MIDNIGHT SUPPLIER DATA PROCESSING ADDENDUM
Last Updated: 30 October 2025
This Data Protection Addendum (“DPA”) is incorporated into the Agreement and is entered into as of the date of the Agreement.
1. DEFINITIONS. The terms and expressions set out in this DPA shall have the following meanings:
“Agreement” the agreement between the parties for the Supplier’s Services.
“Applicable Privacy Law” means all privacy, data security, and data protection laws, directives, regulations, and rules in any jurisdiction applicable to the Personal Data processed under this DPA including, without limitation and to the extent applicable, the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), the UK GDPR from December 31st 2020 and the United Kingdom Data Protection Act of 2018 (together “UK Privacy Law”), the Swiss Federal Act on Data Protection (“FADP”), the Cayman Islands Data Protection Act (2021 revision), the British Virgin Islands' Data Protection Act, 2021, and the US States Data Laws (as defined in Annex 4). For the avoidance of doubt, if Supplier’s processing of Personal Data is not within the scope of a given Applicable Privacy Law, such law is not applicable for purposes of this DPA.
“Controller”, “Data Subject”, “Processor” and “processing” shall have the meanings given to them in GDPR and any other Applicable Privacy Law.
“Data Breach” means a) an investigation into or seizure of the Personal Data by government officials, or a specific indication that such an investigation or seizure is imminent; b) any unauthorized or accidental access, processing, deletion, loss or any form of unlawful processing of the Personal Data; or c) any breach of the security and/or confidentiality measures set out in this DPA leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, the Personal Data, or any indication of such breach having taken place or being about to take place.
“Personal Data” means all personal data relating to individuals as such term is used or defined in Applicable Privacy Law, which is processed by Supplier on behalf of Midnight in accordance with this DPA.
“SCCs” means the Standard Contractual Clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“Services” means those goods, services or deliverables which Supplier provides to Midnight under the Agreement, and which are further defined in the Agreement.
“Sub-processor” means any third party that Supplier engages to Process Personal Data on behalf of Supplier to provide the Services.
2. RELATIONSHIP OF THE PARTIES. With regards to any Personal Data Processed by Supplier on behalf of Midnight under this DPA, when Midnight engages the Supplier to provide Services solely for Midnight’s purposes, Midnight is the Controller, and Supplier is the Processor.
3. CATEGORIES OF PERSONAL DATA. The categories of Personal Data, the types of Data Subjects, and purposes for which the Personal Data are being processed is defined in Annex 1.
4. PROCESSING AND USE OF PERSONAL DATA
4.1. Both Parties shall comply with Applicable Privacy Law while processing Personal Data.
4.2. Supplier is to process Personal Data received from Midnight (a) strictly in compliance with instructions provided by Midnight as set out in this DPA (b) exclusively for the purpose of providing the Services established in the Agreement or (c) as otherwise notified by Midnight in writing. Supplier shall immediately notify Midnight if it deems an instruction from Midnight to be unlawful.
4.3. Supplier agrees to comply with any reasonable measures required by Midnight to ensure that its obligations under this DPA are satisfactorily performed in accordance with all Applicable Privacy Law. Supplier shall not perform its obligations under this DPA, or the Agreement, in such way as to cause Midnight to breach any of its applicable obligations under Applicable Privacy Law.
4.4. Supplier shall, taking into account the nature of processing and the information available to Supplier, assist Midnight in complying with its obligations to carry out data protection impact assessments and/or consult a supervisory authority prior to a data protection impact assessment as required by Applicable Data Protection Laws.
4.5. Supplier shall support Midnight with prior consultation of the supervisory authority taking into account the nature of processing and the information available to Supplier. Midnight and Supplier shall cooperate, on request, with the competent data protection supervisory authority in performance of its tasks. Midnight shall be informed of any inspections and measures conducted by the supervisory authority, insofar as they relate to this DPA, without undue delay. This also applies insofar as Supplier is under investigation or is party to an investigation by a competent authority in connection with infringements to any civil or criminal Law, or administrative rule or regulation regarding the processing of Personal Data under this DPA.
