DPA
Data processing agreement
Last updated: September 3rd, 2026
This Data Processing Agreement (“DPA”) forms part of, and is supplemental to, the Terms and Conditions (the “Principal Agreement”) between the Customer (as defined in the Principal Agreement) in their capacity as Data Controller (the “Controller”) and Generation Impact Global SA, Rue de Lausanne 82, 1202 Geneva, Switzerland, CHE-260.384.863, in its capacity as Data Processor (the “Processor” or “we”, “us”, “our”).
This DPA sets out the terms and conditions under which the Processor shall process Personal Data on behalf of the Controller in connection with the Services provided under the Principal Agreement.
Whereas
(A) The Controller has engaged the Processor to provide ESG data management, sustainability reporting, impact analytics, and utility management services (the “Services”) under the Principal Agreement.
(B) The provision of the Services involves the Processing of Personal Data by the Processor on behalf of the Controller, including through artificial-intelligence-assisted and external document-processing functionality made available through the Platform from time to time.
(C) The Parties wish to ensure that the Processing of Personal Data complies with all applicable Data Protection Laws.
(D) This DPA is intended to satisfy the requirements of Article 28 of the EU GDPR, Article 9 of the Swiss FADP, and equivalent provisions under other applicable Data Protection Laws.
It is agreed as follows:
Table of contents
Jump to section
1. Interpretation and definitions
“Applicable Data Protection Laws” means all laws and regulations relating to the processing of Personal Data that are applicable to the Processing under this DPA, including but not limited to: (a) the Swiss Federal Act on Data Protection of 25 September 2020 (FADP/nDSG) and its Ordinance (DPO); (b) the EU General Data Protection Regulation (EU) 2016/679 (EU GDPR); (c) the UK GDPR and UK Data Protection Act 2018; (d) Directive 2002/58/EC (ePrivacy Directive); (e) the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA); (f) Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and successor legislation; (g) South Africa’s Protection of Personal Information Act (POPIA); (h) Nigeria’s Data Protection Act (NDPA); (i) Kenya’s Data Protection Act (DPA); (j) Brazil’s Lei Geral de Proteção de Dados (LGPD); (k) Mexico’s Ley Federal de Protección de Datos Personales (LFPDPPP); (l) Chile’s Data Protection Act; (m) Colombia’s Law 1581 of 2012; (n) Argentina’s Habeas Data Law; (o) Japan’s Act on the Protection of Personal Information (APPI); (p) Singapore’s Personal Data Protection Act (PDPA); (q) India’s Digital Personal Data Protection Act (DPDP Act); (r) Australia’s Privacy Act 1988 (as amended); and (s) any other applicable data protection legislation, in each case as amended or replaced from time to time.
“Controller” means the Customer (as defined in the Principal Agreement), who determines the purposes and means of the Processing of Personal Data.
“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.
“Personal Data” means any information relating to an identified or identifiable natural person that is Processed by the Processor on behalf of the Controller in connection with the Services.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. A Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
“Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
“Processor” means Generation Impact Global SA, which Processes Personal Data on behalf of and on the instructions of the Controller.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), and/or the Swiss Federal Data Protection and Information Commissioner (FDPIC), as applicable and as may be amended or replaced from time to time.
“Sub-Processor” means any third party engaged by the Processor (or by another Sub-Processor) to Process Personal Data on behalf of the Controller in connection with the Services.
“AI Features” means artificial-intelligence-assisted functionality made available through the Platform from time to time, including document processing and information extraction, information retrieval, drafting assistance and other AI-assisted workflows described in the AI Transparency Notice.
2. Scope, roles, and details of processing
2.1 Roles
For the purposes of this DPA, the Controller is the Data Controller and the Processor is the Data Processor. The details of the Processing are set out in Annex 1 (Details of Processing).
2.2 Scope
This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services, including Processing by any Sub-Processors engaged by the Processor and Processing by AI Features. This DPA does not apply to Personal Data for which the Processor is an independent Data Controller (e.g. account registration data, billing data, usage analytics), which is governed by our Privacy Policy.
