1 BACKGROUND AND PURPOSE 1.1 As part of the customer’s wish to receive the Reen Services (the “Services” ), Supplier (the “Processor” ) will process certain personal data on behalf of the Customer (the “Controller” ), each a “Party” and jointly the “Parties” .
1.2 The purpose of this data processing agreement (the “DPA” ) is to set out the rights and obligations of the Parties concerning the Processor’s processing of personal data on behalf of the Controller in order to provide Services pursuant to the at all times applicable terms and conditions of the Services (the “Agreement” ). The DPA forms an integral part of the Agreement.
1.3 This DPA does not govern personal data that the Processor processes on its own behalf (as a controller), such as for bookkeeping purposes and customer relation purposes.
1.4 In the event of inconsistency between the terms of the Agreement and the DPA on matters specifically concerning data protection, the latter shall prevail.
2.1 In this DPA, the following terms shall have the meanings set out below.
2.1.1 “Applicable Data Protection Law” : Any applicable data protection and privacy law, including but not limited to the GDPR, or any law replacing or supplementing the GDPR, and local law implementing the GDPR.
2.1.2 “EEA” : The European Economic Area.
2.1.3 “GDPR” : The EU General Data Protection Regulation 2016/679.
2.1.4 “Standard Contractual Clauses” : The standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, issued by the European Commission on 4 June 2021 and/or laid down by the European Commission or a relevant supervisory authority in accordance with Article 46(2)(c) or 46(2)(d) of the GDPR.
2.1.5 “Sub-processor” : Another processor engaged by the Processor for the processing of personal data on behalf of the Controller.
2.1.6 “Third Country” : A non-EEA country or an international organisation that is not approved by the EU Commission as having an adequate level of data protection (adequacy decision).
2.1.7 Other terms shall have the meaning as given to them in the GDPR.
3 GENERAL OBLIGATIONS 3.1 Each Party shall comply with its obligations under Applicable Data Protection Law.
3.2 The Controller warrants that the personal data is processed for legitimate and objective purposes and that the Processor does not process more personal data than required for fulfilling such purposes. The Controller is responsible for ensuring that a valid legal basis for processing exists for and that the data subjects are informed about the processing covered by this DPA in accordance with Applicable Data Protection Law.
3.3 The Controller hereby instructs the Processor to process personal data solely for the purposes and within the scope as set out in APPENDIX 1 and otherwise in accordance with this DPA.
3.4 The Processor shall immediately inform the Controller in writing if, in its reasonable opinion, (i) an instruction from the Controller infringe Applicable Data Protection Law, or (ii) a legal requirement laid down by EEA law to which the Processor is subject requires the Processor to process personal data beyond the scope of the Controller’s documented instructions, unless that law prohibits such information on important grounds of public interest (if so, the Processor shall inform the Controller as soon as permitted by law).
4 ASSISTANCE TO THE CONTROLLER
4.1 The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to and comply with requests for exercising the data subject’s rights laid down in Applicable Data Protection Law, including chapter III of the GDPR.
4.2 Taking into account the nature of processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with Article 32 to 36 of the GDPR, including the obligations of data security, personal data breach notification, data protection impact assessments and prior consultation with supervisory authorities.
4.3 The Processor shall not engage in any direct communication with data subjects or supervisory authorities, unless approved in advance by the Controller or required by applicable law. The Processor shall, without undue delay, forward to the Controller any request or complaint received from a data subject or a supervisory authority concerning the processing of personal data under this DPA, unless prohibited by applicable law (if so, the Processor shall inform the Controller as soon as permitted by such law).
4.4 The Controller shall pay the Processor for any assistance provided under this DPA, including this section 4, at the Processor’s hourly rates.
5 TECHNICAL AND ORGANISATIONAL SECURITY MEASURES 5.1 The Processor shall implement and maintain throughout the term appropriate technical and organisational data security measures to protect the personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access pursuant to Article 32 of the GDPR.
5.2 The Processor shall limit the access to the personal data to its personnel on a need-to-know basis. The Processor shall ensure that the personnel have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that the confidentiality also applies after the termination of the DPA.
6 USE OF SUB-PROCESSORS
6.1 The Supplier has the right to use the sub-processors which are listed at www.reen.com/terms-and-conditions. The Supplier use few sub-processors outside the European Economic Area (EEA) where European Standard Contract Clauses (SCCs) are used as a basis for transfer.
6.2 If the Processor intends to make changes by adding or replacing Sub-processors (including changes in processing locations of approved Sub-processors), the Processor shall notify the Controller about such intended change to enable the Controller to consider whether to object to such change. The Controller must object to such change within two weeks from the Processor’s notification. Objections may only be based on legitimate reasons, such as lack of security for the personal data. The Controller will be deemed to have consented to the change unless such objection is provided to the Processor within this time limit.
6.3 If it is critical to replace or add a new sub-processor to fulfil the services under the Agreement, the Processor may, notwithstanding the above, implement the change immediately after the Controller has been notified.
6.4 The Processor must ensure that materially the same data protection obligations as set out in this DPA are imposed upon any Sub-processor by a written agreement.
6.5 The Processor shall not in any way be liable for any processing carried out by the Sub-processor as a result of instructions received by the Sub-processor directly from the Controller.