4.6. Insofar as Midnight is subject to an inspection by the supervisory authority, an administrative or summary offence or criminal procedure, a liability claim by a Data Subject or by a third party or any other claim in connection with the processing of Personal Data by Supplier on behalf of the Midnight under this DPA, Supplier shall make reasonable efforts to support Midnight.
5. SECURITY OF PERSONAL DATA
Supplier agrees to implement and maintain an appropriate information security program with technical and organisational measures to protect the security of Personal Data to a level of security appropriate to the risk; in particular, against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure, including, at a minimum, the technical and organisational systems described in Annex 2.
6. CONFIDENTIALITY AND TRAINING
6.1. Where Supplier processes Personal Data (whether stored in the form of physical or electronic records) on behalf of Midnight it shall take reasonable steps to ensure the reliability of all employees and Sub-processors.
6.2. Supplier will take reasonable measures to inform and train its employees about relevant privacy legislation and data security.
6.3. All Personal Data provided to Supplier by Midnight or obtained by Supplier in the course of its work with Midnight is confidential and may not be copied, disclosed or processed in any way without the express authority of Midnight. Supplier shall inform all its employees, agents and/or approved Sub-processors engaged in processing the Personal Data of the confidential nature of the Personal Data. Supplier shall ensure that all such persons or parties have signed an appropriate confidentiality agreement, are otherwise bound to a duty of confidentiality, or are under an appropriate statutory obligation of confidentiality. Supplier shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality and ensure that all employees and Sub-processors are informed of the confidential nature of the Personal Data and are aware of Supplier’s duties under this DPA and their personal duties and obligations under Applicable Privacy Law. The obligation of confidentiality shall continue after the end of such person’s employment or other contractual agreement.
7. SUB-PROCESSING
7.1. Midnight hereby grants Supplier a general written authorization to engage Sub-processors for the processing of Personal Data under this DPA. The Sub-processors authorized as of the effective date of this DPA are listed in Annex 3. Supplier shall notify Midnight in writing at least thirty (30) days in advance of appointing or replacing any Sub-processor. Midnight may object to the engagement of a new Sub-processor on reasonable grounds, by notifying Supplier in writing within twenty (20) days of receiving the notice. If an objection is raised which cannot be reasonably resolved, and Supplier cannot provide the Services without the objected-to sub-processor, Midnight may terminate the affected Services with thirty (30) days’ written notice, without penalty.
7.2. Supplier shall not disclose, transfer and/or grant access to Personal Data to a Sub-processor unless Supplier executes a written agreement with such Sub-processor that contains substantially similar data protection obligations imposed on Supplier by this DPA and ensures the same level of protection for the Personal Data, including but not limited to by implementing appropriate technical and organizational measures. Supplier remains liable for Sub-processor’s failure to fulfil its obligations with respect to the processing of Personal Data as if Supplier had failed to fulfil such obligations.
8. INTERNATIONAL DATA TRANSFERS
8.1. Transfers outside of the EEA. The parties agree that transfers of Personal Data of Data Subjects located in the European Economic Area or a jurisdiction that qualifies the SCCs as a sufficient method for transferring Personal Data (“EEA Personal Data”), if any, are made pursuant to the SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows:
a. Module Two (Controller to Processor) of the SCCs applies when Midnight is a Controller and Supplier is a Processor of EEA Personal Data.
b. Module Three (Processor to Sub-Processor) of the SCCs applies when Midnight is a Processor and Supplier is a sub-processor of EEA Personal Data.
c. For both modules, where applicable the following applies:
d. Clause 7. The optional docking clause does not apply.
e. Clause 9. Option 2 (general authorisation) applies, and the notice period is defined in section 7.1 of the DPA.
f. Clause 11. The optional language does not apply.
g. Clause 13. All square brackets are hereby removed.
h. Clause 17 (Option 1). The SCCs will be governed by Irish law.
i. Clause 18(b). Disputes will be resolved before the courts of Ireland.
8.2. Annex 1 of this DPA is deemed to be Annex I of the SCCs, Annex 2 the Annex II of the SCCs and Annex 3 the Annex III of the SCCs. By entering into this DPA, the parties are deemed to have signed the SCCs incorporated herein, including their Annexes.
