Criteo Data Protection Agreement ENG.pdf

CRITEO DATA PROTECTION AGREEMENT

PREAMBLE

This Criteo Data Protection Agreement (hereafter the “DPA”) supplements the Criteo Umbrella Terms of Service (the “Terms”) and the relevant Criteo Specific Terms of Service or any other applicable agreement with the Partner (collectively, the “Agreement”) and is hereby incorporated into the Agreement between Criteo and the Partner for the provision of the relevant Services.

This DPA describes the data protection and security obligations of the Partner and Criteo SA (RCS 484 786 249), except where the audience selected by the Partner is in the United States of America, in which case this DPA is binding upon the Partner and Criteo Corp., with respect to any Processing of Personal Data carried out in connection with the provision of the relevant Services. The term includes similar terms as defined under applicable Data Protection Law such as “Personal Information” and “personally identifiable information.”

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Regulatory Authority” means the competent public authority(ies) or government agency(ies) responsible for supervising compliance with Data Protection Law, including but not limited to the French CNIL (Criteo’s lead supervisory authority), UK Information Commissioner’s Office, California Privacy Protection Agency or U.S. state attorneys general.

“Sale" means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, Personal Information to a Third Party for monetary or other valuable consideration.

“Sharing" means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, an individual’s Personal Information to a Third Party for cross-context behavioral advertising (as defined by the CCPA), whether or not for monetary or other valuable consideration.

“Third Party” means the natural or legal person that receives Personal Information from the Business for its own independent purposes, and that is not engaged by the Business as a Service Provider or contractor.

2 Scope and Roles of the Parties

2.1 This DPA applies to Processing of Personal Data carried out in the context of the provision of the Services ordered by the Partner where, for purposes of EU GDPR and UK GDPR, Criteo and the Partner act as independent Controllers, except for the reading/writing of information on devices for which Criteo and the Partner act as joint Controllers. For purposes of the CCPA, Partner acts as a Business and Criteo as a Third Party.

3 Compliance with Law

3.1 Each Party shall comply and shall be able to demonstrate its compliance with its respective obligations under Data Protection Law and in accordance with this DPA. 3.2 Each Party represents and warrants that (i) it shall not, through any act or omission, put the other Party in violation of the Bulk Data Transfer Rule through the use of Personal Data, (ii) it is not a covered person (as defined by the Bulk Data Transfer Rule) or controlled directly or indirectly by a covered person; or (iii) it is not located in a country of concern (as defined by the Bulk Data Transfer Rule), whether via the presence of an office or personnel, and (iv) it shall ensure that no Personal Data associated with U.S. Data Subjects is transferred to or accessible by, directly or indirectly, a covered person or to a country of concern in a manner that does not maintain full compliance with the Bulk Data Transfer Rule by both Parties. If a Party is a foreign person (as defined by the Bulk Data Transfer Rule) but not a covered person, it shall immediately report any known or suspected violation of the foregoing representations to the other Party and the U.S. Department of Justice, in accordance with 28 C.F.R. § 202.302. Upon written request from a Party, the other Party shall have an authorized officer of such Party sign a certification attesting to compliance with this section and the Bulk Data Transfer Rule. “Bulk Data Transfer Rule” means the “Provisions Pertaining to Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons” (28 CFR Part 202) issued by the U.S. Department of Justice, as modified from time to time, together with all guidance thereto provided by the U.S. Department of Justice and any comparable laws.

4 Authorizations

4.1 A Party shall not disclose Personal Data to the other Party, except where the disclosing Party (c) Maintain records (e) Where Partner is required by Data Protection Law to obtain valid Consent prior to the Processing of Personal Data as part of the Services, offer Data Subjects the right to withdraw Consent; (f) Where Partner is required by Data Protection Law to offer valid opt-out mechanisms prior to the Processing of Personal Data as part of the Services, offering Data Subjects the right to opt-out of the Sale and Sharing of their Personal Data and use of the Personal Data for purposes of cross contextual behavioral advertising; (g) Request Consent from the Data Subjects once the validity period of this Consent (as provided for under Data Protection Law) has expired; (h) Where applicable, Partner represents and warrants that each of its third-party advertising technology partners whose advertising space on Digital Properties is made available for sale through Criteo Platform (each a “Consented Third-party Vendor”) fully complies with the provision of this DPA; and (i) Providing promptly to Criteo, upon request and at any time, proof that a Data Subject’s Consent has been obtained by the Partner.