We use essential cookies for the website to function, as well as analytics cookies for analyzing and creating statistics of the website performance. To agree to the use of analytics cookies, click "Accept All". You can manage your preferences at any time by clicking "Cookie Settings" on the footer. More Information.

Only Essential Cookies
Accept All
Application DistributionAppGallery Policy CenterAppGallery Connect AgreementAppGallery Connect Data Processing Addendum

AppGallery Connect Data Processing Addendum

Click to download AppGallery Connect Data Processing Addendum.

You ("Customer") and Huawei (hereinafter collectively referred to as the "Parties" and individually as a "Party") have entered into the HUAWEI AppGallery Connect Service Agreement and other related agreements (the "Agreements") under which Huawei has agreed to provide and you have agreed to receive the AppGallery Connect ("AGC") Services as described therein.

Each person signing or by other means accepting this AppGallery Connect Data Processing Addendum ("DPA") represents and warrants that he or she is duly authorized and has legal capacity to enter into this DPA on behalf of the Party he or she represents and to bind that Party to this DPA.

This DPA will be effective and replace any data processing and security terms previously concluded between the Parties as from the Effective Date (as defined below) with respect to the subject matter hereof.

1. Introduction

This DPA reflects the Parties' Agreements with respect to the terms governing the Processing and security of Customer Data under the Agreements, when Huawei is providing AppGallery Connect Services requested by Customer.

This DPA is effective only for the Customer's HUAWEI ID account it was agreed for. If Customer owns multiple HUAWEI ID accounts, a DPA will be contracted for each individual HUAWEI ID account separately.

This DPA supplements the Agreements and shall apply to the Parties if and insofar as Huawei Processes Personal Data on behalf of Customer as a Processor when providing the AGC Services to Customer.

This DPA shall be valid and legally binding only for the natural or legal person that registered a HUAWEI ID account and only for the AGC Services provided by Huawei directly to that respective HUAWEI ID account.

In the event of any conflict among the Agreements and attachments, annexes, schedules or exhibits to the Agreements, the following order of precedence will govern, with higher numbers governing over lower ones:

  1. Agreements;
  2. DPA;
  3. Standard Contractual Clauses (in case of transfers of Personal Data, Schedule 2 including its all attachments);
  4. Data Transfer Agreement (in Schedule 3).

2. Definitions

2.1 Capitalized terms used but not defined in this DPA have the meanings set out in the Agreements. In this DPA, unless stated otherwise:

2.1.1 "Additional Product" means a product, service or application provided by Huawei or a third party that: (a) is not part of the AGC Services; and (b) is accessible for use within the user interface of the AGC Services or is otherwise integrated with the AGC Services.

2.1.2 "Affiliate" has the meaning given in the Agreements or, if not such meaning is given, means with respect to any entity, any other entity that directly or indirectly controls, is controlled by, or is under common control with, such entity. "Control" refers to a party's ownership, directly or indirectly, of the shares or other securities representing thirty percent (30%) or more of the voting rights for the election of board members (or other management executives) in the controlled party or the party under common control.

2.1.3 "Applicable Laws and Regulations" means any privacy or data protection laws, regulations and rules that apply to the Processing of Customer Personal Data at each given time, such as the GDPR and any laws and rules which supersede the former, as applicable.

2.1.4 "Customer Data" means Personal Data provided by Customer or Customer End Users via the Services under the HUAWEI ID account.

2.1.5 "Customer End Users" means the users of Customer's services (for example, the users of a Customer app).

2.1.6 "Customer Personal Data" means the Personal Data contained within the Customer Data.

2.1.7 "Effective Date" means the date on which Customer accepted, or the Parties otherwise agreed to, this DPA.

2.1.8 "EEA" means the European Economic Area.

2.1.9 "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

2.1.10 "Huawei" has the meaning ascribed to it in the HUAWEI Developers Service Agreement.

2.1.11 "HUAWEI ID account" has the same meaning as HUAWEI ID in the HUAWEI Developers Service Agreement.

2.1.12 "Huawei's Third Party Auditor" means a Huawei-appointed, qualified and independent third Party auditor, whose then-current identity Huawei will disclose to Customer.

2.1.13 "ISO 27001 Certification" means an ISO/IEC 27001:2013 certification or a comparable certification for the Audited Services.

2.1.14 "Notification Email Address" means the email address(es) designated by Customer in the AGC to receive certain notifications from Huawei.

2.1.15 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data on systems managed by or otherwise Processed by Huawei. "Personal Data Breach" will not include unsuccessful Security Incident described in Clause 5.7.

2.1.16 "Security Measures" has the meaning given in Clause 4.1.1.

2.1.17 "Security Documentation" means all certificates made available by Huawei under Clause 4.4.1.

2.1.18 "Services" has the meaning all the services provided by Huawei to the Customer under the different Agreements entered into by Customer on the HUAWEI Developers platform as defined in the HUAWEI Developers Service Agreement.

2.1.19 "Sub-processors" means third parties authorized under this DPA to have logical access to and Process Customer Data in order to provide parts of the Services.

2.1.20 "Term" means the period from the Effective Date until the end of Huawei's provision of the Services, including, if applicable, any period during which provision of the Services may be suspended and any post-termination period during which Huawei may continue providing the Services for transitional purposes.

2.1.21 “Third Country” means a country that is neither part of the EEA nor has been declared adequate by a decision of the European Commission according to the mechanism lined out in Article 45 GDPR.

2.1.22. Standard Contractual Clauses” mean the contractual clauses issued by the European Commission by implementing decision 2021/914 of 4th of June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

2.2 The terms "Personal Data", "Data Subject", "Processing", "Controller", "Processor" and "Supervisory Authority" as used in this DPA have the meanings given in the Applicable Laws and Regulations. Should any of the terms in 2.1 have a different meaning under Applicable Laws and Regulations, then the meaning given to the term in the Applicable Laws and Regulations shall prevail.

