Data Processing Addendum
Nasdaq Content Services Appendices
21 February 2025
1. LIST OF PARTIES
DATA EXPORTER(S)
Name | Customer and its Affiliates |
Address | The address for Customer as set forth in the Agreement |
Contact person’s name, position and contact details | The contact details for Customer as set forth in the Agreement |
Activities relevant to the data transferred under the Standard Contractual Clauses | Receipt of the Services |
Signature and date | Customer’s signature and date on the Agreement |
Role (controller/processor) | Data Controller |
DATA IMPORTER(S)
Name | Nasdaq and its Affiliates |
Address | The address for Nasdaq as set forth in the Agreement |
Contact person’s name, position and contact details | By e-mail: privacy@nasdaq.com By postal mail at: Office of General Counsel – Privacy Team Nasdaq, Inc. 805 King Farm Blvd First Floor Rockville, MD 20850 Office of General Counsel – Stockholm Office Tullvaktsvägen 15, 10578 Stockholm Sweden |
Activities relevant to the data transferred under the Standard Contractual Clauses | Performance of the Services |
Signature and date | Nasdaq’s signature and date on the Agreement |
Role (controller/processor) | Data Processor |
2. DESCRIPTION OF THE TRANSFER
2.1 Categories of data subjects whose personal data is transferred
Customer may submit Customer Personal Data to the Services (as determined and controlled by the Customer in its sole discretion subject to any constraints set forth in the Agreement), which may relate to the following categories of Data Subjects:
2.2 Categories of personal data transferred
Customer may submit Customer Personal Data to the Services (as determined and controlled by the Customer in its sole discretion subject to any constraints set forth in the Agreement), which may relate to the following categories of Personal Data:
2.3 Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
2.4 The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
2.5 Nature of the processing
2.6 Purpose(s) of the data transfer and further processing
2.7 The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
2.8 For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
3. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13 of the Standard Contractual Clauses.
For Clause 13 (Supervision), the Supervisory Authority with responsibility for ensuring compliance by the data exporter with the GDPR with regard to Restricted Transfers, namely, the lead Supervisory Authority of the data exporter, shall act as the competent Supervisory Authority.
Taking into account the nature, scope, context and purpose of the Processing, and the risks for the rights and freedoms of natural persons. Nasdaq has implemented, and will maintain, a comprehensive written information security program ("Information Security Program") with respect to the Customer Personal Data transferred to or received by Nasdaq in performance of the Services that includes administrative, technical, and physical safeguards to ensure the confidentiality, security, integrity, and availability of Customer Personal Data and to protect against unauthorized access, use, disclosure, alteration or destruction of Customer Personal Data.
In particular, the Information Security Program will include the following safeguards where appropriate or necessary to ensure the protection of Customer Personal Data:
Measures of pseudonymisation and encryption of personal data
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing
Measures for user identification and authorization
Measures for the protection of data during transmission
Measures for the protection of data during storage
Measures for ensuring physical security of locations at which personal data are processed
Measures for ensuring events logging
Measures for ensuring system configuration, including default configuration
Measures for internal IT and IT security governance and management
Measures for certification/assurance of processes and products
Measures for ensuring data quality
Measures for ensuring limited data retention
Measures for ensuring accountability
Measures for allowing data portability and ensuring erasure
For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter
THIRD-PARTY SUB-PROCESSORS
Entity Name and Registered Address | Contact Details | Subprocessing Activities | Subprocessing Location(s) |
Amazon Web Services, Inc. | https://aws.amazon.com/compliance/data-privacy/ | Hosting services | Subject to location requirements in the Agreement, location may be European Economic Area (EEA), United Kingdom, Australia and/or United States of America |
NASDAQ AFFILIATE SUB-PROCESSORS
Certain Nasdaq Affiliates may act as Subprocessors and may assist in or provide certain Services to Nasdaq Customers. The use of Affiliates may depend on the location of a Customer.
Affiliate Name | Registered Address | Subprocessing Location(s) |
Nasdaq, Inc. | 151 W 42nd Street, New York, NY 10036 | United States of America |
Nasdaq Vilnius Services UAB | Lvovo 25, 10th Floor, Vilnius, LT-08501, Lithuania | Lithuania |
Nasdaq Corporate Solutions (India) Private Limited | Affluence No72/1 St. Marks Road Bangalore 560001 | India |
Nasdaq Technology AB Philippines Branch | 18F BGC Corporate Center, 30th St. corner 11th Avenue, Bonifacio Global City, Taguig City, Manila, Philippines | Philippines |
Nasdaq Technology AB | Tullvaktsvagen 15, Stockholm, SE 105 78, Sweden | Sweden |
Any capitalized term used herein and not specifically defined in the Agreement shall be deemed to have the meaning given to it in the UK International Data Transfer Addendum.
