GDPR contractual annex

GDPR contractual annex – Rental management

ANNEX 6 – Processing of personal data

A. Processing of personal data relating to the parties (and their possible agents) as data controllers

As part of the execution of this agreement, each party is required to process the personal data of the other party (and its possible employees) as data controller. The parties undertake to carry out this processing in accordance with the provisions of the GDPR and the Belgian law of July 30, 2018 relating to the protection of individuals with regard to the processing of personal data when these apply.

The parties may collect and process the following personal data:

  • identification data: surname, first name, place and date of birth, marital status, BCE number, IPI number;
  • contact data: address, registered office, email address, telephone number, position;
  • banking data: from the Manager for payment of fees and, where applicable, from the Principal in the event of retrocession of sums collected by the Manager;
  • data relating to the property(ies) given for management: address and description of the property, real rights encumbering the property, etc.

The processing of this data is necessary for the execution of this agreement, with a view to achieving the following purposes:

  • to enable the execution of the agreement and its monitoring by the parties;
  • to enable the management of the contractual relationship between the parties;
  • to enable invoicing of services and possible recovery of debts;

These data are then processed on the basis of article 6.1 (b) of the GDPR.

The Manager may also process the Principal’s data in the pursuit of its legitimate interests:

  • to enable the Manager to send commercial communications to the Client intended to promote its services to its existing clients;
  • for security reasons and to combat fraud;

These data are then processed on the basis of article 6.1. (f) GDPR.

Finally, data may be processed by the parties when this processing is necessary for compliance with a legal obligation to which a party is subject, including in particular:

  • the Administrator may process the Data of the Principal in order to comply with its legal obligation in the fight against money laundering and the financing of terrorism.

These data are then processed on the basis of article 6.1. (c) GDPR.

Within the strict limits of what is necessary for the execution of this agreement, the personal data of the parties may be communicated to the following recipients:

  • candidate tenants (or any interested party) and other parties involved in the mission;
  • postal services responsible for distributing letters or parcels;
  • public administrations responsible for taxation and social security;
  • the parties’ accountant to ensure compliance with their legal obligations;
  • the IT service provider in charge of the IT environment;
  • any partner of the Manager with a view to carrying out the missions entrusted and with the agreement of the Principal.

Personal data will be retained for a maximum period of 10 years from the end of this agreement for liability reasons.

In the event that data is transferred outside the European Union, to countries that the European Commission does not consider to have an adequate level of protection of personal data, the party concerned takes the necessary measures to protect the data using the standard contractual clauses relating to data protection adopted by the Commission as well as any additional measures to ensure an adequate level of protection. The party concerned makes these clauses available for consultation at its headquarters.

Each party or its agents may, upon dated and signed request, sent by email or postal mail, obtain written communication of the personal data processed and the portability of the data, as well as, where applicable, their rectification, limitation, deletion or exclusion of those which are neither accurate nor complete nor relevant.

In addition, each party may object, in the same way, to processing based on the legitimate interest of the other party.

Each party or its agents may also file a complaint with the Belgian data protection authority (Rue de la presse 35, 1000 Brussels – contact@apd-gba.be – Tel. + 32 2 274 48 00 – Fax + 32 2 274 48 35) for the exercise of these rights.

If a party discloses to the other party personal data concerning its agents, the party disclosing this information must ensure that it has informed the employees concerned.

B. Processing by the Controller of personal data of third parties as a subcontractor

As part of the execution of the missions entrusted to it under this real estate management agreement, the Manager is required to process the personal data of third parties as a subcontractor within the meaning of the GDPR. It processes this data on behalf of and according to the instructions of the Principal who is the data controller within the meaning of the GDPR.

In accordance with Article 28, paragraphs 3 and 4 of the GDPR, this data processing must be the subject of a legal act between the parties defining the terms of this processing. The following provisions constitute the agreement of the parties relating to this processing and must be read and interpreted in light of the GDPR.

1. Description of treatment

a) Purpose of processing: Processing by the Manager of third party data for the management of real estate(s) on behalf of the Principal.

b) Duration of processing: as long as necessary to carry out the missions entrusted by the main agreement to the Manager and, in any case, for a duration not exceeding the duration of the main agreement.

c) Nature of processing: collection and use of third party data with a view to ensuring the necessary contacts to carry out the missions entrusted within the framework of the management of real estate(s).

d) Purpose of the processing: the management of real estate(s) belonging to the Principal by the Manager in accordance with the instructions given by the latter within the framework of the main agreement.

e) Type of personal data:

  • identification data (surname, first name, address);
  • contact data (email address, telephone number);
  • banking data;
  • any other data necessary taking into account the purpose of the mission entrusted.

f) Categories of persons concerned: the categories of persons concerned are determined by the purpose of the mission entrusted to the Manager.

This may include, in particular:

  • tenants/candidate tenants of the property managed by the Manager (and their possible deposits);
  • co-owners or owners or Principal;
  • of the trustee of the real estate which the Manager is responsible for managing;
  • holders of real rights to the real estate which the Manager manages;
  • of the previous manager;
  • third parties whose intervention is desired in connection with the property managed by the Manager (contractors, etc.)

The persons whose intervention is necessary or desired are, where applicable, identified by the Principal when concluding this agreement or during its execution.

2. Hierarchy

In the event of any contradiction between these clauses and the provisions of related agreements which exist between the parties at the time these clauses are agreed or which are subsequently entered into, these clauses shall prevail.

3. Obligations of the parties

3.1. Instructions

a) The Controller only processes personal data on the documented instructions of the Principal, unless he is required to do so under Union law or the law of the Member State to which he is subject. In this case, the Administrator informs the Principal of this legal obligation before processing, unless the law prohibits it for important reasons of public interest.

Instructions relating to data processing may also be given subsequently by the Client for the duration of the processing of personal data. These instructions must always be documented.

b) The Controller shall immediately inform the Principal if, in his opinion, an instruction given by the Principal constitutes a violation of the GDPR or other provisions of Union or Member State law relating to data protection.

3.2. Lawfulness of processing

The Principal guarantees the lawfulness of the processing which it entrusts to the Manager. He ensures that third party data transmitted to the Manager is relevant and up to date. It guarantees that this data has been lawfully collected.

3.3. Limitation of purpose

The Controller processes personal data only for the specific purpose(s) of the processing, as defined in Article 1 of this Appendix, unless otherwise instructed by the Principal.

3.4. Duration of processing of personal data

Processing by the Administrator only takes place for the duration specified in Article 1 of this Appendix.

3.5. Treatment safety

a) The Regulator implements appropriate technical and organizational measures to ensure the security of personal data and, in particular, the protection of data against any security breach leading, accidentally or unlawfully, to the destruction, loss, alteration, unauthorized disclosure of personal data or unauthorized access to such data (personal data breach). When assessing the appropriate level of security, the parties shall take due account of the state of knowledge, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for data subjects.

b) The Manager only grants members of his staff access to the personal data being processed to the extent strictly necessary for the execution, management and monitoring of the agreement. The Regulator ensures that persons authorized to process personal data undertake to respect confidentiality or are subject to an appropriate legal obligation of confidentiality.

3.6. Sensitive data

If the processing concerns personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data or biometric data for the purposes of uniquely identifying a natural person, data concerning health or data concerning the sex life or sexual orientation of a natural person, or data relating to criminal convictions and offenses (“sensitive data”), the Controller applies specific limitations and/or additional safeguards.

3.7. Documentation and compliance

a) The parties ensure that they are able to demonstrate compliance of the processing with these clauses.

b) The Administrator processes requests from the Principal regarding the processing of data in accordance with these clauses quickly and adequately.

c) The Manager makes available to the Principal all the information necessary to demonstrate compliance with the obligations set out in these clauses and arising directly from the GDPR.

