Data Processing Addendum
Last Updated: December 21, 2022
- For the purposes of this Data Processing Addendum, the following definitions shall apply:
Applicable Laws means (for so long as and to the extent that they apply to Proto) the law of the European Union, the law of any member state of the European Union and/or Domestic Law;
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing and appropriate technical and organizational measures: as defined in the applicable Data Protection Legislation;
Data Protection Legislation: the UK Data Protection Legislation and any other European Union legislation relating to personal data and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications);
Domestic UK Law: the UK Data Protection Legislation and any other law that applies in the UK; and
UK Data Protection Legislation: all applicable data protection and privacy legislation in force from time to time in the UK including the General Data Protection Regulation ((EU) 2016/679); the Data Protection Act 2018; the Privacy and Electronic Communications Directive2002/58/EC (as updated by Directive 2009/136/EC) and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended.
- Proto and Client will comply with all applicable requirements of the Data Protection Legislation. This Data Processing Addendum is in addition to, and does not relieve, remove or replace, a party’s obligations or rights under the Data Protection Legislation.
- The parties acknowledge that for the purposes of the Data Protection Legislation, Client is the Controller and Proto is the Processor.
- Without prejudice to the generality of paragraph 1.3, Client will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Personal Data to Proto for the duration and purposes of this Agreement.
- Without prejudice to the generality of paragraph 1.3, Proto shall, in relation to any Personal Data processed in connection with the performance by Proto of its obligations under this Agreement:
(a) process that Personal Data only on the documented written instructions of Client unless Proto is required by Applicable Laws to otherwise process that Personal Data. Where Proto is relying on Applicable Laws as the basis for processing Personal Data, Proto shall promptly notify Client of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit Proto from so notifying Client;
(b) ensure that it has in place appropriate technical and organizational measures, reviewed and approved by Client, to protect against unauthorized or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, ensuring a level of security appropriate to the risk in accordance with Data Protection Legislation;
(c) ensure that all Representatives who have access to and/or Process Personal Data are obliged to keep the Personal Data confidential;
(d) not transfer any Personal Data outside of the European Economic Area unless the prior written consent of Client has been obtained and the following conditions are fulfilled:
(i) Client or Proto has provided appropriate safeguards in relation to the transfer;
(ii) the data subject has enforceable rights and effective legal remedies;
(iii) Proto complies with its obligations under the Data Protection Legislation by providing an adequate level of protection to any Persona lData that is transferred; and
(iv) Proto complies with reasonable instructions notified to it in advance by Client with respect to the processing of the Personal Data;
(e) assist Client, at Client's cost, in responding to any request from a Data Subject and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
(f) notify Client without undue delay on becoming aware of a Personal Data Breach;
(g) at the written direction of Client, delete or return Personal Data and copies thereof to Client on termination of the Services unless required by Applicable Law to store the Personal Data; and
(h) maintain complete and accurate records and information to demonstrate its compliance with applicable Data Protection Legislation and, at Client’s request but subject to the confidentiality obligations set out in this, make such records and information available to Client and allow for and contribute to audits by Client or an independent auditor of the Processing activities carried out under this Data Processing Addendum, provided that any such audits shall be carried out:
• at Client’s sole cost;
• on at least 30 days’ prior notice;
• not more than once per year, unless Proto has a Personal Data Breach;
• in accordance with the scope agreed with Proto in advance.
- Client provides its prior, general authorization for Proto to appoint Sub-Processors to Process Personal Data on Proto’s behalf, provided that Proto:
(a) shall ensure that the terms on which it appoints such Sub-Processors comply with all applicable Data Protection Legislation, and are consistent with the obligations imposed on Proto in this Data Processing Addendum;
(b) shall remain responsible for the acts and omission of any such Sub-Processor as if they were the acts and omissions of Proto; and
(c) shall inform Client of any intended changes concerning the addition or replacement of the Sub-Processors, thereby giving Client the opportunity to object to such changes provided that if Client objects to the changes and cannot demonstrate, to Proto’s reasonable satisfaction, that the objection is due to an actual or likely breach of Data Protection Legislation, Client shall indemnify Proto for any losses, damages, costs (including legal fees) and expenses suffered by Proto in accommodating the objection.
Description of processing activities: