Airline – NDC or Hybrid
Last updated: 29 March 2024
SCOPE: Where (a) Carrier is using a New Distribution Capability (NDC) exclusively or in combination with a global distribution system (GDS) to distribute data to Expedia; and (b) Expedia and Carrier are processing personal data in connection with providing or receiving services or promoting or marketing (or remarketing) the services, products or supply of the other party (in each case, as such activities or services are further described under the relevant agreement entered into between the parties (the “Agreement”), herein collectively referred to as “Relevant Activities”), this global controller to controller agreement (“C2C Agreement”) is supplemental to and applies to such Agreement, and sets out additional terms, requirements and conditions on which Expedia and Carrier will each process personal data in connection with the Agreement. In this C2C Agreement, “Expedia” refers to Expedia, Inc. and/or any other Expedia group company/ies party to the Agreement. “Carrier” refers to one or more third-party airline that contracts with Expedia for Relevant Activities (and all references to either Expedia or Carrier will be construed as plural terms to the extent required by the Agreement).
1. DEFINITIONS AND INTERPRETATION
1.1 This C2C Agreement is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms set forth in the Agreement apply to the interpretation of this C2C Agreement unless otherwise defined herein; and:
- “appropriate technical and organizational measures“, “controller”, “personal data”, “process”, “processor“, “personal data breach” and “supervisory authority” or their equivalent terms each have the meaning given to them in Applicable Data Protection Law(s).
- “Applicable Data Protection Law(s)” means any applicable laws and regulations in any relevant jurisdiction relating to the use or processing of Relevant Personal Data.
- “CBPR Country” means a country that is a full or associate member of the CBPR System.
- “CBPR Party” means an organization that holds a current certification under the CBPR System.
- “CBPR System” means the Asia-Pacific Economic Cooperation Cross Border Privacy Rules System.
- “DPF” means the EU-U.S. Data Privacy Framework and/or Swiss-U.S Data Privacy Framework or any successor self-certification program operated by the U.S Department of Commerce and approved by the European Commission from time to time and which has not been invalidated (and in each case, includes the UK Extension to the EU-U.S. Data Privacy Framework and any other country extension to such framework that operates to extend the application of the EU-U.S. Data Privacy Framework to that country).
- “Permitted Purpose” means for the purpose of (a) facilitating the Relevant Activities (including providing customer support); (b) improving the provision of the Relevant Activities, including the underlying technology; (c) account administration and support between the Parties; (d) facilitating payment of commission, fees and/or other amounts pursuant to the Agreement; (e) generating reports for the other Party and any further processing required for reconciliation, complaints handling and similar activities connected with servicing the Agreement; (f) creating reports for analytics, business intelligence and business reporting; (g) fraud prevention; (h) responding to law enforcement requests and tax authority audit requests; (i) facilitating business asset transactions (which may extend to any mergers, acquisitions or asset sales); (j) otherwise complying with a Party’s obligations under the Agreement and applicable laws; and (k) for the determination, calculation and reporting of Travel Taxes and other applicable taxation purposes as may be required from time to time.
- “Relevant Personal Data” means personal data collected or otherwise processed by Expedia or Carrier in connection with the Agreement.
- “Restricted Transfer Country” means any country in the European Economic Area, Switzerland, the United Kingdom and Brazil.
- “Restricted Transfer Data” means any Relevant Personal Data relating to a booking made via a point of sale intended by a Party to be accessed by Travelers in a Restricted Transfer Country.
- “SCCs” means the approved European Commission’s Standard Contractual Clauses for the transfer of personal data from the European Union to third countries, as issued on 4 June 2021, and as amended, replaced, supplemented, or superseded from time to time, and the full current version of which can be found at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en
- “Traveler” means an individual whose personal data is processed as Relevant Personal Data by a Party in connection with the Agreement.