3. Roles, Scope of Processing, and General Obligations

3.1 The Parties acknowledge and agree that:

3.1.1 For the Processing of Personal Data under this DPA, Customer shall be regarded as the Controller and Huawei shall be regarded as the Processor as defined under Applicable Laws and Regulations.

3.1.2 Each Party undertakes to comply with its obligations under the Applicable Laws and Regulations. Each Party is solely responsible for compliance with the obligations of the Applicable Laws and Regulations which apply to it. As between the Parties, the Customer shall have sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which the Customer acquired the Personal Data.

3.1.3 Processor shall Process Personal Data only in accordance with this DPA, and/or to the extent necessary to provide the AGC Services to Customer under the Agreements.

3.1.4 In order to perform the AGC Services to Customer, Huawei shall Process Customer Personal Data. Huawei may not use Customer Personal Data for its own purposes.

3.1.5 The Agreements and this DPA shall be seen as instructions from Customer to Huawei for the Processing of Personal Data. Additional instructions outside the scope of the Agreements or this DPA (if any) require prior written Agreements between Customer and Huawei, including Agreements on any additional fees payable by Customer to Huawei for carrying out such instructions. Customer is entitled to terminate this DPA and the Agreements if Huawei refuses to follow instructions reasonably required by Customer that are outside the scope of, or changed from, those given in this DPA or the Agreements.

3.1.6 Huawei will comply with the instructions described in Clause 3.1.5 unless applicable law to which Huawei is subject requires other Processing of Customer Personal Data by Huawei, in which case Huawei will inform Customer (unless that law prohibits Huawei from doing so on important grounds of public interest) via the Notification Email Address before Processing.

3.1.7 In order to perform the AGC Services to Customer, Huawei shall Process the Personal Data to comply with Applicable Laws and Regulations, and other laws that Huawei may be subject to.

3.2 Without prejudice to Clause 3.1.1, if Customer is a Processor, Customer warrants to Huawei, which will be acting as Sub-processor in that case, that Customer's instructions and actions with respect to that Customer Personal Data, including its appointment of Huawei as a Sub-processor in that case, have been authorized by the relevant Controller.

3.3 If Customer requests Huawei to comply with any privacy or data protection laws and regulations that would otherwise not apply to Huawei's Processing of Customer Personal Data, Huawei reserves the right to, at its sole discretion, (i) either reject the Customer requirement, if compliance is commercially unreasonable; or (ii) comply with the new requirements, if commercially reasonable, upon payment of a fee determined by Huawei.

3.4 If Customer uses any Additional Product, the Services may allow that Additional Product to access Customer Personal Data as required for the interoperation of the Additional Product with the Services. For clarity, this DPA does not apply to the Processing of Personal Data in connection with the provision of any Additional Product used by Customer, including Personal Data transmitted to or from that Additional Product.

4. Data Security

4.1 Huawei's Security Measures, Controls and Assistance

4.1.1 Huawei's Security Measures

Huawei implements the appropriate physical, technical, and organizational security measures to protect Customer data throughout its lifecycle according to common industry standards to prevent data breach, damage, or loss and ensure security, confidentiality, integrity and availability of Customer data. The measures are including but not limited to communication and storage encryption, data center access control, access minimization, and recording access to Personal Data systems as detailed on Schedule 1. In order to respond to the new identified security threats and vulnerabilities the security measures will be updated in time to time in such manner that overall security of the services is ensured.

4.1.2 Security Compliance by Huawei Staff and Sub-processors

Huawei will take appropriate steps to ensure compliance with the Security Measures by its employees, contractors and Sub-processors to the extent applicable to their scope of performance, including ensuring that all persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.1.3 Additional Security Controls

As an additional security control, Huawei validates the efficiency of the security measures of AGC via periodical security tests by internal or independent third party as well as continues to upkeep the relevant security certificates.

4.1.4 Huawei's Security Assistance

Customer agrees that Huawei will (taking into account the nature of the Processing of Customer Personal Data and the information available to Huawei, and any restrictions on disclosing the information, such as confidentiality) assist Customer in ensuring compliance with any of Customer's obligations in respect of security of Personal Data and Personal Data Breaches, including Customer's obligations pursuant to Applicable Laws and Regulation, including, if applicable, Articles 32 to 34 (inclusive) of the GDPR, by:

a) Implementing and maintaining the Security Measures in accordance with Clause 4.1.1 (Huawei's Security Measures);

b) Complying with the terms of Clause 5 (Personal Data Breach); and

c) Providing Customer with the Security Documentation in accordance with Clause 4.4.1 (Reviews of Security Documentation) and the information contained in the applicable Agreement including this Data Processing Amendment.

4.2 Customer's Security Responsibilities and Assessment

4.2.1 Customer's Security Responsibilities

Customer agrees that, without prejudice to Huawei's obligations under Clause 4.1 (Huawei's Security Measures, Controls and Assistance.) and Clause 5 (Personal Data Breach):

a) Customer is solely responsible for its use of the Services, including:

i. Making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Customer Data;

ii. Securing the account authentication credentials, systems and devices Customer uses to access the Services;

iii. Backing up its Customer Data as appropriate; and

b) Huawei has no obligation to protect copies of Customer Data that Customer elects to store or transfer outside of Huawei's and its Sub-processors' systems (for example, offline or on-premises storage).

4.2.2 Customer's Security Assessment

4.2.2.1 Customer is solely responsible for reviewing the Security Documentation and evaluating for itself whether the Services, the Security Measures, the Additional Security Controls and Huawei's commitments under this Clause 4 (Data Security) will meet Customer's needs, including with respect to any security obligations of Customer under Applicable Laws and Regulations.

4.2.2.2 Customer acknowledges and agrees that (taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the Processing of Customer Personal Data as well as the risks to individuals) the Security Measures implemented and maintained by Huawei as set out in Clause 4.1.1 (Huawei's Security Measures) provide a level of security appropriate to the risk in respect of the Customer Data.

