Module 1: Contractual Provisions for Controller-to-Processor Transfers
- Definitions
- “AMS Law”: Any and all written laws of an ASEAN Member State relating to data protection (or are, minimally, relevant to the transfer of Personal Data) which the Data Exporter or the Data Importer (or both) are subject to.
- “Data Breach”: Any loss or unauthorised use, copying, modification, disclosure, or destruction of, or access to, Personal Data transferred under this contract.
- “Data Exporter”: The Party which transfers Personal Data to the Data Importer under this contract.
- “Data Importer”: The Party which receives Personal Data from the Data Importer for Processing under this contract.
- “Data Sub-Processor”: Any person or legal entity which may be engaged by the Data Importer to assist in the Data Exporter’s Processing of Personal Data on behalf of the Data Exporter.
- “Enforcement Authority”: Any public authority empowered by applicable AMS Law to implement and enforce the applicable AMS Law.
- “Personal Data”: Any information relating to an identified or identifiable natural person (“Data Subject”) transferred under this contract.
- “Processing”: Any operation or set of operations that are performed on Personal Data or on sets of Personal Data, whether or not by automated means, including, for example, collection, use and disclosure of Personal Data.
- Obligations of Data Exporter
The Data Exporter warrants, represents and undertakes that:
- The Personal Data has been collected, used, disclosed and transferred to the Data Importer under this contract in accordance with applicable AMS Law. In the absence of such law, where reasonable and practicable, the Data Subject has been notified of and given consent to the purpose(s) of the collection, use, disclosure and/or transfer of his/her Personal Data.
- Any Personal Data that have been transferred under this contract is accurate and complete to the extent necessary for the purposes identified by the Data Exporter in order to comply with Clause 2.1.
- The Data Exporter shall implement adequate technical and operational measures to ensure the security of the Personal Data during transmission to the Data Importer.
- The Data Exporter shall respond to enquiries from Data Subjects or Enforcement Authorities regarding the Processing of Personal Data by the Data Importer as required by applicable AMS Law, including requests to access or correct Personal Data, unless the Parties have agreed in writing that the Data Importer shall so respond, and such delegation is permitted by applicable AMS Law. Responses to such enquiries and requests shall be made within a reasonable time frame or within the time frame and in the manner, if any, required under the applicable AMS Law.
- Obligations of Data Importer
The Data Importer warrants, represents and undertakes that:
- The Data Importer shall process the Personal Data only in compliance with the Data Exporter’s instructions and for the purposes described in Exhibit 1 of the DPA.
- The Data Importer shall not further disclose or transfer the Personal Data it receives from the Data Exporter to another person, Enforcement Authority or legal entity, including to Data Sub-Processors, unless it has notified the Data Exporter of such further disclosure or transfer in writing, and provided reasonable opportunity for the Data Exporter to object.
- The Data Importer agrees that prior to any disclosure or transfer of Personal Data to third parties, including to Data Sub-Processors, the Data Importer shall ensure that the third party shall be subject to and bound by the obligations of the Data Importer to the Data Exporter.
- The Data Importer shall promptly communicate and refer to the Data Exporter any enquiries and requests from Data Subjects relating to the Personal Data transferred by the Data Exporter, including requests to access or correct the Personal Data.
- Upon the termination of this contract or completion of Processing required under this contract, the Data Importer shall, at the election of the Data Exporter, either return to the Data Exporter the Personal Data held in its possession pursuant to this contract, or cease to retain such Personal Data in manner approved of by the Data Exporter. The Data Importer agrees to confirm this with the Data Exporter in writing once action has been taken to cease to retain such Personal Data.
- The Data Importer shall have in place reasonable and appropriate technical, administrative, operational and physical measures, consistent with applicable AMS Laws to protect the confidentiality, integrity and availability of Personal Data, in particular against risks of Data Breaches.
- If the Data Importer becomes aware that a Data Breach has occurred affecting Personal Data in its possession or under its control, or in the possession or under the control of an importer of an onward disclosure or transfer of the Personal Data, it shall notify the Data Exporter without undue delay.
