These data processing terms come into effect on the date of validity and replace all prior agreements on the same subject matter (e.g., all amendments and supplementary agreements on data processing or provisions on contract data processing).
Registered PEP-Screener.com API user.
belsignum UG (haftungsbeschränkt)
Zeppelinstraße 73
81669 München
The order includes the following:
REST API service for checking entities against EU sanctions lists.
In this context, the processor processes personal data for the controller as defined in Art. 4 No. 2 and Art. 28 GDPR based on this agreement.
The contractually agreed service will be provided exclusively within a member state of the European Union or in a contracting state of the Agreement on the European Economic Area. Any relocation of the service or parts thereof to a third country requires the prior consent of the controller and may only take place if the special conditions of Art. 44 ff. GDPR are met (e.g. adequacy decision by the Commission, standard data protection clauses, approved codes of conduct).
The durations and notice periods of the overarching hosting and service agreement apply.
Regardless of the aforementioned duration, the controller can terminate the agreement at any time without notice if there is a serious breach by the processor against data protection regulations or the provisions of this agreement, the processor cannot or does not want to execute an instruction of the controller, or the processor wrongfully denies the controller's control rights. In particular, the non-compliance with the obligations agreed upon in this contract and derived from Art. 28 GDPR constitutes a serious breach.
Type of processing (according to the definition of Art. 4 No. 2 GDPR):
Type of personal data (according to the definition of Art. 4 No. 1, 13, 14, and 15 GDPR):
Categories of data subjects (according to the definition of Art. 4 No. 1 GDPR):
The data controller is solely responsible for assessing the permissibility of the processing according to Art. 6 Para. 1 GDPR and for upholding the rights of the data subjects according to Art. 12 to 22 GDPR. Nonetheless, the data processor is obligated to promptly forward any such requests, if they are recognizably directed exclusively to the data controller.
Changes in the object of processing and procedural changes are to be agreed upon jointly between the data controller and data processor and set down in writing or in a documented electronic format.
The data controller issues all orders, partial orders, and instructions typically in writing or in a documented electronic format. Verbal directives should be immediately confirmed in writing or in a documented electronic format.
The data controller has the right, as stipulated in Paragraph 5, to convince themselves of the data processor's compliance with the technical and organizational measures taken and the obligations set out in this contract before the start of processing and then regularly in an appropriate manner.
The data controller will notify the data processor promptly if they identify any errors or irregularities when reviewing the order results.
The data controller is obligated to treat all knowledge gained in the context of the contractual relationship about the data processor's trade secrets and data security measures confidentially. This obligation remains in effect even after the termination of this contract.
Persons authorized to give instructions on behalf of the data controller are:
Contact listed in the administration panel (https://api.pep-screener.com/profile)
Instruction recipients at the data processor are:
Andreas Sommer
Communication channels to be used for instructions:
In the event of a change or long-term absence of the contact persons, the contractual partner must be promptly informed, typically in writing or electronically, about the successors or the representatives. Instructions are to be retained for their duration of validity and subsequently for three full calendar years.
The data processor processes personal data exclusively within the scope of the agreements made and according to the instructions of the data controller unless he is obliged by the law of the Union or of the Member States to which the data processor is subject to carry out another processing (e.g., investigations by law enforcement or state protection authorities). In such a case, the data processor informs the data controller of these legal requirements before the processing, unless the law in question prohibits such a notification due to a significant public interest (Art. 28 Para. 3 Sentence 2 lit. a GDPR).
The data processor does not use the personal data provided for processing for any other purposes, especially not for his own purposes. Copies or duplicates of personal data are not created without the data controller's knowledge.
The data processor guarantees the contractual implementation of all agreed measures in the area of data processing on behalf of the data controller. He ensures that the data processed for the data controller is strictly separated from other data stocks.
Data carriers originating from or used for the data controller are specially marked. Entry, exit, and ongoing use are documented.
The data processor must carry out the following checks in his area for the entire processing service for the data controller:
The result of the checks must be documented.
In assisting the data controller in fulfilling the rights of the data subjects under Articles 12 to 22 of the GDPR, in creating the directories of processing activities, and in required data protection impact assessments, the data processor must cooperate to the necessary extent and support the data controller as far as possible (Art. 28 Para. 3 Sentence 2 lit e and f GDPR). The necessary information must be passed on to the following point of the data controller without delay:
The data processor will promptly notify the data controller if, in his opinion, an instruction issued by the data controller violates legal regulations (Art. 28 Para. 3 Sentence 3 GDPR). The data processor is entitled to suspend the implementation of the relevant instruction until it is confirmed or changed by the data controller after checking.
The data processor must correct, delete, or restrict the processing of personal data from the contractual relationship if the data controller demands it via an instruction and if no legitimate interests of the data processor oppose it.
