Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into between Coalition, Inc. and its Affiliates (“Coalition" defined below, also referred to as “Controller”) and (2) Vendor (defined below, also referred to as “Processor”). Coalition and Vendor shall each be referred to as a “Party” and collectively as the “Parties”. This DPA is effective as of the effective date of the Agreement (“Effective Date”).
I. Applicability and Effective Date
This DPA is made pursuant to Applicable Privacy Laws (defined below) including but not limited to CCPA (defined below) and GDPR (defined below). This DPA shall amend and be incorporated into any current valid written contracts between the Parties requiring the processing of Personal Data on behalf of Controller by Processor (collectively, the “Agreement”).
II. Definitions
Capitalized terms not otherwise defined herein shall have the meaning given to them under the Agreement or Applicable Privacy Law. In particular, the terms “Commission”, “Controller”, “Personal Data Breach”, “Processor” and “Supervisory Authority” shall have the meaning as set forth in the GDPR. The terms “Data Exporter” and “Data Importer” shall have the same meaning as in the Standard Contractual Clauses. The terms “Business”, “Business Purpose”, “Collects”, “Consumer”, “Contractor”, “Person”, “Processing”, “Sell”, “Service Provider”, and “Share” shall have the meaning set forth in the CCPA. The following terms in the GDPR and CCPA are understood to have the same meaning: “Controller” and “Business”, “Data Subject” and “Consumer”, “Processor” and “Service Provider”, and “Person” and “Subprocessor”.
“Affiliates” means any company that controls, is controlled by, or is under common control with another company.
“Applicable Privacy Laws” means any laws that regulate the Processing, privacy or security of Coalition Personal Data and that are directly applicable to each Party when Processing Coalition Personal Data. Applicable Privacy Laws include but are not limited to (i) the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and any local laws implementing or supplementing the GDPR, (ii) the United Kingdom (“UK”) Data Protection Act 2018 and the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), (iii) the California Consumer Privacy Act of 2018 effective January 1, 2020, and its implementing regulations, as amended or superseded from time to time (“CCPA”), (iv) the Australia Privacy Act 1988 (No. 119 1988), as amended (“Privacy Act”), and the Australian Privacy Principles (“APPs”), (v) Canadian Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial laws, and (vi) Swiss Data Protection Laws.
“Coalition” means Coalition, Inc. or the Affiliate of Coalition, Inc. that (a) is indicated below in the signature block, or (b) entered into the Agreement with Coalition, if there is no signature block or it is not completed. Coalition entities are listed in Exhibit 3 to this DPA.
“Coalition Personal Data” means (i) Personal Data as defined under GDPR, (ii) Personal Information, as defined under CCPA, and/or (iii) similar terms as defined under Applicable Privacy Laws processed by Vendor, or its Subprocessor (as applicable), on behalf of Coalition in the provision of the Services pursuant to the Agreement.
“Data Subject” means (i) “data subject” as defined under GDPR, (ii) “consumer” as defined under CCPA, or (iii) similar term under Applicable Privacy Laws.
“EEA” means the member states of the European Union and Iceland, Liechtenstein and Norway.
“EEA SCCs” means Module 2 (Controller to Processor) of the Standard Contractual Clauses for the transfer of personal data to Third Countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (and “EEA SCCs” shall be construed accordingly), specifically:
a) the optional docking clause 7 of the EEA SCCs does not apply and is deemed to be deleted;
b) for the purposes of clause 9 of the EEA C2P SCCs, option 2 (General Written Authorisation) applies and the relevant time period is 15 calendar days;
c) the independent dispute resolution option in clause 11 of the EEA SCCs does not apply;
d) for the purposes of clause 17 of the EEA SCCs, the chosen option is option 1 and the chosen law is that set forth under the Agreement. If none provided, the chosen law shall be that of Ireland;
e) for the purposes of clause 18(b) of the EEA SSCs, the chosen courts are courts set forth under the Agreement. If none provided, the chosen courts are those in Ireland;
f) the Appendices of the EEA SCCs shall be completed as follows: 1. Coalition shall be the controller and data exporter and Vendor shall be the processor and data importer for the purposes of Annex I.A to the EEA SCCs and the contact information for each shall be as follows: (i) Vendor contact person’s name, position and contact details: as forth in the Agreement; and (ii) Coalition contact person’s name, position and contact details: as set forth in the Agreement. 2. the contents of Exhibit 1 shall form Annex I.B to the EEA SCCs; 3. the competent supervisory authority shall be Ireland for the purposes of Annex I.C to the EEA SCCs; and 4. the contents of Exhibit 2 shall form Annex II to the EEA SCCs.