2.3 Duration
This DPA shall remain in force for the duration of the Processing. It shall survive the termination or expiry of the Principal Agreement for as long as the Processor continues to Process Personal Data on behalf of the Controller.
3. Processor obligations
3.1 Lawful Processing
The Processor shall: (a) Process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law, in which case the Processor shall inform the Controller of that legal requirement before Processing (unless such law prohibits such notification on important grounds of public interest); (b) immediately inform the Controller if, in the Processor’s opinion, an instruction from the Controller infringes Applicable Data Protection Laws; and (c) Process Personal Data only to the extent, and in such a manner, as is necessary for the provision of the Services, and in accordance with this DPA and the Principal Agreement.
3.2 Confidentiality
The Processor shall ensure that all persons authorised to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall ensure that access to Personal Data is limited to those personnel who require access to perform the Services.
3.3 Security
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR and equivalent provisions under other Applicable Data Protection Laws. These measures are described in Annex 2 (Technical and Organisational Measures). The Processor shall regularly test, assess, and evaluate the effectiveness of these measures.
3.4 Assistance to the Controller
Taking into account the nature of the Processing, the Processor shall assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligations to: (a) respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws (including access, rectification, erasure, restriction, portability, and objection); (b) comply with obligations relating to the security of Processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities (Articles 32–36 of the GDPR and equivalent provisions); and (c) comply with any other obligation under Applicable Data Protection Laws that requires the Processor’s assistance. Such assistance shall be provided at no additional charge for standard requests.
3.5 Data Subject Requests
If the Processor receives a request from a Data Subject to exercise any right under Applicable Data Protection Laws, the Processor shall promptly (and in any event within forty-eight (48) hours) notify the Controller and shall not respond to the request directly unless instructed to do so by the Controller or required by applicable law.
4. Controller obligations
The Controller represents, warrants, and undertakes that: (a) it has complied, and will continue to comply, with all Applicable Data Protection Laws in respect of the collection, transfer, and Processing of Personal Data; (b) it has obtained, and will maintain, all necessary consents, authorisations, and legal bases for the Processing of Personal Data by the Processor as contemplated by this DPA; (c) it has provided, and will continue to provide, all required notices to Data Subjects in accordance with Applicable Data Protection Laws; (d) its instructions to the Processor will comply with Applicable Data Protection Laws; and (e) it is responsible for the accuracy, quality, and legality of the Personal Data provided to the Processor.
5. Sub-processors
5.1 General Authorisation
The Controller hereby grants the Processor a general written authorisation to engage Sub-Processors to Process Personal Data on behalf of the Controller, subject to the conditions set out in this Section 5. The current list of approved Sub-Processors, including their legal name, location, processing activities and, where applicable, the relevant international data transfer mechanism, is available upon request by contacting [email protected].
5.2 Notification of Changes
The Processor shall notify the Controller in writing (including by email) at least fourteen (14) days in advance of any intended addition or replacement of a Sub-Processor, providing the name, location, and description of the Sub-Processor’s processing activities.
5.3 Right to Object
If the Controller objects to a new or replacement Sub-Processor on reasonable grounds relating to data protection, the Controller shall notify the Processor in writing within fourteen (14) days of receiving the notification. The Parties shall discuss the objection in good faith with a view to achieving a commercially reasonable resolution. If no resolution can be reached within thirty (30) days, either Party may terminate the affected Services (and the corresponding portion of the Principal Agreement) without penalty.
5.4 Sub-Processor Obligations
The Processor shall: (a) impose on each Sub-Processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA; (b) remain fully liable to the Controller for the acts and omissions of each Sub-Processor as if they were the Processor’s own; and (c) ensure that each Sub-Processor provides sufficient guarantees to implement appropriate technical and organisational measures.
6. Personal data breach
6.1 Notification
The Processor shall notify the Controller of any Personal Data Breach without undue delay, and in any event within twenty-four (24) hours of becoming aware of the breach. This timeline is designed to enable the Controller to comply with the 72-hour notification obligation under GDPR Article 33 and equivalent provisions under other Applicable Data Protection Laws (including the Swiss FADP, which requires notification “as soon as possible”).
