Examples of the data transfer clause
Below are some examples of data transfer clauses from different kinds of agreements. While these examples do not necessarily cover the full range of data transfer clauses one may encounter, they are meant to illustrate the degree to which these provisions can vary from contract to contract. Where an example includes broader contextual language, the data transfer clause is highlighted in bold.
Example 1: From a SaaS Agreement
7.5 International Data Transfers. Our Services are operated in the United States and intended for users located in the United States. If you are located outside of the United States, please be aware that information we collect, including Personal Data, will be transferred to, and processed, stored, and used in the United States in order to provide the Service to you. Where the General Data Protection Regulation applies and our processors of your Personal Data are located outside the European Economic Area, such transfer will only be to a recipient country that ensures an adequate level of data protection.
Example 2: From a License and Services Agreement
4.4 Privacy and Security We follow the privacy policy available at [link]. Cloud Services may use third-party data centers, which are independently audited and certified as SOC 2 compliant. Based on our reasonable diligence We comply with all laws applicable to Us as the provider of the Cloud Services. We process Customer Data (as defined in Section 6.2) via the Cloud Services on behalf of You only and in accordance with the terms of this Agreement and any reasonable instructions that You might give Us from time to time. We reserve the right to hire other companies to provide services on Our behalf in connection with Our provision of the Cloud Service. We will prohibit such subcontractors from using Customer Data for any purpose other than to perform services on Our behalf. We reserve the right to transfer Customer Data to the U.S. and other countries for processing in connection with Our provision of the Cloud Service. We will maintain reasonable administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of customer data as described in the Cloud and Support Security Exhibit to the Informatica License and Services Agreement available here: [link]. Those safeguards will include measures for preventing access, use, modification and disclosure of Customer data except (a) to provide the Services and prevent or address service or technical problems, (b) as compelled by law or (c) as You may expressly permit in writing. Where Your use of the Support Services, Cloud Services, or Professional Services includes the processing of personal data by Informatica, the terms of the data processing agreement at [link] shall apply to such processing, and are hereby incorporated by reference.
Example 3: From a License Agreement
10.3 If Licensor processes any personal data on Your behalf when performing its obligations under this agreement, the parties record their intention that You shall be the data controller and Licensor shall be a data processor and in any such case: a) You acknowledge and agree that, subject to Licensor’s compliance with its duties as data processor, the personal data may be transferred or stored outside the EEA, Switzerland, or the country where You and the Authorised Users are located in order to carry out the Services and Licensor’s other obligations under this Agreement;
b) You shall ensure that You are entitled to transfer the relevant personal data to Licensor so that Licensor may lawfully use, process and transfer the personal data in accordance with this agreement on Your behalf;
Example 4: From a SaaS Agreement
10.4 No Transfer. Nothing in this Agreement shall operate to transfer, assign or otherwise grant to Vendor any right or interest to the Customer Data, unless otherwise expressly.
10.5 Data Transfers outside of EU or EEA. Vendor (and its applicable sub-processors) shall not transfer personal data to a country outside the EU or EEA which the EU Commission has found does not provide an adequate level of protection unless the parties have agreed to such transfer and Vendor ensures that such processing is performed under appropriate safeguards and otherwise complies with the statutory requirements regarding the processing of personal data outside of the EU/EEA.
Example 5: From a SaaS Agreement
7.7. We will, at all times, physically store the Customer Data and any Backups in a designated country. At no point will We transfer, electronically or physically, the Customer Data or any Backups to another country. We cannot warrant in which countries any data is routed through over the internet in the normal course of carrying out the obligations under this Agreement. We may, at any time, without consent and without notice, move the Customer Data to a new location provided that the new location is either within the same country of the Customer or the same designated country.
Example 6: From a Customer License Agreement
3.9.2 Data Privacy. With respect to Customer Content, Licensor shall act as the data processor of Customer Content in accordance with Customer’s instructions as contemplated by this Agreement. If Customer Content includes any data subject to specific legal or regulatory requirements (including, but not limited to, health care data, sensitive personal information, export-controlled data, or sensitive government data), Licensor shall not have any responsibility to discover or determine the appropriate classification of Customer Content or to comply with such requirements, except to the extent that the applicable service documentation specifies that the APPLICATION SERVICE meets a particular standard. Customer consents to Licensor’s collection, use, and disclosure of information associated with the APPLICATION SERVICES as described in this Agreement and the applicable Data Protection Plan and to the processing of Customer’s Content in, and the transfer of Customer Content into, any country in which Licensor or its Affiliates or subcontractors maintain facilities (including the United States). Licensor shall treat Customer contact information (including business contact information of Customer representatives) in accordance with Licensor’s Privacy Policy available at [link]. Customer consents to the disclosure of Customer Content to Licensor’s subcontractors and Affiliates who agree to maintain and use Customer Content in accordance with this Agreement.
Example 7: From a SaaS Agreement
- PERSONAL DATA
14.1 In performing the Services, We will comply with Our Privacy Policy, which is available at [link] and incorporated herein by reference. Our Privacy Policy is subject to change at Our discretion.
14.2 We reserve the right to provide the Services from locations, and/or through use of subcontractors, worldwide. We subscribe to the United States/European Union Safe Harbor Principles and will only use third party providers that are in compliance of the Safe Harbor Principles.
14.3 Customer agrees to provide any notices and obtain any consents related to Customer’s use of the services and Our provision of the Services, including those related to the collection, use, processing, transfer and disclosure of personal information. Customer shall have sole responsibility for the accuracy, quality, integrity, legality, reliability, appropriateness and ownership of all of its data.
