TAAP 在线协议 – 控制方到控制方协议(包括 SCC)

本 C2C 协议的英文原始版本可能已翻译成其他语言。如果本协议的英文版本与任何其他语言译本之间存在不一致或矛盾的情况,应以英文版本为准。

范围:当 Expedia 和贵方各自根据与另一方签订的协议(可能采用在线点击生效条款的形式)处理个人数据(根据该协议,贵方已被指定为 TAAP 下的营销合作伙伴),以及与该活动相关的所有相关活动(在此称为“相关活动”)时,本全球控制方到控制方协议(以下简称“C2C 协议”)是对双方就相关活动达成的此类协议(以下简称“协议”)的补充并适用于此类协议,还规定了 Expedia 和贵方各自处理与协议相关的个人数据的附加条款、要求和条件。在本“C2C 协议”中,“Expedia”、“我们”和“我方”是指 Expedia, Inc. 和/或“协议”涉及的任何其他 Expedia Group 旗下公司。“贵方”是指“协议”中所述的 App 中声明的指定实体。

1. 定义与解释

1.1 本“C2C 协议”受“协议”条款约束,并纳入协议。除非本“C2C 协议”另有规定,否则“协议”中规定的解释及定义的术语适用于本“C2C 协议”的解释;并且:

  1. a.每个恰当的技术和组织措施、控制方、个人数据、个人数据泄露、处理、监管机构(或合理对等术语)应具有适用数据保护法律赋予其的含义;
  2. b. 适用数据保护法律 是指任何相关司法管辖区中与个人数据的使用或处理有关的任何适用的法律和法规;
  3. c. 获准用途 指下述用途:(i) 履行预订;(ii) 提供预订支持;(iii) TAAP 注册和帐户管理;(iv) 根据“协议”支付佣金和其他款项;(v) 为贵方生成报告以及与服务“协议”相关的对账、投诉处理和类似活动所需的任何进一步处理;(vi) TAAP 帐户支持;(vii) 与 TAAP 成员和子用户的通信;(viii) 改进我方的服务,包括优化预订体验;(ix) 为分析、商业情报和业务报告创建报告;(x) 预防欺诈;(xi) 回应执法协查要求和税务机关审计要求;(xii) 促进业务资产交易(可扩展至任何兼并、收购或资产出售);(xiii) 以其他方式遵照我方在“协议”、Expedia 隐私政策和适用法律下的义务,以及 (xiv) 用于确定、计算、报告旅行税和其他可能不时要求的适用税务用途;
  4. d. DPF指美国商务部的欧盟-美国数据隐私框架认证或欧盟委员会(或其他相关国家机构)不时批准的任何替代或补充认证机制;并包括任何其他国家/地区发布的允许在美国和该第三国家/地区(例如但不限于英国和瑞士)之间扩展 DPF 的任何补充的充分性决定;
  5. e. 受限转移国家/地区是指欧洲经济区内的任何国家/地区、瑞士、英国和巴西;
  6. f. 受限转移数据是指与通过我方用于供受限转移国家/地区的客户访问的销售网站进行的预订相关的客户数据;
  7. g. 标准合同条款/SCC 指于 2021 年 6 月 4 日发布的、经批准的欧盟委员会关于从欧盟向第三国家/地区传输个人数据的标准合同条款,并不时修订、替换、补充或取代,其完整的最新版本可以通过以下链接找到: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
  8. h. TAAP 个人数据指贵方通过 TAAP 网站或其他与 TAAP 本身相关或有助于推动使用 TAAP 网站进行预订而提供给我方的个人数据。
双方关系
  1. 1.2 贵方和我方将各自收集和处理客户数据,以行使贵方和我方根据“协议”分别具有的权利并履行相关的义务,以及贵方和我方根据适用的数据保护法各自应承担的责任。因此,各方应:(i) 作为独立自主的控制方处理个人数据;(ii) 遵照适用的数据保护法;且 (iii) 对自身在违反适用的数据保护法方面的任何作为或不作为负责。
贵方的责任

1.3 贵方必须:

Your responsibilities
  1. a. 满足法律要求,以便能够为我方提供任何 TAAP 个人数据,以便我们出于获准用途对其进行处理;
  2. b. 确保通过贵方隐私政策以及任何其他适当手段,让客户知道他们的个人数据将共享给我方用于获准用途;
  3. c. 将客户定向至我方的隐私政策,以便客户了解关于我方处理其个人数据的更多信息;并且
  4. d. 配合我方并向我方提供合理协助,以协助我方在处理与“协议”相关的 TAAP 个人数据的过程中遵照适用的数据保护法。
我方的责任

1.4 我方(及我方集团成员,视情况而定)应: 

  1. a. 仅处理与获准用途有关的 TAAP 个人数据;
  2. b. 不得向任何人泄露 TAAP 个人数据的全部或任何部分,但与获准用途有关的泄露除外;
  3. c. 配合贵方并向贵方提供合理协助,以协助贵方在处理与“协议”相关的 TAAP 个人数据过程中遵照适用的数据保护法律。
  4. d. 在 TAAP 网站上显示并遵照合法且最新的 cookie 通知(如需要)和我方的隐私政策。
客户和第三方

1.5 贵方确认,我方:

  1. a. 可向客户发送预订相关的电子邮件;
  2. b. 可出于以下目的向我方的第三方服务提供商传输 TAAP 个人数据(包括银行数据):
    1. i. 提供、管理和支持贵方的 TAAP 帐户、贵方代表的 TAAP 帐户和贵方子用户的 TAAP 帐户;
    2. ii. 提供预订支持;及
    3. iii. 根据“协议”支付佣金和其他款项。
数据安全

1.6 作为控制方,双方应:

  1. a. 继续采取恰当的技术和组织措施以保护各方处理的个人数据免遭个人数据泄露;且
  2. b. 在一方拥有或控制的系统中,如果确认个人数据已泄露,且个人数据泄露涉及以下两种情况,则及时通知另一方:(i) 影响到根据“协议”还会由另一方处理的 TAAP 个人数据;并且 (ii) 应向监管机构报告,并提供该数据泄露的完整详情。在此情况下,双方应当合理善意地配合以补救或减轻个人数据泄露的影响,且此类配合的合理费用应由遭遇个人数据泄露的一方承担。
跨境传输 

