SONIC ODEEO DEMAND PARTNER DATA SHARING ADDENDUM
This Sonic Odeeo Demand Partner Data Sharing Addendum (“DSA”) is entered into, as of the effective date of the Agreement (defined below), by and between the Sonic Odeeo entity set forth in the Agreement (“Odeeo”), and the Demand Partner defined in the Agreement (each, a “Party” and together, the “Parties”), to reflect the Parties’ agreement with regard to the Processing of Shared Personal Data by the Parties. The Parties hereby agree that the terms and conditions set out below shall be added as an addendum to the main agreement established between the Parties (“Agreement”) and shall constitute an integral part thereof.
This DSA reflects the Parties’ agreement on the Processing of Shared Personal Data in connection with the Parties’ obligations under the Agreement in accordance with the Data Protection Laws. Any reference to a legal framework, statute or other legislative enactment is a reference to it as amended or re-enacted from time to time. Odeeo’s privacy policy is available here.
1. Definitions
1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control”, for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
1.2 The terms, “Business”, “Controller”, “Data Subject”, “Member State”, “Processing”, “Supervisory Authority”, “Personal Data”, “Personal Data Breach”, “Service Provider” and “Third Party” shall have the meaning ascribed to them under the relevant Data Protection Laws.
1.3 “Data Protection Laws” means the General Data Protection Regulation (“GDPR”), the e-Privacy Directive, the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419) (“UK GDPR”), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (“CCPA”), the other comprehensive consumer privacy laws of the states of the United States, the Children’s Online Privacy Protection Act and the rules promulgated thereunder (“COPPA”), the Israeli Protection of Privacy Law, 5741-1981 and the regulations promulgated thereunder, the Swiss Federal Act on Data Protection, and the Rules and Self-Regulatory Principles of the European Interactive Digital Advertising Alliance, and any other data protection, privacy or electronic communications laws, as applicable to the Parties in relation to the Shared Personal Data hereunder and in effect at the time of the Parties’ performance hereunder.
1.4 “End-User(s)” means the individuals that interact or engage with the Properties (as defined in the Agreement) on which Ads provided by the Demand Partner are displayed, played or otherwise served, across all Supply Channels and Media Formats (each as defined in the Agreement).
1.5 “Onward Transfer” means the onward transfer of Shared Personal Data received by either of the Parties (in this case acting as a Data Importer) from the other Party (in this case acting as the Data Exporter) to a third entity.
1.6 “Privacy Signals” means, End-Users’ preference regarding the processing of Shared Personal Data, including, without limitations, “do not share or sell my personal information” under the CCPA, the Google restricted data processing “rdp”, Digital Advertising Alliance, Network Advertising Initiative, and the IAB Global Privacy Platform (“GPP”) or IAB Transparency & Consent Framework (“TCF”) signals, Global Privacy Control (“GPC”) string, or any current, future standard signal initiated by an approved consent management platform (“CMP”) which indicated the End-User’s preference with respect to Processing of the Shared Personal Data and providing personalized, interest-based advertisement.
1.7 “Shared Personal Data” means the Personal Data Processed by one Party to the extent that such Party received the Personal Data from the other Party in connection with the performance of the Agreement, and as further detailed in Schedule 1 attached hereto. For the avoidance of doubt, a Party is also deemed to “receive” Personal Data from the sharing Party when the sharing Party grants access to such Personal Data to the receiving Party.
1.8 “SCC” shall mean (a) where the GDPR applies, the standard contractual clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCC”), or (b) where the UK GDPR applies, the International Data Transfer Addendum to the EU SCC as issued by the Information Commissioner’s Office (“UK SCC”), each as incorporated by reference under Schedule 2 attached hereto.
1.9 "Processor" means any processor (as defined under the Data Protection Laws) engaged by the Party for carrying out specific processing activities with respect to the Shared Personal Data.
