EU Data Processing Addendum
This EU Data Processing Addendum (EU Addendum) supplements the Master Data Processing Agreement between the Customer and Setyl Ltd (the DPA), which in turn forms part of the Master Software License Agreement between the parties (the Principal Agreement). It applies where and to the extent that the Supplier’s processing of Customer Personal Data is subject to European Data Protection Law.
Capitalised terms used but not defined in this EU Addendum have the meaning given in the DPA or the Principal Agreement.
1. Purpose and application
1.1.
The DPA is drafted around UK Data Protection Laws. This EU Addendum extends the DPA so that, where European Data Protection Law applies, the parties’ obligations meet the requirements of that law, and any restricted transfer of Customer Personal Data out of the European Economic Area (EEA) is made subject to an appropriate transfer mechanism.
1.2.
This EU Addendum applies automatically, without further action by either party, whenever the Supplier processes Customer Personal Data that is subject to European Data Protection Law in connection with the Services.
1.3.
Except as expressly amended by this EU Addendum, the DPA remains in full force and effect. This EU Addendum does not replace, and is in addition to, any rights or protections the Customer has under the DPA.
2. Definitions
2.1.
In this EU Addendum:
European Data Protection Law means, as applicable: (a) Regulation (EU) 2016/679 (the EU GDPR); (b) the EU e-Privacy Directive 2002/58/EC; and (c) the Swiss Federal Act on Data Protection (the Swiss FADP); in each case together with any implementing or supplementary national laws, and as amended, superseded or replaced from time to time.
EU SCCs means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Restricted Transfer means a transfer of Customer Personal Data from the Customer (as exporter) to the Supplier (as importer), or an onward transfer, that is subject to the transfer restrictions in Chapter V of the EU GDPR (or the equivalent under the Swiss FADP) and that would be unlawful without a transfer mechanism such as the EU SCCs.
Supervisory Authority means an independent public authority established under Article 51 of the EU GDPR (or the equivalent authority under the Swiss FADP).
2.2.
The terms controller, processor, data subject, personal data, processing, personal data breach and appropriate technical and organisational measures have the meanings given in the EU GDPR when European Data Protection Law applies.
3. Extension of the DPA to European Data Protection Law
3.1.
Where European Data Protection Law applies, references in the DPA to “Data Protection Laws” are deemed to include European Data Protection Law, and references to the “UK GDPR” are deemed to include the EU GDPR, so that the obligations in the DPA (including as to security, confidentiality, assistance with data subject rights, personal data breach notification, records, sub-processing and audits) apply equally in respect of Customer Personal Data protected by European Data Protection Law.
3.2.
Where the DPA refers to the “DP Regulator” or the UK Information Commissioner’s Office, that reference is deemed to include the competent Supervisory Authority under European Data Protection Law.
3.3.
The roles of the parties are as set out in the DPA: the Customer is the controller (or, where the Customer is itself a processor acting on behalf of a third-party controller, a processor) and the Supplier is the processor (or sub-processor).
4. International transfers and the EU SCCs
4.1.
To the extent that the Supplier’s processing of Customer Personal Data involves a Restricted Transfer, the parties agree that the EU SCCs are incorporated into and form part of this EU Addendum, and apply to that Restricted Transfer, completed as set out in this clause 4 and the Annexes.
4.2.
Modules. The EU SCCs apply as follows:
4.2.1.
where the Customer is a controller and the Supplier is a processor, Module Two (Controller to Processor) applies; and
4.2.2.
where the Customer is a processor acting on behalf of a third-party controller and the Supplier is a sub-processor, Module Three (Processor to Processor) applies.
4.3.
Clause elections. For the purposes of the EU SCCs:
4.3.1.