6.2 Content of Notification
The notification shall include, to the extent available: (a) a description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected; (b) the name and contact details of the Processor’s contact point for further information; (c) a description of the likely consequences of the breach; and (d) a description of the measures taken or proposed to address the breach, including measures to mitigate its potential adverse effects.
6.3 Cooperation
The Processor shall cooperate with the Controller and take all reasonable steps as directed by the Controller to assist in the investigation, mitigation, and remediation of the breach. The Processor shall document all Personal Data Breaches, including their effects and the remedial actions taken.
6.4 No Communication to Data Subjects
The Processor shall not communicate a Personal Data Breach to any Data Subject or any third party (other than law enforcement where required) without the prior written consent of the Controller, unless required to do so by applicable law.
7. Processing by artificial intelligence features
7.1 AI Processing
The Services may include AI Features that Process Personal Data on behalf of the Controller for the purposes described in Annex 1. The Processor acknowledges that this Processing is subject to Applicable Data Protection Laws and, where applicable, the EU AI Act (Regulation (EU) 2024/1689) and the Council of Europe Framework Convention on Artificial Intelligence.
7.2 AI and External Processing Providers
AI Features and related document-processing steps may use third-party services. These currently include services supplied directly by OpenAI, LLC through the OpenAI API and document-processing services supplied by LlamaIndex Inc. through LlamaParse. Certain customer-initiated workflows may also transmit submitted information to an external classification, mapping or reference service operated by the European Commission Joint Research Centre (JRC); such a service is not treated as a GIG AI Feature merely because it is accessed through the Platform. Where any such provider Processes Personal Data on behalf of the Controller, it is treated as a Sub-Processor and is subject to Section 5. The relevant processing activities, locations, provider-side retention and transfer safeguards are identified in the AI Transparency Notice or current Sub-Processor list, as applicable.
7.3 Restrictions
The Processor shall not: (a) use Personal Data Processed on behalf of the Controller to train or improve any general-purpose AI model or third-party machine-learning model unless the Controller expressly authorises that use in writing; (b) retain Personal Data Processed by AI Features beyond what is necessary to deliver the Services, comply with the Controller’s documented instructions or satisfy applicable legal obligations; or (c) use Personal Data for any AI-related purpose not documented in the Controller’s instructions, the Principal Agreement or this DPA. Customer Content is not used to train or improve third-party general-purpose models unless the Controller expressly authorises that use in writing.
7.4 Transparency
The Processor shall provide the Controller, upon request, with information about: (a) the categories of third-party AI technologies used in the Processing; (b) the general logic involved in AI-assisted Processing; and (c) the measures taken to ensure accuracy, fairness, and non-discrimination in AI-assisted Processing. Further details are available in our AI Transparency Notice.
8. International data transfers
8.1 Processing Locations
Personal Data may be Processed in Switzerland, the European Economic Area (EEA) and the other locations identified in Annex 1, the current Sub-Processor list or the AI Transparency Notice. The Controller’s general authorisation under Section 5 includes Processing in those identified locations, subject to the transfer safeguards in this Section 8. The Processor shall notify the Controller of any intended addition or replacement of a Sub-Processor in accordance with Section 5.2. No additional prior written authorisation is required for a transfer covered by that general authorisation and the safeguards in this DPA.
8.2 Transfer Mechanisms
Where Personal Data is transferred to a country that has not been deemed to provide an adequate level of data protection by the European Commission, the Swiss Federal Council, or the UK Government (as applicable), the Processor shall ensure that appropriate safeguards are in place, including: (a) Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), Module 2 (Controller to Processor) or Module 3 (Processor to Sub-Processor), as applicable; (b) the Swiss FDPIC-approved modifications for Swiss transfers; (c) the UK International Data Transfer Addendum issued by the ICO; (d) binding corporate rules; or (e) other recognised transfer mechanisms under Applicable Data Protection Laws.