“Restricted Transfer” means any transfer of Coalition Personal Data by Coalition to a Vendor established in a Third Country where (1) the transferring Coalition entity is established in the UK, EEA or Switzerland and/or (2) the Personal Data originated in the UK, the EEA or Switzerland.
“Services” means any and all services provided by Vendor to Coalition pursuant to the Agreement.
“Standard Contractual Clauses” means the applicable module of the EEA, the Swiss or the UK government-approved contract mechanism for the cross-border transfer of Coalition Personal Data from the EEA, Switzerland or the UK (as applicable) to Third Countries.
“Swiss SCCs” means the EEA SCCs, as amended as follows:
a) general and specific references in the EEA SCCs to Regulation (EU) 2016/679 or “that Regulation” or EU or member state law have the same meaning as the equivalent reference in Swiss Data Protection Law;
b) the term “member state” will not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with clause 18(c) of the EEA SCCs;
c) the details of the transfers are those specified in Schedule 1 where Swiss Data Protection Law apply to the transfer;
d) the EEA SCCs also apply to the transfer of information relating to an identified or identifiable legal entity where such information is protected similarly as “Personal Data” under Swiss Data Protection Laws until such laws are amended to no longer apply to a legal entity; and
e) the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for the purposes of clause 13 of the EEA SCCs.
“Swiss Data Protection Law” means the data protection and privacy laws and regulations of Switzerland.
“Third Countries” means countries other than (1) EEA member states; (2) Switzerland; (3) the UK or (4) those subject to an adequacy Coalition Personal Data by the European Commission and/or the UK Secretary of State (as applicable) from time-to-time.
“UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioners’ Office under s.119(A) of the UK Data Protection Act 2018 as may be updated from time-to-time, currently found at International Data Transfer Addendum to the EU Commission Standard Contractual Clauses.
“UK SCCs” means the UK Addendum, where:
a) Table 1 and Table 3 of the UK Addendum are deemed to have been completed with the corresponding details set out in Exhibit 1 to this DPA and, for the purposes of Table 1 of the UK Addendum, 1. the "Start Date" is the Effective Date; and 2. the official company registration numbers (where applicable) of the Parties are as set out in the Agreement.
b) for the purposes of Table 2 of the UK Addendum, (1) the version of the "Approved EU SCCs" is the EEA SCCs; (2) the choices regarding clause 7 (docking clauses), clause 11 (option), clause 9a (prior authorisation or general authorisation) and clause 9a (time period) of the EEA SCCs are as set out in the definition of EEA SCCs in this DPA; and
c) "Importer" is deemed to have been chosen for the purposes of Table 4 of the UK Addendum.
“Vendor” means the (a) person or entity that is indicated below in the signature block, or (b) if there is no signature block or it is not completed, then Vendor is the person or entity that has entered into the Agreement with Coalition.