1.7 数据隐私框架 (DPF):: 贵方和我方同意,将贵方和我方之间的受限传输数据传输至美国或根据美国适用数据保护法未被视为“适当”的国家/地区时,(a) 如果 DPF 是相关机构认可的传输方法,DPF 就应成为从受限传输国家/地区向我方在美国的机构跨境传输数据的商定机制,以及 (b) 如果 DPF 不是有效的传输方法(包括将受限传输数据传输到原始受限传输国家/地区的适用数据保护法未被视为“适当”的国家/地区),SCC 应适用于此类传输,我方将根据下文第 1.11 条的规定签订这些条款。如果贵方还持有最新的 DPF 认证,则同样可以根据 DPF 向贵方传输受限传输数据,并将 SCC 作为后备机制,如上所述。

1.8 DPF 传输义务:: 贵方同意将为受限传输数据提供至少与 DPF 要求级别相同的保护;如果贵方确定无法再提供此类级别的保护,贵方应立即通知我方。在这种情况下,或者如果我方有理由认为贵方没有按照 DPF 要求的标准保护受限传输数据,我方可以:(a) 指示贵方采取合理且适当的措施来停止和纠正任何未经授权的处理,在这种情况下,贵方需要立即真诚地与我方合作,确定、同意并实施此类步骤;(b) 同意根据适用的数据保护法可能适用于处理的替代保障措施;(c) 通过向贵方发出通知终止本“C2C 协议”和“协议”(或由我方选择终止其任何受影响的部分),而不需要支付罚金。如果贵方还持有有效的 DPF 认证,则应适用上述规定和下文第 1.9 条的规定,因为义务是双向的。

1.9 DPF 披露义务:: 贵方承认,我方可以应美国商务部、联邦贸易委员会、任何欧洲数据保护机构或任何其他美国或欧盟司法或监管机构的要求,向其披露本“C2C 协议”和“协议”中的任何相关隐私条款,并且任何此类披露均不应被视为违反保密规定。

1.10 将 SCC 扩展到非受限传输国家/地区:: 关于贵方与我方之间来自非受限传输国家/地区但受相关措施保障的传输,根据适用的数据保护法,在将该 TAAP 个人数据传输到来源国之外(每个非限制传输国家/地区)之前必须适用的保障措施。此外,贵方和我方同意 (a) 下文第 1.11 条规定的 SCC 应被视为扩展到此类额外传输,前提是此类扩展将满足该特定国家/地区的保障措施;和/或 (b) 如果第 1.11 条规定的措施不足或需要补充措施,双方同意采取进一步措施,例如,签署相关文件、收集同意、进行必要的备案,以满足适用的数据保护法不时的要求。

1.11 根据上述第 1.7 条,贵方和我方特此同意在保持不变的基础上签订 SCC,但以下情况除外::

  1. a. 如果贵方位于受限传输国家/地区或根据 GDPR 第 45 条被视为“适当”的国家/地区,则仅 SCC 模块一 (1) 将单向适用于从贵方到 Expedia 的传输。否则,模块一 SCC 适用于从我方到贵方以及从贵方到我方的双向传输。
  2. b. 依据 SCC 第 11 (a),删除了可选语言。
  3. c. 依据 SCC 第 13 条,相关段落是“主管监管机构应为按照法规 (EU) 2016/679 第 27 (1) 条的含义设立了代表的成员国所在的监管机构,如附件 I.C 所示。”
  4. d. 依据 SCC 第 17 条,管辖法律是爱尔兰法律。
  5. e. 依据 SCC 第 18(b) 条,所选国家/地区是爱尔兰。
  6. f. 在 SCC 中新增了第 19 条,以涵盖从英国到英国境外的个人数据传输,如下所示:

“第 19 条

英国 GDPR 和 DPA 2018

双方同意,这些条款将在与相关传输相关的范围内扩展和适用,以涵盖属于英国 GDPR 和《2018 年数据保护法》范围的跨境传输(英国传输)。就此类英国传输而言,标准合同条款 B1.0 版的国际数据传输附录(不时修订、替换、补充或取代)的规定应按照附录所附表格中的规定适用。

  1. h. 在 SCC 中新增了第 20 条,以涵盖从瑞士到瑞士境外的个人数据传输,如下所示:

“第 20 条

瑞士 – FADP

双方同意,这些条款将在与相关传输相关的范围内扩展和适用,以涵盖属于《联邦数据保护法》(FADP)范围的跨境传输(在本条款中称为瑞士传输)。就此类瑞士传输而言,管辖法律应为所选成员国的法律,所选法院应为所选成员国的法院,联邦数据保护和信息专员 (FDPIC) 应为主管监管机构。双方进一步同意,此类进一步变更应解释为 FCPIC 认为有必要为遵照英国 GDPR 和 FADP 而对有关瑞士传输的条款进行此类变更,并且这些条款应根据这些法律对瑞士传输的要求或 FDPIC 发布的指南中规定的其他要求进行解释,双方无需签订专门为其瑞士传输准备的单独标准合同条款。双方应进一步采取一切可能必要的行动和措施,以确保在进行瑞士传输时遵照 FADP。”

  1. i. 在 SCC 中新增了第 21 条,以涵盖从巴西到巴西境外的个人数据传输,如下所示:

“第 21 条

巴西 – LGPD

双方同意,这些条款将在与相关传输相关的范围内扩展和适用,以涵盖属于巴西第 13,709/18 号《通用数据保护法》 (LGPD)范围内的跨境传输(本条款中称为巴西传输)。就此类巴西传输而言,管辖法律应为所选成员国的法律,所选法院应为所选成员国的法院,巴西国家数据保护局 (ANPD管监管机构。双方进一步同意,此类进一步变更应解释为 ANPD 认为有必要为遵照 LGPD 而对有关巴西传输的条款进行此类变更,并且这些条款应根据这些法律对巴西瑞士传输的要求或 ANPD 或其他相关巴西机构发布的指南中规定的其他要求进行解释,双方无需签订专门为其巴西传输准备的单独标准合同条款。双方应进一步采取一切可能必要的行动和措施,以确保在进行巴西传输时遵照 LGPD。”

