, data protection impact assessments and consultations with supervisory authorities or regulators.
2.2 Third Parties.
(a) Third Party provider as controller. Certain VikingCloud Services use tools and services from Third Party providers, where the Third Party processes personal data as an independent controller, Client acknowledges and agrees that: (i) the Third Party’s processing activities shall be governed by its own privacy notice; (ii) VikingCloud shall not be responsible for, nor exercise control over, the Third Party’s processing activities undertaken in its capacity as an independent controller; and (iii) the Third Party will be independently responsible for compliance with its obligations as controller.
For the avoidance of doubt, a Third Party’s status as a processor to VikingCloud for certain processing activities shall not prevent that Third Party from acting as an independent controller in relation to separate processing activities where it determines the purposes and means of such processing. A list of Third Parties as controllers can be found here https://www.vikingcloud.com/subprocessors , any changes to this list will be notified to the Client in advance in accordance with the notification process set out in clause 4.1(a).
(b) Third Party partner. Where Client purchases services through a VikingCloud Partner, , and / or where Client otherwise requests or authorises VikingCloud to provide a Third Party (including a VikingCloud Partner) with access to Services Personal Data, Client acknowledges and agrees that such Third Party’s processing or further use of the Services Personal Data is not covered by this DPA. Any such processing or further use shall be governed by a separate agreement between Client and relevant Third Party. VikingCloud shall not be responsible for the Third Party’s processing or use of Services Personal Data except to the extent expressly agreed between VikingCloud and the Client or otherwise required by applicable Data Protection Legislation.
2.3 Processor. In respect of any Services Personal Data processed by VikingCloud under this DPA, the Parties acknowledge that the Client shall be the controller or primary processor (as applicable) and VikingCloud shall be a processor (or sub-processor).
To the extent that VikingCloud processes Services Personal Data, as a processor or sub-processor, pursuant to this DPA, VikingCloud shall:
(a) process the Services Personal Data only for the permitted purpose(s) set forth in the Agreement and / or as necessary to provide the Services and in accordance with instructions from the Client, or where otherwise expressly permitted under the Data Protection Legislation. VikingCloud shall notify the Client of such legal requirement before such processing occurs or is permitted, unless that law prohibits such notification on grounds of public interest;
(b) implement and at all times maintain appropriate technical and organizational measures to ensure the security of the Services Personal Data taking into account: (i) the state of the art; (ii) the costs of implementation; (iii) the nature, scope, context and purposes of the processing; and (iv) the inherent risk of the processing activities to data subjects;
(c) immediately notify the Client if an instruction is believed to breach applicable Data Protection Legislation or otherwise notify the Client if it is unable to meet its obligations under the Data Protection Legislation. Notwithstanding the foregoing, VikingCloud shall have no obligation to proactively review the lawfulness of any instruction received from Client;
(d) grant the Client the right to take reasonable and appropriate steps as required by the applicable Data Protection Legislation, to ensure that VikingCloud’s use of Services Personal Data is consistent with its privacy and security obligations under the Data Protection Legislation;
(e) not sell or share Services Personal Data (“sell” or “share” are as defined by the CCPA);
(f) ensure that all personnel authorized to process the Services Personal Data are party to confidentiality obligations in respect of the personal data;
(g) taking into account the nature of processing and the information available to VikingCloud, co-operate as reasonably requested by the Client and as required by the applicable Data Protection legislation: (i) to enable the Client to comply with any exercise of rights by a data subject under the Data Protection Legislation in respect of personal data; (ii) to determine reasonable and appropriate steps to stop and remediate unauthorised use; (iii) where the Client conducts a data protection impact assessment (or similar assessment) including any prior consultation with regulators; and (iv) assist Client in taking any actions deemed reasonably necessary or appropriate to deal with complaints or allegations in connection with a failure to comply with the Data Protection Legislation.
(h) notify the Client if VikingCloud receives a request from a data subject to exercise any of their rights under the Data Protection Legislation. VikingCloud shall not respond directly to such data subject but will provide reasonable assistance in accordance with 2.3(g)(i);
(i) notify the Client, without undue delay, of any Security Breach and provide reasonable assistance with assessing the nature and impact of the Security Breach in order to support the Client with meeting mandatory breach notifications.