III. Processing of Coalition Personal Data
A. Processor shall only Process Coalition Personal Data on behalf of Controller in accordance with this DPA and in accordance with Controller's instructions, unless Processing is required by Applicable Privacy Laws to which Processor is subject, in which case Processor shall, to the extent permitted by Applicable Privacy Law, inform and coordinate with Controller prior to Processing. B. Processor acknowledges and agrees that Exhibit 1 (Description of Processing Activities) to this DPA is an accurate description of the Processing carried out under this DPA, which shall be amended from time to time to reflect accurate nature, duration, purpose, types and categories related to the Processing of Coalition Personal Data. C. Processor shall document all instructions issued by Controller, including the name of the person issuing the instruction, as well as the date and content of the instruction. Processor shall inform Controller immediately in writing if the instruction issued by Controller is in violation of Applicable Privacy Law. D. Processor shall not sell or disclose Coalition Personal Data to third parties other than as provided under this DPA. No copies or duplicates of Coalition Personal Data may be produced without the knowledge of Controller. This does not apply to the creation of backup copies to facilitate compliance with Applicable Privacy Laws. E. Processor shall not combine Coalition Personal Data with personal data received from another person or entity other than with the express permission of Controller. F. Processor shall maintain a record of all categories of Processing activities carried out on behalf of Controller, which shall be compliant with Applicable Privacy Laws.
IV. Notification Obligations
A. Processor shall immediately notify Controller of any monitoring activities and measures undertaken by a supervisory authority or other applicable regulatory body in respect of it. B. Processor shall immediately and in any event within 5 business days inform the Controller in the event that it receives a request from a Data Subject relating to the Coalition Personal Data. C. Processor shall notify Controller of a Personal Data Breach without undue delay and in any event within 48 hours of Processor becoming aware of the Personal Data Breach. In consultation with Controller, Processor shall take reasonable and appropriate measures in accordance with Applicable Privacy Laws and industry standards to secure Personal Data and limit possible detrimental effects to Data Subjects. Where obligations are placed on Controller under Applicable Privacy Laws, Processor must provide reasonable assistance to Controller in meeting such obligations.
V. Technical and Organizational Measures
1. Processor shall implement the technical and organizational measures set forth in Exhibit 2 (Technical and Organizational Measures). 2. The technical and organizational measures are subject to technical progress and development under Applicable Privacy Laws and industry standards, and Processor may implement equivalent alternative measures or improvements from time to time. These must not, however, fall short of the level of security specified in Exhibit 2. Any material changes must be documented [and notified to Controller]. 3. Processor shall keep records and as required, update the technical and organizational measures as best practice evolves, with such records available upon request by Controller.
VI. Authorized Persons and Training
Processor shall ensure that only its designated authorized persons shall be provided access to Coalition’s Personal Data. Processor shall ensure that its designated authorized persons receive adequate training to ensure compliance with Processing requirements under this DPA and are subject to a confidentiality agreement or are under an appropriate statutory obligation of confidentiality.
VII. Compliance with Applicable Privacy Laws
Upon written request of Controller and taking into account the nature of Processing and information available, Processor shall assist Controller in ensuring compliance with the obligations pursuant to Applicable Privacy Laws, including but not limited to security of Processing, Personal Data Breach notification, data protection impact assessment, consultation with or requests of a competent data protection authority and inquiries about Controller’s Processing of Coalition Personal Data pursuant to this DPA. Processor shall provide all available information to Controller to demonstrate compliance with personal data processing obligations under this DPA.
VIII. Data Protection Officer
Where stipulated by Applicable Privacy Laws, Processor shall appoint a data protection officer (“DPO”) to fulfill the duties and responsibilities set forth under Applicable Privacy Laws. Coalition has appointed a DPO that may be reached at privacy@coalitioninc.com.
IX. Audit Rights of Controller
Controller may carry out audits concerning the compliance of this DPA by Processor and may appoint external auditors to carry out such audits as it deems necessary.
X. Data Subject Rights
Taking into consideration the nature of Coalition Personal Data Processing, Processor shall: 1. Not respond to the Data Subject request itself or by Subprocessor unless required by Applicable Privacy Laws. 2. Notify Controller without undue delay if Processor or any Subprocessor receives a request from a Data Subject under any Applicable Privacy Laws with respect to Coalition Personal Data. 3. Reasonably assist Controller through appropriate technical and organizational measures to fulfill Controller’s obligation to respond to Data Subject requests arising under Applicable Privacy Laws.
