Personal data processing schedule—controller and processor—intra-group
Published by a LexisNexis Information Law expert
PrecedentsPersonal data processing schedule—controller and processor—intra-group
Published by a LexisNexis Information Law expert
PrecedentsDefined terms: In addition to the definitions below, this precedent also uses the defined terms ‘Agreement’, ‘Business Day’, ‘Customer’, ‘party’ / ‘parties’, ‘Services’ and ‘Supplier’, which are not specific to data processing and which it is assumed are separately defined in the relevant agreement. See the drafting notes for further guidance.
The Schedule
1
Definitions and interpretation
1.1
In this Schedule:
Adequacy Regulation
- •
means any valid adequacy regulation as referred to in Article 45 of the GDPR;
Attached Standard Contractual Clauses
- •
means the provisions set out in [Annex [insert] to ] Appendix 7;
- •
means the binding corporate rules referred to in Appendix 6;
Controller
- •
has the meaning given in Data Protection Laws;
Data Protection Impact Assessment
- •
shall be construed in accordance with Data Protection Laws;
Data Protection Laws
- •
means all applicable laws relating to the processing, privacy, and/or use of personal data, as applicable to either party or the Services, including:
- (a)
the GDPR;
- (b)
the Data Protection Act 2018;
- (c)
any laws which implement or supplement any such laws; and
- (d)
any laws which replace, extend, re-enact, consolidate or amend any of the foregoing;
- (a)
Data Protection Supervisory
- •
To view the latest version of this document and thousands of others like it,
sign-in with LexisNexis or register for a free trial.