1.10 “Permitted Purposes” means, solely to the extent permitted by the applicable Privacy Signals and Data Protection Laws: (a) evaluating and bidding on Inventory in real time, including by reference to audience segments that Demand Partner lawfully held prior to, and independently of, its receipt of the Shared Personal Data; and (b) with respect to impressions won by Demand Partner only, serving Ads, frequency capping, measurement, attribution, reporting, fraud and Invalid Traffic detection and prevention, and billing.
1.11 “Child Data” means Shared Personal Data relating to an End-User (i) of a Property that is directed to children; (ii) in respect of which the bid request or other Privacy Signal indicates that the End-User is a child or a minor, or that the Property is child-directed (including the OpenRTB “coppa” flag or any equivalent signal); or (iii) whom Demand Partner knows to be under the age at which consent, or parental consent, is required for the relevant Processing under applicable Data Protection Laws.
2. Roles and Processing of Shared Personal Data
2.1 The Parties acknowledge that their respective roles under the Data Protection Laws are determined by the factual arrangement between them.
2.2 The Parties acknowledge and agree that regarding the Shared Personal Data, each Party is a separate and independent Data Controller, and each Party will individually determine the purposes and means of its Processing of Shared Personal Data.
2.3 The Parties acknowledge and agree that they do not jointly determine the purposes and means of processing and will not process the Shared Personal Data as joint controllers (as defined in the GDPR, UK GDPR, or other Data Protection Law, as applicable). To the extent that the Shared Personal Data is subject to the CCPA, each Party shall be considered a Business and/or a Third-Party under the CCPA, as applicable, when Processing the Shared Personal Data. For the avoidance of doubt, neither Party is a Processor/Service Provider of the other.
2.4 Each of the Parties acknowledges and agrees that Schedule 1 is an accurate description of the Shared Personal Data.
2.5 The Parties acknowledge that Shared Personal Data provided to the Party will only be used for the Permitted Purposes.
2.6 Each Party will comply with the obligations applicable to it under the Data Protection Laws with respect to the Processing of Shared Personal Data, including following the Privacy Signals concerning the Shared Personal Data (if any available). As required under Data Protection Laws, Demand Partner shall disclose its Processing activities with respect to its Processing of the Shared Personal Data in its privacy notice. Demand Partner hereby acknowledges that Odeeo does not operate as a publisher and does not have a direct relationship with the relevant Data Subjects hereunder. Instead, Odeeo operates as an intermediary party, on behalf of its publisher partners and/or supply-side partners.
2.7 The Demand Partner shall refrain from disclosing or sharing any Shared Personal Data with third parties, except as expressly permitted under the Agreement and/or this DSA. Furthermore, the Demand Partner shall promptly erase or destroy all Shared Personal Data under its control in the event of the first of the following occurrences: (i) immediately upon the Demand Partner's failure to secure the winning bid for an impression associated with said Shared Personal Data; (ii) with respect to Shared Personal Data relating to impressions won by Demand Partner, once such Shared Personal Data is no longer strictly necessary for the Permitted Purposes, in accordance with the retention periods disclosed by Demand Partner in its privacy notice and, where applicable, in its IAB TCF vendor registration, and in any event no later than thirteen (13) months after the applicable impression; or (iii) upon Odeeo’s (and/or the relevant publisher/SSP’s) request. In addition, the Demand Partner shall not retain, utilize, disclose, or otherwise Process any Shared Personal Data for the purposes of profiling, tracking, or creating profiles of any End-User, Data Subject, Property, or publishers, either directly or by permitting any third party to engage in such Processing.
2.8 The Demand Partner shall use Shared Personal Data solely for the Permitted Purposes or as required by law. It shall not share or disclose the Shared Personal Data (other than to the recipients permitted under Schedule 1), use it to build, append to or enrich any user profile or audience segment, or use it for re-targeting purposes, nor resell, license, or distribute the Shared Personal Data. The Demand Partner must adhere to all publisher and Odeeo’s instructions, including opt-out requests and do not sell requests. Shared Personal Data shall not be linked to any information that directly identifies an End-User (such as name, email address or telephone number), or used to create or update user profiles.