Example 8: From a SaaS Agreement
(e) Cross Border Transfers. Where Personal Data originates from the European Economic Area and is transferred to the United States, We will act in compliance with the EU-U.S. Privacy Shield Framework. Where Personal Data originates from Switzerland and is transferred to the United States, We will act in compliance with the U.S.-Swiss Safe Harbor Framework. As of the Effective Date of this SaaS Agreement, We have self- certified to and comply with the EU-U.S. Privacy Shield Framework and the U.S.-Swiss Safe Harbor Framework and will maintain such certification throughout the term of this SaaS Agreement.
Example 9: From a Privacy Policy
- International Transfer. Your information is stored on controlled servers with limited access and may be stored and processed in the United States or another country where our service providers are located. We offer our Services to individuals located in the United States, and we do not advertise our Services outside the United States. If you are located outside the United States and choose to provide your Personal Information to us, please note that we may transfer your Personal Information to the United States or another country where our service providers are located, and such countries may not provide the same data protection. Those who choose to access and use the Services from outside the United States do so on their own initiative, at their own risk, with this understanding.
Example 10: From a Data Processing Addendum
- Data Transfer. Customer hereby consents to the transfer of the Customer Personal Data to, and processing of the Customer Personal Data in, the United States of America and/or in any other jurisdiction in which Company, its affiliates or its subprocessors have operations. The parties hereby enter into the Standard Contractual Clauses for Processors, as approved by the European Commission under Decision 2010/87/EU, attached hereto as Schedule I and made a part of this DPA in their entirety.
Example 11: From a SaaS Agreement
2.3. Privacy Compliance. Customers are recommended not to store EEA/Swiss/UK personal data (as defined under EU/Swiss/UK relevant law) or any Content that may be governed by industry specific legislation in the Service. The Company is neither the Data Controller nor the Data Processor (as defined under relevant EU/Swiss law) of any personal data Content inputted by Customer or any Authorized User. If Customer or any Authorized User chooses to input personal data Content, Customer shall remain solely liable and responsible for complying with applicable privacy laws with respect to Customer’s and its Authorized Users’ use of the Services and the Content, including but not limited to EU General Data Protection Regulation and any other privacy/data protection obligations in relation to the processing of such Content (including but not limited to the obligations to delete data, process it lawfully, and restrictions regarding transfer outside of the EEA/Switzerland/UK, and responding to data subject access requests). All Content used by or within the Services may be stored on servers located outside of the EEA/Switzerland/UK, unless options (if available) are selected and used by the Customer to retain the data on relevant servers within the EEA/Switzerland/UK. Further, Customer and Authorized Users are not permitted to store maintain, process or transmit sensitive personal information, including but not limited to financial information, country identifications numbers (such as social insurance, social security, driver’s license or passport numbers) or Protected Health Information (as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)) in the Services.
Example 12: From a Privacy Policy
VIII. Transfer Of Your Personal Information Among Jurisdictions.
The Service is based in the United States. Your Personal Information may be processed, transferred to, and maintained on, servers and databases located within the U.S. and elsewhere where the privacy laws may not be as protective as your jurisdiction. We reserve the right to transfer your Personal Information to and from any state, province, country or other governmental jurisdiction. Your consent to this Privacy Policy followed by your submission or our collection of such Personal Information represents your agreement to any such transfer.
Example 13: From an Employment Agreement
20.1 The Executive consents to the Group holding and processing both electronically and manually, personal data, including sensitive personal data (as defined in the Data Protection Act 1998) and information contained in e-mail and e-mail attachments it collects, stores and/or processes, which relates to the Executive for the purposes of the administration and management of its business and as may be required by law. It may also be necessary for a Group Company to forward such personal information to other offices it may have or to another Group Company outside the EEA where such company has offices or storage for the processing and/or for administrative purposes and the Executive consents to such Group Company doing so as may be necessary from time to time.
Example 14: From a Master Services Agreement
C. For compliance with EU Data Protection Directive:
1. Each of Client and Provider warrants that it will implement and maintain appropriate written policies, the terms of which are reasonably designed to ensure its compliance with the EEA Data Protection Laws.
2. In respect to any Personal Information processed pursuant to this Agreement by Provider, Provider warrants and undertakes that it shall, and any of its subcontractors shall:…
c. not cause or permit the Personal Information to be transferred or otherwise processed outside the European Economic Area without the prior written consent of Client.
3. In the event that the services involve the processing of Personal Information outside the European Economic Area, the parties agree to execute the Standard Contractual Clauses for Data Processors established in Third Countries pursuant to the Commission Decision (2010/87/EU) of 5 February 2010 under the EU Directive 95/46/EC. In addition, to the extent that the Services involve processing of Personal Information transferred from Germany, the Parties agree to use commercially reasonable efforts to execute additional terms as agreed between the Parties.
Example 15: From a Master Statement of Work
9.7 Additional Warranties for Handling of Sensitive Personal Information.
The following section is applicable when Supplier is handling Sensitive Personal Information (SPI) on behalf of Buyer or Customer. Examples of SPI include Social Security Number (SSN)) or other governmentally issued identification number such as driver’s license or passport number, bank account number and credit card or debit card number. SPI is considered Confidential Information.
1. Supplier shall not transfer or disclose Personal Data to any third party without the prior written consent of Buyer. Supplier shall put in place with any third party to whom it transfers or discloses Personal Data an agreement sufficient to ensure that such third party treats Personal Data in accordance with the provisions of this Agreement. Supplier shall ensure that any third party to whom it transfers or discloses Personal Data has implemented a data privacy incident reporting process for the immediate reporting to Buyer of any potential or actual privacy and/or security breaches. Supplier shall conduct an ongoing (annual or when changes occur) privacy assessment and security validation of those third parties to whom it has transferred Personal Data.