Online Data Processing Agreement

The Parties have entered into a separate agreement (the “Agreement”) which requires that Xperi Inc. its affiliates and subsidiaries (collectively “Xperi”) to access and Process Personal Data while providing the contracted products or services (“Services”) to the other party to the Agreement (“Company”). This Data Processing Agreement (the “DPA”) and its Appendices specify the obligations of the Parties relating to the Processing of Personal Data pursuant to the Agreement. This DPA will be effective upon signature, is expressly incorporated into the Agreement, and applies from the effective date of the Agreement. Capitalized terms shall have the meaning provided herein, or the meaning given in the Agreement if not defined herein.

  1. Responsibilities and Obligations of the Parties
    • Company determines the purposes and means by which Xperi will Process Personal Data, and therefore Company shall be the Data Controller and Xperi shall be the Data Processor.
    • Each Party shall be responsible for complying with its respective obligations under the Data Protection Laws.
    • Nothing in this DPA shall be deemed to create a joint Processing relationship, joint venture, agency, or partnership relationship between the Parties, and neither Party is authorized nor shall act toward any third party, individual entity, or the public in any manner that would indicate any such relationship to the other.
    • Company shall ensure that it has provided Data Subjects with the means and opportunity to exercise any privacy rights afforded by Data Protection Laws, and has prominently posted and shall maintain a clear and conspicuously available privacy notice that informs Data Subjects regarding Processing of their Personal Data in connection with the Agreement, which privacy notice shall comply with applicable Data Protection Laws.
    • Company has obtained all licenses, permissions, authorizations, consents, and any other approvals needed, if any, to grant Xperi the rights required to Process Personal Data for the purposes contemplated by the Agreement and this DPA. Upon request, Company will provide Xperi with an accurate visual representation and all content presented to Data Subjects regarding any such mechanism provided to offer privacy rights or obtain consents.
  2. Terms Applicable to Xperi as a Data Processor
    • Company Instructions. Xperi will Process Personal Data in accordance with Company’s instructions. This DPA and the Agreement, along with any accompanying statements of work, work orders, or similar documentation will constitute Company’s written instructions to Xperi. The Parties agree that Company may communicate any additional instructions to Xperi by way of written notification to Xperi. For the avoidance of doubt, any instructions that would lead to Processing outside the scope of this DPA (e.g. because a new processing purpose is introduced, Company would be required to secure any legal bases and applicable consents) will require mutual agreement of the Parties and, where applicable, shall not take effect until the relevant Appendices to this DPA are amended or supplemented. Xperi will inform Company promptly if Xperi believes Company’s instructions infringe Data Protection Law, or if Xperi determines it can no longer meet its legal obligations under Data Protection Law, in which case Company shall have the right to correct or cease such Processing or take reasonable and appropriate steps to ensure Processing is consistent with Data Protection Law. The Parties shall reasonably cooperate to resolve such concerns.
    • CCPA Compliance. Where Xperi acts as a Data Processor, it shall Process Personal Data only on behalf of Company and at all times in accordance with this DPA, including the Appendices, the Agreement and in compliance with applicable Data Protection Laws. Xperi agrees that it will, with respect to Personal Data subject to the CCPA: (i) only Process that Personal Data for a “business purpose” (as defined by the CCPA), the purposes authorized by this DPA, or as otherwise permitted for Data Processors under the CCPA; (ii) not “sell” or “share” Personal Data (as defined by the CCPA); (iii) not retain, use, or disclose Personal Data outside the direct business relationship between Company and Xperi; (iv) not combine Personal Data with other personal data received from another source, unless permitted by the CCPA.
    • Xperi Personnel. Xperi will limit access to Personal Data to its personnel who have a reasonable need to Process such Personal Data. Xperi will ensure that such personnel have committed to a duty of confidentiality and are aware of their responsibilities with respect to Personal Data.
    • Disclosures to Governmental Parties. Unless required by law, Xperi will not disclose Personal Data to any governmental party, such as a supervisory authority, court, or law enforcement agency except with written consent from Company. If Xperi is obligated to disclose Personal Data to a governmental party, Xperi shall give Company prompt notice and allow Company the opportunity to seek a protective order or other appropriate remedy if it so chooses. If such notice is legally prohibited, Xperi will take reasonable measures to minimise the nature and extent of the Personal Data disclosed to the minimum necessary to comply with the request or order and shall inform Company as soon as possible if and when permitted to do so.
