CINXE.COM
Global DPA
<!DOCTYPE html> <html lang="en" dir="ltr" prefix="og: http://ogp.me/ns#" data-behavior="i18n" data-environment="prod" data-server-mode="publish" data-dc="p"> <head> <meta charset="utf-8"/> <meta name="viewport" content="width=device-width, initial-scale=1"/> <title>Global DPA</title> <meta name="description"/> <link rel="canonical" href="https://privacy.x.com/en/for-our-partners/global-dpa"/> <meta property="og:url" content="https://privacy.x.com/en/for-our-partners/global-dpa"/> <meta property="og:type" content="article"/> <meta property="og:title" content="Global DPA"/> <meta property="og:image" content="https://cdn.cms-twdigitalassets.com/content/dam/privacyexternal-twitter/genericblogshare.jpg.twimg.768.jpg"/> <meta name="keywords"/> <meta name="twitter:card" content="summary"/> <link rel="alternate" hreflang="en" href="https://privacy.x.com/en/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="de" href="https://privacy.x.com/de/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="es" href="https://privacy.x.com/es/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="fr" href="https://privacy.x.com/fr/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="ja" href="https://privacy.x.com/ja/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="ru" href="https://privacy.x.com/ru/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="ko" href="https://privacy.x.com/ko/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="it" href="https://privacy.x.com/it/for-our-partners/global-dpa"/> <link rel="alternate" hreflang="pt" href="https://privacy.x.com/pt/for-our-partners/global-dpa"/> <meta name="twitter:widgets:new-embed-design" content="on"/> <meta name="twitter:widgets:csp" content="on"/> <link href="https://abs.twimg.com/favicons/twitter.3.ico" rel="shortcut icon" type="image/x-icon"/> <script type="application/json" id="analytics-settings">{"google":{"accounts":[],"options":{"displayAdvertisingFeatures":false}},"scribe":{"scribeSectionWithImpression":false},"trackingPixel":{},"bing":{}}</script> <script type="application/json" class="u14-data-layer" data-component="u14-data-layer" id="data-layer">{"page":{"pageId":"5f64d79","pageKey":"5f64d79-en-en","pageName":"Global DPA","pagePath":"/content/privacyexternal-twitter/en/for-our-partners/global-dpa","pageType":"content-page","pagePublishDate":"","language":"en","geoRegion":"en","category":{"tags":{"tagIDs":[],"tagNames":[]},"scribe":{"component":"global-dpa","section":"for-our-partners","page":"privacyexternal","element":"page"}},"attribute":{}}}</script> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/css/core.css.twhash.p.f.ad34c37de9518cc012edc53c88d262dd.css" media="screen" type="text/css"/> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/css/legacy-colors.css.twhash.p.f.20fd26d638816cbce52d44904fc9c3c2.css" type="text/css"/> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/css/project.css.twhash.p.f.983313f061a46f4dcefd45c9530bc2b5.css" media="screen" type="text/css"/> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/css/print.css.twhash.p.f.67de1c964d9398cbf614aab841910ad6.css" media="print" type="text/css"/> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/css/languages.css.twhash.p.f.ad7062672948db2fe784ee48cbba355a.css" type="text/css"/> </head> <body class=" twtr-theme--blue page content-page page-- twtr-color-bg--white-neutral js-no-scroll atm-light " style="--theme-color: var(--blue-dark)" data-analytics-page="privacyexternal" data-analytics-section="for-our-partners" data-analytics-component="global-dpa" data-analytics-element="page"> <div style="--nav-height: var(--navbar-tall)"> <div id="twBearerToken" data-value="AAAAAAAAAAAAAAAAAAAAACHguwAAAAAAaSlT0G31NDEyg%2BSnBN5JuyKjMCU%3Dlhg0gv0nE7KKyiJNEAojQbn8Y3wJm1xidDK7VnKGBP4ByJwHPb" style="display:none"></div> <div id="twAuthenticationFlag" data-value="guest" style="display:none"></div> <div id="twGeoLocationRegion" data-value="other" style="display:none"></div> <div class="u01b__page-padding"></div> <div class="u01b js-twtr-nav u01b--white u01b--text-dark twtr-color-bg--white-neutral is-fixed"> <div class="twtr-container--wide"> <div class="twtr-grid"> <div class="twtr-col-12"> <div class="u01b__nav-content"> <a class="u01b__skip-nav-content" href="#twtr-main">Skip to main content</a> <div class="u01b__nav-home"> <div class="u01b__nav-controls"> <a class="u01b__logo twtr-scribe-clicks" href="https://privacy.x.com/en" data-twtr-scribe-section="u01b-navigation" data-twtr-scribe-element="5076" data-twtr-scribe-component="twitter-logo-icon" aria-label="Privacy home"> <svg viewbox="0 0 1200 1227" xmlns="http://www.w3.org/2000/svg" aria-hidden="true" role="none" class="u01b__icon-home"> <path d="M714.163 519.284L1160.89 0H1055.03L667.137 450.887L357.328 0H0L468.492 681.821L0 1226.37H105.866L515.491 750.218L842.672 1226.37H1200L714.137 519.284H714.163ZM569.165 687.828L521.697 619.934L144.011 79.6944H306.615L611.412 515.685L658.88 583.579L1055.08 1150.3H892.476L569.165 687.854V687.828Z" /> </svg> <span class="u01b__home-link twtr-type--bold-24"> Privacy </span> </a> </div> </div> <div class="u01b__dynamic-nav" data-links-json="[{"isActive":false,"hasActiveChild":false,"children":[{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Terms of Service","linkDisabled":false,"title":"Terms of Service","path":"https://twitter.com/en/tos"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Privacy