PARTIES
(1) The Licenceenames in Schedule 1 (Controller)
(2) DealerManagement Services Limited of Navigator House, Unit 5, 12 O’Clock Court,Attercliffe Road, Sheffield S4 7WW (Processor)
BACKGROUND:
(A) The Controller and the Processor entered into a Software Licence this forms a schedule to that may require the Processor to process Personal Data on behalf of the Controller.
(B) This Processor Agreement (Agreement) sets out the terms and conditions on which the Processor will process Personal Data when providing services under the Services Agreement. This Agreement contains the mandatory clauses required by Article 28(3) of the General Data Protection Regulation ((EU) 2016/679)for contracts between controllers and processors.
AGREED TERMS:
1. DEFINITIONS AND INTERPRETATION
The following definitions and rules of interpretation apply in this Agreement.
1.1 Definitions:
2. PROCESSING PURPOSES
2.1 The Controller and the Processor acknowledge that the Controller is the controller and the Processor is the processor and that the Controller retains control of the Personal Data and remains responsible for its compliance obligations under Data Protection Legislation.
2.2. Where the Processor appoints a subcontractor pursuant to clause 4 below, the Processor shall be a data controller in relation to such processing.
2.3The Processor may process the Personal Data categories and DataSubject types set out in Schedule 1 of this Agreement.
3. PROCESSOR’S OBLIGATIONS
3.1 The Processor shall:
3.1.1 implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of Data Protection Legislation and ensure the protection of therights of the Data Subject, as further set out below in this Agreement;
3.1.2 only use subcontractors to help with the processing of Personal Data in the circumstances set out in clause 4 below;
3.1.3 process the Personal Data only on documented instructions fromthe Controller, unless required to do so by Union or Member State law to whichthe Processor is subject; in such a case, the Processor shall inform theController of that legal requirement before processing, unless that lawprohibits such information on important grounds of public interest;
3.1.4 ensure that persons authorised to process the personal data(such as its employees) have committed themselves to confidentiality or areunder an appropriate statutory obligation of confidentiality;
3.1.5 take the security measures set out in clause 5 below;
3.1.6 taking into account the nature of the processing, assist theController by appropriate technical and organisational measures, insofar asthis is possible, for the fulfilment of the Controller’s obligation to respondto requests for exercising the Data Subject’s rights as set out in clause 6below;
3.1.7 assist the Controller in ensuring compliance with theobligations set out in clause 7 below (data breach) taking into accountthe nature of processing and the information available to the Processor;
3.1.8 at the choice of the Controller, delete or return all the Personal Data to the Controller after the termination or expiry of the Services Agreement and delete existing copies (unless UK law requires storage of the Personal Data);
3.1.9 make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller;
3.1.10 assist the Controller in ensuring compliance with the requirement to carry out Data Protection Impact Assessments as set out in Article 35 of GDPR, taking into account the nature of processing and the information available to the Processor;
3.1.11 Designate a Data Protection Officer if required by Article 37(1) of GDPR and in accordance with the provisions of Articles 37, 38 and 39 of GDPR; and
3.1.12 immediately inform the Controller, if in the opinion of the Processor, an instruction from the Controller infringes Data Protection Legislation.
3.2 The Processor will promptly comply with any request by or instruction from the Controller to process the Personal Data, or to stop, mitigate or remedy any unauthorised processing.
3.3 The Processor will keep all Personal Data confidential and notdisclose such data to third parties unless specifically authorised in writingby the Controller or as required by law. If the Processor is required by law, court, regulator or supervisoryauthority to process or disclose any Personal Data, the Processor will firstinform the Controller of this and allow the Controller to object or challengethe requirement, unless the law prohibits the Processor from informing theController.