At the request of the Principal, the Controller also allows audits of the processing activities covered by these clauses to be carried out and contributes to them, at reasonable intervals or in the presence of indications of non-compliance. The Principal may decide to carry out the audit himself or to appoint an independent auditor. When deciding on an examination or audit, the Principal may take into account the relevant certifications in the possession of the Supervisor.

The Principal may decide to carry out the audit himself or to appoint an independent auditor. Audits may also include inspections of the premises or physical installations of the Regulator and are, where applicable, carried out with reasonable notice.

(d) The Parties shall make available to the competent supervisory authority(ies), upon request, the information set out in this clause, including the results of any audit.

3.8. Use of sub-processors within the meaning of the GDPR

a) The Manager has the general authorization of the Principal regarding the recruitment of subcontractors on the basis of a list agreed when defining the mission entrusted. The Manager specifically informs the Principal in writing of any proposed modification of this list by the addition or replacement of subcontractors at least 1 month in advance, thus giving the Principal sufficient time to be able to oppose these changes before recruiting the subcontractor(s) concerned. The Manager provides the Principal with the necessary information to enable him to exercise his right of opposition.

b) Where the Controller engages a sub-processor to carry out specific data processing activities (on behalf of the Principal), it does so by means of a contract which imposes on the sub-processor, in substance, the same data protection obligations as those imposed on the Controller under the clauses of this annex.

The Controller ensures that the subcontractor complies with the obligations to which it is itself subject under these clauses and the GDPR.

c) At the request of the Principal, the Manager provides him with a copy of this contract concluded with the subcontractor and of any modification subsequently made to it. To the extent necessary for the protection of business secrets or other confidential information, including personal data, the Administrator may redact the text of the contract before distributing a copy.

d) The Manager remains fully responsible, with regard to the Principal, for the execution of the obligations of the subcontractor in accordance with the contract concluded with the subcontractor.

The Manager informs the Principal of any failure by the subcontractor to fulfill its contractual obligations.

e) The Controller agrees with the subcontractor a third-party beneficiary clause according to which — in the event that the subcontractor has materially disappeared, ceased to exist in law or has become insolvent — the Principal has the right to terminate the contract concluded with the subcontractor and to instruct the subcontractor to erase or return the personal data.

3.9. International transfers

a) Any transfer of data to a third country or an international organization by the Controller is only carried out on the basis of documented instructions from the Principal in order to satisfy a specific requirement of Union law or Member State law to which the processor is subject and is carried out in accordance with Chapter V of the GDPR.

b) The Principal agrees that where the Controller engages a sub-processor in accordance with clause 6.8 to carry out specific processing activities (on behalf of the Principal) and those processing activities involve a transfer of personal data within the meaning of Chapter V of the GDPR, the Controller and the sub-processor may ensure compliance with Chapter V of the GDPR by using the standard contractual clauses adopted by the Commission on the basis of Article 46 (2) GDPR, provided that the conditions of use of these standard contractual clauses are met.

4. Assistance to the Principal (responsible for processing)

a) The Administrator shall immediately inform the Principal of any request relating to the processing of personal data that he has received from a data subject. He does not himself respond to this request, unless the Principal has authorized him to do so.

b) The Controller assists the Principal in fulfilling its obligation to respond to requests from data subjects to exercise their rights, taking into account the nature of the processing.

In the execution of its obligations in accordance with points a) and b), the Manager complies with the instructions of the Principal.

c) In addition to the Controller’s obligation to assist the Principal under clause 4(b), the Controller further assists the Principal in ensuring compliance with the following obligations, taking into account the nature of the processing and the information available to the Controller:

1) the obligation to carry out an assessment of the impact of planned processing operations on the protection of personal data (“data protection impact assessment”) where a type of processing is likely to present a high risk to the rights and freedoms of natural persons;

2) the obligation to consult the competent supervisory authority(ies) prior to processing where a data protection impact assessment indicates that the processing would present a high risk if the Principal did not take measures to mitigate the risk;

3) the obligation to ensure that personal data is accurate and up to date, by immediately informing the Principal if the Controller learns that the personal data it processes are inaccurate or have become obsolete;

4) the obligations provided for in Article 32 of the GDPR.