1.2 In the case of conflict or ambiguity between:
- any of the provisions of this C2C Agreement and the provisions of the Agreement, the provisions of this C2C Agreement will prevail to the extent of the subject matter of this C2C Agreement; and
- any of the provisions of this C2C Agreement and the SCCs incorporated by reference into them, the provisions of the executed SCCs will prevail.
2. RELATIONSHIP OF THE PARTIES
Each of Expedia and Carrier acknowledge that for the purpose of Applicable Data Protection Law, each party is an autonomous and independent controller.
3. General mutual obligations
3.1 Each Party will:
- comply with all Applicable Data Protection Law applicable to controllers when processing Relevant Personal Data;
- ensure that it has an appropriate lawful basis under Applicable Data Protection Law for its processing of Relevant Personal Data, including for the sharing of Relevant Personal Data with the other Party for use by that Party as an independent and autonomous controller for a Permitted Purpose in accordance with the Agreement;
- implement and maintain all appropriate technical and organizational measures and safeguards to protect Relevant Personal Data they each process from and against a personal data breach, taking into account the risks represented by the processing and the nature of the Relevant Personal Data;
- take all necessary measures to ensure that Relevant Personal Data is transferred in accordance with Applicable Data Protection Law; and
3.2 Transparency and disclosures: Each party will ensure that all Travelers are made aware in a timely manner, via its privacy policy and/or by any other appropriate means, that their personal data will be shared with the other party for the Permitted Purposes (or such category of parties in general terms, if permitted under Applicable Data Protection Law); and will direct Travelers to the other party’s privacy policy (specifically or generally) for more information about their handling of their personal data.
3.3 Naming the other Party: Neither Party will name the other in any public statement or disclosure to an individual or to a Supervisory Authority or other legal body relating to privacy without obtaining prior written approval from the other, unless legally prohibited from liaising with the other party.
3.4 Connectivity Providers: Where a Party (Instructing Party) directs the other (Instructed Party) to receive or transfer Personal Data via a third party (a Connectivity Provider) who is acting as a processor on behalf of the Instructing Party and as a third party intermediary recipient or transferor vis-à-vis the Instructed Party, then the Instructing Party confirms that it shall be liable to the Instructed Party for the acts and omissions of its Connectivity Provider, subject to any agreed limitation of liability agreed between the Parties in the Agreement.
3.5 DPF: While, and to the extent that the DPF is a valid and recognized basis for transfers to the US from time to time, DPF shall apply for transfers of Restricted Transfer Data from Carrier to Expedia. In such event, the provisions of Clause 3.9-3.11 (inclusive) below apply only, in respect of Expedia’s receipt of Restricted Transfer Data in the United States, if and to the extent that Expedia’s DPF certification lapses or otherwise ceases to apply. If the Carrier has elected to also rely on its DPF certification, the above condition shall equally apply to Carrier.
3.6 DPF Flowdown Obligations: If Carrier is certified under the DPF, it will comply with the Notice and Choice Principles of the DPF (as defined in the EU-U.S. DPF). For the avoidance of doubt, if Carrier is not DPF certified, then the SCCs will be relied on for transfers of Restricted Transfer Data from Expedia to Carrier.
3.7 DPF Disclosure Obligations: Carrier acknowledges that Expedia may disclose this C2C Agreement and any relevant privacy provisions in the Agreement to the US Department of Commerce, the Federal Trade Commission, any European data protection authority, or any other US or EU judicial or regulatory body upon their request and that any such disclosure shall not be deemed a breach of confidentiality.
3.8 CBPR System:
- The Parties agree and acknowledge that (a) a CBPR Party is bound by a legally enforceable set of obligations to provide comparable protection to Applicable Data Protections Laws; and (b) Expedia is a CBPR Party. Where the Partner is also a CBPR Party, the provisions of this Clause 3.8 will be construed to apply two-way.