XI. Deletion of Coalition Personal Data
A. Processing of Coalition Personal Data by Processor shall only take place for the duration specified in the Agreement, unless terminated earlier pursuant to the terms and conditions of the Agreement (“Processing Time Frame”). B. At the end of the Processing Time Frame: 1. Coalition Personal Data will be deleted within 30 days following the end of the Processing Time Frame, unless retention of Coalition Personal Data is required pursuant to Applicable Privacy Laws. 2. Upon Coalition’s written request, Processor shall, at the choice of Controller: a. Return the Coalition Personal Data to Controller; or b. Delete the Coalition Personal Data and provide Controller with a written confirmation of deletion of the Coalition Personal Data.
XII. Subprocessors
A. Processor may engage Subprocessors to assist in providing the Services to the extent permitted under this section XII. Processor shall maintain a list of Subprocessors that process Coalition Personal Data and shall provide a copy of such list to Controller upon request. B. Processor shall carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Coalition Personal Data required by Applicable Privacy Laws, this DPA and the Agreement. Processor shall enter into a written agreement with each Subprocessor containing in substance data protection obligations that provide an equivalent level of protection for Coalition Personal Data as provided by this DPA, to the extent applicable to the nature of the Services provided by such Subprocessor. Processor shall maintain copies of its agreements with Subprocessors and make such agreements available as Controller may request from time to time. To the extent necessary to protect confidential information, Processor may redact copies prior to sharing with Controller. C. To the extent a Subprocessor is established in a Third Country, Processor shall ensure that any onward transfer of Personal Data originally transferred pursuant to clause XIII(A) shall be made in compliance with the requirements of the Applicable Privacy Law and in particular, where required, that Processor (as data exporter) and the Subprocessor (as data importer) will enter into the applicable Standard Contractual Clauses. D. Processor shall be liable for the acts and omissions of its Subprocessors to the same extent Processor would be liable if performing the Services under the terms of this DPA. E. Processor shall provide Controller with written notice of newly appointed Subprocessors (including the jurisdiction in which each Subprocessor is established) before authorizing such Subprocessors to Process Coalition Personal Data in connection with providing the Services. Controller may object to Processor’s appointment of a new Subprocessor by providing written notice to Processor within fifteen (15) calendar days of receiving Processor’s notification. Such notice shall explain the reasonable grounds for the objection. In the event Controller objects to a new Subprocessor, Processor will use commercially reasonable efforts to make available to Controller a change in the Services or recommend a commercially reasonable change to Controller’s configuration or use of the Services to avoid the Processing of Coalition Personal Data by the objected-to new Subprocessor without unreasonably burdening Controller. If Processor is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) calendar days, either Party may terminate this DPA without penalty by providing written notice to the other Party.
XIII. Restricted Transfers
A. To the extent that a Restricted Transfer of Coalition Personal Data is made: 1. To the extent that the Coalition Personal Data originated in the EEA and/or the Controller is established in the EEA, the EEA SCCs shall apply; 2. To the extent that the Coalition Personal Data originated in Switzerland and/or the Controller is established in Switzerland, the Swiss SCCs shall apply; and/or 3. To the extent that the Coalition Personal Data originated in the UK and/or the Controller is established in the UK, the UK SCCs shall apply. B. Where clause XIII(A) of this DPA applies, the Parties agree to be bound by, observe, comply with and perform the applicable Standard Contractual Clauses as if the Standard Contractual Clauses were set out in, and incorporated into this DPA. Controller and Processor are deemed to have executed and signed the applicable Standard Contractual Clauses by entering into and signing this DPA.