5. Notification of personal data breaches

In the event of a personal data breach, the Controller cooperates with the Principal and assists him in complying with his obligations under Articles 33 and 34 of the GDPR, taking into account the nature of the processing and the information available to the Controller.

5.1. Data breach in relation to data processed by the Principal (the data controller)

In the event of a personal data breach relating to data processed by the Principal, the Manager shall assist the Principal:

a) for the purposes of reporting the personal data breach to the competent supervisory authority(ies), as soon as possible after the Principal becomes aware of it, where applicable (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);

b) for the purposes of obtaining the following information which, in accordance with Article 33(3) of the GDPR, must appear in the notification from the Principal, and include, at least:

1) the nature of the personal data, including, where possible, the categories and approximate number of individuals affected by the breach and the categories and approximate number of personal data records affected;

2) the likely consequences of the personal data breach;

3) the measures taken or the measures that the Principal proposes to take to remedy the personal data breach, including, where applicable, measures to mitigate possible negative consequences.

Where and to the extent that it is not possible to provide all information at once, the initial notification shall contain the information available at that time and, as it becomes available, additional information shall subsequently be provided as soon as possible;

c) for the purposes of satisfying, in accordance with Article 34 of the GDPR, the obligation to communicate the personal data breach to the data subject as soon as possible, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

5.2. Data breach in relation to data processed by the Controller (the subcontractor)

In the event of a personal data violation relating to data processed by the Manager, the latter will inform the Principal as soon as possible after becoming aware of it. This notification contains at least:

(a) a description of the nature of the breach found (including, where possible, the categories and approximate number of persons affected by the breach and of personal data records affected);

(b) contact details of a contact point from which further information can be obtained regarding the personal data breach;

(c) its likely consequences and the measures taken or proposed to be taken to remedy the violation, including to mitigate possible negative consequences.

Where and to the extent that it is not possible to provide all information at the same time, the initial notification shall contain the information available at that time and, as it becomes available, additional information shall subsequently be provided as soon as possible.

6. Non-compliance with clauses and termination

a) Without prejudice to the provisions of the GDPR, in the event of failure by the Controller to fulfill its obligations under the clauses of this annex, the Principal may instruct the Controller to suspend the processing of personal data until the latter has complied with these clauses or until the contract is terminated. The Manager will promptly inform the Principal if he is unable to comply with these clauses, for whatever reason.

b) The Principal is entitled to terminate the contract insofar as it concerns the processing of personal data in accordance with these clauses if:

1) the processing of personal data by the Controller has been suspended by the Principal in accordance with point a) and compliance with these clauses is not restored within a reasonable time and, in any event, within one month from the suspension;

2) the Administrator is in serious or persistent violation of these clauses or of its obligations under the GDPR;

3) the Regulator does not comply with a binding decision of a competent court or the competent supervisory authority(ies) concerning its obligations under these clauses or the GDPR.

c) The Controller is entitled to terminate the contract insofar as it concerns the processing of personal data under these clauses where, having informed the Principal that its instructions contravene the applicable legal requirements in accordance with clause 3.1(b), the Principal insists that its instructions be followed.

d) Following termination of the contract, the Controller deletes, at the Client’s choice, all personal data processed on behalf of the Client and certifies to the Client that he has carried out this deletion, or returns all personal data to the Client and destroys existing copies, unless Union law or national law requires them to be retained for a longer period. The Controller continues to ensure compliance with these clauses until the data is deleted or returned.

GDPR contractual annex – Brokerage

Object. This appendix governs the processing of personal data carried out as part of the real estate brokerage missions entrusted to RealtyCare. It incorporates the structure and guarantees of Appendix 6 applicable to rental management, adapted to the brokerage activity.

Qualification of roles. For processing operations imposed by law, IPI ethics, the fight against money laundering, the constitution of proof of due diligence and the specific organization of its activity, the Broker acts as data controller. The provisions relating to subcontracting only apply to processing carried out exclusively on behalf and according to the documented instructions of the Principal.

A. Processing of personal data relating to the parties (and their possible agents) as data controllers

As part of the execution of this agreement, each party is required to process the personal data of the other party (and its possible employees) as data controller. The parties undertake to carry out this processing in accordance with the provisions of the GDPR and the Belgian law of July 30, 2018 relating to the protection of individuals with regard to the processing of personal data when these apply.

The parties may collect and process the following personal data:

identification data: surname, first name, place and date of birth, marital status, BCE number, IPI number;

contact data: address, registered office, email address, telephone number, position;

banking data: of the Broker for payment of fees and, where applicable, of the Principal in the event of retrocession of sums collected by the Broker;

data relating to the property(ies) concerned by the brokerage mission: address and description of the property, real rights encumbering the property, etc.

The processing of this data is necessary for the execution of this agreement, with a view to achieving the following purposes:

to enable the execution of the agreement and its monitoring by the parties;

to enable the management of the contractual relationship between the parties;

to enable invoicing of services and possible recovery of debts;

These data are then processed on the basis of article 6.1 (b) of the GDPR.

The Broker may also process the Client’s data in the pursuit of its legitimate interests:

to enable the Broker to send the Principal commercial communications intended to promote its services to its existing clients;

for security reasons and to combat fraud;

These data are then processed on the basis of article 6.1. (f) GDPR.

Finally, data may be processed by the parties when this processing is necessary for compliance with a legal obligation to which a party is subject, including in particular:

the Broker may process the Client’s data in order to comply with its legal obligation to combat money laundering and the financing of terrorism.

These data are then processed on the basis of article 6.1. (c) GDPR.

Within the strict limits of what is necessary for the execution of this agreement, the personal data of the parties may be communicated to the following recipients:

candidate tenants (or any interested party) and other parties involved in the mission;

postal services responsible for distributing letters or parcels;

public administrations responsible for taxation and social security;

the parties’ accountant to ensure compliance with their legal obligations;

the IT service provider in charge of the IT environment;

any partner of the Broker with a view to carrying out the missions entrusted and with the agreement of the Principal.

Personal data will be retained for a maximum period of 10 years from the end of this agreement for liability reasons.

In the event that data is transferred outside the European Union, to countries that the European Commission does not consider to have an adequate level of protection of personal data, the party concerned takes the necessary measures to protect the data using the standard contractual clauses relating to data protection adopted by the Commission as well as any additional measures to ensure an adequate level of protection. The party concerned makes these clauses available for consultation at its headquarters.

Each party or its agents may, upon dated and signed request, sent by email or postal mail, obtain written communication of the personal data processed and the portability of the data, as well as, where applicable, their rectification, limitation, deletion or exclusion of those which are neither accurate nor complete nor relevant.

In addition, each party may object, in the same way, to processing based on the legitimate interest of the other party.

Each party or its agents may also file a complaint with the Belgian data protection authority (Rue de la presse 35, 1000 Brussels – contact@apd-gba.be – Tel. + 32 2 274 48 00 – Fax + 32 2 274 48 35) for the exercise of these rights.

If a party discloses to the other party personal data concerning its agents, the party disclosing this information must ensure that it has informed the employees concerned.

B. Processing by the Broker of personal data of third parties as part of a brokerage mission

As part of the execution of the missions entrusted to it under this agreement relating to a real estate brokerage mission, the Broker is required to process the personal data of third parties as a subcontractor within the meaning of the GDPR. It processes this data on behalf of and according to the instructions of the Principal who is the data controller within the meaning of the GDPR.