  1. j. 在 SCC 中新增了第 22 条,以涵盖来自迄今为止未指定的任何其他国家/地区的个人数据传输。可以将 SCC 扩展到这些国家/地区,以确保从该国家/地区向位于该国家/地区以外的一方传输个人数据时提供适当的保障,如下所示:

“第 22 条

其他第三国家/地区传输

双方同意,这些条款将在与相关传输相关的范围内扩展和适用,以涵盖属于任何相关司法管辖区的任何其他适用法律和法规范围的跨境传输,这些法律和法规与个人数据的使用或处理有关(适用的数据保护法),需要与这些条款大致相同的条款和保护,以便将个人数据从该国家/地区传输到另一个国家/地区(在本条款中称为第三国家/地区传输)。就此类第三国家/地区传输而言,管辖法律应为选定成员国的法律,所选法院应为所选成员国的法院,该国家/地区的数据保护机构或监管机构应为主管监督机构。双方进一步同意,此类进一步变更应解释为对该监管机构认为有必要为遵照该国家/地区适用的数据保护法而对有关第三国家/地区传输的条款进行此类变更,并且这些条款应根据这些法律对第三国家/地区传输的要求或相关监管机构发布的指南中规定的其他要求进行解释,双方无需签订专门为其第三国家/地区传输准备的单独标准合同条款。双方应进一步采取一切可能必要的行动和措施,以确保在进行第三国家/地区传输时遵照适用的数据保护法。”

1.12 本“C2C 协议”的附件 1(SCC 处理概述)构成 SCC 的附件 1。本“C2C 协议”的附件 2(技术和组织措施)构成 SCC 的附件 2,如果贵方已提供(且我方已接受)充分的技术和组织措施以满足 SCC 附件 2 要求,则仅适用于 Expedia;如果情况并非如此,附件 2 将解释为适用于双方,并且所有提及 Expedia 和 Expedia Group 的内容将解释为相应地提及任何一方。对于 SCC 而言,本“C2C 协议”的附录构成英国附录。

附件 I – SCC 处理概述
模块一:控制方到控制方(贵方到我方)
A. 模块一:控制方到控制方(贵方到我方)

数据导出方:

缔约方

规定为“贵方”、TAAP 成员或同等术语的各方

地址

如“协议”所述

Expedia Group 所有各方的联系人姓名、职位和详细联系信息

客户经理使用不时通知 Expedia 联系人的邮箱地址

与根据 SCC 进行传输的数据相关的活动

 

我方根据“协议”通过 TAAP 网站提供给贵方下单的预订

角色

控制方

数据导入方: 

缔约方

“协议”中规定为“我方”或“Expedia”的非欧盟方

地址

如“协议”所述

联系人姓名、职位和详细联系信息

客户经理使用不时通知 TAAP 会员的邮箱地址

与根据这些条款进行传输的数据相关的活动

我方根据“协议”通过 TAAP 网站提供给贵方下单的预订

角色

控制方

 

B. 传输说明

 

  1. 通讯地址
  2. 邮箱地址
  3. 电话号码(固定电话号码和手机号码)
  4. 传真号码
  5. 其他联系信息
  6. 出生日期(适用于航班)
  7. 性别(适用于航班)
  8. 国籍(以护照为准)
  9. TSA 详细信息

财务详细信息:

  1. 银行帐号
  2. 银行信息
  3. 支付卡详细信息

旅行信息:预订历史记录和旅行偏好

对于税务代理,只有:

  1. 税号

TAAP 成员要求并同意的其他信息,包括但不限于与以下方面相关的个人数据:

  1. 报告、监控和分析
  2. 单点登录、会员计划

数据主体类别

客户和 TAAP 会员及其子用户

个人数据的类别

身份证明数据:

  1. 名字和姓氏(代理和旅客)
  2. 出生日期
  3. 性别
  4. 登录详细信息(代理)

个人数据的类别

详细联系信息:

敏感数据

无,除非个人自愿提供用于满足其旅行的无障碍需求。

传输频率(例如,数据是一次性传输还是持续传输)。

根据 TAAP 会员的业务需要,持续或临时传输

处理的性质

为实现以下目的所需的所有处理操作

数据传输和进一步处理的目的

“协议”中定义的获准用途

个人数据的保留期限,或者用于确定该期限的标准(如果不能保留数据)

根据 Expedia Group 的保留政策,如果在“协议”终止后出于备份或法律原因保留任何 TAAP 个人数据,Expedia 将继续根据“协议”保护此类个人数据

对于到(子)处理方的传输,还需指定处理的主题、性质和持续时间

https://support.ean.com/hc/en-us/articles/360000986389-EAN-Data-Services-Vendor-List,不时更新

 

C.主管监管机构

根据 SCC 第 13 条明确主管监管机构

爱尔兰数据保护局

 

模块一:控制方到控制方(我方到贵方)

A. 缔约方名单

数据导出方: 

上述模块一 (1)(贵方到我方)中规定为数据导入方的一方。请参阅上文了解更多详情。

 

数据导入方:

上述模块一 (1) (贵方到我方)中规定为数据导出方的一方。请参阅上文了解更多详情。

A. 传输说明
  • 数据主体类别
  • 个人数据的类别
  • 敏感数据

遵照模块一 (1) 的要求

  • 传输频率
  • 处理的性质
  • 用途

遵照模块一 (1) 的要求

个人数据的保留期限,或者用于确定该期限的标准(如果不能保留数据)

符合 TAAP 会员保留政策

对于到(子)处理方的传输,还需指定处理的主题、性质和持续时间

不适用

 

C. 主管监管机构

遵照模块一 (1) 的要求

 

附件 II - 技术和组织措施 

适用于模块一 (1) 目的的技术和组织措施如下。

主题

措施

个人数据的假名化处理和加密措施

  • Expedia Group 支持基于 Expedia Group 的信息分类和处理标准的行业标准数据传输加密协议。
  • 数据处理要求以数据类别为基础。根据所处理的数据,Expedia Group 制定了不同的安全要求。例如,信用卡数据属于高度敏感数据,在传输过程中和存储时都需要进行加密。
  • Expedia Group 将根据 EG 的信息、分类和处理标准的要求,在可能的情况下对客户(及其员工)的个人数据进行假名化(和匿名化)处理。
  • 对信用卡卡号标记化/假名化处理,以消除对明文信用卡卡号的处理。
  • Expedia Group 通过 VPN、SSL 等方式采用加密连接,并采用多因素身份验证机制。