Clause 7 (the optional docking clause) applies;
4.3.2.
in Clause 9 (use of sub-processors), Option 2 (general written authorisation) applies, and the minimum notice period for changes to sub-processors is 30 days, consistent with clause 4 of the DPA;
4.3.3.
in Clause 11 (redress), the optional wording allowing data subjects to lodge a complaint with an independent dispute resolution body does not apply;
4.3.4.
in Clause 17 (governing law), the EU SCCs are governed by the law of Ireland;
4.3.5.
in Clause 18(b) (choice of forum and jurisdiction), disputes are to be resolved before the courts of Ireland; and
4.3.6.
the Annexes to the EU SCCs are completed using the information in the Annexes to this EU Addendum.
4.4.
Precedence. In the event of any conflict between the EU SCCs and any other term of this EU Addendum, the DPA or the Principal Agreement, the EU SCCs prevail in respect of the Restricted Transfer.
4.5.
Alternative mechanisms. If the European Commission adopts an adequacy decision covering the destination country, or if the parties adopt another lawful transfer mechanism, that mechanism applies to the relevant transfers instead of the EU SCCs, and the EU SCCs will cease to apply to those transfers to the extent that the alternative mechanism provides an adequate safeguard.
5. Switzerland
5.1.
Where the Swiss FADP applies to a Restricted Transfer, the EU SCCs apply with the following adaptations: (a) references to the “GDPR” are to be understood as references to the Swiss FADP in respect of data protected by it; (b) the competent Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner; (c) the term “member state” must not be interpreted to exclude data subjects in Switzerland from suing for their rights in their place of habitual residence; and (d) the EU SCCs also protect the personal data of legal entities until the entry into force of revised Swiss data protection law that no longer applies to legal entities.
6. United Kingdom
6.1.
Transfers subject to UK Data Protection Laws are addressed in the DPA (including through the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as applicable) and are not governed by this EU Addendum.
7. Order of precedence
7.1.
In the event of any conflict, the following order of precedence applies to the subject matter of data protection and international transfers: (1) the EU SCCs (in respect of a Restricted Transfer); (2) this EU Addendum; (3) the DPA; and (4) the Principal Agreement.
8. General
8.1.
This EU Addendum is governed by, and takes effect in accordance with, the governing law and jurisdiction provisions of the DPA, except that the EU SCCs are governed by the law and subject to the forum stated in clause 4.3.
8.2.
This EU Addendum takes effect on the effective date of the DPA (or, if later, the date European Data Protection Law first applies to the processing) and continues for as long as the Supplier processes Customer Personal Data subject to European Data Protection Law.
Annex I to the EU SCCs
A. List of parties
Data exporter
Identity and contact details: the Customer, as set out in the Contract Details of the DPA.
Role: controller (Module Two) or processor (Module Three).
Signature and date: executed via the Order Form that incorporates the Principal Agreement and the DPA.
Data importer
Identity and contact details: Setyl Ltd, St James House, St James Road, London, KT6 4QH, UK. Contact: hello@setyl.com.
Role: controller (Module Two) or processor (Module Three).
Signature and date: executed via the Order Form that incorporates the Principal Agreement and the DPA.
B. Description of transfer
The categories of data subjects, categories of personal data, nature and purpose of processing, and duration are as set out in Annex 1 (Processing details) of the DPA. In summary:
C. Competent supervisory authority
The competent Supervisory Authority is the Irish Data Protection Commission, consistent with the choice of Irish law and forum in clause 4.3. Where the data exporter is established in another EEA member state, or has appointed an EU representative in another member state, the competent Supervisory Authority is the authority of that member state.
Annex II to the EU SCCs — Technical and organisational measures
The technical and organisational security measures are those set out in Annex 3 (Technical and organisational measures) of the DPA, which apply to the processing under the EU SCCs.
Annex III to the EU SCCs — List of sub-processors
For Module Two and Module Three, the Customer has authorised the use of the sub-processors listed on the Supplier’s Sub-processor Page at setyl.com/legal, as referenced in Annex 2 of the DPA. Changes are notified in accordance with clause 4 of the DPA (minimum 30 days’ notice).