In accordance with Article 28, paragraphs 3 and 4 of the GDPR, this data processing must be the subject of a legal act between the parties defining the terms of this processing. The following provisions constitute the agreement of the parties relating to this processing and must be read and interpreted in light of the GDPR.

1. Description of treatment

a) Purpose of processing: processing by the Broker of third party data for the execution of the real estate brokerage mission entrusted by the Principal.

b) Duration of processing: as long as necessary to carry out the missions entrusted by the agreement relating to the brokerage mission to the Broker and, in any event, for a duration not exceeding the duration of the agreement relating to the brokerage mission.

c) Nature of processing: collection and use of third party data with a view to ensuring the contacts necessary to carry out the missions entrusted as part of the execution of a real estate brokerage mission.

d) Purpose of the processing: the execution of a real estate brokerage mission belonging to the Principal by the Broker in accordance with the instructions given by the latter within the framework of the agreement relating to the brokerage mission.

e) Type of personal data:

identification data (surname, first name, address);

contact data (email address, telephone number);

banking data;

any other data necessary taking into account the purpose of the mission entrusted.

f) Categories of persons concerned: the categories of persons concerned are determined by the purpose of the mission entrusted to the Broker.

This may include, in particular:

tenants/candidate tenants of the property managed by the Broker (and their possible deposits);

co-owners or owners or Principal;

of the trustee of the real estate which the Broker manages;

holders of real rights to the real estate which the Broker manages;

from the previous broker;

third parties whose intervention is desired in connection with the property managed by the Broker (contractors, etc.)

The persons whose intervention is necessary or desired are, where applicable, identified by the Principal when concluding this agreement or during its execution.

2. Hierarchy

In the event of any contradiction between these clauses and the provisions of related agreements which exist between the parties at the time these clauses are agreed or which are subsequently entered into, these clauses shall prevail.

3. Obligations of the parties

3.1. Instructions

a) The Broker only processes personal data on the documented instructions of the Principal, unless it is required to do so under Union law or the law of the Member State to which it is subject. In this case, the Broker informs the Client of this legal obligation before processing, unless the law prohibits it for important reasons of public interest.

Instructions relating to data processing may also be given subsequently by the Client for the duration of the processing of personal data. These instructions must always be documented.

b) The Broker shall immediately inform the Principal if, in its opinion, an instruction given by the Principal constitutes a violation of the GDPR or other provisions of Union or Member State law relating to data protection.

3.2. Lawfulness of processing

The Principal guarantees the lawfulness of the processing it entrusts to the Broker. It ensures that third party data transmitted to the Broker is relevant and up to date. It guarantees that this data has been lawfully collected.

3.3. Limitation of purpose

The Broker processes personal data only for the specific purpose(s) of the processing, as defined in Article 1 of this Appendix, unless otherwise instructed by the Principal.

3.4. Duration of processing of personal data

Processing by the Broker only takes place for the duration specified in Article 1 of this Appendix.

3.5. Treatment safety

a) The Broker implements appropriate technical and organizational measures to ensure the security of personal data and, in particular, the protection of data against any security breach resulting, accidentally or unlawfully, in the destruction, loss, alteration, unauthorized disclosure of personal data or unauthorized access to such data (personal data breach). When assessing the appropriate level of security, the parties shall take due account of the state of knowledge, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for data subjects.

b) The Broker only grants members of its staff access to the personal data subject to processing to the extent strictly necessary for the execution, management and monitoring of the agreement. The Broker ensures that persons authorized to process personal data undertake to respect confidentiality or are subject to an appropriate legal obligation of confidentiality.

3.6. Sensitive data

If the processing concerns personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data or biometric data for the purposes of uniquely identifying a natural person, data concerning health or data concerning the sex life or sexual orientation of a natural person, or data relating to criminal convictions and offenses (“sensitive data”), the Broker applies specific limitations and/or additional safeguards.

3.7. Documentation and compliance

a) The parties ensure that they are able to demonstrate compliance of the processing with these clauses.

b) The Broker handles requests from the Client regarding the processing of data in accordance with these clauses promptly and adequately.

c) The Broker makes available to the Principal all the information necessary to demonstrate compliance with the obligations set out in these clauses and resulting directly from the GDPR.

At the request of the Principal, the Broker also allows audits of the processing activities covered by these clauses to be carried out and contributes to them, at reasonable intervals or in the presence of indications of non-compliance. The Principal may decide to carry out the audit himself or to appoint an independent auditor. When deciding on an examination or audit, the Principal may take into account the relevant certifications in the Broker’s possession.

The Principal may decide to carry out the audit himself or to appoint an independent auditor. Audits may also include inspections of the Broker’s premises or physical facilities and are, where applicable, carried out upon reasonable notice.

(d) The Parties shall make available to the competent supervisory authority(ies), upon request, the information set out in this clause, including the results of any audit.

3.8. Use of sub-processors within the meaning of the GDPR

a) The Broker has the general authorization of the Principal with regard to the recruitment of subcontractors on the basis of a list agreed when defining the mission entrusted. The Broker specifically informs the Principal in writing of any proposed modification of this list by the addition or replacement of subcontractors at least 1 month in advance, thus giving the Principal sufficient time to be able to object to these changes before recruiting the subcontractor(s) concerned. The Broker provides the Principal with the necessary information to enable him to exercise his right of opposition.

b) Where the Broker engages a sub-processor to carry out specific data processing activities (on behalf of the Principal), it does so by means of a contract which imposes on the sub-processor, in substance, the same data protection obligations as those imposed on the Broker under the clauses of this annex.

The Broker ensures that the sub-processor complies with the obligations to which it is itself subject under these clauses and the GDPR.

c) At the request of the Principal, the Broker provides him with a copy of this contract concluded with the subcontractor and of any modification subsequently made to it. To the extent necessary to protect trade secrets or other confidential information, including personal data, the Broker may redact the text of the contract before distributing a copy.

d) The Broker remains fully responsible, with regard to the Principal, for the execution of the obligations of the sub-processor in accordance with the contract concluded with the sub-processor.

The Broker informs the Principal of any failure by the subcontractor to fulfill its contractual obligations.

e) The Broker agrees with the subcontractor a third-party beneficiary clause according to which — in the event that the subcontractor has materially disappeared, ceased to exist in law or has become insolvent — the Principal has the right to terminate the contract concluded with the subprocessor and to instruct the subprocessor to erase or return the personal data.

3.9. International transfers

a) Any transfer of data to a third country or an international organization by the Broker is carried out only on the basis of documented instructions from the Principal in order to satisfy a specific requirement of Union or Member State law to which the processor is subject and is carried out in accordance with Chapter V of the GDPR.

b) The Principal agrees that where the Broker engages a sub-processor in accordance with clause 3.8 to carry out specific processing activities (on behalf of the Principal) and such processing activities involve a transfer of personal data within the meaning of Chapter V of the GDPR, the Broker and the sub-processor may ensure compliance with Chapter V of the GDPR by using the standard contractual clauses adopted by the Commission on the basis of Article 46 (2) GDPR, provided that the conditions of use of these standard contractual clauses are met.

4. Assistance to the Principal (responsible for processing)

a) The Broker shall immediately inform the Principal of any request relating to the processing of personal data that it has received from a data subject. He does not himself respond to this request, unless the Principal has authorized him to do so.

b) The Broker assists the Principal in fulfilling its obligation to respond to requests from data subjects to exercise their rights, taking into account the nature of the processing.

