Hotel – Chain - Controller to Controller Agreement (including the SCCs) -

 HOTEL – CHAIN - CONTROLLER TO CONTROLLER AGREEMENT (INCLUDING THE SCCS)

SCOPE: Where you and we are sharing personal data as part of the agreement we have between us for us to promote or market (or remarket) or otherwise facilitate hotel bookings for you (described in these terms as “Relevant Activities”) as further described under the relevant agreement entered between us (the “Agreement”), this controller to controller agreement (“C2C Agreement”) forms part of that Agreement, and sets out the additional terms that relate to our and your processing of personal data under that Agreement between us. In this C2C Agreement, “Expedia” or “us” refers to Expedia, Inc. and/or any other Expedia group company/ies party to the Agreement. “Hotel” or “you” refers to one or more parties identified as “you” in the Agreement (and all references to either us or you can be treated as plural as relevant).

1. DEFINITIONS AND INTERPRETATION

1.1 This C2C Agreement is subject to the terms of the Agreement and is incorporated into the Agreement. Interpretations and defined terms in the Agreement apply to this C2C Agreement and:

  1. controller”, “personal data”, “personal data breach”, “process”, “processor” and “supervisory authority” or their equivalent terms each have the meaning given to them in Applicable Data Protection Law(s).
  2. Applicable Data Protection Law(s)” means all data protection/privacy laws that apply to personal data processed under the Agreement.
  3. EU-U.S DPF” means an EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework and/or Swiss-U.S. Data Privacy Framework self-certification program operated by the U.S. Department of Commerce and approved by the European Commission from time to time and which has not been invalidated.
  4. Guest” means an individual whose personal data is processed as Relevant Personal Data by a Party in connection with the Agreement.
  5. Permitted Purpose” means for the purpose of (a) facilitating the Relevant Activities; (b) improving the provision of the Relevant Activities, including the underlying technology; (c) creating internal reports for analytics, business intelligence and business reporting; (d) responding to law enforcement requests; (e) facilitating business asset transactions (which may extend to any mergers, acquisitions or asset sales); and (f) otherwise complying with our obligations under the Agreement and applicable laws.
  6. Relevant Personal Data” means personal data collected or otherwise processed by us or you in connection with the Agreement.
  7. Restricted Transfer Data” means any personal data processed by or on behalf of us under the Agreement that relates to individuals who are located in the European Economic Area, Switzerland or UK.
  8. SCCs” means the approved European Commission’s Standard Contractual Clauses for the transfer of personal data from the European Union to third countries, as issued on 4 June 2021, and as amended, replaced, supplemented, or superseded from time to time, and the full current version of which can be found at https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc/standard-contractual-clauses-international-transfers_en
  9. Staff” means past, potential, present and future staff of a party (including those who work on a non-temporary basis, and includes volunteers, agents, independent contractors, interns, temporary and casual workers) ("Employees"); relatives, beneficiaries, parents and guardians of Employees ("Relatives"); and job applicants.
  10. Third-Party Controller” means a third-party partner of an Expedia group company that contracts with such Expedia group company for API feed of hotel supply and where Expedia acts as a processor of such Third-Party Controller.

1.2 In the case of conflict or ambiguity between: 

  1. any of the provisions of this C2C Agreement and the provisions of the Agreement, the provisions of this C2C Agreement will prevail to the extent of the subject matter of this C2C Agreement; and
  2. any of the provisions of this C2C Agreement and the SCCs incorporated by reference into them, the provisions of the executed SCCs will prevail.

2. RELATIONSHIP OF THE PARTIES AND DATA PROTECTION

2.1 Subject to Clause 2.4, each of Expedia and Hotel acknowledge that for the purpose of Applicable Data Protection Law, each party is an autonomous and independent controller.

2.2 Hotel acknowledges that where Expedia has self-certified its compliance to the EU-U.S. DPF, it has done so in respect of guest personal data only and not in respect of its own employee personal data. Hotel further acknowledges that to the extent EU-U.S. DPF applies to the Relevant Personal Data, Expedia is required to flow down certain EU-U.S. DPF data protection requirements to Hotel under this C2C Agreement as set out in Clauses 3.8 and 3.9 below.

2.3 Expedia acknowledges that where (a) Hotel has indicated reliance on its self-certification of its compliance to EU-U.S. DPF in the Agreement; and (b) to the extent EU-U.S. DPF applies to the Relevant Personal Data, Hotel is required to flow down certain EU-U.S. DPF data protection requirements to Expedia, and the obligations set out in Clauses 3.8 and 3.9 below will be deemed to be reciprocal obligations, and references to each of Expedia and Hotel shall be construed accordingly.