    • Data Subject Requests. Xperi shall provide Company with reasonable cooperation, information, and assistance in relation to any request or right available to Data Subjects under Data Protection Law (“Request”) that relates to Xperi’s Processing. If Xperi receives a Request, Xperi shall not directly respond and promptly notify Company. To the extent necessary, Xperi will provide assistance to Company to enable it to comply with its obligations to Data Subjects of providing access to Personal Data, deletion, restriction and/or rectification of Personal Data under the Data Protection Laws and, if required by Company, to return or delete all copies of the Personal Data promptly on request.
    • Data Protection Impact Assessments, Risk Analyses, and Audits. Where a data protection impact assessment, risk analysis, or audit is required under applicable Data Protection Laws related to the Processing of Personal Data, Xperi shall provide upon request to Company any information and assistance reasonably required to complete the assessment, analysis, or audit, and will consult with data protection supervisory authorities regarding the assessment, where required.
    • Cooperation. Xperi shall make available to Company upon Company’s request information and assistance reasonably required to demonstrate Xperi’s compliance with the obligations in this DPA. Company shall have the right to take reasonable and appropriate steps to eliminate or remediate any unauthorized Processing by Xperi.
    • Inspections. Xperi shall, upon reasonable notice of at least thirty (30) days by Company, allow for and contribute to inspections of Xperi’s Processing of Personal Data (limited to security questionnaires and a review of policies, procedures and records), during regular business hours no more than once per year, without unreasonably disrupting Company’s business operations. Such inspections are conducted by Company, its affiliates and subsidiaries or an independent third-party on Company’s behalf (which will not be a competitor of the Xperi) that is subject to reasonable confidentiality obligations. Information gathered from such inspections of Xperi shall be considered confidential and proprietary documentation of Xperi.
    • Supervisory Authorities. Xperi will promptly refer to Company any requests received from data protection authorities or other regulators that relate to the Xperi’s Processing of Personal Data. Xperi shall provide reasonable cooperation and assistance promptly for Company to address with any such request.
    • Data Breach. In the event Xperi discovers a Data Breach, it shall notify Company without undue delay, using reasonable endeavours to do so within 48 hours after becoming aware of the Data Breach. Xperi shall provide reasonable information, cooperation, and assistance to Company in relation to any Data Breach as required by Data Protection Laws, including information as may be reasonably necessary for Company to notify Data Subjects or data protection authorities of the Data Breach.
    • Subcontracting. Xperi shall be permitted to subcontract Processing to the parties identified in Appendix 1 of this DPA. When Xperi subcontracts Processing Personal Data, it shall do so only by way of a binding written contract with the subcontractor which imposes obligations substantially similar to this DPA. Xperi shall perform appropriate due diligence to ensure each such subcontractor can perform as necessary for Xperi to meet its obligations under the provisions of this DPA. Xperi shall notify Company of any changes to the authorized subcontractors in sufficient time to afford Company an opportunity to object to the engagement, in which case the Parties shall cooperate to reasonably resolve any such objection. Xperi shall remain fully liable to Company for the performance of the subcontractors’ obligations with respect to their Processing of Personal Data.
    • Security Measures. Xperi shall implement and maintain appropriate technical and organizational security measures (“TOMs”) designed to ensure that Personal Data is Processed in accordance with this DPA and to protect Personal Data against Data Breaches. Xperi’s TOMs are provided at Appendix 2. Xperi shall assess and evaluate the effectiveness of TOMs on an ongoing basis.
    • Deletion or Return of Personal Data. Xperi shall without undue delay securely delete or return all Personal Data it Processes as a Data Processor upon receipt of such direction from Company or upon termination or expiration of the Agreement.
  3. International Data Transfers and Risk Assessments
    • EEA Data Transfers.If and to the extent Personal Data Processed by either Party is subject to an EEA Data Transfer, the EEA SCCs are incorporated herein by reference and shall apply as follows:
      1. Application.Xperi shall act as the data importer with respect to any EEA Data Transfer where Company acts as the data exporter; Company shall act as the data importer with respect to any EEA Data Transfer where Xperi acts as the data exporter;
      2. Docking.For the purposes of Section I, Clause 7, the optional docking clause applies;