Subject to paragraph 3 below, the Parties agree that where:
- (a) Relevant Personal Data is being transferred from one CBPR Country to another CBPR Country; and
- (b) the data importer is a CBPR Party,
then, to the extent that and for so long as the CBPR System is a recognized method of transfer by a relevant supervisory authority, the CBPR System shall be the agreed mechanism for cross-border transfers of Relevant Personal Data to such CBPR Party.- The CBPR System will only apply for transfers that involve at least one of the Parties being located in a Asia-Pacific Region country that is also a CBPR Country.
- Expedia confirms that it will provide at least the same level of protection for the Relevant Personal Data as is required under the CBPR System; and it will promptly notify the other Party if it makes a determination that it can no longer provide this level of protection. In such event, or if the other Party otherwise reasonably believes that Expedia is not protecting the Relevant Personal Data to the standard required under the CBPR System, the other Party may either: (a) instruct Expedia to take reasonable and appropriate steps to stop and remediate any unauthorized processing, in which event the Parties will promptly cooperate in good faith to identify, agree and implement such steps; (b) agree an alternate safeguard that may apply to the processing under Applicable Data Protection Law; or (c) if (a) and (b) fail to resolve the issue, terminate this C2C Agreement and the Agreement (or, at the other Party’s election, any affected portion thereof) without penalty by giving notice to Expedia. If the other Party also holds a current CBPR System certification, then the above provisions will be deemed to be apply as if the obligations are two-way.
3.9 Extension of SCCs to Non-Restricted Transfer Countries: In relation to transfers of Relevant Personal Data between the Parties originating from a country that is not a Restricted Transfer Country but is otherwise subject to safeguards that, according to Applicable Data Protection Law, must be applied before a transfer can be made of that Relevant Personal Data outside of the country of origin (each a Non-Restricted Transfer Country), then the Parties agree that (a) the SCCs set out in clause 3.10 below shall be deemed to extend to such additional transfers to the extent that such deemed extension would satisfy the safeguards of that particular country; and/or (b) where the measures set out in Clause 3.10 are insufficient or require supplementary measures, the Parties agree to take such further measures, including, for example, execution of relevant documents, collection of consent, making of required filings, as may be required from to time in order to satisfy Applicable Data Protection Law.
3.10 SCCs: Subject to Clause 3.5 above, the Parties agree to enter into the SCCs which are incorporated by reference into this C2C Agreement on an unchanged basis save for the following selections:
- Where Carrier is located in a Restricted Transfer Country or otherwise in a country deemed “adequate” in accordance with Article 45 of the GDPR, Module one (1) of the SCCs will apply one-way only in respect of transfers from Carrier to Expedia. Otherwise, Module One (1) of the SCCs applies two-way to cover both transfers from Expedia to Carrier and from Carrier to Expedia.
- For the purposes of clause 11(a) of the SCCs, the optional language is deleted.
- For the purposes of clause 13 of the SCCs, the relevant paragraph is “The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated in Annex I.C, shall act as competent supervisory authority”.
- For the purposes of clause 17 of the SCCs, the governing law is Ireland.
- For the purposes of clause 18(b) of the SCCs, the selection is Ireland.
A new clause 19 is added to the SCCs to cover transfers of personal data from the United Kingdom to outside of the United Kingdom as follows:
“Clause 19
UK GDPR and DPA 2018
The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover extra-territorial transfers that fall under the scope of UK GDPR and Data Protection Act 2018 (UK transfer). For the purposes of such UK transfer, the provisions of the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses shall apply as set out in the form attached as the Addendum."
A new clause 20 is added to cover transfers of personal data from Switzerland to outside of Switzerland as follows:
“Clause 20
Swiss – FADP
The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover extra-territorial transfers that fall under the scope of Federal Act of Data Protection (FADP) (referred to in this Clause as a Swiss transfer). For the purposes of such Swiss transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and the Federal Data Protection and Information Commissioner (FDPIC) shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Swiss transfer as are deemed necessary by the FCPIC to comply with the UK GDPR and FADP, and the Clauses shall be interpreted in accordance with the requirements for Swiss transfers arising under those laws or as otherwise set out in guidance issued by the FDPIC, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Swiss transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the FADP when engaging in Swiss transfers.”