3 International Transfers
3.1 The Client hereby agrees to the transfer of Services Personal Data processed under this DPA from a territory with Cross Border Transfer Restrictions PROVIDED that in effecting any such transfer of Services Personal Data, VikingCloud shall ensure that: (a) it has authorization in accordance with clause 4; and (b) it has appropriate safeguards in place in relation to the transfer, which may include an International Data Transfer Mechanism.
3.2 The following provisions shall apply to the extent that Services Personal Data is subject to the applicable Data Protection Legislation of the relevant territories below:
(a) The EEA. For transfers of Services Personal Data to a third country for which an Adequacy Decision has not been adopted, nor is an alternative appropriate safeguard in place, the Standard Contractual Clauses shall apply in addition to this DPA. The SCCs, pursuant to this Clause 3.2(a), shall be structured as follows:
(i) Module Two (Controller to Processor Clauses) terms shall apply, and where the Client acts as a Processor, Module Three (Processor to Processor Clauses) terms shall also apply;
(ii) Clause 7 – shall be deleted in its entirety and the Parties acknowledge that they may add additional entities to this DPA by executing an additional DPA;
(iii) Clause 9 – Option 2 shall apply, and the time period shall be 14 days prior to the engagement of the Sub-Processor (as detailed in Clause 4.1 of this DPA);
(iv) Clause 11(a) - The optional language shall not apply;
(v) Clause 13(a)- Supervision. Clause 13 shall apply as follows: The Irish DPC shall be the competent supervisory authority for transfers from the EEA;
(vi) Clause 17 - Option 1 shall apply, the Standard Contractual Clauses will be governed by the laws of Ireland for transfers from the EEA; and
(vii) Clause 18(b) - the exclusive jurisdiction of the Irish courts shall apply for transfers from the EEA.
(b) Switzerland. For transfers of Services Personal Data, the applicable Standard Contractual Clauses, as referred to in Clause 3.2(a), shall be modified as follows:
(i) references to “Regulation (EU) 2016/679” shall be interpreted as references to the Swiss FADP;
(ii) references to “EU”, “Union”, and “Member State” shall be amended to include Switzerland;
(iii) references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the “Swiss Federal Data Protection and Information Commissioner” and the “competent Swiss courts”;
(iv) the term “member state” as used in the Standard Contractual Clauses shall not be interpreted in a way that would preclude data subjects in Switzerland from exercising their rights at their place of habitual residence; and
(v) the Standard Contractual Clauses shall be governed by the laws of Switzerland and disputes shall be resolved before the Swiss courts having appropriate jurisdiction.
(c) UK. For transfers of Services Personal Data to a country for which the UK ICO has not adopted an Adequacy Decision, the Parties will supplement the applicable Standard Contractual Clauses, as referred to in Clause 3.2(a), with the International Data Transfer Addendum. The details of transfer required under the International Data Transfer Addendum are outlined in Schedule 3 to this DPA.
(d) Brazil / South Africa. For transfers of Services Personal Data subject to Brazilian LGPD and South African POPIA:
(i) to a third country for which the relevant transferring country has not adopted an Adequacy Decision, the Parties hereby agree to enter into the Controller to Processor Clauses and / or the Processor to Processor Clauses, as applicable;
(ii) where applicable, VikingCloud will (1) provide its Services under the express obligations imposed by the LGPD and / or POPIA on a data processor; and (2) as required under Articles 33 through 36 of the LGPD and / or Article 72 of POPIA, transfer Services Personal Data on the basis of the Standard Contractual Clauses as set out in clause 3.2(a), as modified in accordance with the LGPD and / or POPIA; and
(iii) where the Standard Contractual Clauses apply, reference to:
(A) “member state” will be interpreted to mean Brazil and South Africa, as applicable;
(B) Clause 13(a) – the Supervisory Authority will be the ANPD or IRSA, as applicable;
(C) Clause 17 - Option 1 (governing law) of the SCCs will be Brazil or South Africa, as applicable; and
(D) Clause 18(b) – the exclusive jurisdiction of the courts of Brazil or South Africa, as applicable.