2.9 To the extent that the CCPA or any other US state privacy law is applicable, the following shall apply: (i) without limitation to any other restriction outlined in the Agreement and/or this DSA, the disclosure of Shared Personal Data to Demand Partner is solely for the Permitted Purposes, and Demand Partner shall Process the Shared Personal Data solely for such purposes; (ii) Demand Partner shall adhere to the CCPA, ensuring the provision of privacy protection equivalent to that mandated for Businesses under the CCPA; (iii) Demand Partner shall promptly notify Odeeo upon determining that it is unable to fulfill its obligations under the CCPA; and (iv) Odeeo may, upon notification, undertake reasonable and appropriate measures to cease and rectify any unauthorized processing of Shared Personal Data. References to the CCPA in this Section shall be read to include any other applicable US state privacy law and its equivalent concepts.
2.10 Child Data. Demand Partner shall honour the OpenRTB “coppa” flag and any equivalent child-directed or age signal passed by Odeeo, and shall Process Child Data solely for contextual advertising and for the activities permitted under COPPA’s “support for the internal operations” exception (and equivalent provisions of other Data Protection Laws). Demand Partner shall not use Child Data for personalized or interest-based advertising, profiling, re-targeting or audience segmentation, and shall not retain Child Data for longer than is strictly necessary for such permitted activities.
2.11 Data Collected Through Ads. To the extent that Demand Partner, its Advertisers or their vendors collect Personal Data directly from End-Users or their devices through Ads, tags, pixels, trackers or similar technologies served through the Inventory (“Directly Collected Data”): (i) Demand Partner (or the applicable Advertiser) shall be the sole Controller or Business of such Directly Collected Data, and Odeeo shall have no responsibility for it; and (ii) Demand Partner shall ensure that such collection, and any storage of or access to information on End-Users’ devices, complies with Data Protection Laws (including the e-Privacy Directive) and the applicable Privacy Signals, including, where applicable, the vendor consent and purpose signals under the IAB TCF.
3. Data Subject Rights and Supervisory Authorities
3.1 It is agreed that where either Party receives a request from a Data Subject with respect to the Shared Personal Data controlled by such Party, then such receiving Party shall be responsible to exercise the request, in accordance with Data Protection Laws. Upon each Party’s reasonable request, the other Party will provide reasonable assistance with respect to the exercising of Data Subjects requests relating to the Shared Personal Data, in order to allow the requesting Party to comply with its obligations under applicable Data Protection Laws.
3.2 If either Party is the subject of a claim by a Data Subject or a supervisory authority or receives a notice or complaint from a supervisory authority concerning the respective Processing activities of both Parties (a “DP Claim”), it shall promptly inform, to the extent permitted by law, the other Party of the DP Claim and provide the other Party with such information as it may reasonably request regarding the DP Claim. The Parties shall use all reasonable endeavors to cooperate with the aim to disputing or settling the DP Claim in a timely manner; provided always that neither Party shall make any admission or offer of settlement or compromise without using all reasonable endeavors to consult with the other Party in advance. Notwithstanding anything to the contrary in the Agreement, where a DP Claim is brought against Odeeo, Odeeo shall have sole control of the defense and settlement of such DP Claim, without derogating from Demand Partner’s indemnification obligations under Section 11.
4. Processors. Each Party shall enter into a contract with the Processor as requested under Data Protection Laws. Where the Processor fails to fulfil its data protection obligations, the respective Party will remain liable for its own Processor’s acts and omissions.
5. Compliance with Law and Information Requests
5.1 Each Party must: (i) comply with its obligations under applicable Data Protection Laws and self-regulatory principles (including IAB protocol); (ii) provide all information regarding its compliance with Data Protection Laws and its data collection, protection, use, disclosure policies and practices reasonably requested by the other Party; and (iii) promptly notify the other Party if it determines that it cannot meet its obligations under this Agreement or Data Protection Laws (including Privacy Signals).
5.2 Demand Partner shall ensure that it complies with any and all applicable Data Protection Laws with respect to the Processing of the Shared Personal Data, including regarding collection, use, or disclosure of Shared Personal Data and honor, in compliance with Data Protection Laws, applicable self-regulatory frameworks, and all Privacy Signals.