Policy","linkDisabled":false,"title":"Privacy Policy","path":"https://twitter.com/en/privacy"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Account settings","linkDisabled":false,"title":"Account settings","path":"https://twitter.com/settings/personalization"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Service providers","linkDisabled":false,"title":"Service providers","path":"https://privacy.x.com/en/subprocessors"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"X Consumer Health Data Policy","linkDisabled":false,"title":"X Consumer Health Data Policy","path":"https://privacy.x.com/en/for-our-users/x-consumer-health-data-policy"}],"overviewTitle":"Contact us","linkDisabled":false,"title":"For our users","path":"https://help.twitter.com/forms/privacy"},{"isActive":false,"hasActiveChild":true,"children":[{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"GDPR","linkDisabled":false,"title":"GDPR","path":"https://gdpr.twitter.com"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"CCPA","linkDisabled":false,"title":"CCPA","path":"https://privacy.x.com/en/ccpa"},{"isActive":true,"hasActiveChild":false,"children":[],"overviewTitle":"Global DPA","linkDisabled":false,"title":"Global DPA","path":"https://privacy.x.com/en/for-our-partners/global-dpa"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Service providers","linkDisabled":false,"title":"Service providers","path":"https://privacy.x.com/en/subprocessors"}],"overviewTitle":"Contact us","linkDisabled":false,"title":"For our partners","path":"https://help.twitter.com/forms/privacy"},{"isActive":false,"hasActiveChild":false,"children":[],"overviewTitle":"Blog","linkDisabled":false,"title":"Blog","path":"https://privacy.x.com/en/blog"}]" data-icon-chevron-right="<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewbox="0 0 24 24" aria-hidden="true" focusable="false" role="none" class="twtr-icon"> <path opacity="0" d="M0 0h24v24H0z" /> <path d="M17.207 11.293l-7.5-7.5c-.39-.39-1.023-.39-1.414 0s-.39 1.023 0 1.414L15.086 12l-6.793 6.793c-.39.39-.39 1.023 0 1.414.195.195.45.293.707.293s.512-.098.707-.293l7.5-7.5c.39-.39.39-1.023 0-1.414z" /> </svg>" data-icon-arrow-left="<svg width="28px" height="28px" viewbox="0 0 28 28" version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" aria-hidden="true" focusable="false" role="none" class="twtr-icon u01b__icon-arrow-left"> <g stroke="none" stroke-width="1" fill="none" fill-rule="evenodd" stroke-linecap="round"> <g transform="translate(-1216.000000, -298.000000)" stroke-width="2.25"> <g transform="translate(1200.000000, 282.000000)"> <g transform="translate(17.000000, 17.000000)"> <path d="M0.756410256,12.8589744 L25.7179487,12.8589744"></path> <path d="M13.2371795,25.3397436 L25.7179487,12.8589744"></path> <path d="M13.2371795,12.4807692 L25.3397436,0.378205128" transform="translate(19.288462, 6.429487) rotate(-90.000000) translate(-19.288462, -6.429487) "></path> </g> </g> </g> </g> </svg>" data-icon-chevron-down="<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewbox="0 0 24 24" aria-hidden="true" focusable="false" role="none" class="twtr-icon"> <path opacity="0" d="M0 0h24v24H0z" /> <path d="M20.207 7.043c-.39-.39-1.023-.39-1.414 0L12 13.836 5.207 7.043c-.39-.39-1.023-.39-1.414 0s-.39 1.023 0 1.414l7.5 7.5c.195.195.45.293.707.293s.512-.098.707-.293l7.5-7.5c.39-.39.39-1.023 0-1.414z" /> </svg>" data-icon-close="<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" viewbox="0 0 24 24" style="enable-background:new 0 0 24 24;" xml:space="preserve" aria-hidden="true" focusable="false" role="none" class="twtr-icon--md"> <g> <g> <defs> <rect id="SVGID_1_" x="-468" y="-1360" width="1440" height="3027" /> </defs> <clippath id="SVGID_2_"> <use xlink:href="#SVGID_1_" style="overflow:visible;" /> </clippath> </g> </g> <rect x="-468" y="-1360" class="st0" width="1440" height="3027" style="fill:rgb(0,0,0,0);stroke-width:3;stroke:rgb(0,0,0)" /> <path d="M13.4,12l5.8-5.8c0.4-0.4,0.4-1,0-1.4c-0.4-0.4-1-0.4-1.4,0L12,10.6L6.2,4.8c-0.4-0.4-1-0.4-1.4,0c-0.4,0.4-0.4,1,0,1.4 l5.8,5.8l-5.8,5.8c-0.4,0.4-0.4,1,0,1.4c0.2,0.2,0.4,0.3,0.7,0.3s0.5-0.1,0.7-0.3l5.8-5.8l5.8,5.8c0.2,0.2,0.5,0.3,0.7,0.3 s0.5-0.1,0.7-0.3c0.4-0.4,0.4-1,0-1.4L13.4,12z" /> </svg>" data-icon-search="<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewbox="0 0 24 24" aria-hidden="true" focusable="false" role="none" class="twtr-icon"> <path opacity="0" d="M0 0h24v24H0z" /> <path d="M22.06 19.94l-3.73-3.73C19.38 14.737 20 12.942 20 11c0-4.97-4.03-9-9-9s-9 4.03-9 9 4.03 9 9 9c1.943 0 3.738-.622 5.21-1.67l3.73 3.73c.292.294.676.44 1.06.44s.768-.146 1.06-.44c.586-.585.586-1.535 0-2.12zM11 17c-3.308 0-6-2.692-6-6s2.692-6 6-6 6 2.692 6 6-2.692 6-6 6z" /> </svg>" data-icon-search-submit="<svg width="21" height="21" viewbox="0 0 21 21" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true" role="none" class="twtr-icon"> <path fill-rule="evenodd" clip-rule="evenodd" d="M16.33 14.21L20.06 17.94C20.646 18.525 20.646 19.475 20.06 20.06C19.768 20.354 19.384 20.5 19 20.5C18.616 20.5 18.232 20.354 17.94 20.06L14.21 16.33C12.738 17.378 10.943 18 9 18C4.03 18 0 13.97 0 9C0 4.03 4.03 0 9 0C13.97 0 18 4.03 18 9C18 10.942 17.38 12.737 16.33 14.21ZM3 9C3 12.308 5.692 15 9 15C12.308 15 15 12.308 15 9C15 5.692 12.308 3 9 3C5.692 3 3 5.692 3 