To the extent that the Parties process Services Personal Data to which PIPEDA, QARPPIS, APIPA, BCPIPA and APA applies, VikingCloud will ensure that the provisions of this DPA will continue to be applicable to any Services Personal Data transferred outside of the relevant jurisdiction.
For the avoidance of doubt, should the transfer mechanisms identified in this Clause 3.2 be deemed invalid by a Supervisory Authority or court with applicable authority, the Parties shall endeavor in good faith to negotiate an alternative mechanism (if available and required) to permit the continued transfer of personal data.
3.3 For jurisdictions not covered by Clause 3.2, the Standard Contractual Clauses, and / or standard contractual clauses that may be approved by a European Commission decision, shall be utilized where required, and / or permitted, for the lawful transfer of personal data, provided that such terms shall be amended to align with Data Protection Legislation, as well as to reflect the appropriate choice of law and location of disputes.
3.4 Where personal data is shared between the parties as independent Controllers, pursuant to clause 2.1, the Controller to Controller clauses shall apply in accordance with clause 3.2, with the exception Clause 9 of the SCCs (which is not applicable to the Controller to Controller clauses).
3.5 If VikingCloud receives a legally binding request from a Public Authority to access Services Personal Data, VikingCloud shall, unless otherwise legally prohibited, notify Client and include in such notification a summary of the nature of the request. To the extent VikingCloud is prohibited by law from providing such notification, VikingCloud shall use commercially reasonable efforts to obtain a waiver of the prohibition to enable VikingCloud to communicate to Client as much information as possible, as soon as possible. Further, VikingCloud shall use commercially reasonable efforts to challenge the Public Authority in relation to the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful. If VikingCloud is obliged to disclose Services Personal Data, VikingCloud will ensure that only the minimum information necessary to meet the request is provided.
4 Sub-Processors
4.1 The Client hereby authorizes VikingCloud to use its Affiliates and third parties to process Services Personal Data in order to provide the Services provided:
(a) VikingCloud shall notify the Client in advance of any proposed use of a Sub-Processor, and any replacement or addition to them and the Client shall have the right to object on reasonable grounds to the use of / or change to any Sub-Processor within 14 days of VikingCloud notifying the Client of the change. In the event of the Client raising such an objection, the Parties will cooperate as reasonably necessary in order to agree additional controls or a suitable alternative solution, as appropriate;
(b) in engaging any Sub-Processor VikingCloud agrees to adopt adequate data protection arrangements that are materially equivalent to those set out in this DPA; and
(c) VikingCloud shall at all times remain liable for the acts and omissions of any Sub-Processor as if such acts and omissions were those of VikingCloud.
4.2 For the purpose of this Clause 4, the Client is hereby notified of the current Sub-Processors used by VikingCloud at: https://www.vikingcloud.com/subprocessors.
5 Audit
5.1 VikingCloud shall make available all information reasonably requested by the Client to satisfy itself that VikingCloud is complying with its data protection obligations under this DPA.
5.2 Client (and its third party representatives) shall be permitted to audit VikingCloud's premises, systems, and facilities during normal business hours PROVIDED THAT:
(a) Such audit will occur, at a maximum of, once per annum, unless the Client holds a reasonable belief that there is a risk of a breach of the applicable Data Protection Legislation and / or this DPA, or as reasonably necessary to comply with any applicable Supervisory Authority request;
(b) Client shall provide at least 30 days' prior written notice of its intention to carry out an audit;
(c) all expenses incurred by VikingCloud shall be promptly discharged by Client;
(d) VikingCloud may request that any third party representative performing an audit on behalf of Client shall provide written confidentiality undertakings to the reasonable satisfaction of VikingCloud and VikingCloud shall be entitled to refuse access to any of its premises or records until such time as it has received such undertakings; and
(e) nothing in this DPA shall entitle Client to access or inspect any records which contain information relating to any other client of VikingCloud and VikingCloud shall be entitled to restrict or prevent access to any part of its premises which it considers in its sole discretion could compromise the security of any information or data relating to such other clients.