PART 1
Table 1: Parties
Start date | As set out on first page of the DPA | |
The Parties | Exporter (who sends the Restricted Transfer) as set out in Appendix 1 of the DPA to the extent such entities are located in the United Kingdom | Importer (who receives the Restricted Transfer) as set out in Appendix 1 of the DPA |
Parties’ details
|
|
|
Key contact | As set out in the Agreement and/or relevant applicable ordering documents, including service orders, order forms, statements of work. | As set out in the Agreement and/or relevant applicable ordering documents, including service orders, order forms, statements of work. |
Signature | The parties agree that the Signature to the DPA to which this Appendix is attached shall serve as the signature for this UK International Data Transfer Addendum. | The parties agree that the Signature to the DPA to which this Appendix is attached shall serve as the signature for this UK International Data Transfer Addendum |
Table 2: Selected SCCs, Modules and Selected Clauses
The version of the Approved EU SCCs which this UK International Data Transfer Addendum is appended to, detailed below, including this appendix information are the Commission Implementing Decision (EU) 2021/914 establishing for data transfers to Third Countries (as amended, modified, or replaced from time to time); specifically, the applicable module within the Standard Contractual Clauses is MODULE TWO (Transfer Controller to Processor). For the avoidance of doubt, MODULE ONE (Transfer Controller to Controller), MODULE THREE (Transfer Processor to Processor), and MODULE FOUR (Transfer Processor to Controller) do not apply to this DPA.
The clauses options are set out in Section 10.1 of the DPA.
TABLE 3: Appendix Information
Annex 1A List of Parties | See appendix 1 to the DPA. |
Annex 1B Description of Transfer | See appendix 1 to the DPA. |
Annex II Technical and organizational measures | See appendix 2 to the DPA. |
Annex III List of Sub processors | See appendix 3 to the DPA. |
TABLE 4: Ending this Addendum when the Approved Addendum Changes
Neither party shall have the right to end this UK International Data Transfer Addendum if the approved addendum changes. In the event any such change occurs, the parties shall work together to agree any relevant updates.
PART 2
Mandatory Clauses
Mandatory Clauses of the approved addendum, being the template addendum B.1.0 issued by the UK Information Commissioner’s Office (ICO) and laid before the UK Parliament in accordance with s119A of the UK GDPR on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses is hereby incorporated by reference into this International Data Transfer Addendum.
1. LIST OF PARTIES
DATA EXPORTER(S)
Name | Customer and its Affiliates |
Address | The address for Customer as set forth in the Agreement |
Contact person’s name, position and contact details | The contact details for Customer as set forth in the Agreement |
Activities relevant to the data transferred under the Standard Contractual Clauses | Receipt of the Services |
Signature and date | Customer’s signature and date on the Agreement |
Role (controller/processor) | Data Controller |
DATA IMPORTER(S)
Name | Nasdaq and its Affiliates |
Address | The address for Nasdaq as set forth in the Agreement |
Contact person’s name, position and contact details | By e-mail: privacy@nasdaq.com By postal mail at: Office of General Counsel – Privacy Team Nasdaq, Inc. 805 King Farm Blvd First Floor Rockville, MD 20850 Office of General Counsel – Stockholm Office Tullvaktsvägen 15, 10578 Stockholm Sweden |
Activities relevant to the data transferred under the Standard Contractual Clauses | Performance of the Services |
Signature and date | Nasdaq’s signature and date on the Agreement |
Role (controller/processor) | Data Processor |
2. DESCRIPTION OF THE TRANSFER
2.1 Categories of data subjects whose personal data is transferred
Customer may submit Customer Personal Data to the Services (as determined and controlled by the Customer in its sole discretion subject to any constraints set forth in the Agreement), which may relate to the following categories of Data Subjects:
2.2 Categories of personal data transferred
Customer may submit Customer Personal Data to the Services (as determined and controlled by the Customer in its sole discretion subject to any constraints set forth in the Agreement), which may relate to the following categories of Personal Data:
2.3 Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
2.4 The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
2.5 Nature of the processing
2.6 Purpose(s) of the data transfer and further processing
2.7 The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
2.8 For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
3. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13 of the Standard Contractual Clauses.
For Clause 13 (Supervision), the Supervisory Authority with responsibility for ensuring compliance by the data exporter with the GDPR with regard to Restricted Transfers, namely, the lead Supervisory Authority of the data exporter, shall act as the competent Supervisory Authority.
Taking into account the nature, scope, context and purpose of the Processing, and the risks for the rights and freedoms of natural persons. Nasdaq has implemented, and will maintain, a comprehensive written information security program ("Information Security Program") with respect to the Customer Personal Data transferred to or received by Nasdaq in performance of the Services that includes administrative, technical, and physical safeguards to ensure the confidentiality, security, integrity, and availability of Customer Personal Data and to protect against unauthorized access, use, disclosure, alteration or destruction of Customer Personal Data.