9Z" fill="white" /> </svg>" data-bg-color="white-neutral" data-root-page-title="Privacy" data-search-placeholder="Search" data-search-page="https://privacy.x.com/en/search" data-search-query-key="q" data-search-query-type="?" data-scribe-element="5076" data-scribe-section="u01b-navigation" data-cta-enabled="true" data-cta-text="Contact Us" data-cta-link="https://help.twitter.com/forms/privacy" data-cta-link-new-tab="false"> </div> <div class="u01b__static-nav"> </div> </div> </div> </div> </div> </div> <main class="twtr-color-bg--white-neutral" id="twtr-main"> <div class="ct01-columns"> <div class="ct01 twtr-padding__section--top twtr-padding__paragraph--bottom "> <div class="ct01__content twtr-container "> <div class="ct01__item twtr-grid "> <div class="ct01__column twtr-col-md-12 none "> <div class="ct01__wrapper "> <div class="b01-headline twtr-component--last twtr-component twtr-component--first"> <div class="b01 twtr-component-space--md"> <div class="b01__item"> <div class="b01__copy "> <h2 class="b01__headline twtr-type--headline-lg twtr-color--gray-900 "> X Data Processing Addendum </h2> </div> </div> </div> </div> </div> </div> </div> </div> </div> </div> <div class="ct01-columns"> <div class="ct01 twtr-padding__group--top twtr-padding__nested--bottom "> <div class="ct01__content twtr-container "> <div class="ct01__item twtr-grid "> <div class="ct01__column twtr-col-md-12 none "> <div class="ct01__wrapper "> <div class="b12-horizontal-rule twtr-component--last twtr-component twtr-component--first"> <div class=" b12 b12-thickness--base twtr-color-border--light-gray-neutral twtr-margin__nested--top twtr-margin__nested--bottom"> </div> </div> </div> </div> </div> </div> </div> </div> <div class="ct01-columns"> <div class="ct01 twtr-padding__section--top twtr-padding__section--bottom "> <div class="ct01__content twtr-container "> <div class="ct01__item twtr-grid "> <div class="ct01__column twtr-col-md-12 none "> <div class="ct01__wrapper "> <div class="b02-rich-text twtr-rte twtr-component-space--md twtr-component--last twtr-component twtr-component--first"> <div class="b02__rich-text twtr-scribe-clicks-within b02__type--large " style=" --headline-color: var(--black-neutral); --paragraph-color: var(--black-neutral);" data-twtr-scribe-section="c02-rich-text-editor" data-twtr-scribe-element="RD0A"> <p>This X Data Processing Addendum (“<b>DPA</b>”) shall amend and apply to all of your agreements (“<b>Agreements</b>”) with X, Inc., X International Unlimited Company (“<b>TIUC</b>”), and their affiliates and/or subsidiaries (collectively,“<b>X</b>”) to the extent that X processes (i) as Your processor, any personal data originating from the European Economic Area (“<b>EEA</b>”), Switzerland, the United Kingdom (“<b>UK</b>”), Brazil or Japan, or (ii) as Your service provider, any personal information of California consumers (collectively, “<b>Your Data</b>”).</p> <h5>1. Definitions</h5> <p>Words and expressions used in this DPA but not defined including, without limitation, “business,” “business purpose,” “consumer”, “controller,” “data subject,” “personal data,” “personal information,” “processing,” “processor,” “sell,” “sensitive data,” “service provider,” “sub-processor” and their respective derivative terms, shall have the meanings set forth in the privacy and data protection laws, regulations, and decisions applicable to a party to this DPA (“<b>Applicable Data Protection Law</b>”), which may include without limitation (i) the EU General Data Protection Regulation (2016/679) (“<b>GDPR</b>”), (ii) the Brazilian General Data Protection Law of 2018, Brazil Federal Law 13.709/2018, Lei Geral de Proteção de Dados, (iii) the Japanese Act on the Protection of Personal Information Act. No.57 of 2003 as amended, and its applicable regulations, and (iv) the California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100 et seq. and its implementing regulations, in each case as amended, superseded or replaced from time to time. “<b>You</b>” refers to the controller or business who has agreed to this DPA with X.</p> <h5>2. Details of the Processing Operations</h5> <p>The nature and subject matter of the processing, including the processing operations carried out by X on your behalf, Your instructions to X, and the security measures deployed by X, are described in the relevant Agreements between You and X. X acts as a processor or service provider (as applicable) for, and on behalf of, You and conducts its processing operations in accordance with Your instructions.</p> <h5>3. Your Obligations</h5> <p style="margin-left: 40.0px;"><b>3.1</b> You determine the purposes for and means by which Your Data is being or will be processed, and the manner in which they are or will be processed.