5.3 Any information obtained by the Client in connection with this Clause 5 or in the course of any such audit and any written description of the security, technical and organisational measures used by VikingCloud shall be maintained by the Client in confidence in a manner in which it treats its own confidential information, shall be used solely for the purposes of determining whether VikingCloud is complying with its obligations under this DPA and shall not be used or disclosed for any other purpose.
6 Term and Termination
6.1 This DPA shall be effective as and from the Effective Date and shall remain in force until such time as VikingCloud ceases to process any and all Services Personal Data.
6.2 On termination of this DPA, VikingCloud shall, at the written direction of the Client, delete or return personal data and copies thereof to the Client save to the extent that VikingCloud is required by applicable law and / or the Payment Card Industry Security Standards Council to retain the Services Personal Data. Client accepts that information within backups will be retained in accordance with VikingCloud’s backup retention policy, subject to VikingCloud ensuring that controls are in place to ensure that any Services Personal Data is further deleted in the case of a backup being restored.
7 General
7.1 Any notice or other communication required to be given to a Party under or in connection with this DPA shall be in writing and shall be delivered by email to dataprotectionprivacy@vikingcloud.com. Any notice or communication shall be deemed to have been received on the first working day after the time of transmission.
7.2 Where the Services are supplied under an Agreement, each Party's aggregate liability, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for all claims arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in that Agreement, and this DPA does not increase, extend, or create any liability beyond those limits. For the avoidance of doubt, liability under this DPA counts towards, and is not excluded from, any aggregate cap in that Agreement.
7.3 Where the Services are supplied under a Partner Agreement: (a) VikingCloud's aggregate liability to the Client, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for all claims, damages, costs, losses, expenses, and other amounts arising out of or relating to this DPA shall not exceed the fees paid to VikingCloud by VikingCloud Partner for the Services supplied in respect of the Client in the twelve months preceding the date of the first event giving rise to such claim; (b) VikingCloud shall not be liable to the Client for any indirect, special, incidental, consequential, or punitive damages, whether foreseeable or unforeseeable, of any kind whatsoever, arising out of or in connection with this DPA, including but not limited to, lost profits, loss of revenue, loss of business opportunities, loss or damage to goodwill, loss of use of system(s) or network or the recovery of such, business interruption or downtime; and (c) VikingCloud shall have no liability to the Client in respect of any loss for which the Client has been compensated by VikingCloud Partner.
7.4 This DPA and all disputes arising from this DPA whether contractual or non-contractual in nature shall be governed by and construed in accordance with the laws of Ireland. The Parties irrevocably submit to the exclusive jurisdiction of the Irish courts in relation to all matters arising out of or in connection with this DPA.
SCHEDULE 1 – Personal Data
Description of processing of personal data
| Categories of data subjects: | Such categories as may be required to provide the Services. |
| Types of personal data: | Personal data processed by VikingCloud is limited to that required to provide the Services. These are mainly supplied in a business-to-business context and include client contact details and certain system configuration details that can be classified under GDPR as personal data such as IP address. VikingCloud does not process any special categories of data. |
| Nature of processing: | Collection, storage, processing and transfer of the data in accordance with the terms of the Agreement / applicable services descriptions. |
| Purpose of processing: | The provision by VikingCloud of the Services in accordance with the terms of the Agreement / / applicable services descriptions. |
| Subject Matter of Processing: | The provision by VikingCloud of the Services in accordance with the terms of the Agreement / / applicable services descriptions. |
| Duration of Processing: | The duration required to fulfil VikingCloud’s obligations under the Agreement / applicable services descriptions. |
SCHEDULE 2 – Standard Contractual Clauses Appendices
ANNEX I
| A. LIST OF PARTIES | |||
|---|---|---|---|
| Data exporter(s): [Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union] | |||
| Name: | The Parties | ||
| Address: | See Agreement / Partner Agreement | ||
| Contact person’s name, position and contact details (in respect of all exporting entities): | See Agreement / Partner Agreement | ||
| Activities relevant to the data transferred under these Clauses: | As per the Agreement / applicable service descriptions. | ||
| Signature and date: | See Agreement / Partner Agreement as applicable (both parties may act as Exporters at times). Role; controller and / or processor |
||
| Data importer(s): [Identity and contact details of the data importer(s), including any contact person with responsibility for data protection] | |||
| Name: | The Parties | ||
| Address: | See Agreement / Partner Agreement | ||
| Contact person’s name, position and contact details: | See Agreement / Partner Agreement | ||