2.4 Where and to the extent that Expedia is transferring personal data to Hotel from a Third Party Controller, Expedia is acting as a processor/service provider of such Third Party Controller, and not for the Hotel, and the Hotel receives such personal data as a third party recipient.  As between the Parties to this Agreement, in respect of such personal data, Hotel agrees it is responsible for complying with all applicable privacy and data protection laws and obligations as they relate to Hotel’s storage, sharing, transmission, use and safeguarding (collectively, “processing”) of all such personal data contemplated by the Agreement.  For the purpose of data protection obligations, Expedia  confirms that to the extent it processes personal data pursuant to the Agreement or transmitted and/or received from a Third Party Controller (i) Expedia does so at the direction of the Third Party Controller and not at the direction of the Hotel, and (ii) if required by applicable privacy and data protection laws, Expedia has a written agreement with the Third Party Controller that addresses its role and responsibilities with respect to Personal Data relating to this Agreement. The obligations set out in the remainder of this C2C Agreement do not apply in respect of personal data transferred under this Clause 2.4.

3. OBLIGATIONS RELATING TO RELEVANT PERSONAL DATA

3.1 Each Party will:

  1. comply with all Applicable Data Protection Law applicable to controllers when processing such Relevant Personal Data;
  2. ensure that it has an appropriate lawful basis under Applicable Data Protection Laws for its processing of Relevant Personal Data, including for the sharing of Relevant Personal Data to the other Party for use by that Party as an independent and autonomous controller in accordance with the Agreement;
  3. implement and maintain all appropriate technical and organizational measures and safeguards to protect Relevant Personal Data they each process from and against a personal data breach, taking into account the risks represented by the processing and the nature of the Relevant Personal Data;
  4. take all necessary measures to ensure that Relevant Personal Data are transferred in accordance with Applicable Data Protection Law; and
  5. not share, distribute, sell or otherwise permit access to Relevant Personal Data with any third party save for any data sharing that is necessary to fulfil a Permitted Purpose or as otherwise agreed between the Parties in the Agreement.

3.2 Transparency and disclosures: Each party will ensure that all Guests are made aware in a timely manner, via its privacy policy and/or by any other appropriate means, that their personal data will be shared with the other party for the Permitted Purposes (or such category of parties in general terms, if permitted under Applicable Data Protection Law); and will direct Guests to the other party’s privacy policy (specifically or generally) for more information about their handling of their personal data. 

3.3 Naming the other Party: Neither Party will name the other in any public statement or disclosure to an individual or to a Supervisory Authority or other legal body relating to privacy without obtaining prior written approval from the other, unless legally prohibited from liaising with the other party.

3.4 Government requests for information: Where either Party ( the Receiving Party) has received a request from government bodies in relation to surveillance activity, it will inform the other Party of such request where legally permitted to do so. In the event that a Party receives a government demand for access to Relevant Personal Data, that Party will (a) provide a copy of the demand to the other Party unless legally prohibited from doing so; (b) consult with the other Party and agree response unless legally prohibited from doing so; (c) challenge such demand to the extent, in the reasonable opinion of the Receiving Party, that such demand conflicts with that Party’s obligations under Applicable Data Protection Law; and (d) shall only disclose or provide access to Relevant Personal Data in response to any demands where compelled to do so.

3.5 Breaches: In the event of a confirmed personal data breach affecting Relevant Personal Data which is both reportable to a supervisory authority and affecting Relevant Personal Data of Staff of the other Party (where that Relevant Personal Data has been specifically collected for the purpose of  facilitating Relevant Activities for Staff of the other Party and not as coincidental occurrence), the Party suffering such breach will promptly notify the other Party, providing full details of the same. In such event, both parties shall cooperate (reasonably and in good faith to remedy or mitigate the effects of such personal data breach, and the reasonable costs of such cooperation shall be borne by the party that suffered the personal data breach.

3.6 Confidential Information: All types of data shared between Parties are to be considered Confidential Information. Therefore, those data can’t be shared without specific written authorization from the Party to which those data belong other than in accordance with the Agreement. Both Parties agree to use those data exclusively in accordance with the Agreement and not for any further purpose without express written consent of the other Party. Parties are also held fully responsible for the conduct of their own Staff.