- The Data Importer shall promptly notify and consult with the Data Exporter regarding any investigation regarding the collection, use, transfer, disclosure, security, or disposal of the Personal Data transferred under this contract, unless otherwise prohibited under law.
- The Data Importer shall provide prompt assistance to the Data Exporter upon request for the purposes of clause 2.4; and where the Data Importer has agreed in writing, to respond to enquiries and requests from Data Subjects or Enforcement Authorities regarding its Processing of Personal Data when notified by the Data Exporter.
Commercial Components
- Choice of Law; Disputes:
- This contract shall be interpreted according to the laws of the Republic of Singapore.
- If there is any conflict or inconsistency between clauses in this contract and AMS Law, then the applicable AMS law shall prevail.
- Suspension of Transfer
- In the event that the Data Importer is in breach of its obligations under this contract or applicable AMS Law, then the Data Exporter may temporarily suspend the transfer of Personal Data to the Data Importer until the breach is repaired or the Processing under this contract is terminated.
- Termination of Contract
- In the event that:
- the transfer of Personal Data to the Data Importer has been temporarily suspended by the Data Exporter for longer than 60 days pursuant to Clause 5.1;
- compliance by the Data Importer with this contract would put it in breach of its obligations under the law in the country in which it is Processing the Personal Data;
- the Data Importer is in material breach of any obligations under this contract;
- the Data Importer ceases its operations voluntarily or involuntarily, announces its intent to cease operations, or transfers all or substantially all of its assets to a non-affiliated entity, then the Data Exporter, without prejudice to any other rights which it may have against the Data Importer shall be entitled to terminate this contract. In cases covered by (6.1.1) or (6.1.2), above the Data Importer may also terminate this contract.
- In the event that:
- compliance by the Data Exporter with this contract would put it in breach of its obligations under the law;
- the Data Exporter is in material breach of any obligations under this contract;
- the Data Exporter ceases its operations voluntarily or involuntarily, announces its intent to cease operations, or transfers all or substantially all of its assets to a non-affiliated entity, then the Data Importer, without prejudice to any other rights which it may have against the Data Exporter, shall be entitled to terminate this contract. In cases covered by (6.2.1) above, the Data Exporter may also terminate this contract.
- The Parties agree that the termination of this contract at any time, in any circumstances and for whatever reason does not exempt them from the obligations of this contract regarding the return or deletion of the Personal Data transferred.
- Variation
- The Parties may, by written agreement, adopt or modify this contract where consistent with the principles set forth in the ASEAN Framework on Personal Data Protection, or as required by applicable AMS Law. This does not preclude the Parties from adding or amending clauses, by written agreement, as appropriate for their commercial or business arrangements.
- Description of the Transfer
- The details of the transfer and the Personal Data involved are specified in Exhibit 1 of the DPA.
Additional Terms for Individual Remedies
This section contains the additional provisions and should be read as forming part of the attached contract between the Parties. Words and phrases given a defined meaning in these additional terms have the same meaning in the contract. If there is any inconsistency between these additional terms and the contract, these additional terms shall prevail.
Individual Remedies:
- The Parties acknowledge that the law of the Republic of Singapore confers a right on Data Subjects to enforce the data protection warranties and undertakings of this contract as third-party beneficiaries. The Parties agree that this contract shall uphold such rights of Data Subjects under the law of the Republic of Singapore.
- Data Subjects can enforce against the Data Exporter (Clauses 2.1 and 2.4) as third-party beneficiary.
- Data Subjects can enforce against the Data Importer (Clause 3.4).
- Data Subjects can enforce against Sub-Processors (Clauses 2.1, 2.4 and 3.4) when both the Data Exporter and Data Importer have ceased operations, ceased to exist in law, or transferred all or substantially all of their assets to a non-associated entity such that the non-associated entity has assumed the legal obligations of the Data Exporter by contract or operation of law.
- To the extent authorized by applicable AMS Law, Data Subjects may obtain compensation for breaches of this contract by either the Data Importer and/or Data Exporter (as prescribed by applicable AMS Law or, if such law is silent on the allocation of compensation, then from both the Data Importer and Data Exporter in equal shares).
- The Parties do not object to a Data Subject being represented by another body if the Data Subject expressly wishes so and such representation is permitted by applicable law.