4.3 Security Certifications and Reports

Huawei will do the following to ensure the continued effectiveness of the Security Measures:

4.3.1 Huawei will use independent external auditors to verify the adequacy of its security measures.

4.3.2 The audit will be performed (i) according to ISO 27001 standards or such other substantially equivalent standards; (ii) at reasonable intervals; and (iii) by independent third party auditors at Huawei's selection and expense.

4.3.3 The audit will generate (a) relevant certificates (Security Documentation); and (b) an audit report, which will be Huawei's confidential information.

4.4 Reviews and Audits of Compliance

4.4.1 Reviews of Security Documentation

In addition to the information contained in this DPA, upon Customer's request, and provided that the parties have an applicable NDA in place, Huawei will make available Security Documentation and other documentation Huawei deems necessary to demonstrate compliance by Huawei with its obligations under this DPA.

4.4.2 Customer's Audit Rights

If Customer's review of Huawei's Security Documentation in accordance with Clause 4.4.1 is not enough for Customer to reasonably verify Huawei's compliance with its obligations under this DPA:

a) Huawei will allow Customer or an independent auditor appointed by Customer to conduct an audit (including an inspection) to verify Huawei's compliance with its obligations under this DPA in accordance with Clause 4.4.3 (Additional Business Terms for Reviews and Audits). Huawei will contribute to such audits as described in Clause 4.3 (Security Certifications and Reports) and this Clause 4.4 (Reviews and Audits of Compliance).

b) If Customer has entered into Standard Contract Clauses as described in Clause 8.2

(Data Locations and Transfers), Huawei will, without prejudice to any audit rights of a Supervisory Authority under such Standard Contract Clauses, allow Customer or an independent auditor appointed by Customer to conduct audits as described in the Standard Contract Clauses in accordance with Clause 4.4.3 (Additional Business Terms for Reviews and Audits).

4.4.3 Additional Business Terms for Reviews and Audits

4.4.3.1 Customer must send written requests for reviews or audits under Clauses 4.4.1 and 4.4.2 to Huawei at https://developer.huawei.com/consumer/en/support/feedback.

4.4.3.2 Following receipt by Huawei of a request under Clause 4.4.3.1, Huawei and Customer will discuss and agree in advance on the reasonable start date, scope and duration of and security and confidentiality controls applicable to any audit under Clause 4.4.2.

4.4.3.3 The audit will include only material necessary to verify Huawei's compliance with this DPA and it will not include any material which Huawei is obligated to keep confidential based on a contractual requirement.

4.4.3.4 Huawei may charge a fee (based on the reasonable costs occurred to Huawei) for any audit under Clause 4.4.2. Huawei will provide Customer with further details of any applicable fee, and the basis of its calculation, in advance of any such audit. Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit.

4.4.3.5 Huawei may object in writing to an auditor appointed by Customer to conduct any audit under Clause 4.4.2 if the auditor is, in Huawei's reasonable opinion, not suitably qualified or independent, a competitor of Huawei, or otherwise manifestly unsuitable. Any such objection by Huawei will require Customer to appoint another auditor or conduct the audit itself.

5. Personal Data Breach

5.1 Where required by Applicable Laws and Regulations, Huawei shall notify Customer without undue delay after becoming aware of a Personal Data Breach. Taking into account the information reasonably available to it, Huawei shall address the following in the notification:

a) Description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects concerned;

b) Name and contact details of Huawei's data protection officer or other point of contact where more information can be obtained;

c) Description of the likely consequences of the Personal Data Breach;

d) Description of the measures taken to address the Personal Data Breach, including where appropriate measures to mitigate its possible adverse effects.

5.2 Where it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.

5.3 Huawei will promptly take the necessary and appropriate actions to investigate, mitigate, and remediate any effects of a Personal Data Breach, and provide assistance to Customer to ensure that Customer can comply with specific obligations under Data Protection Legislation it may be subject to in relation to the Personal Data Breach.

5.4 Notification of any Data Incident will be delivered to the Notification Email Address or, at Huawei's discretion, by direct communication (for example, by phone call or an in-person meeting). Customer is solely responsible for ensuring that the Notification Email Address is current and valid.

5.5 Huawei will not assess the contents of Customer Data in order to identify information subject to any specific legal requirements. Without prejudice to Huawei's obligations under this Clause 6 (Assistance to the Controller), Customer is solely responsible for complying with incident notification laws applicable to Customer and fulfilling any third party notification obligations related to any Data Incident(s).

5.6 Huawei's notification of or response to a Data Incident under this Clause 6 (Assistance to the Controller) will not be construed as an acknowledgement by Huawei of any fault or liability with respect to the Data Incident.

5.7 Customer agrees that an unsuccessful Security Incident will not be subject to this Clause 5 (Personal Data Breach). An unsuccessful Security Incident is one that results in no unauthorized access to Customer Data or to any of Huawei's equipment or facilities storing Customer Data, and may include, without limitation, pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents.

6. Assistance to the Controller

6.1 To the extent required by Applicable Laws and Regulations and taking into account the nature of the Processing and the information reasonably available, Huawei shall provide Customer with reasonable assistance with regards to:

6.1.1 ensuring compliance with Controller's obligations pursuant to Applicable Laws and Regulations;

6.1.2 making available to Controller all reasonable information necessary to demonstrate compliance with Applicable Laws and Regulations;

6.1.3 where applicable, performing the necessary data protection impact assessments and prior consultation procedures as mentioned in articles 35 and 36 GDPR, respectively;

6.1.4 providing the information contained in the Agreements including this DPA.

6.2 Where assistance requested by Customer and provided by Huawei in accordance with Clause 6.1 is not part of the AGC Services and Huawei's regular activities related thereto, Huawei may charge Customer for the reasonable costs occurring to Huawei for such assistance.

6.3 Where required by Applicable Laws and Regulations, Huawei shall maintain a record of all categories of Processing activities carried out on behalf of the Customer. Accordingly Customer will, where requested, provide such information to Huawei on the Console of the HUAWEI Developers website and ensure that all such information is accurate.