3.7 EU-U.S. DPF: While, and to the extent that EU-U.S. DPF is a valid and recognized basis for transfers to the US from time to time, EU-U.S. DPF shall apply for transfers of Restricted Transfer Data from Hotel to Expedia. In such event, the provisions of Clause 3.10 below apply only, in respect of Expedia’s receipt of Restricted Transfer Data in the United States, if and to the extent that Expedia’s EU-U.S. DPF certification lapses or otherwise ceases to apply. If the Hotel has elected to also rely on EU-U.S. DPF, the above condition shall equally apply to Hotel.

3.8 EU-U.S. DPF Flowdown Obligations: Hotel will provide at least the same level of protection for the Relevant Personal Data as is required under EU-U.S. DPF; and Hotel shall promptly notify Expedia if it makes a determination that it can no longer provide this level of protection. In such event, or if Expedia otherwise reasonably believes that Hotel is not protecting the Relevant Personal Data to the standard required under EU-U.S. DPF, Expedia may either: (a) instruct Hotel to take reasonable and appropriate steps to stop and remediate any unauthorized processing, in which event Hotel will promptly cooperate with Expedia in good faith to identify, agree and implement such steps; (b) agree an alternate safeguard that may apply to the processing under Applicable Data Protection Law; or (c) terminate this C2C Agreement and the Agreement without penalty by giving notice to Hotel. If the Hotel indicates in the Agreement that it also elects to rely on EU-U.S. DPF in the Agreement, then the above provisions and those of Clause 3.9 below shall be deemed to be apply as if the obligations are two-way.

3.9 EU-U.S. DPF Disclosure Obligations: Hotel acknowledges that Expedia may disclose this C2C Agreement and any relevant privacy provisions in the Agreement to the US Department of Commerce, the Federal Trade Commission, any European data protection authority, or any other US or EU judicial or regulatory body upon their request and that any such disclosure shall not be deemed a breach of confidentiality.

3.10 SCCs: To the extent that (a) Restricted Transfer Data is in scope; and (b) EU-U.S. DPF either is not valid or does not apply to a Restricted Data Transfer from time to time, the Parties agree to enter into the SCCs which are incorporated by reference into this C2C Agreement on an unchanged basis save for the following elections:

  1. Module 1 (Controller to Controller) only of the SCCs apply.
  2. For the purposes of clause 9(a) of the SCCs, option 1 (“Specific Prior Authorization”) is deleted.
  • For the purposes of clause 11(a) of the SCCs, the optional language is deleted.
  1. For the purposes of clause 13 of the SCCs, the relevant paragraph is “The supervisory authority of the Member State in which the representative within the meaning of Article 27(1) of Regulation (EU) 2016/679 is established, as indicated in Annex I.C, shall act as competent supervisory authority”.
  2. For the purposes of clause 17 of the SCCs, the governing law is Ireland.
  3. For the purposes of clause 18(b) of the SCCs, the selection is Ireland.
  • A new clause 19 is added to the SCCs to cover transfers of personal data from the United Kingdom to outside of the United Kingdom as follows:

Clause 19 

UK GDPR and DPA 2018

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover extra-territorial transfers that fall under the scope of UK GDPR and Data Protection Act 2018 (a UK transfer). For the purposes of such UK transfer, the provisions of the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses shall apply as set out in the form attached as the Addendum.

  • A new clause 20 is added to cover transfers of personal data from Switzerland to outside of Switzerland as follows:

“Clause 20 

Swiss – FADP

The Parties agree that these Clauses will extend and apply, to the extent relevant to the transfer in question, to cover extra-territorial transfers that fall under the scope of Federal Act of Data Protection (FADP) (referred to in this Clause as a Swiss transfer). For the purposes of such Swiss transfers, the governing law shall be deemed to be the selected Member State, the choice of forum shall be the selected Member State and the Federal Data Protection and Information Commissioner (FDPIC) shall be the competent supervisory authority. The Parties further agree that such further changes shall be construed to be made to the Clauses in respect of a Swiss transfer as are deemed necessary by the FCPIC to comply with the UK GDPR and FADP, and the Clauses shall be interpreted in accordance with the requirements for Swiss transfers arising under those laws or as otherwise set out in guidance issued by the FDPIC, without the Parties having to enter into separate standard contractual clauses prepared specifically for their Swiss transfers. The Parties shall further do all such acts and things as may be necessary to ensure compliance with the FADP when engaging in Swiss transfers.” 

