Technical and Organizational Measures
Processor maintains a comprehensive written information security program designed to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. This program includes the following safeguards:
1. Governance and Certifications
(i) Processor has implemented an information security management system conforming to:
(a) ISO/IEC 27001:2022 standard (Statement of Applicability); and
(b) SOC 2 Type II Trust Services Principles.
(ii) Processor maintains current certification and provides Controller with a copy of its valid certification or report within thirty (30) days of receipt or upon written request.
(iii) Certifications are renewed annually or as otherwise required by the certifying body.
2. Personnel Security and Confidentiality
(i) All personnel with access to Controller Personal Data are bound by written confidentiality obligations and subject to annual security/privacy training.
(ii) Pre-employment and ongoing verification requirements (including background checks where legally permissible) are applied to employees and extended to affiliates and contractors.
(iii) Access to Controller Personal Data is limited to those with a legitimate business need-to-know.
3. Access Controls and Logical Separation
(i) Unique user IDs are issued; shared accounts are prohibited.
(ii) Access is role-based, reviewed regularly, and revoked promptly upon termination or role change.
(iii) Multi-factor authentication is required.
(iv) Controller Personal Data is logically separated from other customer data.
4. System and Network Security
(i) Firewalls are maintained to protect networks hosting Controller Personal Data.
(ii) Anti-malware software is deployed and automatically updated.
(iii) Systems are kept current with security patches, upgrades, and updates.
(iv) Secure VPN with multi-factor authentication is required for remote access.
5. Encryption
(i) Controller Personal Data is encrypted in transit (TLS 1.2+ or equivalent) and at rest using industry-standard encryption methods consistent with NIST or CIS recommendations.
6. Monitoring, Testing, and Vulnerability Management
(i) Security logging and monitoring are maintained to detect unauthorized access or anomalies.
(ii) Independent third-party penetration testing is performed at least annually, covering application and infrastructure layers.
(iii) Identified vulnerabilities are remediated within SLAs. Controller may receive attestations confirming that testing occurred and that (i) no material findings were identified or (ii) remediation was completed.
(iv) Processor may also operate a vulnerability management program and periodic internal testing.
7. Data Deletion and Media Handling
(i) When media is retired, data is securely deleted in accordance with NIST SP 800-88 Rev.1 or successor standards, rendering data irrecoverable.
8. Physical and Data Center Security
(i) Data centers used by Processor or its Subprocessors implement industry-standard physical safeguards, including access restrictions, surveillance, fire suppression, and environmental controls, and maintain ISO 27001 or equivalent certifications.
9. Resilience, Business Continuity, and Disaster Recovery
(i) Systems are designed with redundancy, backup, and disaster recovery capabilities.
(ii) Backups are encrypted and periodically tested for restoration.
(iii) Business continuity and disaster recovery plans are reviewed and tested at least annually.
10. Incident Response
(i) Processor maintains a documented incident response plan.
(ii) Upon becoming aware of a Personal Data Breach, Processor will notify Controller without undue delay in accordance with Section 7 of this DPA.
(iii) Processor will investigate and remediate security incidents and provide Controller with information reasonably available to meet Controller’s legal obligations.
11. Auditing and Reporting
(i) Processor engages independent auditors to verify its security measures under ISO 27001 and/or SOC 2 Type II standards.
(ii) Audit reports (e.g. SOC 2 Type II) are made available to Controller upon written request no more than annually, subject to confidentiality obligations.
(iii) Processor may provide Controller with summaries or attestations instead of full reports where appropriate.
Table of contents
1. Governance and Certifications 2. Personnel Security and Confidentiality 3. Access Controls and Logical Separation 4. System and Network Security 5. Encryption 6. Monitoring, Testing, and Vulnerability Management 7. Data Deletion and Media Handling 8. Physical and Data Center Security 9. Resilience, Business Continuity, and Disaster Recovery 10. Incident Response 11. Auditing and Reporting