</p> <p style="margin-left: 40.0px;"><b>3.2</b> You represent, warrant and agree that with respect to Your Data provided to X pursuant to this DPA, You:</p> <p style="margin-left: 80.0px;"><b>3.2.1</b> comply with data security and other obligations prescribed by Applicable Data Protection Law for controllers or businesses;</p> <p style="margin-left: 80.0px;"><b>3.2.2 </b>confirm that the provision of Your Data to X complies with Applicable Data Protection Law;</p> <p style="margin-left: 80.0px;"><b>3.2.3</b> have established a procedure for the exercise of the rights of the data subjects/consumers whose personal data or personal information is collected;</p> <p style="margin-left: 80.0px;"><b>3.2.4</b> only process personal data or personal information that has been lawfully and validly collected and ensure that such data or information is relevant and proportionate to the respective uses;</p> <p style="margin-left: 80.0px;"><b>3.2.5</b> disclose Your Data to X for a lawful business purpose consistent with the disclosures You make to Your data subjects/consumers in Your privacy policies, and You do not sell Your Data to X;</p> <p style="margin-left: 80.0px;"><b>3.2.6</b> ensure that after you have assessed the requirements of Applicable Data Protection Law, the security and confidentiality measures supported by this DPA are suitable for protection of Your Data against any accidental or unlawful destruction, accidental loss, alteration, unauthorized or unlawful disclosure or access, in particular when the processing involves data transmission over a network, and against any other forms of unlawful or unauthorized processing; and</p> <p style="margin-left: 80.0px;"><b>3.2.7</b> will take reasonable steps to ensure compliance with the provisions of this DPA by Your personnel and by any person accessing or using Your Data on Your behalf.</p> <h5>4. Obligations of X</h5> <p style="margin-left: 40.0px;"><b>4.1</b> X carries out the processing of Your Data on your behalf.</p> <p style="margin-left: 40.0px;"><b>4.2</b> Accordingly, X agrees that it will:</p> <p style="margin-left: 80.0px;"><b>4.2.1</b> unless otherwise required by applicable law, process Your Data only on Your behalf and in compliance with Your instructions (including relating to international data transfers), including instructions in this DPA and all Agreements between You and X;</p> <p style="margin-left: 80.0px;"><b>4.2.2</b> immediately inform You if in X’s opinion an instruction from You infringes Applicable Data Protection Law;</p> <p style="margin-left: 80.0px;"><b>4.2.3</b> implement appropriate technical and organizational security measures as provided for in Your Agreements with X prior to the commencement of the processing activities for Your Data, maintain such security measures (or better security measures) for the duration of this DPA, and provide You with reasonable evidence of its privacy and security policies;</p> <p style="margin-left: 80.0px;"><b>4.2.4</b> take reasonable steps to ensure that (i) persons employed by it and (ii) other persons engaged at its place of business who may process Your Data are aware of and comply with this DPA;</p> <p style="margin-left: 80.0px;"><b>4.2.5</b> comply with confidentiality obligations in respect of Your Data as detailed in all Agreements and take appropriate steps to ensure that its employees, authorized agents and any sub-processors comply with and acknowledge and respect the confidentiality of Your Data, including after the end of their employment, contract or at the end of their assignment;</p> <p style="margin-left: 80.0px;"><b>4.2.6 </b>inform You of:</p> <p style="margin-left: 120.0px;"><b>4.2.6.1</b> any legally binding request for disclosure of Your Data by a law enforcement authority, unless otherwise prohibited, such as in order to preserve the confidentiality of an investigation by the law enforcement authorities, and you acknowledge that X may disclose Your Data to comply with such a legally binding disclosure request;</p> <p style="margin-left: 120.0px;"><b>4.2.6.2</b> any personal data breach (or analogous concept) under Applicable Data Protection Law relating to Your Data (“Security Incident”);</p> <p style="margin-left: 120.0px;"><b>4.2.6.3</b> any relevant notice, inquiry or investigation by a supervisory authority relating to Your Data; and</p> <p style="margin-left: 120.0px;"><b>4.2.6.4</b> any requests from a data subject/consumer to exercise their data protection rights under Applicable Data Protection Law without responding to that request, unless You have authorized a response or such a response is required by law;</p> <p style="margin-left: 80.0px;"><b>4.2.7</b> provide You with reasonable co-operation and assistance in respect of Your obligations regarding:</p> <p style="margin-left: 120.0px;"><b>4.2.7.1</b> requests from data subjects/consumers in respect of the exercise of their data protection rights under Applicable Data Protection Law with respect to Your Data;</p> <p style="margin-left: 120.0px;"><b>4.2.7.2</b> the investigation of any Security Incident and the notification to the supervisory authority and data subjects in respect of such a Security Incident;</p> <p style="margin-left: 120.0px;"><b>4.2.7.3</b> the preparation of data protection impact assessments and, where applicable, carrying out consultations with the supervisory authority, in each case where and to the extent required by Applicable Data Protection Law;</p> <p style="margin-left: 120.0px;"><b>4.2.7.4</b> the security of Your Data, including by implementing the technical and organizational security measures detailed in Your Agreements with X;</p> <p style="margin-left: 80.0px;"><b>4.2.8</b> if X is required by law to process Your Data, take reasonable steps to inform You of this requirement in advance of any processing, unless X is prohibited from informing You on grounds of important public interest; and</p> <p style="margin-left: 80.0px;"><b>4.2.9 </b>upon reasonable request, make available to You all information necessary to demonstrate compliance with the obligations in this Section 4.2. X will further comply with its audit responsibilities set out in Section 4.4 below.