| Activities relevant to the data transferred under these Clauses: | As per the Agreement / applicable service descriptions. | ||
| Signature and date: | See Agreement / Partner Agreement as applicable (both parties may act as Exporters at times). Role; controller and / or processor |
||
| B. DESCRIPTION OF TRANSFER | |||
| Categories of data subjects whose personal data is transferred | See Schedule 1 | ||
| Categories of personal data transferred | See Schedule 1 | ||
| Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. | N/a | ||
| The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). | As per the Agreement / applicable service descriptions. | ||
| Nature of the processing | See Schedule 1 | ||
| Purpose(s) of the data transfer and further processing | See Schedule 1 | ||
| The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period | See Schedule 1 | ||
| For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing | See Clause 4.2. | ||
C. COMPETENT SUPERVISORY AUTHORITY Irish Data Protection Commissioner |
|||
ANNEX II
| TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA | |
|---|---|
EXPLANATORY NOTE: The technical and organisational measures must be described in specific (and not generic) terms. See also the general comment on the first page of the Appendix, in particular on the need to clearly indicate which measures apply to each transfer/set of transfers. |
|
| Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons. | |
[Examples of possible measures:
|
VikingCloud has global policies in place which include:
|
For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter. The Importer has in place a Rights Requests Procedure which includes requirements to check if any request relates to a data subject of the Importer, where it is not obviously related to the Importer’s own activities (i.e. the Importer’s activities as a Controller). This includes details of the process agreed with the IT Team to search across all instances of systems for data subjects. The Data Protection & Privacy Policy contains a Client Data section which requires rights requests from data subjects (merchants) to be sent immediately to the Exporter (the client), with advice sought where there is any doubt as to which client the request relates to, and that any suspicion of an infringing instruction need to be reported immediately, including to the Data Protection Team. It also references client breach reporting requirements and that any and all issues relating to information or security are to be reported immediately This policy also mandates that any requests from government authorities must be sent immediately to the General Counsel, who will consult with the Global Data Protection Manager where the request relates to personal information. The Legal Team consults with the Data Protection Team in relation to any new or amended supplier agreements, to ensure materially equivalent terms are flowed down to any sub-processors (or sub-sub-processor), which includes prompt assistance in relation to rights requests, breach notification and any other assessment / consultations. |
|
SCHEDULE 3 – International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
VERSION B1.0, in force 21 March 2022
This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.
Part 1: Tables
Table 1: Parties
Start date |
||
The Parties |
Exporter (who sends the Restricted Transfer) |
Importer (who receives the Restricted Transfer) |
Parties’ details |
Full legal name: See Schedule 2, Annex 1 Trading name (if different): Main address (if a company registered address): See Schedule 2, Annex 1 Official registration number (if any) (company number or similar identifier): See Agreement / Partner Agreement |
Full legal name: See Schedule 2, Annex 1 Trading name (if different): Main address (if a company registered address): See Schedule 2, Annex 1 Official registration number (if any) (company number or similar identifier): See Agreement / Partner Agreement |
Key Contact |
Full Name (optional): See Schedule 2, Annex 1 Job Title: See Schedule 2, Annex 1 Contact details including email: See Schedule 2, Annex 1 |
Full Name (optional): See Schedule 2, Annex 1 Job Title: See Schedule 2, Annex 1 Contact details including email: See Schedule 2, Annex 1 |
Table 2: Selected SCCs, Modules and Selected Clauses
Addendum EU SCCs |
The version of the Approved EU SCCs which this Addendum is appended to, detailed below, including the Appendix Information: Date: Reference (if any): Other identifier (if any): Or the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum: |
Module |
Module in operation |
Clause 7 (Docking Clause) |
Clause 11 |
Clause 9a (Prior Authorisation or General Authorisation) |
Clause 9a (Time period) |
Is personal data received from the Importer combined with personal data collected by the Exporter? |
|---|---|---|---|---|---|---|
1 |
Yes |
No |
No |
N/a |
N/a |
N/a |
2 |
Yes |
No |
No |
General |
14 days |
N/a |
3 |
Yes |
No |
No |
General |
14 days |
N/a |
4 |
No |
N/a |
N/a |
N/a |
N/a |
N/a |
Table 3: Appendix Information
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:
Schedule 2, Annex IA: List of Parties. |
Schedule 2, Annex IB: Description of Transfer. |
Schedule 2, Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data. |
Schedule 2, Annex III: List of Sub-Processors (Modules 2 and 3 only). |
Table 4: Ending this Addendum when the Approved Addendum Changes
Ending this Addendum when the Approved Addendum changes |
Which Parties may end this Addendum as set out in Section 19: Importer Exporter neither Party |
Part 2: Mandatory Clauses
Entering into this Addendum
1 Each Party agrees to be bound by the terms and conditions set out in this Addendum, in exchange for the other Party also agreeing to be bound by this Addendum.
