APAC Data Processing Addendum
The Data Processing Addendum that applies where Your Agreement is governed by the law of Australia or Singapore
This APAC Data Processing Addendum applies where the table at clause 2 of the Data Processor Terms identifies it as the Data Processing Addendum for Your Agreement. It forms part of the Data Processor Terms, and sets out the position specific to Australian privacy law — including how We characterise Our role for the purposes of the Privacy Act, and how individual rights requests are handled.
The terms that apply across every Data Processing Addendum are at www.theaccessgroup.com/en-gb/legal-hub/documents/data-processor-terms — read this Addendum together with that page.
1. Definitions
Data Breach — means, in respect of any of Your Personal Information held by Us under the Agreement, any (i) unauthorised access to, modification of, or disclosure of; or (ii) interference with, loss of, or misuse of, that Personal Information.
Personal Information — means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Privacy Laws — means the Privacy Act 1988 (Cth) and any other applicable law regulating the storage, handling and use of Personal Information in Australia.
Privacy Policy — means the Access Privacy Policy.
2. Complying with the Privacy Laws
- 2.1 We comply with the Privacy Laws in respect of all Personal Information You disclose to Us. You comply with the Privacy Laws in respect of all Personal Information disclosed to Us, or collected by Us, in connection with Your use of the Access Products and Services.
- 2.2 Where You disclose or input Personal Information in connection with the Access Products and Services, and where required to do so by Privacy Laws, You warrant that You have the express written consent of the relevant individuals to do so.
- 2.3 Any Personal Information We collect or hold in providing the Access Products and Services is handled in accordance with Our Privacy Policy, and You consent to Our collection, use and disclosure of it on that basis. Where an Access Product’s log-in page has its own privacy policy, that policy takes precedence over the Privacy Policy to the extent of any inconsistency.
- 2.4 We process Personal Information solely on Your instructions and for the purpose of providing the Access Products and Services (including the purposes described in the Product Fact Sheet). We do not access, use or otherwise deal with Personal Information for any purpose of Our own, other than as necessary for security, Sub-Processing in line with clause 3.4 of the Data Processor Terms, or as required by law. This is a relevant factor in determining who controls the Personal Information within the meaning of the Privacy Act, and We consider You to be the appropriate first point of contact for a request under Australian Privacy Principle 12 (access) or 13 (correction).
3. Individual rights requests
- 3.1 Where an individual contacts You to exercise a right under Australian Privacy Principle 12 or 13, or an equivalent right under the Privacy Laws, clause 3.6 of the Data Processor Terms applies, and We will give You reasonable assistance to respond.
- 3.2 Where an individual contacts Us directly, We will redirect them to You wherever We can reasonably identify You as the relevant party. If We cannot reasonably identify You, or You do not give Us instructions within 10 business days of Our request for them, We will take the steps We consider reasonably necessary to respond to the individual directly, consistent with Our own obligations under the Privacy Laws, and We may charge You on a time-and-materials basis for doing so.
4. Notifiable data breaches
- 4.1 If either of us determines, or has reasonable grounds to believe, that a Data Breach is an eligible data breach reportable to the Office of the Australian Information Commissioner, the parties will work together to coordinate any required notifications. You must not make a notification unless You have first obtained Our prior written consent, which We will not unreasonably withhold.
5. Other matters
- 5.1 Where We provide Access Products over the internet using networks We only partially control, Our obligations under clauses 2 to 4 extend only to networks and equipment within Our control. We are not responsible for delay, loss, interception or alteration of Your data on a network or infrastructure outside Our control.
- 5.2 Nothing in this Addendum requires either of us to take, or refrain from taking, any action that would result in a breach of the Privacy Laws.
AU & NZ
SG
MY
US
IE