</p> <p style="margin-left: 40.0px;"><b>4.3</b> You and X further agree that:</p> <p style="margin-left: 80.0px;"><b>4.3.1</b> X is acting solely as a processor, service provider or in such other similar capacity as may be understood under Applicable Data Protection Law with respect to Your Data;</p> <p style="margin-left: 80.0px;"><b>4.3.2</b> X shall not retain, use or disclose Your Data for any purpose other than for the specific purpose of performing the services specified in this DPA or any other Agreement between You and X; and</p> <p style="margin-left: 80.0px;"><b>4.3.3</b> X may deidentify, aggregate, or anonymize all or portions of Your Data so that it no longer constitutes personal data or information under Applicable Data Protection Laws as part of its performance of services specified in this DPA and any other Agreement between You and X.</p> <p style="margin-left: 40.0px;"><b>4.4</b> X will, upon Your request (not to exceed one request per calendar year unless required by Applicable Data Protection Law) by email to dpo@X.com, certify compliance with Sections 4-6 of this DPA in writing. X will also provide to you each year an opinion or Service Organization Control report provided by an accredited, third-party audit firm under the Statement on Standards for Attestation Engagements (SSAE) No. 18 (“<b>SSAE 18</b>”) (Reporting on Controls at a Service Organization) or the International Standard on Assurance Engagements (ISAE) 3402 (“<b>ISAE 3402</b>”) (Assurance Reports on Controls at a Service Organization) standards applicable to the data processing services under the Agreements (each such report, a “<b>Report</b>”). If a Report does not provide, in Your reasonable judgment, sufficient information to confirm X’s compliance with the terms of this DPA, then You or an accredited third-party audit firm agreed to by both You and X may audit X’s compliance with the terms of this DPA during regular business hours in a manner that is not disruptive to X’s business, upon reasonable advance notice to X of no less than 60 days and subject to reasonable confidentiality procedures. You are responsible for all costs and fees related to such audit, including all reasonable costs and fees for any and all time X expends for any such audit, in addition to the rates for support services performed by X and any expenses incurred by X in complying with this Section 4.4 and Section 4.2.7. Before the commencement of any such audit, You and X will mutually agree upon the timing, duration and scope of the audit, which will not involve physical access to the servers from which the data processing services are provided in order to maintain the security of X’s systems and to preserve the confidentiality of other customers’ data. You will promptly notify X of information regarding any non-compliance discovered during the course of an audit. Where applicable, you agree to exercise Your audit rights under the SCCs (defined below) by instructing us to comply with the audit measures described in this Section 4.4.</p> <p style="margin-left: 40.0px;"><b>4.5</b> If (i) Your Data includes any personal data that is protected under the GDPR or Applicable Data Protection Law of Switzerland or the UK, (ii) X processes such personal data outside of the EEA, Switzerland, or the UK; and (iii) such processing takes place in a country that is not subject to an adequacy determination by the European Commission, the UK or Swiss authorities (as applicable), then the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 (“<b>SCCs</b>”) are hereby incorporated by reference and form an integral part of this DPA. The SCCs shall apply as follows:</p> <p style="margin-left: 80.0px;"><b>4.5.1.</b> <b>EEA Transfers</b>, To the extent that Your Data is subject to the GDPR, the SCCs apply as follows:</p> <p style="margin-left: 120.0px;">i. the “data exporter” is You and the “data importer” is X;</p> <p style="margin-left: 120.0px;">ii. the Module Two terms are selected;</p> <p style="margin-left: 120.0px;">iii. in Clause 7, the optional docking clause applies; </p> <p style="margin-left: 120.0px;">iv. in Clause 9, Option 2 applies and the time period for prior notice of sub-processor changes is set out in Section 5 of this DPA;</p> <p style="margin-left: 120.0px;">v. in Clause 11, the optional language does not apply; </p> <p style="margin-left: 120.0px;">vi. in Clause 17, Option 1 applies and the SCCs are governed by Irish law;</p> <p style="margin-left: 120.0px;">vii. in Clause 18(b), disputes will be resolved before the courts of Ireland;</p> <p style="margin-left: 120.0px;">viii. in Annex I.A and I.B, the details of the parties and description of the transfer are set out in the relevant Agreements between You and X;</p> <p style="margin-left: 120.0px;">ix. in Clause 13(a) and Annex I.C, the competent supervisory authority is the supervisory authority of the EEA member state in which You or Your representative is in or where the data subjects are predominantly located;</p> <p style="margin-left: 120.0px;">x. in Annex II, the description of the technical and organizational security measures is set out in the relevant Agreements between You and X; and</p> <p style="margin-left: 120.0px;">xi. in Annex III, the list of Sub-processors is outlined in Section 5 of this DPA.