8.3. If Midnight or Data Subjects are residents of the United States, or if transfers are from the UK or Switzerland, Annex 4 applies
8.4. Supplementary Measures. In respect of any transfers of EEA Personal Data, or Personal Data of Data Subjects in Switzerland or the UK, if any, the following supplementary measures shall apply:
a. As of the date of this Amendment, Supplier has not received any formal legal requests from any government intelligence or security service/agencies in the country to which the Personal Data is being exported, for access to (or for copies of) Personal Data (“Government Agency Requests”);
b. If, after the date of this Amendment, Supplier receives any Government Agency Requests, Supplier shall attempt to redirect the law enforcement or government agency to request that data directly from Midnight. As part of this effort, Supplier may provide Midnight’s basic contact information to the government agency. If compelled to disclose Personal Data to a law enforcement or government agency, Supplier shall Midnight reasonable notice of the demand and cooperate to allow Midnight to seek a protective order or other appropriate remedy unless Supplier is legally prohibited from doing so. Supplier shall not voluntarily disclose Personal Data to any law enforcement or government agency. The parties shall (as soon as reasonably practicable) discuss and determine whether all or any transfers of Personal Data pursuant to this DPA should be suspended in the light of the such Government Agency Requests; and
c. The Parties will meet as needed to consider whether:
- the protection afforded by the laws of the country of the Supplier to Data Subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, whichever the case may be;
- additional measures are reasonably necessary to enable the transfer to be compliant with the Applicable Privacy Laws; and
- it is still appropriate for Personal Data to be transferred to Supplier, taking into account all relevant information available to the parties, together with guidance provided by the supervisory authorities.
8.5. To the extent that Midnight or Supplier are relying on a specific statutory mechanism for international data transfers that is subsequently modified, revoked, or held in a court of competent jurisdiction to be invalid, Midnight and Supplier agree to cooperate in good faith to promptly terminate the transfer or to pursue a suitable alternate mechanism that can lawfully support the transfer. Provided that the parties use the SCCs to transfer Personal Data, Midnight may give notice to the Supplier with effect from the date set forth in such notice, that the application of the SCCs shall be amended so that the SCCs cease to apply to transfers, and any new applicable version of the SCCs specified in such notice shall apply going forward. To the extent that the use of the new SCCs require the parties to complete additional information, the parties shall reasonably and promptly work together to complete such additional information.
9. DATA SUBJECT REQUESTS AND DATA BREACH
9.1. Supplier shall promptly notify Midnight if it receives a request from a complaint or request from a Data Subject relating to Midnight’s obligations under the Applicable Privacy Law. Supplier shall provide Midnight with full co-operation and assistance in relation to any complaint or request made by a Data Subject, including by providing Midnight with full details of the complaint or request and complying with a data access request within the relevant timescale set out Applicable Privacy Law and in accordance with Midnight’s instructions.. Supplier may not on its own authority rectify, erase or restrict the processing of Personal Data that is being processed on behalf of Midnight without documented instructions from Midnight.
9.2. If Supplier becomes aware of any Data Breach Supplier shall, at its own expense, immediately (and in any event within 24 hours of becoming aware of the Data Breach) notify Midnight in writing. Supplier shall fully co-operate with and assist Midnight, in dealing with the Data Breach and in ensuring compliance with its obligations under Applicable Privacy Law.
9.3. Any notifications according to section 9.2 made to Midnight shall contain: a) description of the nature of the Data Breach, including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned; b) the name and contact details of Supplier’s data protection officer or another contact point where more information can be obtained; c) description of the likely consequences of the Data Breach; and d) description of the measures taken or proposed to be taken by Supplier to address the Data Breach including, where appropriate, measures to mitigate its possible adverse effects.
10. AUDIT AND ASSISTANCE
10.1. Supplier agrees that, on reasonable prior notice, permit persons authorised by Midnight to access any premises on which Personal Data provided by Midnight to Supplier is processed and to inspect Supplier’s systems comply with this DPA. Midnight acknowledges that Supplier’s obligations under this clause may be satisfied in whole or part by the provision to Midnight of appropriate information; records; and certifications and audit reports issued by reputable independent third parties provided that there have been no material changes to the controls used by Supplier since the certification or audit report was issued.