Information about personal data from the contractual relationship to third parties or the data subjects may only be given by the data processor with prior instruction or consent from the data controller.
The data processor agrees that the data controller is entitled – generally by appointment – to check the compliance with data protection and data security regulations as well as contractual agreements to the necessary and reasonable extent himself or through third parties commissioned by the data controller, in particular by obtaining information and inspecting the stored data and data processing programs and by checking and inspecting on-site (Art. 28 Para. 3 Sentence 2 lit. h GDPR).
The data processor assures that he will cooperate supportively in these controls, if necessary. The following is agreed upon until further notice:
The data processor confirms that he is aware of the GDPR provisions relevant to data processing.
The data processor undertakes to maintain confidentiality during the contractual processing of the data controller's personal data. This obligation continues even after the termination of the contract.
The data processor assures that he familiarizes the employees involved in the work with the relevant data protection provisions before starting their activity and commits them to confidentiality in an appropriate manner both during their activity and after the end of the employment relationship (Art. 28 Para. 3 Sentence 2 lit. b and Art. 29 GDPR). The data processor monitors compliance with data protection regulations in his company.
If relevant:
The data processor undertakes to inform the data controller immediately about the exclusion of approved codes of conduct according to Art. 41 Para. 4 GDPR and the revocation of certification according to Art. 42 Para. 7 GDPR.
The data processor must immediately inform the data controller of disruptions, violations by the data processor or persons employed by him against data protection regulations or the stipulations made in the order, as well as suspicions of data protection violations or irregularities in the processing of personal data. This is especially relevant considering potential notification and reporting obligations of the data controller under Art. 33 and Art. 34 GDPR. The data processor guarantees to support the data controller adequately in his duties according to Art. 33 and 34 GDPR if necessary (Art. 28 Para. 3 Sentence 2 lit. f GDPR). The data processor may only carry out reports according to Art. 33 or 34 GDPR for the data controller following a prior instruction as per Section 4 of this contract.
The data processor is granted a general authorization to commission subcontractors. However, each subcontracting must be announced in advance by the data processor to the data controller. The data controller has the right to object within a reasonable period (max. 2 weeks). The data processor will ensure that he carefully selects the subcontractor, especially considering the suitability of the technical and organizational measures taken by the subcontractor according to Art. 32 GDPR.
The data processor must contractually ensure that the agreed regulations between the data controller and data processor also apply to subcontractors.
If several subcontractors are used, this also applies to the responsibilities between these subcontractors. In particular, the data controller must be entitled to carry out appropriate checks and inspections, including on-site, at subcontractors or have them carried out by commissioned third parties.
The contract with the subcontractor must be in writing, which can also be in an electronic format (Art. 28 Para. 4 and Para. 9 GDPR).
Data may only be passed on to the subcontractor when the subcontractor has met the obligations according to Art. 29 and Art. 32 Para. 4 GDPR concerning its employees.
The data processor must check the subcontractor's compliance with its obligations as follows:
Annual review by random sampling.
The data processor is liable to the data controller for ensuring that the subcontractor complies with the data protection obligations that were contractually imposed on him by the data processor in line with this contract section.
At present, subcontractors specified in Annex 1 by name, address, and order content are employed by the data processor to process personal data to the extent specified there. The data controller agrees to their commissioning.
A protection level appropriate to the risk to the rights and freedoms of the natural persons affected by the processing is guaranteed for the specific order processing. The protection objectives of Art. 32 Para. 1 GDPR, such as confidentiality, integrity, and availability of systems and services, and their resilience concerning the type, scope, circumstances, and purpose of the processing, are taken into account in such a way that the risk is continuously minimized through suitable technical and organizational remedial measures.
Significant decisions regarding the organization of data processing and the methods used must be coordinated between the data processor and data controller.
If the measures taken by the data processor do not meet the data controller's requirements, he must notify the data controller immediately.
The measures at the data processor can be adapted to the technical and organizational development during the contractual relationship, but may not fall below the agreed standards.
The data processor must coordinate substantial changes with the data controller in documented form (in writing, electronically). Such coordination must be retained for the duration of this contract.
Upon completion of the contractual works, the data processor is obligated to securely delete or destroy all data, documents, and generated processing or usage results that have come into his possession or that of subcontractors in connection with the contractual relationship, in compliance with data protection regulations.
The deletion or destruction must be confirmed to the data controller in writing or in a documented electronic format, specifying the date.
For any side agreements, the written form or a documented electronic format is generally required.
The right of retention in accordance with § 273 BGB (German Civil Code) with respect to the data processed for the data controller and the associated data carriers is excluded.
Should individual parts of this agreement be invalid, this does not affect the validity of the rest of the agreement.