</p> <p style="margin-left: 80.0px;"><b>4.5.2.</b> <b>Swiss Transfers</b>. To the extent that Your Data is subject to the Applicable Data Protection Law of Switzerland, the SCCs apply as set out in Section 4.5.1 of this DPA with the following modifications:</p> <p style="margin-left: 120.0px;">i. references to ‘Regulation (EU) 2016/679’ are interpreted as references to the Swiss Federal Data Protection Act of 19 June 1992 or any successor thereof (“<b>Swiss DPA</b>”);</p> <p style="margin-left: 120.0px;">ii. references to specific articles of ‘Regulation (EU) 2016/679’ are replaced with the equivalent article or section of the Swiss DPA;</p> <p style="margin-left: 120.0px;">iii. references to ‘EU’, ‘Union’ and ‘Member State’ are replaced with ‘Switzerland’;</p> <p style="margin-left: 120.0px;">iv. Clause 13(a) and Part C of Annex 2 are not used and the ‘competent supervisory authority’ is the Swiss Federal Data Protection Information Commissioner (“<b>FDPIC</b>”), or, if the transfer is subject to both the Swiss DPA and the GDPR, the FDPIC (insofar as the transfer is governed by the Swiss DPA) or the supervisory authority of the EEA member state in which You or Your representative is in or where the data subjects are predominantly located (insofar as the transfer is governed by the GDPR;</p> <p style="margin-left: 120.0px;">v. references to the ‘competent supervisory authority’ and ‘competent courts’ are replaced with the FDPIC and ‘competent Swiss courts’;</p> <p style="margin-left: 120.0px;">vi. in Clause 17, the SCCs are governed by the laws of Switzerland;</p> <p style="margin-left: 120.0px;">vii. in Clause 18(b), disputes will be resolved before competent Swiss courts; and </p> <p style="margin-left: 120.0px;">viii. the SCCs also protect the data of legal entities until entry into force of the revised Swiss DPA.</p> <p style="margin-left: 80.0px;"><b>4.5.3.</b> <b>UK Transfers.</b> To the extent that Your Data is subject to the Applicable Data Protection Law of the UK, the SCCs apply as amended by Part 2 of the UK Addendum to the SCCs issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018 (“<b>UK Addendum</b>”), and Part 1 of the UK Addendum is deemed completed as follows:</p> <p style="margin-left: 120.0px;">i. in Table 1, the details of the parties are set out in the Agreements between You and X;</p> <p style="margin-left: 120.0px;">ii. in Table 2, the selected modules and clauses are set out in Section 4.5.1 of this DPA</p> <p style="margin-left: 120.0px;">iii. in Table 3, the appendix information is set out in the Agreements between You and X; and</p> <p style="margin-left: 120.0px;">iv. in Table 4, the ‘Importer’ is selected.</p> <p style="margin-left: 80.0px;"><b>4.5.4. Alternative Transfer Mechanism.</b> In the event that a court of competent jurisdiction or supervisory authority orders (for whatever reason) that the measures described in this DPA cannot be relied on to lawfully transfer Your Data, You shall fully co-operate with X to sign an amendment to this DPA and/or execute such other documents and take such other actions as may be necessary to remedy such non-compliance. In addition, if X adopts an alternative data transfer mechanism to the mechanisms described in this DPA, including any new version of or successor to the SCCs or Privacy Shield (“<b>Alternative Transfer Mechanism</b>”), such Alternative Transfer Mechanism shall apply automatically instead of the measures described in this DPA but only to the extent such Alternative Transfer Mechanism complies with Applicable Data Protection Law and extends to the territories in which Your Data is transferred.<br /> </p> <h5>5. Transfer, Disclosure and Third Parties</h5> <p style="margin-left: 40.0px;"><b>5.1 </b>You acknowledge and agree that (a) X’s affiliates may be retained as sub-processors and (b) X and X’s affiliates may engage sub-processors in connection with the provision of the data processing services. X or a X affiliate shall enter into contractual arrangements with such sub-processors requiring them to guarantee a similar level of data protection compliance and information security to that provided for herein. For the purposes of this Section 5, You hereby authorize X to engage sub-processors required to assist X for the purposes of providing the data processing services under the Agreements.</p> <p style="margin-left: 40.0px;"><b>5.2 </b>A current list of sub-processors for the data processing services is accessible via <a href="https://privacy.twitter.com/en/subprocessors" target="_blank">privacy.twitter.com</a>. We will endeavor to provide reasonable notice to You before we engage a new sub-processor of Your Data, including the date on which the new sub-processor will begin processing Your Data (the “<b>Sub-Processor Effective Date</b>”). You may object to X’s engagement of a new sub-processor by ceasing to use the applicable product, program or feature prior to the Sub-Processor Effective Date. Your continued use of the applicable product, program or feature on or after the Sub-Processor Effective Date constitutes your acceptance of the new sub-processor. For the purposes of the SCCs, You acknowledge that we may be restricted from disclosing sub-processor agreements to You due to confidentiality obligations but where we cannot disclose a sub-processor agreement, we shall provide all information (on a confidential basis) to You that we reasonably can in connection with such agreement.