XIV. General Terms
A. Governing Law and Jurisdiction. The Parties to this DPA hereby submit to the choice of jurisdiction specified in the Agreement. B. Order of Precedence. In the event of any inconsistency between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail with respect to the subject matter herein. The EEA SCCs, UK SCCs and/or Swiss SCCs (as applicable) shall take precedence over the provisions of this DPA and the Agreement. C. Changes in Applicable Privacy Laws. In the event of any changes to Applicable Privacy Laws affecting the terms of this DPA, the Parties agree to negotiate in good faith the amendment of this DPA as applicable and necessary to comply with the changes in Applicable Privacy Laws. D. Severance. Should any provision of this DPA be deemed invalid or unenforceable by a court of competent jurisdiction, then the remainder of this DPA shall remain in full force and effect. The invalid or unenforceable provisions shall either be: (a) amended by the Parties as necessary to ensure validity and enforceability, while preserving the Parties’ intentions as closely as possible; or, if (a) is not feasible, construe such provision in a manner as if the invalid or unenforceable provision was not originally made a part of this DPA. E. Assignment of Rights and Delegation of Duties. This DPA is binding upon and inures to the benefit of the Parties and their respective successors and permitted assigns. However, neither Party may assign any of its rights or delegate any of its obligations under this DPA without the prior written consent of the other Party, which consent shall not be unreasonably withheld or delayed, with the exception of any assignment or deemed assignment resulting from an internal reorganization, merger, or acquisition of a non-competitor of the non-assigning Party. Assignments made in violation of this provision are null and void. F. Force Majeure. Non-performance of either Party will be excused to the extent performance is rendered impossible by strike, fire, war, flood, governmental acts or orders or restrictions, or act of God, or any other reason where failure to perform is beyond the reasonable control of the non-performing Party.] G. Nature of DPA. Nothing in this DPA shall be construed to create (i) a partnership, joint venture or other joint business relationship between the Parties or any of their affiliates, (ii) any fiduciary duty owed by one Party to another Party or any of its affiliates, or (iii) a relationship of employer and employee between the Parties. H. No Waiver. Failure or delay on the part of either Party to exercise any right, power, privilege, or remedy hereunder shall not constitute a waiver thereof. No provision of this DPA may be waived by either Party except by a writing signed by an authorized representative of the Party making the waiver. I. No Third Party Beneficiaries. Save as otherwise provided by the EEA SCCs, UK SCCs and/or Swiss SCCs (as applicable) nothing in this DPA shall be considered or construed as conferring any right or benefit on a person not Party to this DPA nor imposing any obligations on either Party hereto to persons not a Party to this DPA. J. Term. The term of this DPA shall commence on the Effective Date and terminate concomitantly with the Agreement, unless terminated earlier in accordance with this Section XIV. K. Termination. Either Party may terminate this DPA immediately if the non-breaching Party determines, in its sole and reasonable discretion, that the other Party has breached a material term of this DPA and a cure is infeasible. Otherwise, the non-breaching Party shall provide the breaching Party with thirty (30) days from the breaching Party‘s receipt of a notice to cure such breach. If the breaching Party fails to cure such breach within thirty (30) days, then the non-breaching Party may terminate this DPA.
Exhibit 1 - Description of Processing Activities
This Exhibit 1 includes certain details of the Processing and Restricted Transfer of Coalition Personal Data as required by Applicable Privacy Laws.
I. Subject matter, nature and duration of Processing of Coalition Personal Data
The subject matter, nature and duration of the Processing and the transfer of Coalition Personal Data are set out in the Agreement and this DPA, and depend on the nature and scope of the Services, manner of receipt, collection, storage, use, dissemination (towards Subprocessors in line with the Agreement and this DPA), retention and erasure of Coalition Personal Data, and Controller’s documented instructions.
II. Purpose for which Coalition Personal is Processed on behalf of Controller
The purposes of the Processing and transfer of Coalition Personal Data is to enable Vendor and Vendor’s Subprocessor(s) to deliver the Services and perform its obligations as set forth in the Agreement, this DPA, and Controller’s documented instructions, or as otherwise agreed by the Parties in mutually executed written form.
III. Categories of Coalition Personal Data Processed including Sensitive Personal Data
The categories of Coalition Personal Data Processed, including Sensitive Personal Data are set out in the Agreement and this DPA, and depend on the nature and scope of the Services, manner of receipt, collection, storage, use, dissemination (towards Subprocessors in line with the Agreement and this DPA), retention and erasure of Coalition Personal Data, and Controller’s documented instructions.