In particular, the Information Security Program will include the following safeguards where appropriate or necessary to ensure the protection of Customer Personal Data:
Measures of pseudonymisation and encryption of personal data
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing
Measures for user identification and authorization
Measures for the protection of data during transmission
Measures for the protection of data during storage
Measures for ensuring physical security of locations at which personal data are processed
Measures for ensuring events logging
Measures for ensuring system configuration, including default configuration
Measures for internal IT and IT security governance and management
Measures for certification/assurance of processes and products
Measures for ensuring data quality
Measures for ensuring limited data retention
Measures for ensuring accountability
Measures for allowing data portability and ensuring erasure
For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter
THIRD-PARTY SUB-PROCESSORS
Entity Name and Registered Address | Contact Details | Subprocessing Activities | Subprocessing Location(s) |
Amazon Web Services, Inc. | https://aws.amazon.com/compliance/data-privacy/ | Hosting services | Subject to location requirements in the Agreement, location may be European Economic Area (EEA), United Kingdom, Australia and/or United States of America |
NASDAQ AFFILIATE SUB-PROCESSORS
Certain Nasdaq Affiliates may act as Subprocessors and may assist in or provide certain Services to Nasdaq Customers. The use of Affiliates may depend on the location of a Customer.
Affiliate Name | Registered Address | Subprocessing Location(s) |
Nasdaq, Inc. | 151 W 42nd Street, New York, NY 10036 | United States of America |
Nasdaq Vilnius Services UAB | Lvovo 25, 10th Floor, Vilnius, LT-08501, Lithuania | Lithuania |
Nasdaq Corporate Solutions (India) Private Limited | Affluence No72/1 St. Marks Road Bangalore 560001 | India |
Nasdaq Technology AB Philippines Branch | 18F BGC Corporate Center, 30th St. corner 11th Avenue, Bonifacio Global City, Taguig City, Manila, Philippines | Philippines |
Nasdaq Technology AB | Tullvaktsvagen 15, Stockholm, SE 105 78, Sweden | Sweden |
Any capitalized term used herein and not specifically defined in the Agreement shall be deemed to have the meaning given to it in the UK International Data Transfer Addendum.
PART 1
Table 1: Parties
Start date | As set out on first page of the DPA | |
The Parties | Exporter (who sends the Restricted Transfer) as set out in Appendix 1 of the DPA to the extent such entities are located in the United Kingdom | Importer (who receives the Restricted Transfer) as set out in Appendix 1 of the DPA |
Parties’ details
|
|
|
Key contact | As set out in the Agreement and/or relevant applicable ordering documents, including service orders, order forms, statements of work. | As set out in the Agreement and/or relevant applicable ordering documents, including service orders, order forms, statements of work. |
Signature | The parties agree that the Signature to the DPA to which this Appendix is attached shall serve as the signature for this UK International Data Transfer Addendum. | The parties agree that the Signature to the DPA to which this Appendix is attached shall serve as the signature for this UK International Data Transfer Addendum |
Table 2: Selected SCCs, Modules and Selected Clauses
The version of the Approved EU SCCs which this UK International Data Transfer Addendum is appended to, detailed below, including this appendix information are the Commission Implementing Decision (EU) 2021/914 establishing for data transfers to Third Countries (as amended, modified, or replaced from time to time); specifically, the applicable module within the Standard Contractual Clauses is MODULE TWO (Transfer Controller to Processor). For the avoidance of doubt, MODULE ONE (Transfer Controller to Controller), MODULE THREE (Transfer Processor to Processor), and MODULE FOUR (Transfer Processor to Controller) do not apply to this DPA.
The clauses options are set out in Section 10.1 of the DPA.
TABLE 3: Appendix Information
Annex 1A List of Parties | See appendix 1 to the DPA. |
Annex 1B Description of Transfer | See appendix 1 to the DPA. |
Annex II Technical and organizational measures | See appendix 2 to the DPA. |
Annex III List of Sub processors | See appendix 3 to the DPA. |
TABLE 4: Ending this Addendum when the Approved Addendum Changes
Neither party shall have the right to end this UK International Data Transfer Addendum if the approved addendum changes. In the event any such change occurs, the parties shall work together to agree any relevant updates.
PART 2
Mandatory Clauses
Mandatory Clauses of the approved addendum, being the template addendum B.1.0 issued by the UK Information Commissioner’s Office (ICO) and laid before the UK Parliament in accordance with s119A of the UK GDPR on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses is hereby incorporated by reference into this International Data Transfer Addendum.