4 SUBCONTRACTORS
4.1 The Processor may only authorise a third party (“subcontractor”)to process the Personal Data if:
4.1.1 the Processor has carried out appropriate due diligence on anysubcontractor to ensure that the subcontractor can satisfy its contractualobligations; and
4.1.2 the Processor and the subcontractor enter into a written contract containing terms the same as those set out in this Agreement, in particular, in relation to data security measures; and
4.1.3 the Processor maintains control over all Personal Data it shareswith the subcontractor; and
4.1.4 the Processor ensures that the subcontractor does not process the Personal Data except on instructions from the Data Controller (unless required to do so by UK law); and
4.2 The Processor shall be fully liable for the actions and in actionsof the subcontractor and shall be responsible for the subcontractor’s performance of obligations.
5. SECURITY
5.1 TheProcessor shall, taking into account the state of the art, thecosts of implementation and the nature, scope, context and purposes ofprocessing as well as the risk of varying likelihood and severity for therights and freedoms of natural persons, implement appropriate technical andorganisational measures to ensure a level of security appropriate to the risk,including as appropriate:
5.1.1 the pseudonymisation and encryption of Personal Data;
5.1.2 the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
5.1.3 the ability to restore the availability and access to personaldata in a timely manner in the event of a physical or technical incident;
5.1.4 a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
5.2 Inassessing the appropriate level of security, the Processor shall take accountin particular of the risks that are presented by processing, in particular fromaccidental or unlawful destruction, loss, alteration, unauthorised disclosureof, or access to personal data transmitted, stored or otherwise processed.
6. RESPONSES TO DATASUBJECTS
6.1 The Processor will put in place such technical and organisational measures as may be appropriate to enable the Controller to comply with the rights of Data Subjects under Data Protection Legislation, including the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object to processing and the right to object to automated individual decision making.
6.2 If the Processor receives any complaint or other communication relating to the processing of the Personal Data or a Subject Access Request from a Data Subject, it must notify the Controller as soon as possible after it receives it and in any event within 3 working days and will provide the Controller with all reasonable assistance in helping the Controller to reply to such communications.
6.3 The Processor will provide to the Controller such information as the Controller may reasonably require in order for the Controller to comply with the rights of Data Subjects under Data Protection Legislation.
6.4 The Processor will provide all appropriate assistance to the Controller to enable it to comply with any information or assessment notices served on the Controller by any supervisory authority under the Data Protection Legislation.
6.5 The Processor shall not disclose Personal Data to any third party other than at the Controller’s written request or as set out in this agreement or as required by law.
7. PERSONALDATA BREACH
7.1 If any Personal Data is lost or destroyed or becomes damaged, corrupted, or unusable (“Personal Data Loss”), the Processor will notify the Controller without undue delay (and in any event within 24 hours) after learning of such Personal Data Loss and the Processor shall to the extent possible restore any such data at its own expense.
7.2If the Processor becomes aware of any unauthorised or unlawful processing of the Personal Data or any Personal Data Breach, it will notify the Controller without undue delay (and in any event within 24 hours) including all relevant information such as:
(a) A description of the nature of the Personal Data Breach, the unauthorised or unlawful processing and/or the Personal Data Loss, including the categories and approximate number of both Data Subjects and Personal Data records concerned;
(b) the likely consequences; and
(c) description of the measures taken, or proposed to be taken, including measures to mitigate the impact.
7.3 The parties will co-ordinate and co-operate with each other to investigate any matters arising as contemplated by this clause.
7.4The Processor shall take all reasonable steps to mitigate the effects and reducethe impact of any Personal Data Breach or unlawful Personal Data processing.
7.5 The Processor agrees that it shall not (and the Controller is solely responsible to):
(a) provide notice of thePersonal Data Breach to any Data Subjects, supervisory authorities, regulators,law enforcement agencies or any other third party, except when the Processor(as opposed to the Controller) is required by law or regulation to provide suchnotice; and
(b) offer any type ofremedy to affected Data Subjects.