8.3 Supplementary Measures
Where required by the Schrems II judgment (CJEU C-311/18) or applicable guidance, the Processor shall implement supplementary technical, organisational, and contractual measures to ensure that the level of protection afforded to Personal Data is not undermined by the transfer.
8.4 Disclosure Requests
If the Processor receives a request from a public authority or law enforcement agency for access to or disclosure of Personal Data Processed on behalf of the Controller, the Processor shall: (a) promptly notify the Controller (unless prohibited by law); (b) challenge the request where it appears to be unlawful; and (c) provide the minimum amount of information permissible when complying with a disclosure obligation.
8.5 Excluded Territories
The Services are not currently offered to customers located in the People’s Republic of China, Saudi Arabia, the United Arab Emirates, or Qatar. No Personal Data is intentionally transferred to or processed in these territories.
9. Deletion, return, and portability of personal data
9.1 Return or Deletion
Upon termination or expiry of the Principal Agreement, or upon the Controller’s written request, the Processor shall, at the Controller’s election: (a) return Personal Data Processed on behalf of the Controller in a structured, commonly used, and machine-readable format; or (b) securely delete such Personal Data and copies thereof. The Processor shall complete the return or deletion within thirty (30) days of the request, unless the sixty-day retrieval period in Section 9.2 applies or a longer period is technically necessary and agreed between the Parties.
9.2 Post-Termination Retention
Following termination of the Principal Agreement, the Processor shall make the Controller’s Content (including Personal Data) available for download for sixty (60) days, in accordance with the Principal Agreement. After this period, the Processor shall securely delete Personal Data Processed on behalf of the Controller unless retention is required by applicable law. This Section 9 does not require deletion of information that the Processor processes as an independent controller, including billing, security, audit, dispute-resolution and legally required records governed by the Privacy Policy, or of irreversibly anonymised information. Residual copies in backups may remain until securely overwritten in the ordinary backup cycle, provided they remain protected and are not restored except for disaster recovery or legal necessity.
9.3 Certification
Upon request, the Processor shall provide written certification to the Controller that it has complied with its obligations under this Section 9 within ten (10) business days of completing the deletion.
9.4 Data Portability (EU Data Act)
To the extent that Regulation (EU) 2023/2854 (the EU Data Act) applies, the Processor shall cooperate with the Controller and, where applicable, with the Controller’s new service provider, to facilitate the switching and porting of data in accordance with Chapter VI of the EU Data Act and the terms of the Principal Agreement.
10. Audit rights
10.1 Information
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws, and shall contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.
10.2 Audit Procedure
Audits shall be conducted: (a) upon reasonable written notice of at least thirty (30) days (except in the case of a suspected Personal Data Breach, where shorter notice is permitted); (b) during normal business hours; (c) in a manner that does not unreasonably disrupt the Processor’s operations; and (d) no more than once per twelve-month period, unless required by a supervisory authority or in connection with a Personal Data Breach.
10.3 Third-Party Certifications
The Processor may satisfy audit requests by providing relevant security documentation, independent assessment reports, penetration-test summaries, or certifications maintained by the Processor or its infrastructure providers, where available and appropriate. Where such materials do not adequately address the Controller’s reasonable concerns, the Controller may request an audit subject to Section 10.2.
10.4 Costs
Each Party shall bear its own costs in connection with audits, unless the audit reveals a material breach of this DPA by the Processor, in which case the Processor shall bear the reasonable costs of the audit.
11. Data protection impact assessment
The Processor shall provide reasonable assistance to the Controller with any data protection impact assessment (DPIA) and, where applicable, prior consultation with supervisory authorities, as required by Articles 35 and 36 of the GDPR, Article 22 of the Swiss FADP, or equivalent provisions under other Applicable Data Protection Laws, in each case solely in relation to the Processing of Personal Data by the Processor and taking into account the nature of the Processing and the information available to the Processor.