6.3.1 The records of Processing shall contain the information required in Article 30.2 of the GDPR, as applicable.

6.3.2 Huawei shall make such information available to the Supervisory Authorities, on request.

6.3.3 Huawei shall maintain the records of Processing in electronic form.

7. Data Subject Rights

7.1 To the extent required by Applicable Laws and Regulations, Huawei provides technical capabilities to assist Customer in fulfilling its obligations towards Data Subjects requests, in a manner consistent with the functionalities of the AGC Services, as described in Clauses 7.2 to 7.4 below. Customer will have access to such capabilities on the AGC.

7.2 Huawei shall enable Customer to delete Customer Data during the Term in a manner consistent with the functionality of the AGC Services. When Customer uses the delete capability Customer Data cannot be recovered by Customer. Huawei will comply with Customer's deletion instruction and remove Customer Data from Huawei's systems in accordance with applicable laws, and as soon as reasonably practicable and within a maximum period of 30 days, unless any law or regulation to which Huawei is subject requires longer storage.

7.3 During the Term, Huawei has no direct relationship with the Data Subject and shall take commercially reasonable efforts to inform Data Subjects to contact Customer first, if it receives any request from a Data Subject in relation to Customer Personal Data. Customer will be responsible for responding to any such request including, where possible, by using the functionalities made available within the AGC Services.

7.4 Huawei shall reasonably cooperate with Customer and assist Customer with respect to any action taken relating to such request, complaint, order or other document as described under Clause 7.1 above. As far as reasonably possible and taking into account the nature of the Processing, the information available to Huawei, industry practices and costs, Huawei will implement appropriate technical and organizational measures to provide Controller with such cooperation and assistance. Huawei may charge Customer for the reasonable costs occurring to Huawei for any assistance which Huawei considers to go beyond the aforementioned cooperation and assistance measures.

8. Data Location and Transfers

8.1 Huawei shall store Customer Data solely in data centers communicated to Customer by Huawei. The Customer Personal Data is located in data centers determined by the Business Area selected by Customer unless Huawei specifically defines a different solution in Exceptions to the selection of data location set out in Data Processing Information. Information about the data centers is available in AppGallery Connect Data Center Location.

8.2 Due to the Huawei entity providing the AGC Services establishment location, and the Customer establishment location or the Customer Data Subjects' location, the Processing by Huawei may be subject to Standard Contractual Clauses or the Data Transfer Agreement. The European Union has developed different Standard Contractual Clauses depending on the role of the Parties. Those constellations and their legal consequences are listed in this section 8.2.

8.2.1 In case where Customer and/or AGC Services provided by Huawei, as identified in clause 15.2 of the Huawei Developers Service Agreement, are subject to the GDPR and Huawei engages Sub-Processors established in Third Countries or the Sub-Processors process Personal Data in a Third Country:

      • Where needed, Huawei shall execute MODULE THREE: “Transfer processor to processor” of the Standard Contractual Clauses with the Sub-processors established in Third Countries. Customer is not a party of the Standard Contractual Clauses in this constellation.
      • In this case, Huawei’s Sub-processors will act as “data importers” and Huawei will act as “data exporter” according to Clause 1 and Annex 1 of the Standard Contractual Clauses.

8.2.2 In case that Customer is established in a Third Country and is entering into this DPA with Huawei, as identified in clause 15.2 of the Huawei Developers Service Agreement, the Parties acknowledge that:

      • the Parties shall be deemed to have executed the Standard Contractual Clauses Module FOUR: “Transfer processor to controller”( Schedule 2) by executing this DPA.
      • Huawei is the “data exporter” and the Customer is the “data importer” in respect of the Clause 1 and Annex 1 of the Standard Contractual Clauses;
      • in clause 7, the Parties choose to include the “docking clause”;
      • in clause 11, the Parties do not choose the optional complaint mechanism;
      • in clause 17, the Parties choose Option 1 and the governing law shall be the law of Ireland;
      • in clause 18, the country of the applicable court in respect of any disputes arising from the Standard Contractual Clauses shall be as the Irish Courts with jurisdiction in Dublin;
      • The information required for Section B of Annex I is documented in connection with the Annex later in document and here; and
      • The competent supervisory authority is the Irish Data Protection Commission

8.2.3 In the constellation that the GDPR does not apply to the Processing, both Huawei and Customer conform, and hereby agree to Schedule 3.

8.3. Without prejudice to Clause 9.2, Huawei may transfer data if it is required by applicable law to which Huawei is subject, provided that Huawei informs the Customer of that legal requirement before Processing, unless the law prohibits such information on important grounds of public interest.

8.4. If the transfer of data in accordance to Clause 8.2 or 9.2 requires under Applicable Laws and Regulations an approval from an authority, the Customer shall obtain the necessary approval prior to such transfer. The Customer and Huawei agree to deposit and/or file (as applicable) a copy of this Agreement with any relevant authority if it so requests or if such filing and/or deposit is required under the Applicable Laws and Regulations.

9. Sub-processors

9.1 Huawei will engage Sub-Processors to carry out Processing activities. Where required by Applicable Laws and Regulations, Huawei will impose data protection obligations on the Sub-Processors which are substantially the same as those set out in this DPA, in particular in relation to the implementation of appropriate technical and organizational measures. Customer hereby provides Huawei with a general authorization to engage Sub-Processors. Huawei shall make available, the information regarding any changes concerning the engagement or replacement of a Sub-Processor, to Customer via the AGC or by other appropriate means. For the lists of the Sub-Processors, Customer shall refer to Aspiegel SE's Sub-Processors, Huawei Services (Hong Kong) Co., Limited's Sub-Processors, and Huawei Software Technologies Co., Ltd.'s Sub-Processors. Customer is deemed to have accepted all Sub-Processors included in the list on the Effective Date.