10.2. Midnight may request that Supplier audit a Sub-processor or provide confirmation that such an audit has occurred (or, where available, obtain or assist a user in obtaining a third-party audit report concerning the Sub-processor’s operations) to ensure compliance with its obligations imposed by Supplier in conformity with this DPA.
10.3. Supplier shall make available to Midnight all information necessary to demonstrate compliance with Supplier’s obligations.
10.4. Supplier shall assist Midnight with prior consultations with supervisory authorities required under Article 36 of the GDPR taking into account the nature of processing and the information available to Supplier.
11. RETURN OR DISPOSAL
Supplier shall destroy or transfer all Personal Data to Midnight on Midnight’s request in the formats, at the times and in compliance with the requirements notified in writing by Midnight to Supplier. The Personal Data of Midnight shall be destroyed or returned (at Midnight's option) no later than thirty (30) days after the expiry or termination of the Contract, and Supplier shall provide written certification of such destruction or return within seven (7) days thereafter.
12. INDEMNIFICATION
Supplier shall indemnify and keep Midnight harmless against all damages, costs, claims (including third party claims), losses, fines, penalties, and expenses (including reasonable legal fees) incurred by Midnight which arise directly or indirectly out of or in connection with Supplier's breach of this DPA or Applicable Data Protection Laws, or Supplier’s data processing activities under this DPA.
13. GENERAL
13.1. Conflict. In the event and to the extent that there is any conflict between the provisions of this DPA and any part of the Agreement in connection with the Processing of Personal Data by Supplier on behalf of Midnight, this DPA will prevail but only with respect to the respective conflict.
13.2. Severability. If any provision of this DPA or part thereof is or becomes void or ineffective, this shall not affect the validity or effectivity of the remaining parts of this DPA.
13.3. Governing law and dispute resolution. This DPA shall be governed by the laws governing the Agreement. All disputes arising out of or in connection with this Agreement shall be finally settled by the dispute resolution body identified in the Agreement.
13.4. Validity. This DPA shall be valid as long as the Supplier processes Personal Data, but at least as long as the Agreement is in force.
ANNEX 1: Details of Processing
A. LIST OF PARTIES
MODULE TWO: Transfer controller to processor
MODULE THREE: Transfer processor to processor
Data exporter(s):
Name: Midnight as defined in this DPA
Address: The address of Midnight as defined in this DPA
Contact person’s name, position and contact details: as per the Agreement.
Activities relevant to the data transferred under these Clauses: As defined in section B below.
Role: Controller or Processor
Data importer(s):
Name: Supplier as defined in this DPA
Address: The address of Supplier as defined in this DPA
Contact person’s name, position and contact details: as per the Agreement.
Activities relevant to the data transferred under these Clauses: As defined in section B below.
Role: Processor or Sub-processor
B. DESCRIPTION OF PROCESSING
Categories of data subjects whose personal data is processed
The categories of data subjects may include, where applicable and appropriate for the Services:
- Employees and other individuals who work for Midnight (including agents, advisors and contractors).
- individuals seeking employment with Midnight such as candidates.
- Individuals whose personal data is processed by Midnight.
Categories of personal data processed
The categories of personal data may include, where applicable and appropriate for the Services:
- Contact details (such as name, email address, telephone number).
- Additional individual information (such as age, gender, birth date, employer, profession, geographic location, education information, financial status, habits and preferences).
- Unique identifiers and account profile information Employment information (such as occupation, ID numbers, government identifiers, tax forms, compensation data)
- Financial-related information (such as financial institution account numbers, credit card numbers, transaction histories).
- Personal health information (such as medical record number, beneficiary names, claims information)
- Device information and log data (such as geo-location, email, calendars, contacts, IP addresses, event and product usage data)
User generated content (such as messages, chat information, posts, comments, pages, profiles, feeds or communications on social media sites networks)
Sensitive data processed
The Parties do not anticipate the transfer or processing of sensitive data. However, if the Services necessitate such processing, the Supplier must obtain agreement from the Midnight business unit prior to processing, and it must be indicated in the Agreement and/or SOW.
The frequency of the processing (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous
Nature of the processing
Collection, storage, organisation, modification, retrieval, disclosure, communication and other uses in performance of the Services as set forth in the Agreement and/or SOW.