</p> <h5>6. Post-termination obligations</h5> <p>You and X agree that on the termination of any of the data processing services, X and any sub-processors shall, upon request, subject to the limitations described in any relevant Agreements, return all of Your Data relating to such data processing services and copies of such data to You or securely destroy them and demonstrate to Your reasonable satisfaction that it has taken such measures, unless applicable law prevents it from returning or destroying all or part of Your Data. In such a case, X or a sub-processor agree to preserve the confidentiality of Your Data retained by it and that it will only actively process Your Data after such date in order to comply with the laws to which it is subject.</p> <h5>7. Conflicts</h5> <p>In the event of any conflict between the terms of this DPA, the SCCs and any other terms between You and X, including but not limited to the terms of any Agreements, the terms shall apply in the following order of precedence: (i) the SCCs, (ii) this DPA, and then (iii) any other terms of your Agreements between You and X. This agreement is written in English and may be translated into other languages and made available by X. The version in English will prevail over versions translated into other languages, which are for mere reference.</p> </div> </div> </div> </div> </div> </div> </div> </div> </main> <div> <footer class="u02 twtr-background--blue-500"> <div class="twtr-container"> <div class="u02__wrapper"> <div class="u02__row u02__network-map"> </div> <div class="u02__row u02__legal"> <div class="twtr-grid u02__twtr-grid u02__bottom-container"> <div class="u02__column u02__column--bottom"> <span class="u02__column-footnote twtr-type--roman-14 twtr-color--gray-0 is-opaque"> © 2024 X Corp. </span> </div> <div class="u02__column u02__column--bottom"> <a href="https://help.x.com/rules-and-policies/twitter-cookies" title="Cookies" target="_blank" class="u02__column-footnote u02__meta-links twtr-type--roman-14 twtr-color--gray-0 is-opaque has-hover twtr-scribe-clicks" data-twtr-scribe-section="u02-footer" data-twtr-scribe-element="7QVD" data-twtr-scribe-component="cookies"> Cookies </a> </div> <div class="u02__column u02__column--bottom"> <a href="https://x.com/privacy" title="Privacy" target="_blank" class="u02__column-footnote u02__meta-links twtr-type--roman-14 twtr-color--gray-0 is-opaque has-hover twtr-scribe-clicks" data-twtr-scribe-section="u02-footer" data-twtr-scribe-element="7QVD" data-twtr-scribe-component="privacy"> Privacy </a> </div> <div class="u02__column u02__column--bottom"> <a href="https://x.com/tos" title="Terms and conditions" target="_blank" class="u02__column-footnote u02__meta-links twtr-type--roman-14 twtr-color--gray-0 is-opaque has-hover twtr-scribe-clicks" data-twtr-scribe-section="u02-footer" data-twtr-scribe-element="7QVD" data-twtr-scribe-component="terms-and-conditions"> Terms and conditions </a> </div> <div class="u02__column u02__column--bottom"> <div class="u03"> <button class="u03__current-region js-open twtr-type--roman-14 twtr-color--gray-0 is-opaque has-hover" aria-label="Select Region" type="button"> English <svg xmlns="http://www.w3.org/2000/svg" width="17" height="9.5" viewbox="0 0 17 9.5" aria-hidden="true" focusable="false" role="none" class="twtr-icon--sm twtr-color-fill--white-neutral has-hover"> <path d="M16.707.293c-.39-.39-1.023-.39-1.414 0L8.5 7.086 1.707.293c-.39-.39-1.023-.39-1.414 0s-.39 1.023 0 1.414l7.5 7.5c.195.195.45.293.707.293s.512-.098.707-.293l7.5-7.5c.39-.39.39-1.023 0-1.414z" /> </svg> </button> <div class="u03__modal twtr-color-bg--blue-extra-dark" role="dialog" aria-label="Select language" aria-modal="true"> <button type='button' class="u03__close-button js-close" aria-label="close"> <span class="twtr-hidden--xs twtr-hidden--sm"><svg xmlns="http://www.w3.org/2000/svg" width="46" height="72" viewbox="0 0 46 72" aria-hidden="true" focusable="false" role="none" class="twtr-icon--lg twtr-color-fill--white-neutral has-hover"> <path d="M27.243 36l14.879-14.879a2.998 2.998 0 0 0 0-4.242 2.998 2.998 0 0 0-4.242 0L23 31.758 8.122 16.879a2.998 2.998 0 0 0-4.242 0 2.998 2.998 0 0 0 0 4.242L18.758 36 3.879 50.879A2.998 2.998 0 0 0 6.001 56a2.99 2.99 0 0 0 2.121-.879L23 40.242l14.879 14.879A2.991 2.991 0 0 0 40 56a2.998 2.998 0 0 0 2.121-5.121L27.243 36z" /> </svg></span> <span class="twtr-hidden--md twtr-hidden--lg twtr-hidden--xl"><svg xmlns="http://www.w3.org/2000/svg" width="46" height="72" viewbox="0 0 46 72" aria-hidden="true" focusable="false" role="none" class="twtr-icon--lg twtr-color-fill--white-neutral has-hover"> <path d="M27.243 36l14.879-14.879a2.998 2.998 0 0 0 0-4.242 2.998 2.998 0 0 0-4.242 0L23 31.758 8.122 16.879a2.998 2.998 0 0 0-4.242 0 2.998 2.998 0 0 0 0 4.242L18.758 36 3.879 50.879A2.998 2.998 0 0 0 6.001 56a2.99 2.99 0 0 0 2.121-.879L23 40.242l14.879 14.879A2.991 2.991 0 0 0 40 56a2.998 2.998 0 0 0 2.121-5.121L27.243 36z" /> </svg></span> </button> <!