Obligations of the Processor 3.1 The Processor undertakes to carry out Data Processing exclusively on the basis of documented instructions from the Controller. If the Processor considers an instruction of the Controller to be unlawful, the Processor shall be entitled to suspend the implementation of the relevant instruction until it is confirmed or amended by the Controller. 3.2 The Processor shall be obliged to treat confidentially any personal data of which it becomes aware in connection with the Data Processing. The Processor shall impose a confidentiality obligation on all persons authorized by it to process the data, unless they are already subject to a statutory duty of confidentiality. The obligation of confidentiality and non-disclosure shall continue to apply after termination of this DPA. 3.3 The Processor shall take all necessary technical and organizational measures within the meaning of Art. 32 of the GDPR. These technical and organizational measures are data security measures to ensure a level of protection appropriate to the risk with regard to confidentiality, integrity, availability and the resilience of the systems. They shall take into account the state of the art, the costs of implementation and the nature, scope and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons. The technical and organizational measures taken by the Processor are available at ▇▇▇▇▇://▇▇▇▇.▇▇/en/legal in the current version. 3.4 The Processor shall, where possible, support the Controller with appropriate technical and organizational measures to enable the Controller to comply with the data subject rights under Chapter III of the GDPR within the legal time limits and shall provide the Controller with the necessary information to do so upon the Controller's request, provided that the Processor has such information. If a subject submits a request to the Processor to exercise the data subject rights, the Processor shall be obliged to forward the request to the Controller if the request relates to Data Processing by the Controller. 3.5 The Processor shall support the Controller in the performance of the obligations incumbent upon the Controller pursuant to Art. 32 to 36 of the GDPR, which shall include, but not be limited to, the implementation of security measures, the notification of data protection breaches and, where applicable, the preparation of a data protection impact assessment. 3.6 The Processor shall delete the personal data of the Data Processing after the expiry of the retention periods provided for in the Main Agreement and/or without delay at the request of the Controller. If the Controller expressly requests this, the personal data shall be returned to the Party. Statutory retention periods remain unaffected by this. 3.7 The Processor is obliged to provide the Controller with information at the latter's request in order to demonstrate compliance with the obligations pursuant to Art. 28 of the GDPR. The Processor shall support the Controller in verifying the Data Processing and shall grant the Controller access to the documents and technical systems necessary for verifying the Data Processing in accordance with Section 5 of this DPA. 3.8 To the extent permitted by law, the Processor shall inform the Controller about control actions and measures taken by the supervisory authorities insofar as they relate to the Controller's Data Processing operations.
Servicer’s Obligations The Issuer shall cause the Servicer to comply with Sections 3.10, 3.11, 3.12, 4.10 and Article Eight of the Sale and Servicing Agreement.
Enforcement of Servicer’s and Master Servicer’s Obligations The Master Servicer, on behalf of the Trustee, the Depositor and the Certificateholders shall monitor the performance of the Servicers under the Purchase and Servicing Agreements, and shall use its reasonable good faith efforts to cause the Servicers duly and punctually to perform all of their respective duties and obligations thereunder. Upon the occurrence of a default of which a Responsible Officer of the Master Servicer has actual knowledge under a Purchase and Servicing Agreement, the Master Servicer shall promptly notify the Trustee thereof, and shall specify in such notice the action, if any, the Master Servicer is taking in respect of such default. So long as any such default shall be continuing, the Master Servicer may, and shall if it determines such action to be in the best interests of Certificateholders, (i) terminate all of the rights and powers of such Servicer pursuant to the applicable provisions of the related Purchase and Servicing Agreement; (ii) exercise any rights it may have to enforce the related Purchase and Servicing Agreement against such Servicer; and/or (iii) waive any such default under the related Purchase and Servicing Agreement or take any other action with respect to such default as is permitted thereunder. Notwithstanding anything to the contrary in this Agreement, with respect to any Additional Collateral Mortgage Loan, the Master Servicer will have no duty or obligation to supervise, monitor or oversee the activities of the related Servicer under any Purchase and Servicing Agreement with respect to any Additional Collateral or under any agreement relating to the pledge of, or the perfection of a pledge or security interest in, any Additional Collateral except upon the occurrence of the following events (i) in the case of a final liquidation of any Mortgaged Property secured by Additional Collateral, the Master Servicer shall enforce the obligation of the Servicer under the related Servicing Agreement to liquidate such Additional Collateral as required by such Servicing Agreement, and (ii) if the Master Servicer assumes the obligations of such Servicer as successor Servicer under the related Servicing Agreement pursuant to this Section 9.01, as successor Servicer, it shall be bound to service and administer the Additional Collateral in accordance with the provisions of such Servicing Agreement.
Obligations of Receiving Party Receiving Party shall hold and maintain the Confidential Information in strictest confidence for the sole and exclusive benefit of the Disclosing Party. Receiving Party shall carefully restrict access to Confidential Information to employees, contractors and third parties as is reasonably required and shall require those persons to sign nondisclosure restrictions at least as protective as those in this Agreement. Receiving Party shall not, without the prior written approval of Disclosing Party, use for Receiving Party's benefit, publish, copy, or otherwise disclose to others, or permit the use by others for their benefit or to the detriment of Disclosing Party, any Confidential Information. Receiving Party shall return to Disclosing Party any and all records, notes, and other written, printed, or tangible materials in its possession pertaining to Confidential Information immediately if Disclosing Party requests it in writing.
The Supplier's Obligations The Supplier shall in writing, by the time and date specified by the Contracting Body following an invitation to tender pursuant to paragraph 2.1.3 above provide the Contracting Body with either: