Section 1
1. Purpose and Scope
1.1 These Data Processing Clauses (hereinafter referred to as the “Clauses”) are intended to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data, on the free movement of such data, and repealing Directive 95/46/EC.
1.2 The data controllers and data processors listed in Annex I have agreed to these Clauses to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679.
1.3 These clauses apply to the processing of personal data as set forth in Annex II.
1.4 Annexes I through IV form an integral part of these clauses.
1.5 These clauses apply without prejudice to the obligations to which the controller is subject under Regulation (EU) 2016/679.
1.6 These clauses do not, on their own, ensure that the obligations relating to international data transfers under Chapter V of Regulation (EU) 2016/679 are fulfilled.
2. Immutability of the Clauses
2.1 The parties agree not to amend the clauses, except to supplement or update the information set forth in the annexes.
2.2 This does not prevent the parties from incorporating the standard contractual clauses set forth in these clauses into a broader contract and from adding further clauses or additional safeguards, provided that these do not directly or indirectly conflict with the clauses or infringe upon the fundamental rights or freedoms of the data subjects.
3. Interpretation
3.1 Where terms defined in Regulation (EU) 2016/679 are used in these clauses, such terms shall have the same meaning as in that Regulation.
3.2 These clauses shall be interpreted in light of the provisions of Regulation (EU) 2016/679.
3.3 These clauses must not be interpreted in a manner that conflicts with the rights and obligations set forth in Regulation (EU) 2016/679 or that infringes upon the fundamental rights or freedoms of the data subjects.
4. Precedence
4.1 In the event of a conflict between these clauses and the provisions of related agreements that exist between the parties or are entered into or concluded at a later date, these clauses shall prevail.
5. Optional: Accession Clause
5.1 An entity that is not a party to these clauses may, at any time, with the consent of all parties, accede to these clauses as a controller or a processor by completing the annexes and signing Annex I.
5.2 Upon completing and signing the annexes referred to in subparagraph (a), the acceding entity shall be treated as a party to these clauses and shall have the rights and obligations of a controller or a processor as specified in Annex I.
5.3 No rights or obligations arising from these clauses shall apply to the acceding entity for the period prior to its accession as a party.
Section 2
6. Description of the Processing
6.1 The details of the processing operations, in particular the categories of personal data and the purposes for which the personal data are processed on behalf of the controller, are set forth in Annex II.
7. Obligations of the Parties
7.1 Instructions
- (a) The processor shall process personal data only on documented instructions from the controller, unless the processor is required to do so by Union law or by the law of a Member State to which the processor is subject. In such a case, the processor shall inform the controller of those legal requirements prior to processing, unless the law in question prohibits this on grounds of an important public interest. The controller may issue further instructions throughout the entire duration of the processing of personal data. These instructions must always be documented.
- (b) The processor shall inform the controller without delay if it considers that instructions issued by the controller infringe Regulation (EU) 2016/679 or applicable data protection provisions of the Union or the Member States.
7.2 Purpose Limitation
- (a) The processor shall process the personal data only for the specific purpose(s) set forth in Annex II, unless it receives further instructions from the controller.
7.3 Duration of the Processing of Personal Data
- (a) The data shall be processed by the processor only for the duration specified in Annex II.
7.4 Security of Processing
- (a) The processor shall implement at least the technical and organizational measures listed in Annex III to ensure the security of the personal data. This includes protecting the data against a security breach that, whether accidental or unlawful, results in the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, the data (hereinafter “personal data breach”). In assessing the appropriate level of protection, the parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context, and purposes of the processing, as well as the risks to the data subjects.
- (b) The Data Processor shall grant its personnel access to the personal data being processed only to the extent strictly necessary for the performance, management, and monitoring of the contract. The Data Processor shall ensure that persons authorized to process the personal data received have committed to confidentiality or are subject to an appropriate statutory duty of confidentiality.
7.5 Sensitive Data
- (a) If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, or genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning a person’s health, sex life, or sexual orientation, or data concerning criminal convictions and offenses (hereinafter “sensitive data”), the processor shall apply specific restrictions and/or additional safeguards.
7.6 Documentation and Compliance with the Clauses
- (a) The parties must be able to demonstrate compliance with these clauses.
- (b) The processor shall respond promptly and appropriately to requests from the controller regarding the processing of data in accordance with these clauses.
- (c) The processor shall provide the controller with all information necessary to demonstrate compliance with the obligations set forth in these clauses and arising directly from Regulation (EU) 2016/679. At the request of the controller, the processor shall also permit an audit of the processing activities covered by these clauses at reasonable intervals or where there are indications of non-compliance, and shall cooperate with such an audit. When deciding whether to conduct an audit or inspection, the controller may take into account relevant certifications held by the processor.
- (d) The controller may conduct the audit itself or appoint an independent auditor. The audits may also include inspections at the processor’s premises or physical facilities and shall be conducted, where appropriate, with reasonable advance notice.
- (e) The parties shall make the information referred to in this clause, including the results of audits, available to the competent supervisory authority or authorities upon request.
7.7 Use of Subprocessors
- (a) The processor may not subcontract any of its processing operations carried out on behalf of the controller pursuant to these clauses to a subprocessor without the controller’s prior separate written authorization. The processor shall submit the request for such separate authorization at least one week prior to engaging the subprocessor in question, together with the information the controller requires to decide on the authorization. The list of subprocessors authorized by the controller is set forth in Annex IV. The parties shall keep Annex IV up to date.
- (b) If the processor engages a subprocessor to carry out specific processing activities (on behalf of the controller), such engagement must be governed by a contract that imposes on the subprocessor essentially the same data protection obligations as those applicable to the processor under these clauses. The processor shall ensure that the subprocessor fulfills the obligations to which the processor is subject under these clauses and in accordance with Regulation (EU) 2016/679.
- (c) The processor shall provide the controller, upon request, with a copy of such a subcontracting agreement and any subsequent amendments. To the extent necessary to protect trade secrets or other confidential information, including personal data, the processor may redact the text of the agreement before providing a copy.
- (d) The processor shall be fully liable to the controller for ensuring that the subprocessor fulfills its obligations under the contract concluded with the processor. The processor shall notify the controller if the subprocessor fails to fulfill its contractual obligations.
- (e) The processor shall agree with the subprocessor on a third-party beneficiary clause, pursuant to which the controller—in the event that the processor ceases to exist de facto or de jure or becomes insolvent—has the right to terminate the subcontract and instruct the subprocessor to delete or return the personal data.
7.8 International Data Transfers
- (a) Any transfer of data by the data processor to a third country or an international organization shall take place exclusively on the basis of documented instructions from the data controller or to comply with a specific provision under Union law or the law of a Member State to which the data processor is subject, and must be in accordance with Chapter V of Regulation (EU) 2016/679.
- (b) The controller agrees that, in cases where the processor engages a subprocessor pursuant to Clause 7.7 to carry out certain processing activities (on behalf of the controller) and such processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the processor and the subprocessor may ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission pursuant to Article 46(2) of Regulation (EU) 2016/679, provided that the conditions for the application of these standard contractual clauses are met.
8. Assistance to the Controller
8.1 The processor shall promptly inform the controller of any request it has received from the data subject. It shall not respond to the request itself unless authorized to do so by the controller.
8.2 Taking into account the nature of the processing, the processor shall assist the controller in fulfilling its obligation to respond to requests from data subjects to exercise their rights. In fulfilling its obligations under subparagraphs (a) and (b), the processor shall follow the controller’s instructions.
8.3 In addition to the processor’s obligation to assist the controller pursuant to Clause 8(b), the processor shall, taking into account the nature of the data processing and the information available to it, also assist the controller in complying with the following obligations:
- (a) The obligation to conduct an assessment of the impact of the intended processing operations on the protection of personal data (hereinafter “data protection impact assessment”) if a form of processing is likely to result in a high risk to the rights and freedoms of natural persons;
- (b) The obligation to consult the competent supervisory authority or authorities prior to processing if a data protection impact assessment indicates that the processing would result in a high risk, unless the controller takes measures to mitigate the risk;
- (c) The obligation to ensure that personal data is accurate and up to date by requiring the processor to notify the controller without delay if it determines that the personal data it is processing is inaccurate or out of date;
- (d) Obligations pursuant to Article 32 of Regulation (EU) 2016/679.
8.4 The parties shall set forth in Annex III the appropriate technical and organizational measures to be taken by the processor to assist the controller in applying this clause, as well as the scope and extent of the required assistance.
9. Notification of Personal Data Breaches
9.1 In the event of a personal data breach, the processor shall cooperate with and provide appropriate assistance to the controller so that the controller can fulfill its obligations under Articles 33 and 34 of Regulation (EU) 2016/679, taking into account the nature of the processing and the information available to the processor.
9.2 Data Breach Involving Data Processed by the Controller
In the event of a personal data breach involving data processed by the controller, the processor shall assist the controller as follows:
- (a) in promptly notifying the competent supervisory authority or authorities of the personal data breach after the controller becomes aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);
- (b) in obtaining the following information, which must be included in the controller’s notification pursuant to Article 33(3) of Regulation (EU) 2016/679, whereby this information must include at least the following:
- (i) the nature of the personal data, to the extent possible, including the categories and the approximate number of data subjects, as well as the categories and the approximate number of personal data records affected;
- (ii) the likely consequences of the personal data breach;
- (iii) the measures taken or proposed by the controller to address the personal data breach and, where appropriate, measures to mitigate its possible adverse effects.