A new clause 21 is added to the SCCs to cover transfers of personal data from Brazil to outside of Brazil as follows:
“Clause 21
Brazil – LGPD
The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of the Brazilian General Data Protection Law No. 13,709/18 (Lei Geral de Proteção de Dados) (LGPD) (referred to in this Clause as a Brazilian transfer). For the purposes of such Brazilian transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and Brazil’s National Data Protection Authority (ANPD) shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Brazilian transfer as are deemed necessary by the ANPD to comply with the LGPD, and the Clauses shall be interpreted in accordance with the requirements for Brazilian transfers arising under those laws or as otherwise set out in guidance issued by the ANPD or other relevant Brazilian authority, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Brazilian transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the LGPD when engaging in Brazilian transfers.”
A new clause 22 is added to the SCCs to cover transfers of personal data from any other country not hitherto specified where the SCCs may be extended to ensure appropriate safeguards for transfers of personal data originating from that country to a party located outside of that country as follows:
“Clause 22
Other third country transfers
The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover cross-border transfers that fall under the scope of the any other applicable laws and regulations in any relevant jurisdiction, relating to the use or processing of personal data (Applicable Data Protection Laws) requiring terms and protections broadly equivalent to these Clauses in order to transfer personal data from that country to another (referred to in this Clause as a Third Country transfer). For the purposes of such Third Country transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and the data protection authority or regulatory body of that country shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Third Country transfer as are deemed necessary by such supervisory authority to comply with the Applicable Data Protection Law of that country, and the Clauses shall be interpreted in accordance with the requirements for Third Country transfers arising under those laws or as otherwise set out in guidance issued by the relevant supervisory authority, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Third Country transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the Applicable Data Protection Law(s) when engaging in Third Country transfers.”
3.11 Annex 1 (SCCs Processing Overview) to this C2C Agreement constitutes Annex 1 of the SCCs. Annex 2 (Technical and Organizational Measures) to this C2C Agreement constitutes Annex 2 of the SCCs and applies only to Expedia where (a) only one-way SCCs apply for transfers of Restricted Transfer Data from Carrier to Expedia; or (b) Carrier has provided, and Expedia has accepted, adequate technical and organizational measures to satisfy Carrier’s Annex 2 requirements of the SCCs. Where the aforementioned conditions are not met, Annex 2 will be construed to apply to both parties and all references to Expedia and Expedia Group will be construed to reference either party accordingly. The Addendum to this C2C Agreement constitutes the UK Addendum for the purposes of the SCCs.
4. PCI Data
Each Party agrees that it will process, store, transmit and access any Relevant Persona Data that comprises payment information (including, without limitation, credit card, debit card, or financial account information) in compliance with the current Payment Card Information Data Security Standard (“PCI DSS”). In addition, where Carrier is the merchant of record and where Expedia possesses, stores, processes, or transmits Traveler’s cardholder data on Carrier’s behalf, or to the extent that Expedia could impact the security of Carrier’s cardholder data environment, Expedia acknowledges that Expedia is responsible for the security of cardholder data that Expedia possesses, stores, processes or transmits and will comply with the PCI DSS as issued by the PCI Security Standard Council, as updated from time to time.
5. Term, termination and notices
5.1 This C2C Agreement will remain in full force and effect so long as the Agreement remains in effect.
5.2 Any provision of this C2C Agreement that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect Relevant Personal Data will remain in full force and effect.
5.3 Any notices under this DPA will be deemed effective if delivered by email to the contact(s) provided by either Party to the other for these purposes in accordance with the notice provisions in the Agreement. In the case of Expedia, this will require an email being sent to the account/relationship manager from time to time and copied to the Expedia privacy mailbox provided from time to time.