确保处理系统和服务持续保密性、完整性、可用性和韧性的措施

  • Expedia Group 维护所有信息处理设施的管理和运营的责任和流程,以确保完整、有效、准确地处理数据。
  • 对关键处理设施进行监控,并通过强大的 SOX 计划对数据处理和完整性的控制进行持续测试和验证。
  • EG 的系统采用行业标准的日志记录和监控,确保安全并防止未经授权的访问、修改和/或删除。
  • Expedia Group 通过冗余架构、数据复制和完整性检查来保持服务韧性。

确保在发生物理或技术事件时,能够及时恢复个人数据的可用性和访问权限的措施

  • Expedia Group 的系统经过专门设计,旨在阻止或防止常见攻击,并确保操作、监控和维护的可用性。为此,Expedia Group
  • 服务器根据 Expedia Group 可靠的修补政策进行修补,并受到行业标准 AV/AM 计划的保护。此外,我方还进行漏洞评估、全面测试和网络检查,以确保 EG 的系统正常运行。
  • 采用可用性和可靠性监控,以确保 Expedia 网站保持在线状态,并最大限度地减少服务中断。
  • Expedia Group 制定了灾难恢复计划,以应对紧急情况和应急计划,从而确保不中断客户服务(视严重程度而定),并定期进行测试以确保可行性。

定期测试、评估和评价技术和组织措施有效性的流程,以确保处理的安全性

  • Expedia Group 的技术和组织措施每年都会由外部评估员进行审计并会进行严格的内部测试。
  • EG 借助第三方评估机构进行年度 PCI 评估,并确保始终遵守 PCI 的要求。
  • EG 全面的内部测试功能包括季度漏洞测试,内部和外部渗透测试,网络、系统和防火墙扫描和检查。此外,内部审计部门每年都会进行风险评估,以确定运营审计的优先级。

用户识别和授权措施,传输期间数据保护措施,存储期间数据保护措施

  • Expedia Group 系统符合行业最佳实践,并具有超时会话、锁定协议以及严格的密码和身份验证控制等通信实践。
  • Expedia Group 始终遵守帐户配置和监督要求,以防止未经授权的访问或滥用 Expedia Group 信息,并根据需要使用行业最佳实践(例如最低权限访问原则、唯一 ID

确保个人数据处理地点的物理安全的措施

  • 安全运营中心提供 24x7 全天候服务,并至少每年检查和测试正式的事件响应计划。
  • 所有系统均由外部服务提供商定期控制和测试。
  • 每个 Expedia Group 客户都会收到自己的客户 ID。相应客户的所有数据集都存储在该 ID
  • 只有获得了 Expedia 明确授权且“有必要了解”的人员才能访问个人数据。采用控制和监控,确保对系统的最低权限访问并阻止未经授权的访问尝试。

确保事件记录的措施

Expedia Group 始终遵守严格的日志记录和监控要求,以说明所记录活动的人员、内容、地点、时间、目标、来源以及成功/失败。

确保系统配置(包括默认配置)的措施,适用于内部 IT 和 IT 安全治理和管理的措施,适用于流程和产品认证/保证的措施

  • Expedia Group (EG) 的信息安全计划符合行业框架和标准,通过其风险管理计划确保稳健、全面的安全态势。Expedia Group
  • Expedia Group
  • Expedia Group 对安全采取分层/纵深防御策略。整个企业都部署了关键功能和控制(例如:反恶意软件、WAF、网络分段、DLP
  • Expedia 的系统托管在 Amazon Web Services (AWS) 和数据中心中,它们每年各为 Expedia Group 提供 1 份 SOC 报告以确保合规性。

确保数据最小化的措施,确保数据质量的措施,确保有限数据保留的措施,确保问责制的措施

  • 最小化:Expedia Group 确保仅收集、处理和存储最少量的数据。我方仅在必要时使用可识别的格式。
  • 保留:Expedia Group
  • 质量:Expedia Group 拥有正式的质量管理计划,即客户体验管理 (CEM) 计划。我们始终致力于改善 EG
  • 问责制:Expedia Group 始终拥有正式的治理计划和法律/隐私机构,通过一致的政策实施、行业法规/框架和法律要求来确保问责制监督。

允许数据可移植性和确保删除的措施

  • Expedia Group 对确保遵照数据保护法(包括与数据主体的请求相关的法律)负有直接责任。Expedia Group 根据适用的数据保护法响应所有主题请求,包括访问、删除和可移植性。
  • EG 数据保留政策根据数据类别(包括根据任何法律义务要求保留此类数据)规定了不同的保留期限和备份,直至某些法律义务(例如税务和会计目的)取消或有其他豁免。如果 Expedia Group 无法销毁个人数据,Expedia Group 将继续扩大双方之间关于此类个人数据的“协议”的相关保护,并终止任何进一步的处理。

针对向(子)处理方的传输,还应描述(子)处理方要采取的具体技术和组织措施,以便能够为控制方以及在从处理方到子处理方和从处理方到数据导出方的传输过程中提供支持

  • Expedia Group 对其供应商的信息安全实践进行尽职调查,并要求供应商满足全面的安全要求,包括要求供应商采取并保持适当的技术和组织措施的义务。
  • Expedia Group 已正式制定详细的安全影响评估 ("SIA") 流程。会在签约前和合约期限内(如有必要)对所有访问数据的新供应商进行筛选。
  • 此外,Expedia Group 还为所有供应商制定了严格的供应商处理条款,确保其任何子处理方也承担相应的义务。

 

欧盟委员会标准合同条款的国际数据传输附录(附录)

本附录由进行受限传输各方的信息专员发布。信息专员认为,当本附录作为具有法律约束力的合同签订时,可为受限传输提供适当的保障措施。

第 1 部分 表格

表 1:缔约方

开始日期

将这些附加到 SCC 的日期(欧盟 SCC).