6. Security. Each Party shall comply with its applicable security requirements under Data Protection Laws for Processing Shared Personal Data. Demand Partner shall implement technical and organizational security measures to prevent (i) the accidental, unlawful, or unauthorized destruction, loss, alteration, or disclosure of, or access to, Shared Personal Data or (ii) any other security incident that amounts to a “personal data breach” (as such term or similar term is defined under Data Protection Laws) of Shared Personal Data.
7. Personal Data Breach. Each Party shall comply with its obligation to report a Personal Data Breach to the appropriate Supervisory Authority and (where applicable) Data Subjects and, where applicable, and the Demand Partner shall inform Odeeo without undue delay of any Personal Data Breach.
The Parties agree to provide reasonable mutual assistance and collaboration as is necessary to each other to facilitate the handling of any Personal Data Breach in a compliant manner.
8. Confidentiality and Training. The Demand Partner shall ensure that the Shared Personal Data is kept confidential, and its personnel engaged in the Processing of Shared Personal Data have committed themselves to confidentiality obligations and have undergone appropriate privacy and security training. Demand Partner shall ensure that all its employees, staff and consultants involved in the Processing of the Shared Personal Data adhere strictly to the provisions delineated in this DSA and/or the Agreement.
9. Cross Border Transfers
9.1 Applicable Data Protection Laws in certain jurisdictions may require additional/different safeguards or transfer mechanisms to facilitate cross-border transfers. In such a case, the Parties agree to respect and implement such additional safeguards or adopt such transfer mechanisms, as appropriate and necessary.
9.2 Either Party may transfer Shared Personal Data from the EEA or UK, to a destination outside of these, provided that it complies with applicable provisions regarding the transfer of Shared Personal Data to countries outside of the EEA, or UK under Data Protection Laws (such as where the transfer of Personal Data is to a jurisdiction that is the subject of an adequacy decision under the GDPR or the UK GDPR (as applicable) or through the use of SCC, as incorporated by reference in Schedule 2, or other applicable frameworks). Where and to the extent that the SCC apply pursuant to this Section 9, Demand Partner will be referred to as the “Data Importer” and Odeeo will be referred to as the “Data Exporter.” If there is any conflict between this DSA and the SCC, the SCC shall prevail. Transfers of Shared Personal Data from Israel shall comply with the Israeli Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001.
9.3 In the event of any Onward Transfer by the Data Importer, it shall procure that the person or entity to which the Shared Personal Data is disclosed or otherwise made available upon the Onward Transfer, provides sufficient guarantees to protect the Shared Personal Data and observes no less onerous obligations as those imposed on the Data Importer under the original relevant transfer.
10. Termination. The Parties agree that this DSA and, if applicable, the SCC shall terminate automatically upon (i) termination or expiration of the Agreement; or (ii) as agreed upon between the Parties, whichever is earlier. Sections 2.5 to 2.11, 3, 6, 7, 8, 9.3 and 11 and Odeeo's remedies under law or equity in connection with Demand Partner’s breach of this DSA and/or violation of Data Protection Laws shall survive the termination of the Agreement, and/or this DSA for any reason, for as long as Demand Partner or its Processors retain any Shared Personal Data.