In carrying out its obligations in accordance with points a) and b), the Broker complies with the instructions of the Principal.

c) In addition to the Broker’s obligation to assist the Principal under clause 4(b), the Broker further assists the Principal in ensuring compliance with the following obligations, taking into account the nature of the processing and the information available to the Broker:

1) the obligation to carry out an assessment of the impact of planned processing operations on the protection of personal data (“data protection impact assessment”) where a type of processing is likely to present a high risk to the rights and freedoms of natural persons;

2) the obligation to consult the competent supervisory authority(ies) prior to processing where a data protection impact assessment indicates that the processing would present a high risk if the Principal did not take measures to mitigate the risk;

3) the obligation to ensure that personal data is accurate and up to date, by immediately informing the Principal if the Broker learns that the personal data it processes are inaccurate or have become obsolete;

4) the obligations provided for in Article 32 of the GDPR.

5. Notification of personal data breaches

In the event of a personal data breach, the Broker cooperates with the Principal and assists it in complying with its obligations under Articles 33 and 34 of the GDPR, taking into account the nature of the processing and the information available to the Broker.

5.1. Data breach in relation to data processed by the Principal (the data controller)

In the event of a personal data breach relating to data processed by the Principal, the Broker shall assist the Principal:

a) for the purposes of reporting the personal data breach to the competent supervisory authority(ies), as soon as possible after the Principal becomes aware of it, where applicable (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);

b) for the purposes of obtaining the following information which, in accordance with Article 33(3) of the GDPR, must appear in the notification from the Principal, and include, at least:

1) the nature of the personal data, including, where possible, the categories and approximate number of individuals affected by the breach and the categories and approximate number of personal data records affected;

2) the likely consequences of the personal data breach;

3) the measures taken or the measures that the Principal proposes to take to remedy the personal data breach, including, where applicable, measures to mitigate possible negative consequences.

Where and to the extent that it is not possible to provide all information at once, the initial notification shall contain the information available at that time and, as it becomes available, additional information shall subsequently be provided as soon as possible;

c) for the purposes of satisfying, in accordance with Article 34 of the GDPR, the obligation to communicate the personal data breach to the data subject as soon as possible, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

5.2. Data breach in relation to data processed by the Broker (the subcontractor)

In the event of a personal data breach relating to data processed by the Broker, the latter shall inform the Principal as soon as possible after becoming aware of it. This notification contains at least:

(a) a description of the nature of the breach found (including, where possible, the categories and approximate number of persons affected by the breach and of personal data records affected);

(b) contact details of a contact point from which further information can be obtained regarding the personal data breach;

(c) its likely consequences and the measures taken or proposed to be taken to remedy the violation, including to mitigate possible negative consequences.

Where and to the extent that it is not possible to provide all information at the same time, the initial notification shall contain the information available at that time and, as it becomes available, additional information shall subsequently be provided as soon as possible.

6. Non-compliance with clauses and termination

a) Without prejudice to the provisions of the GDPR, in the event of failure by the Broker to fulfill its obligations under the clauses of this annex, the Principal may instruct the Broker to suspend the processing of personal data until the latter has complied with these clauses or until the contract is terminated. The Broker will promptly inform the Principal if he is unable to comply with these clauses, for whatever reason.

b) The Principal is entitled to terminate the contract insofar as it concerns the processing of personal data in accordance with these clauses if:

1) the processing of personal data by the Broker has been suspended by the Principal in accordance with point a) and compliance with these clauses is not restored within a reasonable time and, in any event, within one month from the suspension;

2) the Broker is in serious or persistent violation of these clauses or of its obligations under the GDPR;

3) the Broker fails to comply with a binding decision of a competent court or competent supervisory authority(ies) regarding its obligations under these clauses or the GDPR.

c) The Broker is entitled to terminate the contract insofar as it concerns the processing of personal data under these clauses where, having informed the Principal that its instructions contravene the applicable legal requirements in accordance with clause 3.1(b), the Principal insists that its instructions be followed.

d) Following termination of the contract, the Broker, at the option of the Principal, deletes all personal data processed on behalf of the Principal and certifies to the Client that it has carried out this deletion, or returns all personal data to the Principal and destroys existing copies, unless Union law or national law requires them to be retained for a longer period. The Broker continues to ensure compliance with these clauses until the data is deleted or returned.