9.2 Customer hereby authorizes Huawei, in the name of and on behalf of the Customer, to enter into a data processing agreement with a Sub-Processor that incorporates the Data Transfer Agreement as provided by Schedule 3 under the following circumstances:

      • Sub-processor, engaged in accordance with Clause 9.1 above, is established or otherwise Processes Customer Data outside the country where Customer and/or Huawei are located and a data transfer agreement is required under Applicable Laws and Regulations; and
      • The Applicable Laws and Regulations do not require entering into relevant Standard Contractual Clauses, as set out above.

Huawei shall clearly indicate in the Data Transfer Agreement that it acts on behalf of the Customer. Customer shall take into account Clause 8.4.

9.3 Customer shall have the right to object to a new Sub-Processor with reasonable grounds by sending a written notice to Huawei at https://developer.huawei.com/consumer/en/support/feedback within 14 days after becoming aware of the new Sub-Processor. If Huawei chooses to engage the new Sub-Processor despite Customer's objection in accordance with this Clause 9.3, Customer shall have the right to terminate the Agreements.

9.4 For the avoidance of doubt, in the event Huawei uses Sub-Processors, Huawei shall, pursuant to Applicable Laws and Regulations, remain fully liable to the Customer for the fulfilment of its obligations under this DPA.

10. Liability

10.1 Each Party is liable for damages incurred by the other Party which are caused directly by a Party's breach of the commitments made in this DPA, subject to the limitations and exclusions of liability agreed in the Agreements.

10.2 Provided that Customer is not in breach of this DPA, Huawei shall indemnify and keep Customer harmless from any claim or proceedings (including reasonable legal fees) brought against Customer by a third party as a result of a breach by Huawei of its data protection commitments in this DPA. Huawei shall be entitled to take control of the defense and investigation of such claim, or any proceedings, and shall employ counsel of its choice to handle and defend the same, at Huawei's sole cost and expense.

10.3 Notwithstanding any other provisions in this DPA, to the extent not in conflict with Standard Contractual Clauses, neither Party shall be liable to the other Party for:

a) loss of profits;

b) loss of business;

c) loss of revenue;

d) damage to goodwill or any similar losses;

e) anticipated savings;

f) loss of use; and

g) any punitive, other indirect or, consequential loss or damage.

11. Changes to This DPA

11.1 From time to time, Huawei may change any URL referenced in this DPA and the content at any such URL.

11.2 Huawei may change this DPA if the change:

a) is expressly permitted by this DPA, including as described in Clause 11.1;

b) reflects a change in the name or form of a legal entity;

c) is required to comply with applicable law, applicable regulation, a court order or guidance issued by a governmental regulator or agency; or

d) does not: (i) result in a degradation of the overall security of the Services; (ii) expand the scope of, or remove any restrictions on, Huawei's Processing of Customer Personal Data, as described in Clause 3.1 (Huawei's Compliance with Instructions); and (iii) otherwise have a material adverse impact on Customer's rights under this DPA, as reasonably determined by Huawei.

11.3 If Huawei intends to change this DPA under Clause 11.2(c) or (d), Huawei will inform Customer at least 30 days (or such shorter period as may be required to comply with applicable law, applicable regulation, a court order or guidance issued by a governmental regulator or agency) before the change will take effect by either: (a) sending an email to the Notification Email Address; or (b) alerting Customer via the AGC. If Customer objects to any such change, Customer may terminate the Agreements by sending a written notice to Huawei at https://developer.huawei.com/consumer/en/support/feedback within 90 days after being informed of the change.

12. Term and Termination

12.1 This DPA shall take effect from the Effective Date and, continues until the termination or expiration of the Agreements. Notwithstanding the termination or the expiration of the Agreements, the DPA will remain in effect until, and automatically expire upon, deletion of all Customer Data by Huawei as described in clause 12.2 below.

12.2 Huawei shall, upon termination or expiration of this DPA, delete all Customer Data (including existing copies) from Huawei's systems in accordance with Applicable Laws and Regulations. Huawei will comply with this instruction as soon as reasonably practicable and within a maximum period of 30 days, unless Applicable Laws and Regulations require storage.

12.3 Customer acknowledges and agrees that Customer will be responsible for exporting to its own systems, before the Term expires, or the termination of the DPA, any Customer Data it wishes to retain afterwards.

SCHEDULE 1: Security Measures

As from the Effective Date, Huawei will implement and maintain the Security Measures set out in this SCHEDULE 1. Huawei may update or modify such Security Measures from time to time provided that such updates and modifications do not result in the degradation of the overall security of the AGC Services.

1. Data Center and Network Security

Huawei uses third party data centers that are geographically distributed within selected region, in which the cloud provider is required to have sufficient security measures in place.

2. Data

(a) Data Storage and Isolation.

Huawei stores data on multi-tenant environment on third party servers. The data and file system architecture are replicated between multiple geographically dispersed data centers. Huawei isolates the Customer's data logically.

(b) Decommissioned Disks and Disk Erase Policy. Disks containing data may experience performance issues, errors or hardware failure that lead them to be decommissioned ("Decommissioned Disk"). Every Decommissioned Disk is subject to a series of data destruction processes that are handled by the Data Center operator.

3. Access Control

3.1 Data Access by Customer

Customer's administrators must authenticate themselves via a central authentication system with two-factor authentication in order to administer the Services.

3.2 Internal Data Access Policy.

Huawei employs a centralized access management system that is integrated to LDAP system to control personnel access to production servers, and only provides role-based access to a limited number of authorized personnel. Huawei requires the use of unique user IDs, strong passwords, two factor authentication and carefully monitored access lists to minimize the potential for unauthorized account use. The granting or modification of access rights is based on: the authorized personnel's job responsibilities; job duty requirements necessary to perform authorized tasks; and a need to know basis.

4. Personnel Security

Huawei personnel are required to conduct themselves in a manner consistent with the company's guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards. Huawei conducts reasonably appropriate backgrounds checks to the extent legally permissible and in accordance with applicable local labor law and statutory regulations.