11. General. Each Party may request in writing variations to this DSA if they are required as a result of any change in, or decision of a competent authority under Data Protection Laws, to allow Processing of Shared Personal Data to be made (or continue to be made) in accordance with the Agreement and/or this DSA without breach of those Data Protection Laws. The Parties shall make commercially reasonable efforts to accommodate such modifications requested by a Party. In addition, Odeeo may update this DSA from time to time by posting an updated version at the URL referenced in the Agreement (or any successor URL), and the updated version shall apply from the date of posting. To the maximum extent permitted by law, this DSA shall be governed by the laws governing the Agreement, except for those provisions of clauses which dictate the application of another law for particular purposes. Capitalized terms not defined herein shall have the meaning ascribed to them in the Agreement. In the event of any conflict between certain provisions of this DSA and the provisions of the Agreement, the provisions of this DSA shall prevail over the conflicting provisions of the Agreement solely with respect to the Processing of Shared Personal Data. In the event of a conflict between this DSA and the SCC (as defined above), the SCC will prevail solely with regards to international transfers of Shared Personal Data, where the SCC are applicable. This DSA shall be assigned only together with, and to the same assignee as, the Agreement, in accordance with the assignment provisions of the Agreement. Notwithstanding anything to the contrary in the Agreement or any agreement between the Parties, the Demand Partner shall indemnify, defend and hold harmless Odeeo against all losses, fines, penalties, costs and expenses and sanctions arising from any claim of any kind by a Data Subject, third party or Supervisory Authority related to the Shared Personal Data, or arising from, or related to, any breach of this DSA and/or violation of Data Protection Laws and/or a personal data breach occurring in the Demand Partner’s (and its Affiliates’) and/or their vendors and service provider’s systems. Notwithstanding anything to the contrary in the Agreement or any agreement between the Parties, the Demand Partner’s liability related to the Shared Personal Data, or for any breach of, or related to, this DSA, violation of Data Protection Laws and/or a personal data breach occurring in the Demand Partner’s (and its Affiliates’) and/or their vendors and service provider’s systems shall be unlimited.
SCHEDULE 1 - DETAILS OF THE SHARED PERSONAL DATA
Purpose of Data Sharing
The Parties share Shared Personal Data solely for the Permitted Purposes (as defined in Section 1 of this DSA), namely: real-time evaluation of and bidding on Inventory (including personalized advertising where permitted by the applicable Privacy Signals, or contextual advertising) and, for impressions won by Demand Partner, ad serving, frequency capping, measurement, attribution, reporting, fraud and Invalid Traffic detection and prevention, and billing.
Nature of the Processing
Collection, storage, organization, analysis, modification, retrieval, disclosure, communication and other uses for the Permitted Purposes.
Duration of the Processing
Continuous and as necessary for the Permitted Purposes, subject to Section 2.7.
Categories of Data Subjects
End-Users of the Properties (including mobile applications, websites, digital audio streaming services and podcasts), which may include children or minors where a Property is child-directed or mixed-audience (see Section 2.10).
Sensitive Shared Personal Data
None, other than Child Data (if any), which is subject to Section 2.10. Odeeo does not share precise geolocation data.
Type of Shared Personal Data
In each case only where available, and where the applicable consent has been obtained or is not required under Data Protection Laws: (a) web inventory: IP address, cookie IDs, extended IDs (such as third-party identity solutions) and user IDs assigned by the publisher; (b) in-app inventory: IP address, mobile advertising IDs (such as IDFA and GAID), extended IDs and user IDs assigned by the publisher (where passed through non-SDK integrations); and (c) for all Supply Channels: approximate (non-precise) geolocation, user-agent, device details (such as device type, make, model and operating system) and privacy signal strings (such as TCF, GPP and US Privacy strings). Inventory in digital audio streaming and podcast environments is treated as web or in-app inventory, according to the platform through which it is delivered.
Frequency of Transfer and Retention
Continuous, in real time, with each bid request. Demand Partner will not retain the Shared Personal Data for longer than as permitted under this DSA as strictly necessary for the Permitted Purposes and in accordance with Section 2.7.
For transfers to (sub-)processors, also specify subject matter, nature and duration of the Processing
The Shared Personal Data transferred may be disclosed solely to the following recipients: Demand Partner’s Processors that are strictly necessary for the Permitted Purposes, and the Advertisers on whose behalf Demand Partner bids, in each case solely for the Permitted Purposes and subject to written obligations no less protective of the Shared Personal Data than those set out in this DSA. The duration of Processing will align with the data retention period described above.