缔约方 主要联系人

Key Contact

导出方:遵照欧盟 SCC。

 

导入方:遵照欧盟 SCC。

 

表 2:所选的 SCC、模块和所选的条款

附录 EU SCC

本附录所附的是已批准的欧盟 SCC 的版本。

表 3:附录信息

附录信息” 是指必须为已批准的欧盟 SCC(缔约方除外)附录中列出的所选模块提供的信息,本附录中列出了这些信息:

附件 IA:缔约方名单

附件 IB 传输说明

附件 II - 技术和组织措施

遵照欧盟 SCC

表 4:当已批准的附录发生变化时终止本附录

哪方可以按照第 19 条的规定终止本附录

任何一方都不可以

第 2 部分: 强制性条款

已批准附录的强制性条款是 ICO 发布的模板附录 B.1.0,并根据《2018 年数据保护法》119A 部分的规定,于 2022 年 2 月 2 日提交议会,还根据这些强制性条款的第 18 条进行了修订。

 

TAAP Privacy Terms – Controller to Controller Agreement (Including the SCCs)

The original English version of this C2C Agreement may have been translated into other languages. In the event of an inconsistency or discrepancy between the English version and any other language version of this Agreement, the English language version shall prevail.

SCOPE: Where each of Expedia and you are processing personal data as part of an agreement (which may be in the form of online clickwrap terms) entered into with the other party (pursuant to which you have been appointed as a marketing partner under TAAP, and all relevant activities connected to such activity referred to herein as the “Relevant Activities”), then this global controller to controller agreement (“C2C Agreement”) is supplemental to and applies to such agreement entered into between the parties in connection with the Relevant Activities (the “Agreement”), and sets out additional terms, requirements and conditions on which Expedia and you will each process personal data in connection with the Agreement. In this C2C Agreement, “Expedia”, “we” and “us” refers to Expedia, Inc. and/or any other Expedia Group company/ies party to the Agreement. “You” refers to the named entity stated on the Application as described in the Agreement (and all references to either Expedia or you will be construed as plural terms to the extent required by the Agreement).

1. DEFINITIONS AND INTERPRETATION

1.1 This C2C Agreement is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set out in the Agreement apply to the interpretation of this C2C Agreement unless otherwise defined in this C2C Agreement; and:

  1. a. each of appropriate technical and organizational measures, controller, personal data, personal data breach, process/processing, and supervisory authority (or reasonably equivalent terms) shall have the meaning given to them in Applicable Data Protection Law;
  2. b. Applicable Data Protection Law(s) means any applicable laws and regulations in any relevant jurisdiction, relating to the use or processing of personal data;
  3. c. Permitted Purpose means the purpose of (i) fulfilling Bookings; (ii) providing support for Bookings; (iii) TAAP registration and account administration; (iv) payment of Commission and other amounts pursuant to the Agreement; (v) generating reports for you and any further processing required for reconciliation, complaints handling and similar activities connected with servicing the Agreement (vi) TAAP Account support; (vii) communications to TAAP Members and Sub-Users; (viii) improving our services, including optimizing the booking experience; (ix) creating reports for analytics, business intelligence and business reporting; (x) fraud prevention; (xi) responding to law enforcement requests and tax authority audit requests; (xii) facilitating business asset transactions (which may extend to any mergers, acquisitions or asset sales); and (xiii) otherwise complying with our obligations under the Agreement, Expedia’s privacy policy and applicable laws and (xiv) for the determination, calculation, reporting of Travel Taxes and other applicable taxation purposes as may be required from time to time;
  4. d. DPF means an EU-US Data Privacy Framework certification with the US Department of Commerce or any replacement or supplementary certification mechanism approved by the European Commission (or other relevant national authority) from time to time; and includes any supplementary adequacy decisions issued by any other country that permit the extension of the DPF between the US and that third country (for example, without limitation, the United Kingdom and Switzerland);
  5. e. Restricted Transfer Country means any country in the European Economic Area, Switzerland, the United Kingdom and Brazil;
  6. f. Restricted Transfer Data means Customer Data relating to a Booking made via a point of sale intended by us to be accessed by Customers in a Restricted Transfer Country;
  7. g. Standard Contractual Clauses/ SCCs means the approved European Commission’s Standard Contractual Clauses for the transfer of personal data from the European Union to third countries, as issued on 4 June 2021, as amended, replaced, supplemented, or superseded from time to time, and the full current version of which can be found following this link: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en ; and
  8. h. TAAP Personal Data means personal data provided to us by you via the TAAP Website or otherwise processed in connection with TAAP itself or facilitating Bookings made using the TAAP Website.
Relationship of the parties
  1. 1.2 You and we shall each collect and process personal data to fulfil our respective rights and obligations under the Agreement, as well as your and our respective responsibilities under applicable laws. As such, each of the parties shall: (i) process personal data as independent and autonomous controllers; (ii) comply with Applicable Data Protection Law; and (iii) be responsible for any of its acts or omissions in breach of Applicable Data Protection Law.

1.3 You must:

Your responsibilities
  1. a. satisfy a legal basis in order to make available any TAAP Personal Data to us to process for the Permitted Purposes;
  2. b. ensure that Customers are made aware, via your privacy policy and by any other appropriate means, that their personal data will be shared with us for the Permitted Purposes;
  3. c. direct Customers to our privacy policy for more information about our handling of their personal data; and
  4. d. cooperate with and provide reasonable assistance to us to assist us with our compliance with Applicable Data Protection laws in the course of our processing of TAAP Personal Data in connection with the Agreement.
Our responsibilities

1.4 We (and our Group Members, where applicable) shall:

  1. a. process TAAP Personal Data in connection only with a Permitted Purpose;
  2. b. not divulge the whole or any part of the TAAP Personal Data to any person, except in connection with a Permitted Purpose;
  3. c. cooperate with and provide reasonable assistance to you to assist you with your compliance with Applicable Data Protection Laws in the course of your Processing of TAAP Personal Data in connection with the Agreement; and
  4. d. display and comply with our lawful and up-to-date cookie notice (if required) and our privacy policy on the TAAP Website.
Customers and Third Parties

1.5 You acknowledge that we:

  1. a. may send emails to Customers relating to Bookings;
  2. b. may transfer TAAP Personal Data (including banking data) to our third-party service providers for the purposes of:
    1. i. administering, managing and supporting you and your Representatives and Sub-Users’ TAAP Accounts;
    2. ii. providing support for Bookings; and
    3. iii. paying Commission and other amounts pursuant to the Agreement.
Data security