If and to the extent that not all of this information can be provided at the same time, the initial notification shall contain the information available at that time, and further information shall be provided without undue delay as soon as it becomes available;
- (c) in compliance with the obligation under Article 34 of Regulation (EU) 2016/679 to notify the data subject without undue delay of the personal data breach if that breach is likely to result in a high risk to the rights and freedoms of natural persons.
9.3 Breach of the protection of data processed by the processor
In the event of a personal data breach involving data processed by the processor, the processor shall notify the controller without undue delay after becoming aware of the breach. This notification must contain at least the following information:
- (a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects affected and the approximate number of data records affected)
- (b) contact details of a point of contact from which further information about the personal data breach can be obtained;
- (c) the likely consequences and the measures taken or proposed to address the personal data breach, including measures to mitigate its potential adverse effects.
If and to the extent that not all of this information can be provided at the same time, the initial notification shall contain the information available at that time, and further information shall be provided without undue delay as soon as it becomes available.
The parties shall set forth in Annex III all other information that the processor must provide to assist the controller in fulfilling its obligations under Articles 33 and 34 of Regulation (EU) 2016/679.
Section 3 – Final Provisions
10. Breaches of the Clauses and Termination of the Agreement
10.1 If the processor fails to comply with its obligations under these clauses, the controller may—without prejudice to the provisions of Regulation (EU) 2016/679—instruct the processor to suspend the processing of personal data until it complies with these clauses or the contract is terminated. The processor shall notify the controller without delay if, for any reason, it is unable to comply with these clauses.
10.2 The controller is entitled to terminate the contract insofar as it relates to the processing of personal data under these clauses if
- (a) the controller has suspended the processing of personal data by the processor pursuant to subparagraph (a) and compliance with these clauses has not been restored within a reasonable period of time, but in any event within one month of the suspension;
- (b) the processor materially or persistently breaches these clauses or fails to fulfill its obligations under Regulation (EU) 2016/679;
- (c) the processor fails to comply with a binding decision by a competent court or the competent supervisory authority or authorities regarding its obligations under these clauses and Regulation (EU) 2016/679.
10.3 The processor is entitled to terminate the contract, insofar as it relates to the processing of personal data under these clauses, if the controller insists on compliance with its instructions after having been notified by the processor that such instructions violate applicable legal requirements pursuant to Clause 7.1(b).
10.4 Upon termination of the contract, the processor shall, at the controller’s discretion, either delete all personal data processed on behalf of the controller and certify to the controller that this has been done, or return all personal data to the controller and delete any existing copies, unless there is an obligation under Union law or the law of the Member States to retain the personal data. Until the data is deleted or returned, the processor shall continue to ensure compliance with these clauses.
Appendix 1 – List of Parties
Data Controller:
Name: [Company Name]
Address: [Company Address]
Contact Person: [Name, Title, Email, Phone]
Data Protection Officer: [Name, Email]
Data Processor:
Name: Lumiform GmbH
Address: Chausseestraße 57, 10115 Berlin
Contact person: Lumiform Team, contact@lumiformapp.com
Appendix 2 – Description of the Processing
1.1 Categories of data subjects whose personal data is processed
- (a) The categories of data subjects whose personal data is processed may vary depending on the activities of the data controller. Notwithstanding this, the categories may include, in particular, the following:
- (i) Employees
- (ii) Suppliers
- (iii) Customers
- (iv) Consultants
- (v) Job applicants
1.2 Categories of Personal Data Processed
- (a) The categories of personal data processed may vary depending on the activities of the data controller. Regardless, this may include, in particular, the following categories:
- Name
- Address
- Signature
1.3 Type of processing
- (a) The type of processing may include the storage, structuring, and modification of the transmitted data.
1.4 Purpose(s) for which the personal data is processed on behalf of the data controller
- (a) The purpose for which the personal data is processed on behalf of the data controller is set forth in the respective agreement between the parties and includes, in particular, the creation of forms and user accounts.
1.5 Duration of processing
- (a) The duration of data processing is determined by the respective agreement between the contracting parties.
Appendix 3 – Technical and Organizational Measures
The technical and organizational measures can be found here: https://lumiformapp.com/legal/technical-organizational-measures
Appendix 4 – List of Subprocessors
The list of subprocessors can be found here: https://lumiformapp.com/legal/subprocessors