-- From accessibility standpoint close button goes first, logo should be second when displayed, as close button is always displayed in all views (desktop and mobile). --> <a href="https://privacy.x.com/en" class="u03__brand"> <svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewbox="0 0 24 24" aria-hidden="true" focusable="false" role="none" class="u03__brand-icon twtr-icon--base twtr-color-fill--white-neutral"> <path opacity="0" d="M0 0h24v24H0z" /> <path d="M23.643 4.937c-.835.37-1.732.62-2.675.733.962-.576 1.7-1.49 2.048-2.578-.9.534-1.897.922-2.958 1.13-.85-.904-2.06-1.47-3.4-1.47-2.572 0-4.658 2.086-4.658 4.66 0 .364.042.718.12 1.06-3.873-.195-7.304-2.05-9.602-4.868-.4.69-.63 1.49-.63 2.342 0 1.616.823 3.043 2.072 3.878-.764-.025-1.482-.234-2.11-.583v.06c0 2.257 1.605 4.14 3.737 4.568-.392.106-.803.162-1.227.162-.3 0-.593-.028-.877-.082.593 1.85 2.313 3.198 4.352 3.234-1.595 1.25-3.604 1.995-5.786 1.995-.376 0-.747-.022-1.112-.065 2.062 1.323 4.51 2.093 7.14 2.093 8.57 0 13.255-7.098 13.255-13.254 0-.2-.005-.402-.014-.602.91-.658 1.7-1.477 2.323-2.41z" /> </svg> <span class="u03__site-name twtr-type--bold-16 twtr-color--gray-0">Privacy</span> </a> <div class="u03__region-list-container"> <div class="twtr-container"> <ul class="u03__region-list twtr-grid" data-choose-text="Choose a region" data-back-text="Back"> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/en/for-our-partners/global-dpa" class="twtr-color--blue-light u03__region-list-item--underline twtr-type--bold-24 has-hover u03__region-link" aria-current="page"> English </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/de/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Deutsch </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/es/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Español </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/fr/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Français </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/ja/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> 日本語 </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/ru/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Русский </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/ko/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> 한국어 </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/it/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Italiano </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/pt/for-our-partners/global-dpa" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Português </a> </li> <li class="u03__region-list-item twtr-col-md-4"> <a href="https://privacy.x.com/nl" class="twtr-color--gray-0 twtr-type--bold-24 has-hover u03__region-link"> Nederlands </a> </li> </ul> </div> </div> </div> </div> </div> </div> </div> </div> </div> </footer> </div> <div id="page-props" data-privacy-config="disabled" data-page-title="Global DPA" data-page-path="/content/privacyexternal-twitter/en/for-our-partners/global-dpa"> </div> <script type="text/javascript" src="https://platform.twitter.com/widgets.js"></script> <script type="text/javascript" src="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/js/core.js.twhash.p.f.c0a06ce3def1bf9035729fcf1b100bd4.js"></script> <script type="text/javascript" src="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/js/project.js.twhash.p.f.5caeb0a72a465377a65bfe8526d47b94.js"></script> <script type="text/javascript" src="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/public/js/languages.js.twhash.p.f.fb1c01199f340f8fde1ec50a6818b688.js"></script> <div id="u12" class="u12-data-protection-notice"> <div class="u12-data-protection-notice__item u12-data-protection-notice__item--b is-hidden"> <div class="u12b-opt-in" id="u12b" data-cname="twtr_pixel_opt_in"> <div class="u12b-opt-in__item u12-data-protection-notice__notice"> <div class="u12b-opt-in__content"> <div class="u12b-opt-in__copy"> <p class="mtc-font twtr-font"> <b>Did someone say … cookies?</b><br /><br /> X and its partners use cookies to provide you with a better, safer and faster service and to support our business. Some cookies are necessary to use our services, improve our services, and make sure they work properly. <a href="https://help.twitter.com/rules-and-policies/twitter-cookies" target="_blank">Show more about your choices</a>. </p> </div> <div class="u12b-opt-in__choice twtr-scribe-clicks-within"> <ul class="u12b-opt-in__choice-list"> <li class="u12b-opt-in__choice-list-item"> <button class="u12b-opt-in__button is-blue u12b-opt-in__button--accept mtc-font twtr-font js-accept twtr-scribe-clicks" data-twtr-scribe-section="u12-data-protection-notice" data-twtr-scribe-element="S8YN" data-twtr-scribe-component="data-protection-notice"> Accept all cookies </button> </li> <li class="u12b-opt-in__choice-list-item"> <button class="u12b-opt-in__button is-naked u12b-opt-in__button--decline mtc-font twtr-font js-decline twtr-scribe-clicks" data-twtr-scribe-section="u12-data-protection-notice" data-twtr-scribe-element="S8YN" data-twtr-scribe-component="data-protection-notice"> Refuse non-essential cookies </button> </li> </ul> </div> </div> </div> </div> </div> </div> <link rel="stylesheet" href="https://cdn.cms-twdigitalassets.com/etc/designs/common-twitter/clientlib-u12-data-protection-notice.min.twhash.p.cl.8d93205985d36dea4268f79e373e2b02.css" type="text/css"> <script src="https://cdn.cms-twdigitalassets.com/etc/designs/common-twitter/clientlib-u12-data-protection-notice.min.twhash.p.cl.3734d48c62d11c8682b708637c1691ea.js"></script> <script src="https://cdn.cms-twdigitalassets.com/etc/designs/boilerplate-twitter/clientlibs-refsource.min.twhash.p.cl.7130200325ea3a5900605ca508f725b9.js"></script> </div> </body> </html>