This APAC data protection addendum (“APAC Addendum”) sets forth the terms under the Data Protection Laws pursuant to which a Disclosing Party may transmit, disclose, or otherwise make available Personal Data to the Receiving Party for the Processing Purposes further defined in Annex A, and is applicable where the Disclosing Party is located within the Asia Pacific region. This APAC Addendum supplements and forms part of the Agreement. This APAC Addendum is effective as of the Effective Date; provided, however, the relevant obligations apply only to the extent the Personal Data is subject to the Data Protection Laws.
For purposes of this APAC Addendum, the following terms will have the meaning ascribed below:
“Security Incident” includes a real or suspected adverse event in relation to cybersecurity that results in unauthorised access, denial of service, disruption, unauthorised use of a computer resource for processing or storage of information or unauthorised changes to data or information.
Terms which are not defined in this APAC Addendum shall bear the meaning ascribed to them in the Global Addendum.
Under this APAC Addendum, each Party acts as a Controller in the processing of the other Party’s Personal Data.
In the event that any Disclosing Party, as a Processor on behalf of a Controller, provides Personal Data to Receiving Party, the Disclosing Party will ensure that the Controller on whose behalf it is providing Personal Data has agreed to the obligations set forth in Section 3 herein.
Each Party will:
Comply with its respective obligations under the relevant Data Protection Laws with respect to the Processing of Personal Data, including having in place appropriate physical, technical and organisational measures which ensure a level of security as required under applicable Data Protection Laws.To the extent acting as a Disclosing Party:
Provide all notices and obtain any consents required by relevant Data Protection Laws necessary to permit each Party to Process Personal Data for the Processing Purposes in accordance with this APAC Addendum (including without limitation in respect of direct marketing);
To the extent providing Personal Data originally collected by another Controller, (i) contractually obligate such Controller to provide all notices and obtain any consents required by relevant Data Protection Laws necessary to permit each Party to Process Personal Data for the Processing Purposes in accordance with this APAC Addendum and (ii) take reasonable steps to ensure compliance with such contractual obligations;
Notify the Receiving Party if it, or any applicable Processor, is, or believes it will be, unable to comply with the terms of this APAC Addendum and/or any relevant Data Protection Laws.
To the extent acting as a Receiving Party:
Except as expressly permitted by the Agreement, not retain, use or disclose Personal Data of the Disclosing Party for longer than necessary to serve the purposes set out in the Agreement and in this APAC Addendum; and
Take reasonable steps to ensure in each case that access to Personal Data is strictly limited to those individuals who need to know and access the relevant Personal Data of the Receiving Party, for the purposes of the Agreement and this APAC Addendum, and to comply with Data Protection Laws.
The Parties shall only transfer or disclose Personal Data of the other Party to a Third Country (or, where the Disclosing Party is subject to the New Zealand Privacy Act 2020, to a Foreign Person or Entity (as defined in the Privacy Act 2020)) with the other Party’s prior written consent and in accordance with Data Protection Laws.
Each Party shall provide prompt reasonable assistance to the other Party in connection with any and all personal data impact assessments and/or security assessments as required under applicable Data Protection Laws to transfer Personal Data to Third Countries and/or to third parties.
Each Party may engage or use Processors, provided that the arrangement with their Processor (if any), is governed by a written contract which includes terms that provide the same level of protection for Personal Data as those set out in this APAC Addendum. For the avoidance of doubt, each Party shall remain liable to the other Party for any and all acts or omissions by each Processor in relation to the Processing of Personal Data.
Each Party (“First Party”) shall as soon as practicable after becoming aware of, or suspecting:
First Party shall co-operate with the Second Party and take steps as are directed by the Second Party to assist in the investigation, mitigation, and remediation of each such Security Incident or Data Breach.
Each Party shall be responsible each for their own reporting requirements of Security Incidents or Data Breaches to relevant Supervisory Authorities and individuals as required by applicable Data Protection Laws.