SCHEDULE 2 – CROSS BORDER TRANSFERS
PART 1 – EEA Cross Border Data Transfers
1. The Parties agree that to the extent the EU SCC apply, they are hereby incorporated by reference as follows:
2. Module One (Controller to Controller) of the EU SCC shall apply where the applicable transfer is effectuated between the Parties, each as an independent and separate data controller of the Shared Personal Data.
3. Clause 7 of the EU SCC (Docking Clause) shall not apply.
4. In Clause 11 of the EU SCC, the optional language will not apply.
5. With respect to Clause 17 of the EU SCC, the Parties agree that the SCC shall be governed by the laws of the Republic of Ireland.
6. In Clause 18(b) of the EU SCC, disputes will be resolved before the courts of the Republic of Ireland.
7. Annex I.A of the EU SCC shall be completed as follows:
Data Exporter: Odeeo
Contact details: As detailed in the Agreement.
Data Exporter Role: The Data Exporter is an independent and separate data controller.
Signature and Date: By entering into the Agreement and DSA, Data Exporter is deemed to have signed these Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Agreement.
Data Importer: Demand Partner
Contact details: As detailed in the Agreement.
Data Importer Role: The Data Importer is an independent and separate data controller.
Signature and Date: By entering into the Agreement and DSA, Data Importer is deemed to have signed these Standard Contractual Clauses, incorporated herein, including their Annexes, as of the Effective Date of the Agreement.
8. Annex I.B of the EU SCC shall be completed as follows:
The categories of data subjects, personal data, frequency of the transfer, nature of the processing and purpose of the processing and duration are described in Schedule 1 (Details of Processing) of this DSA.
9. Annex II of the EU SCC: The technical security measures are detailed under “Part 3” below.
PART 2 – UK Cross Border Data Transfers
The Parties have agreed that to the extent the UK SCC apply, they are hereby incorporated by reference as follows:
The UK SCC is hereby incorporated by reference:
Table 1: The Parties: as detailed in the Agreement.
Table 2: Selected SCCs, Modules and Selected Clauses: as detailed in Part 1.
Table 3: Appendix Information: as set out in the Annexes to Part 1.
Table 4: Clause 19 of the UK Mandatory Clauses: Odeeo shall be permitted.
PART 3 – Additional Safeguards
Security Measures: Demand Partner shall implement and maintain current and appropriate technical and organizational measures to protect the Shared Personal Data against accidental, unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, disclosure or access, as set forth below:
1. Demand Partner shall provide third-party attestation of static or dynamic application security testing or penetration testing on all software or systems Processing Shared Personal Data, remediate any identified high vulnerabilities, provide written remediation plans for medium and low vulnerabilities.
2. Demand Partner shall maintain a level of security appropriate to the harm that may result from any unauthorized or unlawful Processing or accidental loss, destruction, damage, denial of service, alteration or disclosure, of Shared Personal Data as appropriate to the nature of the Shared Personal Data Processed.
3. Demand Partner shall oblige its employees, agents or other personnel to whom it provides access to the Shared Personal Data to keep it confidential; take reasonable steps to ensure the integrity of any employees who have access to Shared Personal Data; provide annual training to staff in order to meet the security requirements contained herein.
4. Demand Partner shall maintain measures designed to ensure the ongoing confidentiality, integrity, availability and resilience of its systems and services.
5. Demand Partner shall adhere to password policies for standard and privileged accounts consistent with industry best practices.
6. Demand Partner shall ensure that only those personnel who need to have access to Shared Personal Data are granted access, such access is limited to the least amount required, and only granted for the purposes of performing the services and the obligations under this DSA.
7. Demand Partner shall maintain a physical security program that is consistent with industry best practices.
8. Demand Partner shall use Backups as part of its data management practices to ensure the security and protection of Shared Personal Data. Any identified vulnerabilities in the Demand Partner's workstations must be addressed promptly.
9. Demand Partner shall ensure that any storage media (whether magnetic, optical, non-volatile solid state, paper, or otherwise capable of retaining information) that captures Shared Personal Data, if applicable, is securely erased or destroyed before repurposing or disposal.
10. Demand Partner shall implement measures to ensure that Shared Personal Data can be restored on time in the event of a physical or technical incident.
