"Applicable Data Protection Laws" means all worldwide data protection and privacy laws and regulations applicable to the Personal Data in question including, where applicable, (i) European Data Protection Laws and (ii) CCPA; in each case, as may be amended, superseded or replaced from time to time.
"CCPA" means the California Consumer Privacy Act, Cal. Civ. Code§ 1798.100 et seq., and its implementing regulations.
"Europe" means, for the purposes of this DPA, the Member States of the European Union, plus Iceland, Liechtenstein, Norway, Switzerland and the United Kingdom.
"European Data Protection Laws" means all data protection laws and regulations applicable to the European Union ("EU") or the European Economic Area ("EEA"), including (a) the General Data Protection Regulation 2016/679 (the "EU GDPR"); (b) the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (collectively, the "UK GDPR"); (c) the Swiss Federal Data Protection Act of 19 June 1992 and its corresponding ordinances ("Swiss DPA"); (d) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (e) applicable national implementations of (a),(b), (c), and (d).
"Data Subject" means any individual about whom Personal Information may be processed pursuant to the Agreement.
"Personal Information" means any information that is protected as "personal data", "personal information" or "personally identifiable information" under Applicable Data Protection Laws and which is processed by Company on behalf of the Customer in connection with the Services, as more particularly described in Annex A of this DPA.
"Privacy Shield" means the EU-U.S. Privacy Shield program operated by the U.S. Department of Commerce and approved by the European Commission pursuant to Decision C(2016) 4176 of 12 July 2016 and by the Swiss Federal Council on January 11, 2017 respectively.
"Privacy Shield Principles" means the Privacy Shield Framework Principles (as supplemented by the Supplemental Principles) contained in the Annex II to the European Commission Decision of July 12, 2016.
"Restricted Transfer" means: (i) where the EU GDPR applies, a transfer of Personal Information from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Information from the United Kingdom to any other country which is not subject based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where Swiss DPA applies, a transfer of Personal Information from Switzerland to any other country which is not based on an adequacy decision recognized under Swiss data protection law.
"Security Incident" means any confirmed breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Information transmitted, stored or otherwise processed by Company in the context of this Agreement. "Security Incident" shall not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
"Sensitive Information" means Personal Information revealing a Data Subject's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation.
"Services" means the services provided by Company to the Customer under the Agreement.
"Model Clauses" or "SCCs" means (i) where the EU GDPR applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (ii) where the UK GDPR applies, standard data protection clauses for processors adopted pursuant to Article 46(2)(c) or (d) of the UK GDPR ("UK SCCs") (as amended, superseded or updated from time to time.
"Sub-processor" means any third party processor engaged by Company to assist in fulfilling its obligations with respect to providing the Services under the Agreement and this DPA.
The terms "controller", "processor" and "processing" shall have the meanings given to them in the GDPR and the terms and "process", "processes" and "processed" shall be interpreted accordingly.