8. CROSS-BORDERTRANSFERS OF PERSONAL DATA
8.1 The Processor (or any sub contractor of the Processor) shall not transfer or otherwise process Personal Data outside the European Economic Area (EEA) without obtaining the Controller’s prior written consent (except where the Processor is required to transfer such data by Union or Member State law, in which case the Processor shall inform the Controller of such legal requirement before processing takes place, unless any law prohibits such disclosure on important grounds of public interest).
8.2 If the Controller consents to the transfer or other processing of the Personal Data outside of the EEA and no appropriate safeguards exist (such as an adequacy decision or the Processor being part of the EU-US Privacy Shield), the Processor and the Controller will each execute the European Commission’s Standard Contractual Clauses for the transfer of Personal Data from the European Union to processors established in third countries (controller-to-processor transfers), as set out in the Schedule to Commission Decision 2010/87/EU (“SCCs”).
8.1 If the Processor is basedoutside of the EEA and is not established within a country for which there isan adequacy decision and the Processor is not part of the EU-US Privacy Shield,the Processor shall, prior to any Personal Data relating to data subjectswithin the Union being transferred to it, execute the European Commission’sStandard Contractual Clauses (controller-to-processor transfers), as set out inthe Schedule to Commission Decision 2010/87/EU (“SCCs”).
8.2 if the Processor appointssubcontractors that are based outside of the EEA, the Processor shall, prior toany Personal Data being transferred to such countries, (i) ensure that suchsubcontractor executes the SCCs and (ii) send a copy of such executed SCCs tothe Controller.
10. DATARETURN AND DESTRUCTION
10.1 The Processor will, on the request of the Controller, provide the Controller with a copy of or access to the Personal Data in its possession or control in the format and on the media reasonably specified by the Controller.
10.2 On termination or expiry of the Services Agreement, the Processor will at least 7 days prior to the date of expiry or termination ask the Controller whether the Controller wants the Personal Data to be deleted, destroyed, returned or retained and shall follow the Controller’s instructions accordingly.
10.3 If the Processor isrequired by any law, regulation, or government or regulatory body to retain anydocuments or materials, the Processor will inform the Controller in writing ofsuch requirement, providing details of the legal basis for retention and settingout the timings for deletion when such retention period ends.
10.4 If the Controllerrequires the Processor to delete or destroy certain documents or materials oranything else containing Personal Data, the Processor shall certify in writingthat it has so deleted or destroyed the Personal Data within 3 days of doingso.
11. AUDIT
11.1The Controller (and any third-party representatives) may audit the Processor’scompliance with its obligations under this Agreement and the Processor willgive the Controller (and its third-party representatives) all necessaryassistance and co-operation to conduct such audits.
11.2 If a Personal DataBreach occurs, or the Processor becomes aware of a breach of any of itsobligations under this Agreement or any Data Protection Legislation, or if theController so requires it, the Processor will:
(a) conduct its owninvestigation to confirm the cause of such Personal Data Breach or breach ofobligations;
(b) provide to theController a written report on the investigation including any proposals toremedy any problems identified by the investigation; and
(c) remedythe problems identified within 7 days of the date of the written report.
11.3 On theController’s written request, the Processor will audit a subcontractor’scompliance with its obligations regarding the Controller’s Personal Data andprovide the Controller with the audit results.
11.4 The Processor will carry out an annualsecurity audit identifying any areas of deficiency (when taking into accountthe scope and nature of the processing of Personal Data and the best practicetechnologies available at such time)
13. WARRANTIES
The Processor warrants andrepresents that:
(a) its employees,subcontractors, agents and any other person or persons processing Personal Dataon its behalf are reliable and trustworthy and have received the requiredtraining on the Data Protection Legislation;
(b) it and anyone operatingon its behalf will process the Personal Data in compliance with the DataProtection Legislation and;
(c) it has no reason tobelieve that the Data Protection Legislation prevents it from providing any ofthe Services Agreement’s contracted services.
