CPRA Amendment to Data Processing Addendum/Agreement
This CCPA Amendment to Data Processing Addendum (“Addendum“), forms part of the Master Subscription Agreement (“Agreement”) between Insider and Customer. This Addendum reflects the parties’ desire and intent to modify and amend the Agreement, in accordance with the terms and conditions hereinafter set forth, with regard to the processing of Customer Personal Information (as defined below) by Insider on behalf of the Customer. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
1. DEFINITIONS
1.1. “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100 et. seq., and its implementing regulations.
1.2. “Customer Personal Information” or “Personal Information” means any Customer Data maintained by Customer and processed by Insider solely on Customer’s behalf, that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, to the extent that such information is protected as “personal information” (or an analogous variation of such term) under applicable U.S. Data Protection Laws.
1.3. “U.S. Data Protection Laws” means all laws and regulations of the United States of America, including the CCPA, applicable to the processing of personal information (or an analogous variation of such term).
1.4. “Service Provider” has the meaning set forth in Section 1798.140(v) of the CCPA.
2. SCOPE AND APPLICABILITY OF THIS ADDENDUM
2.1. This Addendum applies to the collection, retention, use, and disclosure of the Personal Information to provide services of Insider to Customer pursuant to the Agreement or to perform a business purpose.
2.2. Customer is a appoints Insider as a Service Provider to process the Personal Information on behalf of Customer. Customer is responsible for compliance with the requirements of the CCPA applicable to its business.
2.3. Insider’s collection, retention, use, or disclosure of Personal Information for its own purposes independent of providing the Services specified in the Agreement are outside the scope of this Addendum.
3. AMENDMENTS
3.1 Roles. The parties acknowledge and agree that with regard to the processing of Customer Personal Information performed solely on behalf of Customer, Insider is a Service Provider as stated under Article 2.2 and receives Customer Personal Information pursuant to the business purpose of providing the Services to Customer in accordance with the Agreement.
3.2 No Sale of Customer Personal Information to Insider. Customer and Insider hereby acknowledge and agree that in no event shall the transfer of Customer Personal Information from Customer to Insider pursuant to the Agreement constitute a sale of information to Insider, and that nothing in the Agreement shall be construed as providing for the sale of Customer Personal Information to Insider.
3.3 Limitations on Use and Disclosure. Insider is prohibited from using or disclosing Customer Personal Information for any purpose other than the specific purpose of performing the Services specified in the Agreement, the permitted business purposes set under applicable law, and as required under applicable law or as otherwise permitted by the CCPA. Insider hereby certifies that it understands the foregoing restriction and will comply with it in accordance with the requirements of applicable U.S. Data Protection Laws. Thus, Insider shall not further collect, sell, or use the Personal Information except as necessary to perform the business purpose. For the avoidance of doubt, Insider shall not use the Personal Information for the purpose of providing services to another person or entity, except that Insider may combine Personal Information received from one or more entities to which it provides similar services to the extent necessary to detect data security incidents or protect against fraudulent or illegal activity.
3.4 Data Subject Access Requests. Insider will reasonably assist Customer with any data subject access, erasure or opt-out requests and objections. If Insider receives any request from data subjects, authorities, or others relating to its data processing, Insider will without undue delay inform Customer and reasonably assist Customer with developing a response (but Insider will not itself respond other than to confirm receipt of the request, to inform the data subject, authority or other third party that their request has been forwarded to Customer, and/or to refer them to Customer, except per reasonable instructions from Customer). Insider will also reasonably assist Customer with the resolution of any request or inquiries that Customer receives from data protection authorities relating to Insider unless Insider elects to object such requests directly with such authorities.
3.5 Effect of this Addendum. In the event of any conflict or inconsistency between the terms of this Addendum and the terms of the Agreement with respect to the subject matter hereof and solely where U.S. Data Protection Laws apply, the terms of this Addendum shall control.
4. NOTICE
4.1. Customer represents and warrants that it has provided notice that the Personal Information is being used or shared consistent with Cal. Civ. Code 1798.140(t)(2)(C)(i).
5. MERGERS, SALE, OR OTHER ASSET TRANSFER
In the event that either Party transfers to a third party the Personal Information of a Consumer as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of such Party to the Agreement, that information shall be used or shared consistently with applicable law. If a third party materially alters how it uses or shares the Personal Information of a Consumer in a manner that is materially inconsistent with the promises made at the time of collection, it shall provide prior notice of the new or changed practice to the Consumer in accordance with applicable law.
6. AS REQUIRED BY LAW
Notwithstanding any provision to the contrary of the Agreement, the Addendum, Insider may cooperate with law enforcement agencies concerning conduct or activity that it reasonably and in good faith believes may violate international, federal, state, or local law.