Personnel are required to execute a confidentiality agreement and must acknowledge receipt of, and compliance with, Huawei's confidentiality and privacy policies. Personnel are provided with security training and their knowledge of security and privacy policies are evaluated periodically. Furthermore the latest security news from the world are delivered to personnel periodically to improve their awareness. Personnel handling Customer Data are required to complete additional requirements appropriate to their role (e.g., Huawei Cyber Security Certification). Huawei's personnel will not process Customer Data without authorization.

SCHEDULE 2:

STANDARD CONTRACTUAL CLAUSES

MODULE FOUR

Processor to Controller

SECTION I

Clause 1

Purpose and scope

(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country.

(b) The Parties:

(i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and

(ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’)

have agreed to these standard contractual clauses (hereinafter: ‘Clauses’).

(c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

(d) The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.

Clause 2

Effect and invariability of the Clauses

(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.

(b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3

Third-party beneficiaries

(a) Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions:

(i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;

(ii) Clause 8.1 (b) and Clause 8.3(b);

(iii) N/A

(iv) N/A

(v) Clause 13;

(vi) Clause 15.1(c), (d) and (e);

(vii) Clause 16(e);

(viii) Clause 18.

(b) Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.

Clause 4

Interpretation

(a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.

(c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.

Clause 5

Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 6

Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7

Docking clause

(a) An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A.

(b) Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A.

(c) The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.

SECTION II – OBLIGATIONS OF THE PARTIES

Clause 8

Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.

8.1   Instructions

(a) The data exporter shall process the personal data only on documented instructions from the data importer acting as its controller.

(b) The data exporter shall immediately inform the data importer if it is unable to follow those instructions, including if such instructions infringe Regulation (EU) 2016/679 or other Union or Member State data protection law.

(c) The data importer shall refrain from any action that would prevent the data exporter from fulfilling its obligations under Regulation (EU) 2016/679, including in the context of sub-processing or as regards cooperation with competent supervisory authorities.

(d) After the end of the provision of the processing services, the data exporter shall, at the choice of the data importer, delete all personal data processed on behalf of the data importer and certify to the data importer that it has done so, or return to the data importer all personal data processed on its behalf and delete existing copies.

8.2   Security of processing

(a) The Parties shall implement appropriate technical and organisational measures to ensure the security of the data, including during transmission, and protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access (hereinafter ‘personal data breach’). In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature of the personal data ([1]), the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subjects, and in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner.

(b) The data exporter shall assist the data importer in ensuring appropriate security of the data in accordance with paragraph (a). In case of a personal data breach concerning the personal data processed by the data exporter under these Clauses, the data exporter shall notify the data importer without undue delay after becoming aware of it and assist the data importer in addressing the breach.

(c) The data exporter shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8.3   Documentation and compliance

(a) The Parties shall be able to demonstrate compliance with these Clauses.

(b) The data exporter shall make available to the data importer all information necessary to demonstrate compliance with its obligations under these Clauses and allow for and contribute to audits.

Clause 9

Use of sub-processors

N/A

Clause 10

Data subject rights

The Parties shall assist each other in responding to enquiries and requests made by data subjects under the local law applicable to the data importer or, for data processing by the data exporter in the EU, under Regulation (EU) 2016/679.

Clause 11

Redress

(a) The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.

Clause 12

Liability

(a) Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.

(b) Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679.

(c) Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.

(d) The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage.

(e) The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.

Clause 13

Supervision

N/A

SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES

Clause 14

Local laws and practices affecting compliance with the Clauses

(where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

(a) The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.

(b) The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements:

(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred;

(ii) the laws and practices of the third country of destination– including those requiring the disclosure of data to public authorities or authorising access by such authorities – relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards ([2]);

(iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.

(c) The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.

(d) The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.

(e) The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a).

(f) Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply.

Clause 15

Obligations of the data importer in case of access by public authorities

(where the EU processor combines the personal data received from the third country-controller with personal data collected by the processor in the EU)

15.1 Notification

(a) The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:

(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or

(ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer.

(b) If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter.

(c) Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.).

(d) The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.

(e) Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.

15.2 Review of legality and data minimisation

(a) The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e).

(b) The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request.

(c) The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.

SECTION IV – FINAL PROVISIONS

Clause 16

Non-compliance with the Clauses and termination

(a) The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.

(b) In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).

(c) The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:

(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension;

(ii) the data importer is in substantial or persistent breach of these Clauses; or

(iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.

In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.

(d) Personal data collected by the data exporter in the EU that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall immediately be deleted in its entirety, including any copy thereof. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law.

(e) Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679.

Clause 17

Governing law

These Clauses shall be governed by the law of a country allowing for third-party beneficiary rights. The Parties agree that this shall be the law of Ireland.

Clause 18

Choice of forum and jurisdiction

Any dispute arising from these Clauses shall be resolved by the courts of Ireland with jurisdiction in Dublin.

ANNEX I

A.   LIST OF PARTIES

Data exporter(s): 

Name: Aspiegel SE

Address: 1F, Simmonscourt House, Ballsbridge, Dublin, D04 W9H6, Ireland

Contact person’s name, position and contact details: Joerg Thomas, Director, DPO Office, dpo@huawei.com

Activities relevant to the data transferred under these Clauses: The provision of the AGC Services to Customer, as selected by the Customer;

Signature and date:

___________________________________________________

Role:

Processor

Data importer(s): 

Name: Shall be the Customer’s name

Address: Shall be the Customer’s place of business, as communicated in connection with registration of the Developer account

Contact person’s name, position and contact details: Customer’s contact details and information as you have provided them in context of the AGC services and your Developer account, including the Notification Email Address

Activities relevant to the data transferred under these Clauses: The use of the AGC Services by Customer, as selected by the Customer

Signature and date:

___________________________________________________

Role:

Controller

B.   DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred

End-Users of the Customer’s products and services

Categories of personal data transferred

Data processed by Huawei in connection with providing the AGC Services that Customer uses. More details about the data categories processed in connection with the different AGC Services are listed here.

Sensitive data transferred (if applicable) and applied restrictions or safeguards

If applicable, as described in connection with the relevant AGC Service as listed here.

The frequency of the transfer.

Depending on the AGC Service used and its specific features, the data may be continuously accessible by Customer or shared to Customer. Further details are provided here.

Nature of the processing

Data is processed by Huawei in order to provide the AGC Services used by Customer, as further described in relation to each AGC Service listed here.

Purpose(s) of the data transfer and further processing

To provide the AGC Services, as further described in connection with each AGC Service listed here.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

In accordance with the privacy policies and data retention practices of the data importer, subject to the applicable data protection laws.

SCHEDULE 3: Data Transfer Agreement (processors)

(Only when GDPR does not apply)

Name of the data exporting organization: Customer as defined in the AGC Agreements and the DPA

(the data exporter)

And

Name of the data importing organization:

Tel.:……………………………………………………..; fax:……………………………………………………..;

e-mail:……………………………………………………..; or

Other information needed to identify the organization:

…………………………………………………………………………………………………………………

(the data importer)

each a "party"; together "the parties",

Clause 1 Definitions

For the purposes of this Data Transfer Agreement ("DTA"):

(a) Applicable Laws and Regulations means any privacy or data protection laws, regulations and rules that apply to the processing of Customer Personal Data at each given time;

(b) Customer Data means Personal Data provided by Customer or Customer End Users via the Services under the HUAWEI ID account;

(c) Customer End Users means the users of Customer's services (for example, the users of a Customer app);

(d) Customer Personal Data means the Personal Data contained within the Customer Data;

(e) "Personal Data", "Special Categories of Data", "Process/Processing", "Controller", "Processor", "Data Subject", "Subprocessing", "Sub-processor" and "Supervisory Authority" shall have the same meaning as in the EU General Data Protection Regulation ("GDPR"), unless the term is differently defined by applicable data protection law; and

Any terms not defined in this DTA shall have the meaning given to these terms (i) in the Data Processing Agreement ("DPA") to which this DTA is attached or (ii) in the Applicable Laws and Regulations.

Clause 2 Details of the Transfer

The details of the transfer (as well as the Personal Data covered) are specified in Appendix 1.

Clause 3 Obligations of the Data Exporter

The data exporter agrees and warrants:

(a) that the Processing, including the transfer itself, of the Personal Data has been and will continue to be carried out in accordance with the relevant provisions of the Applicable Laws and Regulations (and, where applicable, it has notified the relevant authorities of the country in which the data exporter is established) including, if required by the Applicable Laws and Regulations, gaining consent from the Data Subject before transfer of the Personal Data and informing the Data Subject of the following:

(i) the name of the data importer;

(ii) the contact details of the data importer;

(iii) the types of Personal Data to be transferred;

(iv) the purpose for which the Personal Data is being transferred; and

(v) any other information required by the Applicable Laws and Regulations;

(b) that after assessment of the requirements of the Applicable Laws and Regulations, the technical and organizational security measures specified in the DPA's Clause 4 (Data Security) and Annex 1 (Security Measures) are appropriate to protect Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the Processing involves the transmission of data over a network, and against all other unlawful forms of Processing, and that these measures ensure a level of security appropriate to the risks presented by the Processing and the nature of the data to be protected having regard to the state of the art and the cost of their implementation;

(c) that, if the transfer involves Special Categories of Data, the Data Subject has, prior to the transfer, been informed of or consent to the transfer of his or her data outside the country in which the data exporter is established in accordance with Applicable Laws and Regulations;

(d) the data exporter agrees to obtain the prior approval of and deposit a copy of this DTA with the Supervisory Authority if it so requests or if such deposit is required under the applicable data protection law; and

(e) where required by Applicable Laws and Regulations, that Customer Data be maintained for a certain period of time.

Clause 4 Obligations of the Data Importer

The data importer agrees and warrants:

(a) to Process the Personal Data only on behalf of the data exporter in accordance with the instructions of the data exporter, this DTA (in particular Appendix 1) and, where required, in accordance with applicable laws, governmental or regulatory bodies, or an order by a court, in which case it shall notify the data exporter as soon as practicable before complying with such law or order; if it cannot provide compliance with the data exporter's instructions or this DTA, for whatever reasons, it agrees to inform the data exporter without undue delay of its inability to comply, in which case the data exporter is entitled to suspend the transfer of Personal Data and the parties shall work together in good faith to agree any steps which have to be taken to allow the data importer to continue to provide such compliance;

(b) where required by the Applicable Laws and Regulations of the country of the data exporter (and in accordance with Clause 11), to protect the Personal Data it receives at a standard that is comparable to that under the Applicable Laws and Regulations of the country of the data exporter; at the request of the data importer, the data exporter shall inform the data importer about the obligations under such Applicable Laws and Regulations that go above and beyond the obligations arising from this DTA or any other data processing agreement entered into by the data exporter and the data importer;

(c) to comply with the requirements under Applicable Laws and Regulations of its country of incorporation, such as those on data transfers;

(d) that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the instructions received from the data exporter and its obligations under the DTA and that in the event of a change in this legislation which is likely to have a substantial adverse effect on the warranties and obligations provided by this DTA, it will promptly notify the change to the data exporter as soon as it is aware, in which case the data exporter is entitled to suspend the transfer of data and the parties shall work together in good faith to agree any steps which have to be taken to allow the data importer to continue to provide such compliance;

(e) that it has implemented the technical and organizational security measures specified in the DPA's Clause 4 (Data Security) and Annex 1 (Security Measures) before Processing the Personal Data transferred to prevent unauthorized or accidental access, collection, use, disclosure, copying, modification, disposal or destruction of Personal Data, or other similar risks;

(f) that it will without undue delay notify the data exporter about:

(i) any legally binding request for disclosure of the Personal Data, including by a law enforcement authority, unless otherwise prohibited, such as a prohibition under criminal law to preserve the confidentiality of a law enforcement investigation;

(ii) any actual or suspected loss, theft, damage, accidental or unauthorized access or Processing;

(iii) any request received directly from a Data Subject, without responding to that request, unless it has been otherwise authorized or required to do so; and

(iv) any complaint received related to the Processing of the Personal Data, and comply with any instructions of data exporter in connection therewith.