1.6 Both parties, in their capacity as controllers, shall:

  1. a. maintain appropriate technical and organizational measures to protect the personal data they each process against a personal data breach; and
  2. b. in the event of a confirmed personal data breach within systems under that party’s possession or control, promptly notify the other party if the personal data breach both (i) affects TAAP Personal Data that is also processed by the other party under the Agreement; and (ii) is reportable to a supervisory authority, providing full details of the same. In such event, both parties shall cooperate reasonably and in good faith to remedy or mitigate the effects of the personal data breach, and the reasonable costs of such cooperation shall be borne by the party that suffered the personal data breach.
Cross-border transfers

1.7 Data Privacy Framework (DPF): You and we agree that in respect of transfers of Restricted Transfer Data between you and us to the United States or to a country which has not been deemed "adequate" under the Applicable Data Protection Laws of the originating Restricted Transfer Country (a) to the extent that and for so long as DPF is a recognized method of transfer by a relevant authority, DPF shall be the agreed mechanism for cross-border transfers of data originating from a Restricted Transfer Country to us in the United States, and (b) to the extent that and for so long as DPF is not a valid method of transfer (including for transfers of Restricted Transfer Data to a country which has not been deemed "adequate" under the Applicable Data Protection Laws of the originating Restricted Transfer Country), the SCCs shall apply to such transfers and we will enter into them on the basis set out in Clause 1.11 below. Where you also hold a current DPF certification, transfers of Restricted Transfer Data to you can similarly be made under the DPF with SCCs as a fallback mechanism as set out above.

1.8 DPF Flow-down Obligations: You agree that you will provide at least the same level of protection for the Restricted Transfer Data as is required under the DPF; and you shall promptly notify us if you make a determination that you can no longer provide this level of protection. In such event, or if we otherwise reasonably believes that you are not protecting the Restricted Transfer Data to the standard required under DPF, we may either: (a) instruct you to take reasonable and appropriate steps to stop and remediate any unauthorized processing, in which event you will promptly cooperate with us in good faith to identify, agree and implement such steps; (b) agree an alternate safeguard that may apply to the processing under Applicable Data Protection Law; or (c) terminate this C2C Agreement and the Agreement (or, at our election, any affected portion thereof) without penalty by giving notice to you. If you also hold a current DPF certification, then the above provisions and those of Clause 1.9 below shall be deemed to be apply as if the obligations are two-way.

1.9 DPF Disclosure Obligations: You acknowledge that we may disclose this C2C Agreement and any relevant privacy provisions in the Agreement to the US Department of Commerce, the Federal Trade Commission, any European data protection authority, or any other US or EU judicial or regulatory body upon their request and that any such disclosure shall not be deemed a breach of confidentiality.

1.10 Extension of SCCs to Non-Restricted Transfer Countries: In relation to transfers of TAAP Personal Data between you and us originating from a country that is not a Restricted Transfer Country but is otherwise subject to safeguards that, according to Applicable Data Protection Law, must be applied before a transfer can be made of that TAAP Personal Data outside of the country of origin (each a Non-Restricted Transfer Country), then you and we agree that (a) the SCCs set out in Clause 1.11 below shall be deemed to extend to such additional transfers to the extent that such deemed extension would satisfy the safeguards of that particular country; and/or (b) where the measures set out in Clause 1.11 are insufficient or require supplementary measures, the parties agree to take such further measures, including, for example, execution of relevant documents, collection of consent, making of required filings, as may be required from to time in order to satisfy Applicable Data Protection Law.

1.11 Subject to Clause 1.7 above, you and we hereby agree to enter into the SCCs on an unchanged basis save for the following selections::

  1. a. where you are located in a Restricted Transfer Country or otherwise in a country deemed “adequate” in accordance with Article 45 of the GDPR, Module one (1) only of the SCCs will apply one-way in respect of transfers from you to Expedia. Otherwise, Module One SCCs apply two-way to cover both transfers from us to you, and from you to us.
  2. b. For the purposes of clause 11(a) of the SCCs, the optional language is deleted.
  3. c. For the purposes of clause 13 of the SCCs, the relevant paragraph is “The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated in Annex I.C, shall act as competent supervisory authority.”
  4. d. For the purposes of clause 17 of the SCCs, the governing law is Ireland.
  5. e. For the purposes of clause 18(b) of the SCCs, the selection is Ireland.
  6. f. A new clause 19 is added to the SCCs to cover transfers of personal data from the United Kingdom to outside of the United Kingdom as follows:

“Clause 19

UK GDPR and DPA 2018

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of UK GDPR and Data Protection Act 2018 (a UK transfer). For the purposes of such UK transfer, the provisions of the International Data Transfer Addendum to the Standard Contractual Clauses Version B1.0 (as amended, replaced, supplemented, or superseded from time to time) shall apply as set out in the form attached as the Addendum.”

  1. h. A new clause 20 is added to the SCCs to cover transfers of personal data from Switzerland to outside of Switzerland as follows:

“Clause 20

Swiss – FADP

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of Federal Act of Data Protection (FADP) (referred to in this Clause as a Swiss transfer). For the purposes of such Swiss transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and the Federal Data Protection and Information Commissioner (FDPIC) shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Swiss transfer as are deemed necessary by the FCPIC to comply with the UK GDPR and FADP, and the Clauses shall be interpreted in accordance with the requirements for Swiss transfers arising under those laws or as otherwise set out in guidance issued by the FDPIC, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Swiss transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the FADP when engaging in Swiss transfers.”

  1. i. A new clause 21 is added to the SCCs to cover transfers of personal data from Brazil to outside of Brazil as follows:

“Clause 21

Brazil – LGPD

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of the Brazilian General Data Protection Law No. 13,709/18 (Lei Geral de Proteção de Dados) (LGPD) (referred to in this Clause as a Brazilian transfer). For the purposes of such Brazilian transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and Brazil’s National Data Protection Authority (ANPD) shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Brazilian transfer as are deemed necessary by the ANPD to comply with the LGPD, and the Clauses shall be interpreted in accordance with the requirements for Brazilian transfers arising under those laws or as otherwise set out in guidance issued by the ANPD or other relevant Brazilian authority, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Brazilian transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the LGPD when engaging in Brazilian transfers.”