IV. Categories of Data Subjects whose Personal Data is Processed
The categories of Data Subjects whose Personal Data is Processed are set out in the Agreement and this DPA, and depend on the nature and scope of the Services, manner of receipt, collection, storage, use, dissemination (towards Subprocessors in line with the Agreement and this DPA), retention and erasure of Coalition Personal Data, and Controller’s documented instructions.
V. Frequency of the Transfer of Coalition Personal Data
Taking into account Vendor’s Coalition Personal Data Processing, including the manner of receipt, collection, storage, and use of Coalition Personal Data, the frequency of the transfer of Coalition Personal Data, depends on the nature and scope of the Services agreed to under the Agreement, Controller’s documented instructions and Vendor’s need to transfer Coalition Personal Data for the performance of the Services. Consequently, transfers may happen on either a continuous or one-off basis, until the termination of the Agreement.
VI. Period for which Coalition Personal Data will be retained
Coalition Personal Data shall be retained by Vendor for the period set forth in the Agreement, this DPA and Controller’s documented instructions.
VII. Subject matter, nature and duration of Processing with respect to Transfers to Subprocessors.
Vendor shall maintain an up-to-date list of Subprocessors including name, contact details, address and Processing details. Vendor shall provide Controller with an up-to-date list of Subprocessors upon execution of this DPA and shall continue to provide Controller with up-to-date lists when applicable. The duration of Processing of Coalition Personal Data with respect to transfers to Vendor Subprocessors is consistent with this DPA and the Agreement.
Exhibit 2 - Technical and Organizational Measures
General Considerations This Exhibit 2 outlines the technical and organizational measures (“TOMs”) Processor shall implement and maintain for secure and compliant processing of personal data. TOMs shall take into account the rights of data subjects and requirements of Applicable Privacy Laws, such as Articles 24, 25 and 32 GDPR to the extent applicable.
Organization If required under Applicable Privacy Laws, Processor shall appoint a data protection officer (DPO) who shall provide advice on data privacy issues, update Processor about changes in Applicable Data Privacy Laws and support the review and improvement of these TOMs.
Confidentiality 3.1 Entry Control Processor shall maintain and enforce a physical security policy which governs physical security controls for both remote work and office requirements. 3.2 Access and Usage Control Processor shall restrict access to authorized users for all personal data and implement automatic control mechanisms for verifying access to systems containing personal data. User access to personal data shall be reviewed by Processor on an annual basis. Processor shall maintain strict password policies, including two factor authentication, for any application storing personal data. Access shall be monitored and logged, including unsuccessful login attempts. The use of personal data shall be limited, so that only authorized individuals can use the personal data necessary for their task (De Minimum Principle).
Integrity and Availability Processor shall maintain sufficient and appropriate (based on the type of personal data exported and its sensitivity) environmental, physical and logical security measures with respect to personal data and to Processor’s system infrastructure. This includes but is not limited to the following:
Require all devices with access to personal data to meet industry security standards, including the installation of anti-malware software.
Encryption of personal data based on data classification, both in transit and at rest.
Personal data is processed on data processing systems that are subject to regular and documented patch management.
Require redundant storage media and backups of systems according to latest technical standards.
Conduct risk assessments and penetration testing on an annual basis to identify vulnerabilities, with remediation of such vulnerabilities.
Security monitoring of systems and facilities storing personal data.
Abide by established document retention and destruction policies for all personal data.
Maintain an inventory of personal data with disposal instructions.
Regular auditing of data processing procedures.
Implementation and maintenance of procedures regarding data breaches and the protection of data subjects’ rights.
Regular review of technical advancements.
Privacy-by-Default Processor shall incorporate privacy-by-design principles for systems and enhancements at the earliest stage of development.
Employee Workplace Processor shall require its employees to complete privacy and security trainings on an annual basis.