Purpose(s) of the data transfer and further processing
Processing activities in the performance of the Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Duration of the Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13
The competent supervisory authority is the Irish Data Protection Commission.
ANNEX 2 - Technical and Organisational Measures
Supplier shall implement, maintain, and regularly update appropriate technical and organizational measures that meet the requirements of Article 32 GDPR, including at minimum:
1. Encryption of personal data in transit and at rest
2. Access controls and authentication measures
3. Regular security testing and assessments
4. Business continuity and disaster recovery procedures
5. Regular staff training on data protection
6. Physical security measures
7. Network security controls
8. Incident response procedures
ANNEX 3 – List of Sub-Processors
Midnight has authorized the use of the following Sub-processors included in the list of Supplier has provided to Midnight in writing prior to entering into the Agreement. Supplier will provide a list of the then current Sub-processors at any time upon Midnight’s request.
ANNEX 4:
US States Data Laws Addendum
This Addendum sets forth the terms and conditions relating to compliance with:
a) The California Consumer Privacy Act of 2018 and any regulations, amendments and/or updates thereto including but not limited to as amended by the California Privacy Rights Act (collectively, the “CCPA”); and
b) Colorado Data Privacy Act, Connecticut Act Concerning Personal Data Privacy and Online Monitoring, Delaware Personal Data Privacy Act, Indiana Consumer Data Protection Act, Iowa Consumer Data Protection Act, Kentucky Consumer Data Protection Act, Maryland Online Data Privacy Act, Minnesota Consumer Data Privacy Act, Montana Consumer Data Privacy Act, Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Protection Act, Oregon Consumer Privacy Act, Rhode Island Data Transparency and Privacy Protection Act, Tennessee Information Protection Act, Texas Data Privacy and Security Act, Utah Consumer Privacy Act, Virginia Consumer Data Privacy Act and any regulations, amendments and/or updates thereto (collectively and together with CCPA and any other U.S. state comprehensive privacy law that comes into effect subsequent to the date hereof, the “US States Data Laws”).
CCPA.
A. In addition to and without limiting any and/or all other provisions of this Addendum, for purposes of compliance with the CCPA, Service Provider agrees that:
a) Personal Data is being disclosed by User to Service Provider only for the limited and specified Processing Services identified by User and Service Provider shall not retain, use or disclose Personal Data for any other purpose.
b) Service Provider shall comply with the applicable obligations under the CCPA and provide the same level of privacy protection as required of businesses covered under the CCPA.
c) User shall have the right (but not the obligation) to take reasonable and appropriate steps to monitor Service Provider’s compliance with this Addendum to ensure that Service Provider is using the Personal Data in a manner consistent with the CCPA.
d) Service Provider shall immediately notify User in writing if it determines that it can no longer meet its obligations under the CCPA.
e) User shall have the right upon notice to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.
f) Service Provider shall not sell, share, retain, use, cache or disclose Personal Data outside of the direct relationship between User and Service Provider as set forth in this Addendum.
g) If Service Provider engages any sub-processors of Personal Data then Service Provider shall notify User of such engagement in writing and ensure that there is a written contract between Service Provider and the sub-processor that binds the sub-processor to all of the contractual requirements and obligations imposed on the Service Provider under the Agreement and/or this Addendum. Service Provider shall be responsible for any breach of this Addendum by its sub-processors as if such breach were a breach by Service Provider.
h) Service Provider is not permitted to use any Personal Data for its own operational purposes or on its own behalf (for example to improve or benchmark Service Provider’s services).
i) Upon User’s request, Service Provider shall delete or return all Personal Data to User as requested at the end of the performance of Processing Services, unless retention of the Personal Data is required by Laws and then only to the extent required.
j) If User provides any de-identified information to Service Provider, then Service Provider shall take reasonable measures to ensure that such information cannot be associated with an individual and shall publicly commit to maintain and use such information in de-identified form only and not attempt to re-identify the information.
k) Service Provider acknowledges and agrees that it fully understands and agrees with the obligations and restrictions set forth in this Addendum.
B. Service Provider shall be responsible for complying with its own obligations as a business to the extent applicable under the CCPA.