ANNEX I – SCCs PROCESSING OVERVIEW
MODULE ONE: Part 1: Controller to Controller (Carrier to Expedia)
A. LIST OF PARTIES
Data exporter(s):
Party | The party/ies identified as the Carrier, partner, supplier, airline or similar in the Agreement “Carrier”) in the Agreement |
Address
| As specified in the Agreement |
Contact name, position & contact details | To account or relationship manager using email address provided to Expedia from time to time |
Activities relevant to data transferred under SCCs
| Relevant Activities, being all processing activities required in connection with the promotion of the services of Carrier by facilitating the booking of airfares and other activities through the Expedia systems, and any other activities set out in the Agreement between the Parties. |
Role | Controller
|
Data importer(s):
Party | The non-EU parties identified as Expedia in the Agreement (“Expedia”) (as defined in the Agreement) |
Address | As specified in the Agreement |
Contact person’s name, position and contact details | Effective notice is deemed made when an email is sent to both (1) Account/relationship manager; and (2) the Expedia privacy mailbox, in each case using email address(es) provided to Carrier from time to time and otherwise in accordance with notice requirements in the Agreement |
Activities relevant to the data transferred under these Clauses | Relevant Activities as set out above. |
Role | Controller |
B. DESCRIPTION OF TRANSFER
Categories of data subject |
|
Categories of personal data |
|
Sensitive Data |
|
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis) |
|
Nature of the processing |
|
Purpose(s) of the data transfer and further processing |
|
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period |
|
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing |
|
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with Clause 13 of SCCs
IRISH DATA PROTECTION AUTHORITY
MODULE ONE: Part 2: Controller to Controller (Expedia to Carrier)
A. LIST OF PARTIES
Data exporter(s):
The Parties identified as Data Importers in Module 1 Part 1 above. See Module 1, Part 1 for further details. |
Data importer(s):
The Party/ies identified as Data Exporter(s) in Module 1, Part 1 above. See Module 1, Part 1 for further details. |
B. DESCRIPTION OF TRANSFER
Categories of data subject Categories of personal data Sensitive Data | As per Module 1, Part 1 |
Frequency of transfer Nature of processing Purposes | As per Module 1, Part 1 |
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period | In accordance with the retention policy of Carrier |
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing | To be provided upon request in the event that SCCs apply |
C. COMPETENT SUPERVISORY AUTHORITY
As per Module 1, Part 1.
ANNEX II - TECHNICAL AND ORGANIZATIONAL MEASURES
The technical and organizational measures that apply to us/Expedia for the purposes of Module 1, Part 1 are set out below.
SUBJECT | MEASURE |
Measures of pseudonymisation and encryption of personal data |
|
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services |
|
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident |
|
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing |
|
Measures for user identification and authorisation Measures for the protection of data during transmission Measures for the protection of data during storage |
|
Measures for ensuring physical security of locations at which personal data are processed |
|
Measures for ensuring events logging |
|
Measures for ensuring system configuration, including default configuration Measures for internal IT and IT security governance and management Measures for certification/assurance of processes and products |
|
Measures for ensuring data minimisation Measures for ensuring data quality Measures for ensuring limited data retention Measures for ensuring accountability |
|
Measures for allowing data portability and ensuring erasure |
|
For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter |
|
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Addendum)
This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.
Part 1 Tables
Table 1: Parties | ||
Start Date | The date of the Agreement incorporating the SCCs to which these are attached (Approved EU SCCs) | |
Parties Key Contact | Exporter: As per Approved EU SCCs
| Importer: As per Approved EU SCCs
|
Table 2: Selected SCCs, Modules and Selected Clauses | ||
Addendum EU SCCs | The version of the Approved EU SCCs to which this Addendum is appended | |
Table 3: Appendix Information | ||
“Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in: | ||
Annex IA: List of Parties Annex 1B Description of Transfer Annex II: Technical and organizational measures | As per Approved EU SCCs | |
Table 4: Ending this Addendum when the Approved Addendum changes | ||
Which Parties may end this Addendum as set out in Section 19 | Neither Party |
Part 2: Mandatory Clauses
Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.