      3. Modules. Module Two (transfer controller to processor, and Module Four (transfer processor to controller) apply will apply;
      4. Redress.For purposes of Section II, Clause 11, the optional language does not apply;
      5. Choice of Law.For the purposes of Section IV, Clauses 17 and 18, to the extent permitted by applicable Data Protection Law, the parties agree that their respective obligations under the EEA SCCs shall be governed by the law(s) of and subject to the jurisdiction of the courts of The Republic of Ireland;
      6. Completion of Annex I, Part A.Annex I, Part A (List of parties) is completed with the details of Company and Xperi, in each case as set out in the Agreement;
      7. Completion of Annex I, Part B.Annex I, Part B (Description of the transfer) is completed with the information provided in Appendix 1;
      8. Completion of Annex I, Part C.With respect to Annex I, Part C (Competent Supervisory Authority) of the EEA SCCs, to the extent permitted by applicable Data Protection Law, the parties select the data protection authority of The Republic of Ireland; and
      9. Completion of Annex II.Annex II of the EEA SCCs (The Technical and organizational measures including technical and organizational measures to ensure the security of the data) is completed with the provisions set out in Appendix 2.
    • Interpretation of EEA SCCs for Restricting Countries.If and to the extent that either Party’s transfer of Personal Data to the other constitutes an Other Data Transfer, the EEA SCCs are incorporated herein by reference and shall apply as set out above for EEA Transfers, except that: (i) references in the EEA SCCs to “EU,” “Union,” “EU Member State,” or “Member State” shall refer instead to that Restricting Country; (ii) references to “Regulation (EU) 2016/679” or “that Regulation” shall refer instead to the Data Protection Laws of that Restricting Country and references to specific provisions or articles of GDPR shall be replaced with the equivalent provision or article of the Restricting Country’s Data Protection Law; (iii) “supervisory authority” shall refer to the data protection authority in that Restricting Country; (iv) references to the “Clauses” means this section as it incorporates and modifies the Clauses.
    • UK Data Transfers.If and to the extent that Personal Data Processed by either Party constitutes a UK Data Transfer, the UK Addendum is incorporated herein by reference and shall apply as follows:
      1. Completion of Table 1.With respect to Table 1 of the UK Addendum, either Party may act as data exporter or data importer, and the details of Company and Xperi are given as provided in the Agreement. The “start date” is the effective date of the Agreement. The “key contact” for each Party is given in their respective signature lines of the Agreement.
      2. Completion of Tables 2 and 3.Table 2 of the UK Addendum is completed by selecting “the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum.” For the purposes of Table 2 and Table 3 of the UK Addendum, the “Approved EU SCCs” are completed as set out above for EEA Transfers.
      3. Completion of Table 4.Table 4 of the UK Addendum is completed by selecting “neither party.”
    • Invalidation of Transfer. In the event that any competent legal authority holds that a data transfer mechanism relied on by the Parties is invalid, or any competent supervisory authority or applicable law requires transfers of Personal Data to be supported by additional measures, suspended, or restricted to a specific jurisdiction, then the Parties will cooperate to facilitate use of an alternative data transfer mechanism, execute additional documents, apply additional protections, or restrict Processing to certain jurisdictions.
  4. Term and Termination
    • This DPA terminates when the Agreement is terminated and Xperi’s Processing obligations under this DPA shall continue to apply for so long as it has access to the Personal Data.
    • Company may terminate this DPA for cause at any time upon reasonable notice, if the Xperi is in material breach of the terms of this DPA and fails to cure such breach within a reasonable time agreed by the Parties, in accordance with the provisions of the Agreement.
  5. Miscellaneous
    • In case of any conflicting terms, the order of precedence is: (a) the EEA SCCs and UK SCCs incorporated by reference; (ii) this DPA; and (iii) the Agreement.
    • Any supplementary agreements or amendments to this DPA must be made in writing and signed by both Parties.
    • Should individual provisions of this DPA become void, invalid or non-viable, the Parties shall cooperate to amend this DPA to help ensure continued compliance with Data Protection Laws by both parties and any such voiding or invalidation shall not affect the validity of unaffected provisions of the DPA.
    • This DPA shall be governed by California law with respect to disputes under any US law, Irish law with respect to disputes under any EEA law, and English law with respect to any disputes under UK law. The place of jurisdiction shall be the courts of the State of California with respect to claims in the US, Ireland with respect to claims brought in the EEU, and England with respect to claims brought in the UK.
  6. Definitions