14. NOTICE
14.1 Anynotice or other communication given to a party under or in connection with thisData Processing Schedule must be in writing and delivered to:
Forthe Controller: The assigned Project Manager for the Implementation ofNavigator (as defined at Project Planning)
Forthe Processor: The DMS NavigatorHelpdesk at emailsupport@dmsnavigator.com
14.2 Clause 14.1 does not apply to the serviceof any proceedings or other documents in any legal action or, where applicable,any arbitration or other method of dispute resolution.
15. PERSONAL DATA PROCESSING PURPOSES ANDDETAILS
15.1 Subject matter ofprocessing:
“CUSTOMER DATA” (ANY PERSONAL DATA THATTHE PROCESSOR PROCESSES ON BEHALF OF THE CONTROLLER IN THE COURSE OF PROVIDINGTHE SERVICES’
15.2 Duration of Processing:
This agreement remains in place for as long as the Software Licence to which it is referred is in place
15.3 Nature and Purpose of Processing:
THEPROVISION OF THE SERVICES TO THE CONTROLLER AND THE PERFORMANCE OF THEPROCESSOR’S OBLIGATIONS UNDER THE SERVICE AGREEMENT AND THIS PROCESSORAGREEMENT OR AS OTHERWISE AGREED BY THE PARTIES
15.4 Data Subject Categories:
ANYPERSON ACCESSING AND/OR USING THE SERVICES THROUGH THE CONTROLLER’S ACCOUNT("USERS") AND ANY PERSON: (I) WHOSE PERSONAL DATA IS STORED ON ORCOLLECTED VIA THE SERVICES, OR (II) TO WHOM USERS ENGAGE OR COMMUNICATE WITHVIA THE SERVICES (COLLECTIVELY, "SUBSCRIBERS")
15.5 Personal Data Types:
CustomerData: data relating to any purchases of goods and/orservices such as name, title, billing address, delivery address email address,phone number, contact details, purchase details and card details.
Prospect Data: Any data collected relating to theprospecting of goods and services.
16. SECURITY MEASURES
16.1 Thetechnical and organizational data security measures to be taken by the Processor include:
16.1.1 Outsourced processing: Navigatorhosts its Service with outsourced cloud infrastructure providers. Additionally,the Controller maintains contractual relationships with vendors in order toprovide the Service in accordance with our Data Processing Agreement. Thecontroller relies on contractual agreements, privacy policies, and vendorcompliance programs in order to protect data processed or stored by thesevendors.
16.1.2 Physical and environmentalsecurity: The Controller hosts its product infrastructure within its ownhardware and network within a multi-tenanted data centre. The physical andenvironmental security controls are audited for ISO 27001 compliance, amongother certifications.
16.1.3 Navigator implements industry standard access controls anddetection capabilities for the internal networks that support its products.
16.1.4 Access controls: Network access control mechanisms aredesigned to prevent network traffic using unauthorized protocols from reachingthe product infrastructure.
16.1.5 Penetration testing: The Controller maintains relationshipswith industry recognized penetration testing service providers for regularpenetration tests. The intent of the penetration tests is to identify andresolve foreseeable attack vectors and potential abuse scenarios.
16.1.6 Authorization: Customer data is stored in storage systemsaccessible to Customers via only application user interfaces and applicationprogramming interfaces. Customers are not allowed direct access to theunderlying application infrastructure. The authorization model in Navigator isdesigned to ensure that only the appropriately assigned individuals can accessrelevant features, views, and customization options. Authorization to data setsis performed through validating the user’s permissions against the attributesassociated with each data set.
16.1.7 Application Programming Interface (API) access: Publicproduct APIs may be accessed using an API key.
16.1.8 Data In-transit: Navigator uses HTTPS encryption (alsoreferred to as SSL or TLS) available on every one of its login interfaces.HTTPS implementation uses industry standard algorithms and certificates