2 Although Annex 1A and Clause 7 of the Approved EU SCCs require signature by the Parties, for the purpose of making Restricted Transfers, the Parties may enter into this Addendum in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in this Addendum. Entering into this Addendum will have the same effect as signing the Approved EU SCCs and any part of the Approved EU SCCs.
Interpretation of this Addendum
3 Where this Addendum uses terms that are defined in the Approved EU SCCs those terms shall have the same meaning as in the Approved EU SCCs. In addition, the following terms have the following meanings:
Addendum |
This International Data Transfer Addendum which is made up of this Addendum incorporating the Addendum EU SCCs. |
Addendum EU SCCs |
The version(s) of the Approved EU SCCs which this Addendum is appended to, as set out in Table 2, including the Appendix Information. |
Appendix Information |
As set out in Table 3. |
Appropriate Safeguards |
The standard of protection over the personal data and of data subjects’ rights, which is required by UK Data Protection Laws when you are making a Restricted Transfer relying on standard data protection clauses under Article 46(2)(d) UK GDPR. |
Approved Addendum |
The template Addendum issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18. |
Approved EU SCCs |
The Standard Contractual Clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021. |
ICO |
The Information Commissioner. |
Restricted Transfer |
A transfer which is covered by Chapter V of the UK GDPR. |
UK |
The United Kingdom of Great Britain and Northern Ireland. |
UK Data Protection Laws |
All laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018. |
UK GDPR |
As defined in section 3 of the Data Protection Act 2018. |
4 This Addendum must always be interpreted in a manner that is consistent with UK Data Protection Laws and so that it fulfils the Parties’ obligation to provide the Appropriate Safeguards.
5 If the provisions included in the Addendum EU SCCs amend the Approved SCCs in any way which is not permitted under the Approved EU SCCs or the Approved Addendum, such amendment(s) will not be incorporated in this Addendum and the equivalent provision of the Approved EU SCCs will take their place.
6 If there is any inconsistency or conflict between UK Data Protection Laws and this Addendum, UK Data Protection Laws applies.
7 If the meaning of this Addendum is unclear or there is more than one meaning, the meaning which most closely aligns with UK Data Protection Laws applies.
8 Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.
Hierarchy
9 Although Clause 5 of the Approved EU SCCs sets out that the Approved EU SCCs prevail over all related agreements between the parties, the parties agree that, for Restricted Transfers, the hierarchy in Section 10 will prevail.
10 Where there is any inconsistency or conflict between the Approved Addendum and the Addendum EU SCCs (as applicable), the Approved Addendum overrides the Addendum EU SCCs, except where (and in so far as) the inconsistent or conflicting terms of the Addendum EU SCCs provides greater protection for data subjects, in which case those terms will override the Approved Addendum.
11 Where this Addendum incorporates Addendum EU SCCs which have been entered into to protect transfers subject to the General Data Protection Regulation (EU) 2016/679 then the Parties acknowledge that nothing in this Addendum impacts those Addendum EU SCCs.