(g) to deal promptly and properly with all inquiries from the data exporter relating to its Processing of the Personal Data subject to the transfer, to provide reasonable cooperation in responding to enquiries from the relevant Supervisory Authority or other relevant authority within the country of the data exporter, and to abide by the legally binding advice of the relevant Supervisory Authority with regard to the Processing of the data transferred;

(h) at the request of the data exporter or a relevant authority within the country of the data exporter, to submit its data Processing facilities used to Process Personal Data pursuant to the DTA, for audit;

(i) that, in the event of Subprocessing, it will previously inform the data exporter and obtain the data exporter's agreement; and

(j) that the Processing services by the Sub-processor will be carried out in accordance with Section 7.

Clause 5 Liability

1. The data importer may not rely on a Sub-processor's breach of its obligations in order to avoid the data importer's own liabilities.

2. The parties agree that if one party is held liable for a violation of this DTA committed by the other party (and for the avoidance of doubt, in the case of the data importer, violation of this DTA committed by any Sub-processor), the latter will, to the extent to which it is liable, indemnify the first party for any cost, charge, damages, expenses or loss it has incurred. Indemnification is contingent upon:

(a) the data exporter promptly notifying the data importer of a claim; and

(b) the data importer being given the possibility to cooperate with the data exporter in the defense and settlement of the claim.

Clause 6 Governing Law

This DTA shall be governed by the law of the country in which the data importer is established.

Clause 7 Sub-processing

The data exporter provides the data importer a general authorization to engage Sub-Processors. Where the data importer subcontracts its obligations under this DTA, with the consent of the data exporter, it shall do so only by way of a written agreement with the Sub-processor which imposes the same obligations on the Sub-processor as are imposed on the data importer under this DTA. Where the Sub-processor fails to fulfill its data protection obligations under such written agreement the data importer shall remain fully liable to the data exporter for the performance of the Sub-processor's obligations under such agreement.

A list of the Sub-Processors currently engaged by the data importer to carry out Processing activities shall be made available to the data exporter and the data exporter is deemed to have accepted all Sub-Processors included in the list on the Effective Date. For any other Sub-Processor, the data exporter shall have the right to object to a new Sub-Processor with reasonable grounds by written notice to the data importer within 14 days after becoming aware of the new Sub-Processor. If the data importer chooses to engage the new Sub-Processor despite the data exporter's objection, the data exporter shall have the right to, terminate this DTA and the agreement which incorporates this DTA.

For the avoidance of doubt, in the event the data importer uses Sub-Processors, the data importer shall, pursuant to Applicable Laws and Regulations, remain fully liable to the data exporter for the fulfilment of its obligations under this DTA.

Clause 8 Data Transfers

The data exporter provides the data importer a general authorization to transfer the Personal Data outside of the data importer's country of incorporation provided such transfer complies, specifically, with the Clause 4(a) and all other clauses of this DTA and with the Applicable Laws and Regulations. The data processing agreement or any other agreement entered into by the data exporter and the data importer shall specify the countries and territories to which the Personal Data may be transferred under the contract.

Clause 9 Obligation after the Termination of Personal Data Processing Services

The parties agree that on the termination of the provision of data Processing services, the data importer and the Sub-processor shall, at the choice of the data exporter, return all the Personal Data transferred and the copies thereof to the data exporter or shall destroy all the Personal Data and certify to the data exporter that it has done so, unless legislation imposed upon the data importer prevents it from returning or destroying all or part of the Personal Data transferred. In that case, the data importer warrants that it will guarantee the confidentiality of the Personal Data transferred and will not actively Process the Personal Data transferred anymore.

Clause 10 Counterparts

This DTA may be executed in any number of counterparts each of which, when executed and delivered, shall be an original but all the counterparts together shall constitute one and the same document. Execution in the signature block of this DTA shall constitute and be deemed signature on each page of this DTA and all Annexes (and their respective annexes and appendices) hereto.

Clause 11 Supplemental Provisions

In the event that the applicable law of the country where the data exporter is located requires additional or more stringent requirements than those established by this DTA, then such applicable law will apply.

Dated: [Please insert]

FOR DATA IMPORTER(S) FOR DATA EXPORTER(S)

[Signature block]

[Please insert] [Please insert]

APPENDIX 1 - DESCRIPTION OF TRANSFER

Data exporter

The data exporter is: the Customer, who is the Controller of Customer Data.

Data importer

The data importer is: Huawei, as defined in the AGC Agreements, that will be Processing Customer Data on Customer's behalf as per the DPA, or the Sub-Processor engaged by Huawei, as applicable.

Data Subjects

The Personal Data transferred concern the following categories of Data Subjects (please specify): Customer End Users

Categories of data

The Personal Data transferred concern the following categories of data: Customer End Users' Personal Data…

Special Categories of Data (if appropriate)

The Personal Data transferred concern the following Special Categories of Data (please specify): …………………………………………………………………………………………………………………………………………………………………………

Processing operations

The Personal Data transferred will be subject to the following basic Processing activities (please specify):

Process the Customer Data to provide the AGC services that the Customer requested through the AGC Agreements. ……………………………………………………………………………………………………………………………………………………………………

APPENDIX 2 - DESCRIPTION OF THE TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES IMPLEMENTED BY THE DATA IMPORTER

This Appendix forms part of the Clauses and must be completed and signed by the parties.

Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 3(b) and 4(c): the measures are provided in the DPA's Clause 4 (Data Security) and Annex 1 (Security Measures)

Search in Distribute Apps
Enter a keyword.