11. Demand Partner shall maintain system monitoring and alerting tools (e.g., SIEM) to detect suspicious activities, intrusion attempts, or any security incidents involving systems processing Shared Personal Data.
12. Demand Partner shall conduct periodic vulnerability scans and ensure timely updates of systems and software to mitigate known security vulnerabilities.
13. Demand Partner shall maintain a well-defined and organized incident response plan for handling cybersecurity incidents, including steps for identification, containment, investigation, and reporting in the event of a data breach.
14. Demand Partner shall ensure that all Shared Personal Data stored or transmitted (in transit and at rest) is protected using strong encryption methods consistent with industry standards (e.g., AES-256).
15. Demand Partner shall enforce the use of multi-factor authentication for access to critical systems or databases containing Shared Personal Data.
16. Demand Partner shall engage an independent third party to conduct security audits at least annually and implement any recommendations provided as part of the audit.
17. Demand Partner shall ensure that any third-party processors of Shared Personal Data comply with the same security measures outlined in this agreement and shall execute appropriate agreements with them to enforce these requirements.
18. Demand Partner shall maintain advanced mechanisms to prevent disruptions to services caused by Distributed Denial of Service (DDoS) attacks.
19. Demand Partner shall implement robust identity and access management solutions to ensure controlled and restricted access to Shared Personal Data.
20. Demand Partner shall promptly notify Odeeo of any security incidents affecting Shared Personal Data, including a detailed incident report and the mitigation actions taken.
SCHEDULE 3 – DATA PROCESSING RESPONSIBILITIES
|
Activity |
Responsibilities under this Agreement |
|---|---|
|
Purposes for which personal data may be collected (Article 5(1)(b)) |
The Permitted Purposes. |
|
Data minimisation (Article 5(1)(c)) |
Each Party is responsible for ensuring the Shared Personal Data it collects and holds are no more than necessary for the purposes stipulated in the Agreement and/or this DSA. |
|
Data accuracy (Article 5(1)(d)) |
Each Party is responsible for ensuring that the Shared Personal Data it collects and holds are accurate and kept up to date. |
|
Data storage limitation (Article 5(1)(e)) |
Each Party is responsible for ensuring that the Shared Personal Data it collects and holds are stored no longer than needed to fulfil the purposes stipulated in the Agreement and/or this DSA. |
|
Integrity and confidentiality (Article 5(1)(f)) |
Each Party is responsible for ensuring that the Shared Personal Data it collects and holds are properly secured in accordance with Article 32 of the GDPR and other Data Protection Laws. |
|
Accountability (Article 5(2)) |
Each Party is responsible for compliance with the Data Protection Laws. |
|
Information notices (Articles 13 and 14) |
Each Party is responsible for providing Data Subjects with information about its own Processing of Shared Personal Data in its privacy notice. As Odeeo has no direct relationship with Data Subjects, notice at the point of collection is provided by the publishers through their consent management platforms. |
|
Data subject rights (Articles 15 to 22) |
Each Party is responsible for responding and complying to requests from Data Subjects to exercise their rights in respect of the processing it undertakes. Also each Party shall assist the other Party to comply with the Data Subject requests, as described in the DSA. |
|
Data protection by design and default (Article 25) |
Each Party is responsible for compliance with the requirements on data protection by design and by default. |
|
Engagement of processor (Article 28) |
Each Party shall engage the processor independently. |
|
Records of processing activities (Article 30) |
Each Party shall keep separate records of processing activities (RoPAs). |
|
Cooperation with supervisory authority (Article 31) |
In case of need, each Party shall cooperate with the responsible Supervisory Authority. |
|
Security of processing (Article 32) |
Each Party is responsible for the security of the Shared Personal Data. |
|
Notification of data breach (Articles 33 and 34) |
In case of a Data Breach, each Party shall inform the other Party as defined in this DSA. |
|
Impact assessments (Articles 35 and 36) |
In case of need, each Party shall conduct a data protection impact assessment (DPIA). |