Incorporation of and changes to the EU SCCs
12 This Addendum incorporates the Addendum EU SCCs which are amended to the extent necessary so that:
(a) together they operate for data transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter’s processing when making that data transfer, and they provide Appropriate Safeguards for those data transfers;
(b) Sections 9 to 11 override Clause 5 (Hierarchy) of the Addendum EU SCCs; and
(c) this Addendum (including the Addendum EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales, in each case unless the laws and/or courts of Scotland or Northern Ireland have been expressly selected by the Parties.
13 Unless the Parties have agreed alternative amendments which meet the requirements of Section 12, the provisions of Section 15 will apply.
14 No amendments to the Approved EU SCCs other than to meet the requirements of Section 12 may be made.
15 The following amendments to the Addendum EU SCCs (for the purpose of Section 12) are made:
(a) References to the “Clauses” means this Addendum, incorporating the Addendum EU SCCs;
(b) In Clause 2, delete the words:
“and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679”;
(c) Clause 6 (Description of the transfer(s)) is replaced with:
“The details of the transfers(s) and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer.”;
(d) Clause 8.7(i) of Module 1 is replaced with:
“it is to a country benefitting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer”;
(e) Clause 8.8(i) of Modules 2 and 3 is replaced with:
“the onward transfer is to a country benefitting from adequacy regulations pursuant to Section 17A of the UK GDPR that covers the onward transfer;”
(f) References to “Regulation (EU) 2016/679”, “Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)” and “that Regulation” are all replaced by “UK Data Protection Laws”. References to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent Article or Section of UK Data Protection Laws;
(g) References to Regulation (EU) 2018/1725 are removed;
(h) References to the “European Union”, “Union”, “EU”, “EU Member State”, “Member State” and “EU or Member State” are all replaced with the “UK”;
(i) The reference to “Clause 12(c)(i)” at Clause 10(b)(i) of Module one, is replaced with “Clause 11(c)(i)”;
(j) Clause 13(a) and Part C of Annex I are not used;
(k) The “competent supervisory authority” and “supervisory authority” are both replaced with the “Information Commissioner”;
(l) In Clause 16(e), subsection (i) is replaced with:
“the Secretary of State makes regulations pursuant to Section 17A of the Data Protection Act 2018 that cover the transfer of personal data to which these clauses apply;”;
(m) Clause 17 is replaced with:
“These Clauses are governed by the laws of England and Wales.”;
(n) Clause 18 is replaced with:
“Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts.”; and
(o) The footnotes to the Approved EU SCCs do not form part of the Addendum, except for footnotes 8, 9, 10 and 11.
Amendments to this Addendum
16 The Parties may agree to change Clauses 17 and/or 18 of the Addendum EU SCCs to refer to the laws and/or courts of Scotland or Northern Ireland.
17 If the Parties wish to change the format of the information included in Part 1: Tables of the Approved Addendum, they may do so by agreeing to the change in writing, provided that the change does not reduce the Appropriate Safeguards.
18 From time to time, the ICO may issue a revised Approved Addendum which:
(a) makes reasonable and proportionate changes to the Approved Addendum, including correcting errors in the Approved Addendum; and/or
(b) reflects changes to UK Data Protection Laws;
The revised Approved Addendum will specify the start date from which the changes to the Approved Addendum are effective and whether the Parties need to review this Addendum including the Appendix Information. This Addendum is automatically amended as set out in the revised Approved Addendum from the start date specified.
19 If the ICO issues a revised Approved Addendum under Section 18, if any Party selected in Table 4 “Ending the Addendum when the Approved Addendum changes”, will as a direct result of the changes in the Approved Addendum have a substantial, disproportionate and demonstrable increase in:
(a) its direct costs of performing its obligations under the Addendum; and/or
(b) its risk under the Addendum,
and in either case it has first taken reasonable steps to reduce those costs or risks so that it is not substantial and disproportionate, then that Party may end this Addendum at the end of a reasonable notice period, by providing written notice for that period to the other Party before the start date of the revised Approved Addendum.
20 The Parties do not need the consent of any third party to make changes to this Addendum, but any changes must be made in accordance with its terms.
Alternative Part 2 Mandatory Clauses:
Mandatory Clauses |
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses. |
.png)