  1. j. A new clause 22 is added to the SCCs to cover transfers of personal data from any other country not hitherto specified where the SCCs may be extended to ensure appropriate safeguards for transfers of personal data originating from that country to a party located outside of that country as follows:

“Clause 22

Other third country transfers

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of the any other applicable laws and regulations in any relevant jurisdiction, relating to the use or processing of personal data (Applicable Data Protection Laws) requiring terms and protections broadly equivalent to these Clauses in order to transfer personal data from that country to another (referred to in this Clause as a Third Country transfer). For the purposes of such Third Country transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and the data protection authority or regulatory body of that country shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Third Country transfer as are deemed necessary by such supervisory authority to comply with the Applicable Data Protection Law of that country, and the Clauses shall be interpreted in accordance with the requirements for Third Country transfers arising under those laws or as otherwise set out in guidance issued by the relevant supervisory authority, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Third Country transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the Applicable Data Protection Law(s) when engaging in Third Country transfers.”

1.12 Annex 1 (SCCs Processing Overview) to this C2C Agreement constitutes Annex 1 of the SCCs. Annex 2 (Technical and Organizational Measures) to this C2C Agreement constitutes Annex 2 of the SCCs and applies only to Expedia where you have provided, and we have accepted, adequate technical and organizational measures to satisfy your Annex 2 requirements of the SCCs or, where this is not the case, Annex 2 will be construed to apply to both parties and all references to Expedia and Expedia Group will be construed to reference either party accordingly. The Addendum to this C2C Agreement constitutes the UK Addendum for the purposes of the SCCs.

ANNEX I – SCCs PROCESSING OVERVIEW
MODULE ONE: Controller to Controller (you to us)
A. LIST OF PARTIES

Data exporter(s):

Party

The party/ies identified as “you”, TAAP Member or equivalent term

Address

As specified in the Agreement

Contact name, position & contact details for all Expedia Group parties

Account manager using email address notified to Expedia contact from time to time

Activities relevant to data transferred under SCCs

 

Bookings made via the TAAP Website made available by us to you in accordance with the Agreement

Role

Controller

Data importer(s):

Party

The non-EU parties identified as “us” or “Expedia” in the Agreement

Address

As specified in the Agreement

Contact person’s name, position and contact details

Account manager using email address notified to TAAP Member contact from time to time

Activities relevant to the data transferred under these Clauses

Bookings made via the TAAP Website made available by us to you in accordance with the Agreement

Role

Controller

 

B. DESCRIPTION OF TRANSFER

 

Categories of data subject

Customers and TAAP Members and their Sub-Users

Categories of Personal Data

Identification data:

  1. first and last names (both agent and traveler)
  2. date of birth
  3. gender
  4. login details (agent)

Contact details:

  1. postal address
  2. email address
  3. fax number
  4. other contact information
  5. date of birth (for flights)
  6. gender (for flights)
  7. nationality (from passport)
  8. TSA details

Financial details:

  1. bank account number
  2. bank details
  3. payment card details
  4. login details (agent)

Travel information: booking history and travel preferences

In the case of Tax Agents, only:

  1. Tax ID

Other information as requested by, and agreed with, the TAAP Member, including without limitation personal data required in connection with:

  1. Reporting, monitoring and analytics
  2. Single sign on, loyalty schemes

Sensitive Data

None, unless it is voluntarily provided by an individual to meet their accessibility needs for travel.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

Continuous or ad hoc basis in accordance with the needs of TAAP Member’s business

Nature of the processing

All processing operations required to facilitate purposes set out below

Purpose(s) of the data transfer and further processing

Permitted Purposes, as defined in the Agreement

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

In accordance with the retention policy of the Expedia Group, provided that to the extent that any TAAP Personal Data is retained beyond the termination of the Agreement for back up or legal reasons, Expedia will continue to protect such personal data in accordance with the Agreement

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

as updated from time to time

 

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13 of SCCs

Irish Data Protection Authority

 

MODULE ONE: Controller to Controller (us to you)

A. LIST OF PARTIES

Data exporter(s):

The Party/ies identified as Data Importers in Module one (1) (you to us) above. See above for further details.

 

Data importer(s):

The Party/ies identified as Data Exporter(s) in Module one (1) (you to us) above. See above for further details.

B. DESCRIPTION OF TRANSFER

· Categories of data subject

· Categories of Personal Data

· Sensitive Data

As per Module (1)

· Frequency of transfer

· Nature of processing

· Purposes

As per Module (1)

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

In accordance with the retention policy of TAAP Member

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

Not applicable

 

C. COMPETENT SUPERVISORY AUTHORITY

As per Module one (1)

 

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES

The technical and organizational measures that apply for the purposes of Module one (1) are set out below.

SUBJECT

MEASURE

Measures of pseudonymisation and encryption of personal data  

· Expedia Group supports industry standard encryption protocols for data transmission based on Expedia Group’s Information Classification and Handling Standard. 

· Data handling requirements are based on a categorical basis. Depending on the data being handled, different security requirements are in place across Expedia Group. For example, credit card data is considered Highly Sensitive and required to be encrypted both in transit and at rest.  

· Personal data of the customer (and its employees) is pseudonymized (and anonymized) by Expedia Group when possible and as required according to EG’s Information, Classification and Handling Standards.

· Credit card numbers are tokenized/pseudonymized to eliminate processing of cleartext credit card numbers. 

· Expedia Group utilizes encrypted connections through VPN, SSL, etc. and utilizes multi-factor authentication mechanisms. 

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services 

· Expedia Group maintains responsibilities and procedures for the management and operation of all information processing facilities to ensure complete, valid and accurate processing of data.  

· The monitoring of key processing facilities is in place, with a robust SOX program where controls over data processing and integrity are tested and attested to on an ongoing basis.  

· Industry standard logging and monitoring is in place on EG’s systems to ensure and protect against unauthorized access, modification and/or deletion.

· Expedia Group maintains service resilience through redundant architecture, data replication, and integrity checking. 

Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident

· Expedia Group’s systems are specifically designed to impede or prevent common attacks and ensure availability for operation, monitoring and maintenance. For this purpose, Expedia Group regularly carries out simulated tests and audits to confirm that its systems maintain availability.

· Servers are patched against Expedia Group’s robust patching policy and protected by industry standard AV/AM programs. Additionally, vulnerability assessments, thorough testing, and network reviews are conducted to ensure EG’s systems are maintained.

· Availability and reliability monitoring is in place to ensure Expedia sites remain online, with minimal interruptions of service.

· Expedia Group maintains a Disaster Recovery Plan that accounts for emergencies and contingency plans to ensure that customer services are uninterrupted according to severity and are tested regularly to ensure viability.

Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing

· Expedia Group’s technical and organizational measures are audited annually by external assessors as well as through robust internal testing.

· EG conducts annual PCI assessments utilizing a third-party assessor and ensures ongoing compliance with PCI.

· EG’s comprehensive internal testing function is comprised of quarterly vulnerability testing, internal and external penetration testing, network, system and firewall scanning and reviews. Additionally, an internal audit department conducts annual risk assessments to prioritize operational audits.

Measures for user identification and authorisation Measures for the protection of data during transmission Measures for the protection of data during storage

· Expedia Group systems are aligned with industry best practices and have in place communication practices such as time-out sessions, lock-out protocols, and robust password and authentication controls.

· Expedia Group maintains requirements for account provisioning and oversight to prevent unauthorized access or misuse of Expedia Group information and uses industry best practices as required, such as the Least Privilege Access principle, unique ID’s and multi factor authentication for strong authentication purposes.

Measures for ensuring physical security of locations at which personal data are processed

· A Security Operations Center provides 24x7 coverage, with a formal incident response plan reviewed and tested at least annually.

· All systems are regularly controlled and tested by external service providers.

· Each Expedia Group customer receives their own customer ID. All datasets of the respective customer are stored under this ID and all customer data is logically segregated. Due to administration rights and database structures, the customer can only access datasets which are assigned to that user ID and data centers/AWS controls.

· Only persons who are expressly authorized by Expedia and have a ‘need to know’ have access to personal data. Controls and monitoring are in place to ensure least privileged access and unauthorized access attempts to the system.

Measures for ensuring events logging

Expedia Group maintains robust logging and monitoring requirements to account for the who, what, where, when, target, source, and success/failure of the logged event.

Measures for ensuring system configuration, including default configuration Measures for internal IT and IT security governance and management Measures for certification/assurance of processes and products

· Expedia Group’s (EG) Information Security program is aligned with industry frameworks and standards, working through its risk management program to ensure a robust and comprehensive security posture. Expedia Group maintains secure operational processes to support the security, availability, integrity and confidentiality of the environment and customers’ data.

· Expedia Group’s build standards only enable system components, services, and protocols that serve a business requirement. Operating Systems, databases, and off-the-shelf applications must be discoverable to satisfy legal and regulatory audit requirements, supports configuration management tools, or deploys configuration management that successfully enforces security controls, must enable encryption for all remote administrative access to a system, display proper use of the system, the system is being monitored to detect improper use and other illicit activity there is no expectation of privacy while using the system.

· Expedia Group takes a layered / defence-in-depth strategy to security. Critical capabilities and controls are in place across the enterprise (e.g.: anti-malware, WAF, network segmentation, DLP, etc.), utilizing a suite of policies, operations and technologies to ensure the environment is monitored through a central security organization and alerts responded to accordingly.

· Expedia's systems are hosted on Amazon Web Services (AWS) and in Data Centers that provide Expedia Group with annual SOC 2 reports to ensure compliance.

Measures for ensuring data minimisation Measures for ensuring data quality Measures for ensuring limited data retention Measures for ensuring accountability

· Minimisation: Expedia Group ensures only minimum amount of data is collected, processed and stored.   We only use identifiable format where necessary.

· Retention: The Expedia Group data retention policy sets out different retention periods and backups depending on the category of data, including any legal obligation or other exemption which requires such data to be retained until certain legal obligations, such as tax and accounting purposes, have been extinguished.

· Quality: Expedia Group has a formalized, quality management program, the Customer Experience Management (CEM) program. We are always striving for improvement within EG’s environment and seeking to streamline processes for higher efficiencies resulting in consistent, high-quality services and interactions with our partners, clients and travelers.

· Accountability: Expedia Group ensure accountability oversight with consistent implementation of policies, industry regulations/frameworks and legal requirements by maintaining a formalized Governance program, and Legal/Privacy body.

Measures for allowing data portability and ensuring erasure

· Expedia Group is directly responsible for ensuring compliance with data protection laws (including in relation to requests from data subjects). Expedia Group responds to all subject requests, including Access, deletion and portability in accordance with applicable data protection law.

· EG’s data retention policy sets out different retention periods and backups depending on the category of data, including any legal obligation or other exemption which requires such data to be retained until certain legal obligations, such as tax and accounting purposes, have been extinguished. In the event that Expedia Group is unable to destroy Personal Data, Expedia Group shall continue to extend relevant protections of the Agreement between the parties governing such personal data and terminate any further processing.

For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter 

· Expedia group conducts due diligence into the information security practices of its vendors and requires vendors to meet comprehensive security requirements, including obligations requiring vendors to have in place and maintain appropriate technical and organisational measures.

· Expedia Group has formalised a detailed Security Impact Assessment (“SIA”) process. All new vendors accessing data are screened prior to engagement and during the term where necessary.

· Additionally, Expedia Group also has robust vendor processor terms that are imposed on all vendors, ensuring the flow down of obligations to any of their sub-processors.

 

International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Addendum)

This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.

Part 1    Tables

Table 1: Parties

Start Date

The Date of the SCCs to which these are attached (EU SCCs).

Parties

Key Contact

Exporter: As per EU SCCs.

 

Importer: As per EU SCCs.

 

Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs

The version of the Approved EU SCCs which this Addendum is appended to.

Table 3: Appendix Information

Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex IA: List of Parties

Annex 1B Description of Transfer

Annex II: Technical and organisational measures

As per EU SCCs

Table 4: Ending this Addendum when the Approved Addendum changes

Which Parties may end this Addendum as set out in Section 19

Neither Party

Part 3: Mandatory Clauses

Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.