12. No sale of personal data
The Processor shall not sell, share, or disclose Personal Data Processed on behalf of the Controller for cross-context behavioural advertising, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. This commitment is intended, where applicable, to comply with the requirements of the CCPA/CPRA and equivalent US state privacy laws. The Processor shall not retain, use, or disclose Personal Data Processed on behalf of the Controller except as necessary to perform the Services under the Principal Agreement.
13. General terms
13.1 Precedence
In the event of any conflict between this DPA and the Principal Agreement, this DPA shall prevail to the extent of the conflict with respect to matters relating to the Processing of Personal Data.
13.2 Liability
The liability of each Party under or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Principal Agreement.
13.3 Amendments
This DPA may be amended only in writing signed by both Parties, except that the Processor may update the Annexes to this DPA (including the list of Sub-Processors and the Technical and Organisational Measures) from time to time, provided that such updates do not materially reduce the level of protection afforded to Personal Data. The Processor shall notify the Controller of any material updates.
13.4 Severability
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
14. Governing law and jurisdiction
This DPA shall be governed by and construed in accordance with the laws of Switzerland, without regard to its conflict of law provisions. The courts of the Canton of Geneva, Switzerland, shall have exclusive jurisdiction to settle any dispute arising out of or in connection with this DPA. Where Applicable Data Protection Laws require a different governing law for specific Processing activities (e.g. GDPR for EU Data Subjects), such mandatory provisions shall prevail.
15. Annex 1: Details of processing
This Annex 1 forms part of the DPA and describes the Processing of Personal Data by
the Processor on behalf of the Controller.
| Element | Description |
| Subject matter and purpose of Processing | Processing of Personal Data as necessary to provide the Services under the Principal Agreement, including ESG data management, sustainability reporting, impact analytics, utility management, document processing and information extraction, information retrieval, drafting assistance and other enabled AI-assisted or external-service workflows |
| Nature of the Processing | Collection, storage, organisation, structuring, retrieval, consultation, use, analysis (including AI-assisted analysis), disclosure (to Authorised Users and authorised recipients), restriction, erasure, and destruction of Personal Data |
| Duration of the Processing | For the duration of the Principal Agreement, plus sixty (60) days post-termination for data retrieval, plus any period required by applicable law. Information processed by the Processor as an independent controller is retained as described in the Privacy Policy. |
| Categories of Data Subjects | Employees, contractors, and representatives of the Controller; employees and representatives of the Controller’s portfolio companies, investees, or business partners whose data is uploaded to the Platform; Authorised Users of the Platform |
| Types of Personal Data | Name, business email address, job title, organisation name, role and responsibilities; ESG-related workforce data (for example diversity metrics, health and safety statistics and employee counts by category) to the extent such information constitutes Personal Data; utility account-holder or invoice data (including name, address, account or customer identifier, tax identifier and telephone number) to the extent uploaded through an enabled workflow; document content, file names, evidence snippets and structured fields submitted for Processing; and user activity or task information relating to the Processing |
| Sensitive / Special Categories of Data | The Controller shall not upload special categories of data (as defined in GDPR Article 9) unless such Processing is expressly supported by the relevant feature and the Controller has established an appropriate legal basis and complied with Applicable Data Protection Laws. To the extent that ESG data includes diversity, health, or similar metrics, the Controller is responsible for ensuring lawful Processing |
| Processing locations | Switzerland and the European Economic Area (primary Platform storage); the United States and other locations used by OpenAI and its Sub-Processors under the applicable data terms and DPA; the United States for the currently configured LlamaParse endpoint; and any other location identified in the current Sub-Processor list for an enabled external service, subject to Section 8 |
| AI Processing | Relevant document text, invoice content, structured fields or evidence snippets may be processed directly through the OpenAI API for extraction or generation. Complete documents may be processed through LlamaParse for parsing or OCR. Customer-initiated classification or mapping workflows may transmit submitted information to the relevant external service, including a JRC-operated service where enabled. Customer Content is not used to train or improve third-party general-purpose models unless the Controller expressly authorises that use in writing. Provider-side retention is described in the AI Transparency Notice or current Sub-Processor list, as applicable. |