3.11 Annex 1 to these C2C Agreement constitutes Annex 1 of the SCCs. Unless the Hotel has provided an alternative Annex 2 which has been accepted as sufficient by Expedia for the purposes of the SCCs, Annex 2 to this C2C Agreement will apply to both Parties for the purposes of the SCCs incorporated under this Part 3, and references to Expedia Group will be deemed to generally apply to both the Expedia group and the group of companies to which the Hotel belongs. The Addendum to this C2C Agreement constitutes the UK Addendum for the purposes of the SCCs.

4. Cardholder and Financial/Payment Account Data

Each Party agrees that it will process, store, transmit and access any Relevant Persona Data that comprises payment information (including, without limitation, credit card, debit card, or financial account information) in compliance with the current Payment Card Information Data Security Standard (“PCI DSS”). In addition, where Hotel is the merchant of record and where Expedia possesses, stores, processes, or transmits Guest’s cardholder data on Hotel’s behalf, or to the extent that Expedia could impact the security of Hotel’s cardholder data environment, Expedia acknowledges that Expedia is responsible for the security of cardholder data that Expedia possesses, stores, processes or transmits and will comply with the PCI DSS as issued by the PCI Security Standard Council, as updated from time to time.

5. TERM AND TERMINATION

5.1 This C2C Agreement will remain in full force and effect so long as the Agreement remains in effect.

5.2 Any provision of this C2C Agreement that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect Relevant Personal Data will remain in full force and effect.        
 

ANNEX I – SCCs PROCESSING OVERVIEW

MODULE ONE: Part 1: Controller to Controller (Hotel to Expedia)

A. LIST OF PARTIES

Data exporter(s):

Party

The party/ies identified as the Hotel, partner, supplier,participating property, corporate or similar in the Agreement  “Hotel”) in the Agreement

Address

 

As specified in the Agreement

Contact name, position & contact details for all Expedia Group parties

To account or relationship manager using email address provided to Hotel from time to time

Activities relevant to data transferred under SCCs

 

Relevant Activities, being all processing activities required in connection with the promotion of the services of Hotel by facilitating the booking of hotel rooms through the Expedia systems, and any other activities set out in the Agreement between the Parties.

Role

Controller

 

 

Data importer(s):

Party

The non-EU parties identified as Expedia in the Agreement (“Expedia”) (as defined in the Agreement)

Address

As specified in the Agreement

Contact person’s name, position and contact details

Account manager or relationship manager using email address notified to Hotel contact from time to time

Activities relevant to the data transferred under these Clauses

Relevant Activities as set out above.

Role

Controller

 

B. DESCRIPTION OF TRANSFER

Categories of data subject

Guests, being individuals whose personal data is collected and otherwise processed in connection with a Relevant Activity

Categories of Personal Data

· Identification data, including title; first and last name; date and place of birth; gender, nationality; login details; passport; ID card; driver's license numbers; including delivery and expiration dates; and loyalty program information and numbers

· Contact details, including postal address; email address; telephone (fixed and mobile); fax number; social media network username /handles

· National identifiers, including tax ID; government identification number

· Economic and financial data: bank account number; bank details; payment card details.

· Billing information, including client ID; invoices; payments including date and number of invoice, address where the invoice is being sent, currency used for the transaction, amount of the airport taxes and VAT, cost center

· Guest booking data, including Guest's history and preferences, including accessibility requirements; Guest group.

· Correspondence/communication with Guest

· User communication: choices and concerns (including Guest newsletter opt-out requests)

· Marketing/ surveys/ reviews data

· Prize draw/ competition entries

· Details of co-travelers/family members or emergency contacts

Sensitive Data

· Sensitive data, as evidenced by room preference requests and to the extent necessary to address any ancillary accessibility, dietary or other special needs arrangements in connection with the provision of accommodation and related services.

· Religious beliefs as evidenced by food preferences.

· LGBTQ-welcoming - reviews/ complaints handling

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

Continuous or ad hoc basis in accordance with the needs of each Party’s business

Nature of the processing

All processing operations required to facilitate purposes set out below

Purpose(s) of the data transfer and further processing

Permitted Purposes, as defined in the C2C Agreement

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

In accordance with the retention policy of Expedia Group, provided that to the extent that any personal data is retained beyond the termination of the Agreement for back up or legal reasons, the Data Hotel will continue to protect such personal data in accordance with the Agreement

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

To be provided upon request.

B. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13 of SCCs

IRISH DATA PROTECTION AUTHORITY

 

MODULE ONE: Part 3: Controller to Controller (Expedia to Hotel)

A. LIST OF PARTIES

Data exporter(s):

The Parties identified as Data Importers in Module 1 above. See Module 1 for further details.

 

Data importer(s):

The Party/ies identified as Data Exporter(s) in Module 1 above. See Module 1 for further details.

C. DESCRIPTION OF TRANSFER

· Categories of data subject

· Categories of Personal Data

· Sensitive Data

As per Module 1

· Frequency of transfer

· Nature of processing

· Purposes

As per Module 1

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

In accordance with the retention policy of Hotel

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

To be provided upon request.

D. COMPETENT SUPERVISORY AUTHORITY

As per Module 1.

 

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES

The technical and organisational measures that apply to us/Expedia for the purposes of Module 2 are set out below.

SUBJECT

MEASURE

Measures of pseudonymisation and encryption of personal data 

· Expedia Group supports industry standard encryption protocols for data transmission based on Expedia Group’s Information Classification and Handling Standard.   

· Data handling requirements are based on a categorical basis. Depending on the data being handled, different security requirements are in place across Expedia Group. For example, credit card data is considered Highly Sensitive and required to be encrypted both in transit and at rest.  

· Personal data of the customer (and its employees) is pseudonymized (and anonymized) by Expedia Group when possible and as required according to EG’s Information, Classification and Handling Standards.

· Credit card numbers are tokenized/pseudonymized to eliminate processing of cleartext credit card numbers. 

· Expedia Group utilizes encrypted connections through VPN, SSL, etc. and utilizes multi-factor authentication mechanisms. 

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services 

· Expedia Group maintains responsibilities and procedures for the management and operation of all information processing facilities to ensure complete, valid and accurate processing of data.  

· The monitoring of key processing facilities is in place, with a robust SOX program where controls over data processing and integrity are tested and attested to on an ongoing basis.  

· Industry standard logging and monitoring is in place on EG’s systems to ensure and protect against unauthorized access, modification and/or deletion.   

· Expedia Group maintains service resilience through redundant architecture, data replication, and integrity checking. 

Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident 

· Expedia Group’s systems are specifically designed to impede or prevent common attacks and ensure availability for operation, monitoring and maintenance.  For this purpose, Expedia Group regularly carries out simulated tests and audits to confirm that its systems maintain availability.

· Servers are patched against Expedia Group’s robust patching policy and protected by industry standard AV/AM programs.  Additionally, vulnerability assessments, thorough testing, and network reviews are conducted to ensure EG’s systems are maintained.

· Availability and reliability monitoring is in place to ensure Expedia sites remain online, with minimal interruptions of service. 

· Expedia Group maintains a Disaster Recovery Plan that accounts for emergencies and contingency plans to ensure that customer services are uninterrupted according to severity and are tested regularly to ensure viability.

Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures in order to ensure the security of the processing 

· Expedia Group’s technical and organizational measures are audited annually by external assessors as well as through robust internal testing.

· EG conducts annual PCI assessments utilizing a third-party assessor and ensures ongoing compliance with PCI.  

· EG’s comprehensive internal testing function is comprised of quarterly vulnerability testing, internal and external penetration testing, network, system and firewall scanning and reviews. Additionally, an internal audit department conducts annual risk assessments to prioritize operational audits. 

Measures for user identification and authorisation Measures for the protection of data during transmission Measures for the protection of data during storage 

· Expedia Group systems are aligned with industry best practices and have in place communication practices such as time-out sessions, lock-out protocols, and robust password and authentication controls.   

· Expedia Group maintains requirements for account provisioning and oversight to prevent unauthorized access or misuse of Expedia Group information and uses industry best practices as required, such as the Least Privilege Access principle, unique ID’s and multi factor authentication for strong authentication purposes. 

Measures for ensuring physical security of locations at which personal data are processed 

· A Security Operations Center provides 24x7 coverage, with a formal incident response plan reviewed and tested at least annually. 

· All systems are regularly controlled and tested by external service providers.  

· Each Expedia Group customer receives their own customer ID. All datasets of the respective customer are stored under this ID and all customer data is logically segregated. Due to administration rights and database structures, the customer can only access datasets which are assigned to that user ID and data centers/AWS controls.  

· Only persons who are expressly authorized by Expedia and have a ‘need to know’ have access to personal data. Controls and monitoring are in place to ensure least privileged access and unauthorized access attempts to the system. 

Measures for ensuring events logging 

Expedia Group maintains robust logging and monitoring requirements to account for the who, what, where, when, target, source, and success/failure of the logged event.