US States Data Laws. In addition to and without limiting any and/or all other provisions of this Addendum, for purposes of compliance with the US States Data Laws, Service Provider agrees that:
a) Service Provider is a “Processor” as such term is defined under the US States Data Laws.
b) User is a “Controller” as such term is defined under the US States Data Laws.
c) User hereby instructs Service Provider to process Personal Data solely for purposes of performing the Processing Services during the term of the Agreement and any applicable survival period for which Service Provider has obligations under such Agreement.
d) If Service Provider engages any sub-processors of Personal Data then Service Provider shall notify User of such engagement in writing, and ensure that there is a written contract between Service Provider and the sub-processor that binds the sub-processor to substantially all of the contractual requirements and obligations imposed on the Service Provider under the Agreement and/or this Addendum. Service Provider shall be responsible for any breach of this Addendum by its sub-processors as if such breach were a breach by Service Provider
e) All employees and personnel of Service Provider must be subject to a written duty of confidentiality with respect to the Processing Services including but not limited to regarding the Personal Data and the processing thereof.
f) Upon User’s reasonable request, Service Provider shall cooperate with User and provide information in a timely manner to User to (i) enable User to conduct and document data protection assessments and cooperate with reasonable audits by User or a qualified independent auditor; (ii) demonstrate Service Provider’s compliance with its obligations under the US States Data Laws; (iii) take appropriate technical and organizational measures to fulfil consumer rights requests made to User; and (iv) help meet User’s obligations in relation to any data security and/or data breach notification.
g) Upon User’s request, Service Provider shall delete or return all Personal Data to User as requested at the end of the performance of the Processing Services, unless retention of the Personal Data is required by Laws and then only to the extent required.
h) If User provides any de-identified information to Service Provider, then Service Provider shall take reasonable measures to ensure that such information cannot be associated with an individual and shall publicly commit to maintain and use such information in de-identified form only and not attempt to re-identify the information.
Transfers from the UK. To the extent Personal Data includes personal data from the UK and for the purposes of localizing the SCCs to United Kingdom law, the parties agree to the following:
The parties agree that the SCCs are deemed amended to the extent necessary that they operate for transfers from the United Kingdom to a third country and provide appropriate safeguards for transfers according to Article 46 of the UK GDPR. Such amendments include changing references to the GDPR to the UK GDPR and changing references to EU Member States to the United Kingdom.
The UK Addendum will apply to transfers of UK Personal Data protected by the UK GDPR and will be completed as follows:
- Table 1 will be completed with the relevant information in Annex 1 of this DPA;
- Table 2 will be completed with the selected modules and clauses the SCCs as identified in Section 8.1 of this DPA;
- Table 3 will be completed with the relevant information from Annexes 1, 2 and 3 of this DPA;
- In Table 4, both the data exporter and data importer may end the UK Addendum in accordance with the terms of the UK Addendum.
Transfers from Switzerland. The parties agree that transfers from Switzerland, if any, are made pursuant to the SCCs with the following modifications:
a) The parties adopt the GDPR standard for all data transfers, or the standard under Swiss law where higher.
b) The parties agree that the references to provisions of the GDPR in the SCCs are to be understood as references to the corresponding provisions of the Swiss Federal Data Protection Act in the version applicable at the moment of initiation of any dispute.
c) The term Member State, where used in the SCCs, also applies to Switzerland. In particular, this shall ensure that data subjects are not excluded from the possibility to sue for their rights in their place of habitual residence.
d) Clause 13 and Annex I(C): The competent authorities under Clause 13, and in Annex I(C), are the Federal Data Protection and Information Commissioner and, concurrently, the EEA member state authority identified above.
e) Clause 17: The parties agree that the governing jurisdiction is the Member State in which the data exporter is established for claims under the GDPR and the substantive laws of Switzerland for claims under the Swiss Federal Data Protection Act.
f) Clause 18:
g) Any dispute arising from these Clauses shall be resolved by the courts of Zurich, Switzerland.
h) A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence.
i) The parties agree to submit themselves to the jurisdiction of such courts.
j) The parties agree to interpret the SCCs so that “data subjects” include legal entities until the revised Swiss Federal Act on Data Protection enters into force.