16. Annex 2: Technical and organisational measures
The Processor implements the following technical and organisational measures to protect Personal Data:
| Measure Category | Description |
| Encryption | Data encrypted in transit (TLS 1.2+) and at rest (AES-256). Encryption keys managed via dedicated key management service with automatic rotation |
| Access control | Role-based access control (RBAC); principle of least privilege; multi-factor authentication (MFA) enforced for all staff with access to Personal Data; unique user accounts; access reviewed quarterly |
| Network security | Firewalls, intrusion detection/prevention systems (IDS/IPS), network segmentation, DDoS protection, VPN for remote administrative access |
| Application security | Secure development lifecycle (SDLC); code reviews; static and dynamic application security testing (SAST/DAST); dependency vulnerability scanning; OWASP Top 10 mitigation |
| Data minimisation | Personal Data collected and Processed only to the extent necessary for the Services; anonymisation and pseudonymisation applied where feasible |
| Backup and recovery | Regular automated backups; geographically redundant storage; documented disaster recovery plan with defined RTO and RPO; backup encryption |
| Logging and monitoring | Centralised logging of access and administrative actions; monitoring and alerting for anomalous activity; security and access logs retained for twelve (12) months. AI usage and operational records are retained separately as described in the Privacy Policy and AI Transparency Notice and are subject to the applicable roles and purposes stated there. |
| Incident response | Documented incident response plan; dedicated security team; regular incident response testing; 24-hour breach notification capability |
| Vendor management | Due diligence on all Sub-Processors; contractual data protection obligations; periodic review of Sub-Processor security posture |
| Employee measures | Background checks for staff with access to Personal Data; mandatory data protection and security training (annual); confidentiality obligations in employment contracts |
| Physical security | Data hosted in professionally managed data centres with physical access controls, monitoring and environmental protections; relevant infrastructure-provider certifications reviewed as part of vendor management |
| Certifications | Relevant security documentation, independent assessment reports, penetration-test summaries and certifications maintained by the Processor or its infrastructure providers, where available and appropriate |
| AI-specific measures | Encrypted transmission to authorised AI and document-processing providers; role-based access controls; data minimisation; provenance and operational records where supported; Customer Content not used to train or improve third-party general-purpose models unless the Controller expressly authorises that use in writing; retention governed by the Principal Agreement, Privacy Policy, AI Transparency Notice and this DPA |
17. Annex 3: Sub-processors
The current list of Sub-Processors is available upon request by contacting [email protected].
The Controller may subscribe to receive notifications of changes to the Sub-Processor list by emailing [email protected] with the subject line “Sub-Processor List Request.”
The Processor will notify the Controller at least fourteen (14) days in advance of any intended addition or replacement of a Sub-Processor. The Controller may object within fourteen (14) days of notification in accordance with Section 5.3 of this DPA.
The Sub-Processor list identifies each Sub-Processor by legal name and specifies the relevant service or processing activity, processing location and, where applicable, international data transfer mechanism. The current Sub-Processor list is available upon request in accordance with Section 5.1.
18. Annex 4: Standard contractual clauses
Where Personal Data is transferred outside Switzerland and the EEA to a country not deemed adequate, the Parties agree that the following Standard Contractual Clauses shall apply:
For EU GDPR transfers: The Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) or Module Three (Processor to Processor), as applicable to the relevant transfer, are hereby incorporated by reference. The completed SCCs, including the applicable module and annexes, are available upon request.
For Swiss FADP transfers: The SCCs as recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) are hereby incorporated by reference, with the modifications required to reflect Swiss law (including references to the FADP and the FDPIC as the competent supervisory authority).
For UK GDPR transfers: The International Data Transfer Addendum to the EU SCCs (UK Addendum), issued by the UK Information Commissioner’s Office (ICO), is hereby incorporated by reference.
Swiss-US Data Privacy Framework: For transfers to US-based Sub-Processors that are certified under the Swiss-US Data Privacy Framework (effective 15 September 2024), the DPF serves as the primary transfer mechanism where applicable.
The Parties agree to complete and execute the SCCs and any required addenda upon request by either Party or by a supervisory authority.