Measures for ensuring system configuration, including default configuration Measures for internal IT and IT security governance and management Measures for certification/assurance of processes and products 

· Expedia Group’s (EG) Information Security program is aligned with industry frameworks and standards, working through its risk management program to ensure a robust and comprehensive security posture. Expedia Group maintains secure operational processes to support the security, availability, integrity and confidentiality of the environment and customers’ data.  

· Expedia Group’s build standards only enable system components, services, and protocols that serve a business requirement. Operating Systems, databases, and off-the-shelf applications must be discoverable to satisfy legal and regulatory audit requirements, supports configuration management tools, or deploys configuration management that successfully enforces security controls, must enable encryption for all remote administrative access to a system, display proper use of the system, the system is being monitored to detect improper use and other illicit activity there is no expectation of privacy while using the system. 

· Expedia Group takes a layered / defense-in-depth strategy to security. Critical capabilities and controls are in place across the enterprise (e.g.: anti-malware, WAF, network segmentation, DLP, etc.), utilizing a suite of policies, operations and technologies to ensure the environment is monitored through a central security organization and alerts responded to accordingly.  

· Expedia's systems are hosted on Amazon Web Services (AWS) and in Data Centers that provide Expedia Group with annual SOC 2 reports to ensure compliance. 

Measures for ensuring data minimisation Measures for ensuring data quality Measures for ensuring limited data retention Measures for ensuring accountability 

· Minimisation: Expedia Group ensures only minimum amount of data is collected, processed and stored.   We only use identifiable format where necessary. 

· Retention: The Expedia Group data retention policy sets out different retention periods and backups depending on the category of data, including any legal obligation or other exemption which requires such data to be retained until certain legal obligations, such as tax and accounting purposes, have been extinguished.  

· Quality: Expedia Group has a formalized, quality management program, the Customer Experience Management (CEM) program. We are always striving for improvement within EG’s environment and seeking to streamline processes for higher efficiencies resulting in consistent, high-quality services and interactions with our partners, clients and travelers.

· Accountability:  Expedia Group ensure accountability oversight with consistent implementation of policies, industry regulations/frameworks and legal requirements by maintaining a formalized Governance program, and Legal/Privacy body.

Measures for allowing data portability and ensuring erasure 

· Expedia Group is directly responsible for ensuring compliance with data protection laws (including in relation to requests from data subjects). Expedia Group responds to all subject requests, including Access, deletion and portability in accordance with applicable data protection law.  

· EG’s data retention policy sets out different retention periods and backups depending on the category of data, including any legal obligation or other exemption which requires such data to be retained until certain legal obligations, such as tax and accounting purposes, have been extinguished. In the event that Expedia Group is unable to destroy Personal Data, Expedia Group shall continue to extend relevant protections of the Agreement between the parties governing such personal data and terminate any further processing.

For transfers to (sub-) processors, also describe the specific technical and organisational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter 

· Expedia group conducts due diligence into the information security practices of its vendors and requires vendors to meet comprehensive security requirements, including obligations requiring vendors to have in place and maintain appropriate technical and organisational measures.  

· Expedia Group has formalised a detailed Security Impact Assessment (“SIA”) process. All new vendors accessing data are screened prior to engagement and during the term where necessary.  

· Additionally, Expedia Group also has robust vendor processor terms that are imposed on all vendors, ensuring the flow down of obligations to any of their sub-processors.

 

International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Addendum)

This Addendum has been issued by the Information Commissioner for Parties making Restricted Transfers. The Information Commissioner considers that it provides Appropriate Safeguards for Restricted Transfers when it is entered into as a legally binding contract.

Part 1    Tables

Table 1: Parties

Start Date

The Date of the SCCs to which these are attached (EU SCCs). 

Parties

Key Contact

Exporter: As per EU SCCs.

 

Importer: As per EU SCCs.

 

Table 2: Selected SCCs, Modules and Selected Clauses

Addendum EU SCCs

The version of the Approved EU SCCs which this Addendum is appended to.

Table 3: Appendix Information

Appendix Information” means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the Parties), and which for this Addendum is set out in:

Annex IA: List of Parties

Annex 1B Description of Transfer

Annex II: Technical and organisational measures

As per EU SCCs

Table 4: Ending this Addendum when the Approved Addendum changes

Which Parties may end this Addendum as set out in Section 19

Neither Party

Part 3: Mandatory Clauses

Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.