The subcontractor undertakes to :
- process data solely for the purposes for which it is subcontracted
- process data in accordance with the controller's documented instructions. If the processor considers that an instruction constitutes a breach of the European Data Protection Regulation or any other provision of Union or Member State law relating to data protection, it shall immediately inform the controller. In addition, if the processor is obliged to transfer data to a third country or to an international organization, by virtue of Union law or the law of the Member State to which it is subject, it must inform the controller of this legal obligation prior to processing, unless the law concerned prohibits such information on important grounds of public interest.
- guarantee the confidentiality of personal data processed under this contract
- ensure that the persons authorized to process personal data under this contract :
- are committed to confidentiality or are subject to an appropriate legal obligation of confidentiality
- receive the necessary training in the protection of personal data
- take into account, with regard to its tools, products, applications or services, the principles of data protection by design and data protection by default
- Subcontracting
The processor may call upon another processor (hereinafter, " the further processor ") to carry out specific processing activities. In this case, it shall inform the controller in advance and in writing of any changes envisaged concerning the addition or replacement of other processors. This information must clearly indicate the processing activities subcontracted, the identity and contact details of the subcontractor and the dates of the subcontracting contract. The data controller has a minimum of 8 calendar days from the date of receipt of this information to present his objections. This period may be reduced to 3 days in the event of an emergency. This subcontracting may only be carried out if the data controller has not raised any objections within the agreed period.
The subsequent processor is required to comply with the obligations of this contract on behalf of and in accordance with the instructions of the controller. It is the responsibility of the original processor to ensure that the subsequent processor presents the same sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that the processing meets the requirements of the European Data Protection Regulation. If the subsequent processor fails to meet its data protection obligations, the original processor remains fully liable to the controller for the other processor's performance of its obligations.
- Data subjects' right to information
It is up to the data controller to provide information to data subjects at the time of data collection.
-
Exercising individual rights
Wherever possible, the processor must help the controller to fulfill its obligation to respond to requests to exercise the rights of data subjects: right of access, rectification, erasure and objection, right to restrict processing, right to data portability, right not to be subject to an automated individual decision (including profiling).
Where data subjects make requests to the processor to exercise their rights, the processor must send these requests to the data controller by e-mail as soon as they are received.)
You have the right to request access to your personal data and the rectification of inaccurate data. You may request the erasure of data and the restriction of processing, and you may also object to processing, in the cases and within the limits provided for by the applicable legislation. You have the right to the portability of the personal data you have provided, under the conditions provided for by the applicable legislation. You also have the right to define directives relating to the conservation, deletion and communication after your death of your processed personal data, in accordance with applicable laws and regulations.
Where processing is based on your consent, you may withdraw it at any time.
You can exercise your rights by sending an e-mail to rgpd.socodec@exco.fr.
- Notification of personal data breaches
The processor shall notify the controller of any personal data breach within 48 hours of becoming aware of it, by e-mail. This notification shall be accompanied by any useful documentation to enable the controller, if necessary, to notify the breach to the competent supervisory authority.
- Safety measures
The processor undertakes to implement appropriate security measures in accordance with the purpose of the processing.
- Fate and data retention
On completion of the data processing services, the data processor undertakes, at the option of the data controller:
- return all personal data to the data controller, or
- to return personal data to the processor appointed by the controller
Your personal data processed by the subcontractor is stored in France, for a period of time adapted to the purpose of each processing operation, for the duration defined contractually with the customer.
Exceptionally, such data may be kept for longer periods to manage claims or disputes, or to meet legal, disciplinary and/or regulatory obligations.
- Register of categories of processing activities
The processor declares that it keeps a written record of all categories of processing activities carried out on behalf of the controller, including:
- the name and contact details of the data controller on whose behalf it is acting, of any subcontractors and, where applicable, of the data protection officer;
- the categories of processing carried out on behalf of the controller;
- where applicable, transfers of personal data to a third country or to an international organization, including identification of the third country or international organization and, in the case of transfers referred to in the second subparagraph of Article 49(1) of the European Data Protection Regulation, documents attesting to the existence of appropriate safeguards;
- as far as possible, a general description of technical and organizational security measures.
- Documentation
The processor provides the controller with the documentation necessary to demonstrate compliance with all its obligations.