CPaaS Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement (DPA) is made by and between Dotdigital, a trading name of Dynmark International Limited, and the Customer identified in any Service Agreement already existing between the parties or that may incorporate this DPA by reference. This DPA shall be in addition to any obligations set out in any Service Agreement.

All capitalised terms in this DPA shall have the meaning as prescribed by the Dotdigital Terms as located at www.dotgitial.com/terms/cpaas-terms or as otherwise agreed between the parties, unless otherwise specified below.

Applicable Law means as applicable and binding on the Customer, Dotdigital and/or the Services:

(a) any law, statute, regulation, byelaw or subordinate legislation in force from time to time to which a party is subject and/or in any jurisdiction that the Services are provided to or in respect of, as may be specified in Terms; (b) the common law and laws of equity as applicable to the parties from time to time;

(c) any binding court order, judgment or decree; or

(d) any applicable direction, policy, rule or order that is binding on a party and that is made or given by any regulatory body having jurisdiction over a party or any of that party’s assets, resources or business;

Appropriate Safeguards means such legally enforceable mechanism(s) for transfers of Personal Data as may be permitted under Data Protection Laws from time to time (including, but not limited to, EU Model Contract Clauses or Privacy Shield certification);

Data Controller has the meaning given to that term (or to the term ‘controller’) in Data Protection Laws;

Data Processor has the meaning given to that term (or to the term ‘processor’) in Data Protection Laws;

Data Protection Laws means as applicable and binding on the Customer, Dotdigital and/or the Services:

(a) in the United Kingdom:

(i) the Data Protection Act 2018; and/or (ii) the General Data Protection Regulation (EU) 2016/679 (or “GDPR”) and/or any corresponding or equivalent national laws or regulations; and/or (iii) the Privacy and Electronic Communications (EC Directive) Regulations 2003 and/or any corresponding or equivalent national laws or regulations.

(b) in member states of the European Union: the Data Protection Directive or the GDPR, once applicable, and all relevant member state laws or regulations giving effect to or corresponding with any of them;

(c) specifically in relation to the Customer, all data protection and/or privacy laws in which recipient Data Subjects are contacted through the Services are located;

(d) any Applicable Laws replacing, amending, extending, re-enacting or consolidating any of the above Data Protection Laws from time to time;

Data Protection Losses means all liabilities, including all:

(a) costs (including legal costs), claims, demands, actions, settlements, interest, charges, procedures, expenses, losses and damages (including relating to material or non-material damage); and

(b) to the extent permitted by Applicable Law:

(i) administrative fines, penalties, sanctions, liabilities or other remedies imposed by a Supervisory Authority;

(ii) compensation which is ordered by a Supervisory Authority to be paid to a Data Subject; and

(iii) the reasonable costs of compliance with investigations by a Supervisory Authority;

Data Subject has the meaning given to that term in Data Protection Laws;

Data Subject Request means a request made by a Data Subject to exercise any rights of Data Subjects under Data Protection Laws;

GDPR Date means from when the GDPR applies on 25 May 2018;

International Organisation means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries;

International Recipient has the meaning given to that term in clause 6; Personal Data has the meaning given to that term in Data Protection Laws;

Personal Data Breach means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Protected Data;

Processing has the meanings given to that term in Data Protection Laws (and related terms such as process have corresponding meanings);

Processing Instructions has the meaning given to that term in clause 3.2.1;

Protected Data means Personal Data received from or on behalf of the Customer in connection with the performance of Dotdigital’s obligations under this Agreement;

Sub-Processor means another Data Processor engaged by Dotdigital for carrying out processing activities in respect of the Protected Data on behalf of the Customer; and

Supervisory Authority means any local, national or multinational agency, department, official, parliament, public or statutory person or any government or professional body, regulatory or supervisory authority, board or other body responsible for administering Data Protection Laws. references to any Applicable Laws (including to the Data Protection Laws and each of them) and to terms defined in such Applicable Laws shall be replaced with or incorporate (as the case may be) references to any Applicable Laws replacing, amending, extending, re-enacting or consolidating such Applicable Law (including the GDPR and any new Data Protection Laws from time to time) and the equivalent terms defined in such Applicable Laws, once in force and applicable. A reference to a law includes all subordinate legislation made under that law.