7 INTERNATIONAL DATA TRANSFERS 7.1 The Customer hereby grants a general authorization for the Supplier to transfer personal data to the Third Countries listed in the sub processor list found at www.reen.com/terms-and-conditions. Processor shall at all times keep an updated list of Sub-processors in Third Countries.
7.2 If the Processor transfers personal data to a Third Country, the Processor shall ensure that the requirements of Applicable Data Protection Law regarding data transfers, including Chapter V of the GDPR, are complied with. Upon the Controller’s reasonable request, the Processor shall provide the Controller with evidence that such requirements are complied with, including copies of Standard Contractual Clauses and transfer impact assessments (commercial terms may be redacted).
8 PERSONAL DATA BREACHES 8.1 In the event of a personal data breach, the Processor shall without undue delay after becoming aware of it notify the Controller in writing about the breach. The notice shall contain all such information the Controller may reasonably require to enable the Controller to comply with its obligations pursuant to Article 33 and Article 34 of the GDPR, provided that the Processor possesses or may reasonably obtain such information.
8.2 The Processor shall without undue delay take adequate measures to address the personal data breach, including, where appropriate, reasonable measures aiming to mitigate its possible adverse effects and to avoid the re-occurrence of similar breaches.
9 AUDITS 9.1 The Processor shall maintain necessary records and make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law.
9.2 The Processor shall allow for and contribute to audits, including inspections, of the Processor’s processing operations. The Controller may perform the audit itself or by use of a third-party auditor, subject to appropriate confidentiality undertakings. The request for audit shall be given in writing with a notice period of at least three weeks, unless otherwise is required under Applicable Data Protection Law. Audits cannot be requested more than once a year, unless the Controller has a particular reason to request additional audits on an ad-hoc basis. To the extent reasonably possible, the audits shall be conducted within ordinary working hours and without obstructing the Processor’s activities.
9.3 Authorities who supervise the Controller have a right to request information from and to conduct audits of the Processor to the same extent as the Controller.
9.4 The Controller shall bear any costs related to audits initiated by the Controller or accrued in relation to audits of the Controller, including compensation to Processor for reasonable time spent by it and its employees complying with on premises audits. The hourly rate for this assistance is 200 EUR. However, if an audit reveals material deviations from the obligations set out in Applicable Data Protection Law or this DPA caused by the Processor or any Sub-processor, the Processor’s costs of the audit shall be borne by the Processor.
9.5 Notwithstanding the above, the Controller will not be allowed access to server rooms and other information and location to the extent this could potentially pose a risk to the Processors security level or to confidential information. The Processor alone assesses this risk.
10 LIABILITY 10.1 The Parties’ liabilities are governed by the Agreement.
11 TERM AND TERMINATION 11.1 This DPA remains in force as long as the Processor is processing personal data on behalf of the Controller under the Agreement.
11.2 If the Processor has not implemented appropriate technical and organisational measures in such a manner that processing will meet the requirements of the GDPR, the Controller may terminate the DPA if the Processor has not implemented such measures within one month after the Controller’s notification thereof.
11.3 Upon expiry or termination, the Processor shall delete the personal data after the Controller has been able to export the personal data.
11.4 Notwithstanding the foregoing, the Processor is entitled to continue storing the personal data to the extent required to comply with applicable law, or to the extent it follows from the Processor’s general backup routines, provided that clause 5 continue to apply for such data, and provided that the Processor does not actively process such data.
APPENDIX 1 Scope of the processing
Purpose of the processing: Processing of personal data necessary to provide tracking services as defined in the Agreement. Nature of the processing: Processing of personal data as provided by the customer through the use of the Services. Categories of data: Information about vehicles, such as Registration number, Make, Model, First time registered date, Emissions data, Vehicle group, Colour, Vehicle name, Vehicle type, Fuel type, Vehicle category, Assigned driver, Initial and corrected mileage readings, Leasing details (Leasing company, Contract number, Contract start date, Mileage limit, Leasing agreement duration, Mileage reading at the start of the leasing period), Insurance details (Insurance company, Contract number, Contract start date, Mileage limit, Insurance agreement duration, Mileage reading at the start of the insurance), Servicing details (Date of last service, Mileage at last service, Service interval by distance driven, Service interval by time, E-mail address on who to notify and who has been notified. Information about equipment, such as Make, Model, Name, Serial nr, Registration number, Department, Tags, Operating hours at last service, Service intervals, Inspection details (Last inspection date, Inspection interval, Inspection notes), E-mail address on who to notify and who has been notified). Data provided by hardware or created from hardware data, such as Location, Engine on and off, Trip start and stop location, Trip start and stop address, Trip start and stop date and time, Current speed, Current direction, Raw Accelerometer data to build driving behaviour score and detect driving events (Rapid acceleration, Hard breaking, Harsh turning, Idling), Hardware diagnostic such as GPS satellites in view, installation angle, Operating hours.
Categories of data subjects: • Employees of the Controller, usually employed drivers • Additional data subjects depending on the data that the Controller provides
APPENDIX 2 Approved Sub-processors
See the at all times updated list at: www.reen.com/terms-and-conditions