Common use of ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES Clause in Contracts

ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES. This Annex forms part of the Clauses and must be completed and signed by the parties and sets forth a description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons. The data importer implements the following measures: • pseudonymization and encryption of personal data • ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services • ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing • user identification and authorization Measures for the protection of data during transmission • protection of data during storage Measures for ensuring physical security of locations at which personal data are processed Measures for ensuring events logging • ensuring system configuration, including default configuration • internal IT and IT security governance and management Measures for certification/assurance of processes and products • ensuring data minimization • ensuring data quality Measures for ensuring limited data retention • ensuring accountability • allowing data portability and ensuring erasure For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter The measures set forth above are required of sub-processors to the extent, and based upon, the nature of the processing carried out by the particular sub-processor.

Appears in 2 contracts

Sources: Terms of Service, Terms of Service

ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES. This Annex Appendix forms part of the Clauses and must be completed and signed by the parties and sets forth a description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons. The data importer implements the following measures: • pseudonymization and encryption of personal data • ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services • ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing • user identification and authorization Measures for the protection of data during transmission • protection of data during storage Measures for ensuring physical security of locations at which personal data are processed Measures for ensuring events logging • ensuring system configuration, including default configuration • internal IT and IT security governance and management Measures for certification/assurance of processes and products • ensuring data minimization • ensuring data quality Measures for ensuring limited data retention • ensuring accountability • allowing data portability and ensuring erasure For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-sub- processor, to the data exporter The measures set forth above are required of sub-processors to the extent, and based upon, the nature of the processing carried out by the particular sub-processor.

Appears in 1 contract

Sources: Service Agreement

ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES. This Annex Appendix forms part of the Clauses and must be completed and signed by the parties and sets forth a description parties. Description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons. The data importer implements the following measures: • Measures of pseudonymization and encryption of personal data Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing Measures for user identification and authorization Measures for the protection of data during transmission Measures for the protection of data during storage Measures for ensuring physical security of locations at which personal data are processed Measures for ensuring events logging Measures for ensuring system configuration, including default configuration Measures for internal IT and IT security governance and management Measures for certification/assurance of processes and products Measures for ensuring data minimization Measures for ensuring data quality Measures for ensuring limited data retention Measures for ensuring accountability Measures for allowing data portability and ensuring erasure erasure] For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-sub- processor, to the data exporter The measures set forth above are required of sub-processors to the extent, and based upon, the nature of the processing carried out by the particular sub-processor.

Appears in 1 contract

Sources: Service Agreement