      In this DPA, the following terms (whether capitalized or not) shall have the following meanings, unless the context implies otherwise:

  • “Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
  • “Data Controller” means the organization which determines the purposes and means of processing Personal Data, inclusive of a “business” or “third party” as defined by CCPA.
  • “Data Processor” means the organization who processes Personal Data on behalf of a Data Controller.
  • “Data Protection Laws” shall mean the data protection laws of the country in which Xperi is established (including the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., inclusive of regulations promulgated pursuant to the same as they become effective) (“CCPA”) and the GDPR) and any other data protection, data security and privacy laws applicable to Xperi and/or Company in connection with Processing of Personal Data under this DPA and the Agreement.
  • “Data Subject” means an identified or identifiable natural person who is the subject of Personal Data.
  • “EEA Data Transfer” means a transfer of Personal Data: (a) that is subject to the GDPR; (b) to a recipient in a country or territory outside of the EEA; and (c) which is not subject to an adequacy decision by the EU Commission.
  • “EEA SCCs” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission decision of 4 June 2021 C(2021) 3972, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?url=CELEX:32021D0914&locale=en.
  • “GDPR” shall mean the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • “Other Data Transfer” means a transfer of Personal Data: (i) that is subject to the laws of a country which restricts the transfer of Personal Data to another country not deemed adequate to receive such Personal Data (a “Restricting Country”); and (ii) which is not an EEA Data Transfer or UK Data Transfer.
  • “Personal Data” shall mean any information relating to an identified or identifiable natural person or is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a household, including any information defined as “personally identifiable information,” “personal information,” “personal data” or similar terms as such terms are defined under Data Protection Laws, limited to that Personal Data Xperi Processes pursuant to this DPA.
  • “Process” or “Processing” means any operation which is performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data.
  • “UK Addendum” means the template addendum issued by the UK’s Information Commissioner’s Office and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section ‎18, available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.
  • “UK Data Transfer” means a transfer of Personal Data: (a) that is subject to the UK GDPR; (b) to a recipient in a country or territory outside of the UK; and (c) which is not subject to an adequacy decision by the UK’s Secretary of State.
  • “UK GDPR” means the GDPR as it forms part of the laws of England and Wales, Scotland and Northern Ireland pursuant to Section 3 of the European Union (Withdrawal) Act 2018.

 

The Parties’ authorized signatories have duly executed this DPA:

 

Xperi Inc.:

 

By: _________________________________

Name: ______________________________

Title: _______________________________

Date: _______________________________

 

Company:

 

By: _________________________________        

Name: _______________________________

Title: ________________________________

Date: _______________________________

 

APPENDIX 1

Description of Processing

  1. Processing Operations

      Describe the nature and purposes of the Processing of Personal Data:

  • Provision of Services, including [insert description relevant to engagement, such as providing an operating system] and associated features such as managing user accounts and preferences
  • Delivery of non-targeted ads, such as contextual ads or first-party ads, consistent with an individual’s expressed privacy preferences
  • Frequency capping or other brand safety services
  • Technical support and product improvements, including debugging
  • Preparation of reports and metrics leveraging aggregated Personal Data
  • Internal business administration such as fraud detection and prevention, security, record keeping and contracts administration
  • Compliance with legal obligations, including responding to Data Subject Requests
  • De-identification of Personal Data using measures sufficient to cause the resultant data to no longer constitute Personal Data under applicable Data Protection Law (“De-Identified Data”), in which case Xperi commits that it will not re-identify De-Identified Data nor permit any recipient of De-Identified Data to reidentify it.
  1. Data Subjects

      The Personal Data Processed concern the following categories of Data Subjects:

      Customers, subscribers or users of Company’s [insert name or description of Xperi’s customer’s product or service].

  1. Categories of Personal Data

      The Personal Data Processed concerns the following categories:

      [Insert]

  1. Special Categories of Personal Data (if applicable)

      The Personal Data Processed concern the following special categories:

      Not applicable.

  1. Frequency of Transfer

      Personal Data will be transferred on a continuous or regular basis as necessary for the performance of the Agreement.

  1. Retention of Personal Data

      Personal Data will be Processed for as long as necessary to fulfill the purposes of Processing.

  1. Subcontracting

      Xperi intends to subcontract Processing of Personal Data to the following parties:

Subcontractor Address/Location Processing International transfer (if applicable)
Microsoft USA Storage SCCs
AWS USA

Ireland

Hosting SCCs
       
  1. Contact Persons

      Questions and notices to Xperi from Company under DPA shall be addressed to:

      Xperi Data Protection Officer
      Email: DataProtectionOfficer@Xperi.com

      Questions and notices to Company from Xperi shall be addressed to:

      [Company Data Protection Officer]
      Email: [insert] 

 

APPENDIX 2

Technical and Organizational Measures (TOMs)

Xperi certifies to the following industry standards:

  1. TISAX Certification
  2. ISO 9001 Project Specific Certification

Xperi also adheres to NIST 800-53 frameworks.

Xperi has incorporated a security framework that adheres to ISO 27001 and 27000.