The purpose of these clauses is to define the conditions under which the subcontractor undertakes to carry out on behalf of the data controller the personal data processing operations defined below. As part of their contractual relations, the parties undertake to comply with the regulations in force applicable to the processing of personal data and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. applicable from May 25, 2018 (hereinafter, “the European data protection regulation”).
The subcontractor is authorized to process on behalf of the data controller the personal data necessary to provide the services detailed below:
Service | Verification of identity documents (ID, passport, residence permit) and other personal documents (RIB, proof of address, salary slip, tax notice, driving license, etc.) |
Nature of operations | Capture of the document image, reception, extraction of document data, control on the basis of defined rules, return of control results. |
Purpose of processing | Verification of documents communicated by end customers. |
Categories of data subjects | End customers |
Information made available to the subcontractor by the data controller for the performance of the service covered by this contract | Image of the identity document or document, possibly acquired directly from the end customer. |
Service | Facial recognition to identify the holder of the identity document |
Nature of operations | Capture a selfie-type photo, receive the selfie and automatically compare it with the face found on the ID document. |
Purpose of processing | Verification of documents communicated by end customers. |
Categories of data subjects | End customers |
Information made available to the subcontractor by the data controller for the performance of the service covered by this contract | Image of the identity card and selfie of the end customer possibly acquired directly from the end customer. |
This contract is valid during the Service Period as defined in the Contract.
The subcontractor undertakes to:
Process the data only for the sole purpose (s) which is / are the subject of the subcontracting
Process the data in accordance with the description of the service communicated to the data controller in the appendix to this contract. If the processor is required to transfer data to a third country or to an international organization, under Union law or the law of the Member State to which it is subject, it must inform the controller the processing of its legal obligations before processing, unless the law concerned prohibits such information for important reasons of public interest.
Guarantee the confidentiality of personal data processed under this contract
Ensure that the persons authorized to process personal data under this contract:
Subcontracting: The processor may use another processor (hereinafter, “the subsequent processor”) to carry out specific processing activities. In this case, it informs the data controller in advance and in writing of any planned change concerning the addition or replacement of other subcontractors. This information must clearly indicate the subcontracted processing activities, the identity and contact details of the subcontractor and the dates of the subcontract. The data controller has a minimum period of 15 days from the date of receipt of this information to present his objections. This subcontracting can only be carried out if the data controller has not objected within the agreed period.
Right to information of data subjects: Depending on whether the information is collected by the data controller or the processor, it is the responsibility of the data controller or the processor, respectively, to provide the information to the people concerned by the processing operations at the time of data collection.
Exercise of personal rights:
As far as possible, the subcontractor must help the controller to fulfill his obligation to respond to requests to exercise the rights of data subjects: right of access, rectification, erasure and 'opposition, right to restriction of processing, right to data portability, right not to be the subject of an individual automated decision (including profiling).
When the data subjects make requests to the subcontractor to exercise their rights, the subcontractor must send these requests as soon as they are received by email to a contact within the data controller whose contact details appear in the annex to the contract.
Notification of personal data breaches:
The processor notifies the data controller of any personal data breach within a maximum of 24 hours after becoming aware of it and by e-mail sent to a contact within the data controller whose contact details appear in the annex to the contract. . This notification is accompanied by any useful documentation to enable the controller, if necessary, to notify this violation to the competent supervisory authority.
After agreement of the controller, the subcontractor notifies the competent control authority (the CNIL), in the name and on behalf of the controller, of the personal data breaches as soon as possible and, if possible 72 hours at the latest after becoming aware of it, unless the violation in question is not likely to create a risk for the rights and freedoms of individuals.
The notification contains at least:
Help from the subcontractor in the context of compliance by the controller with its obligations: The processor helps the data controller to carry out:
Security measures: The subcontractor undertakes to implement the following security measures:
Data fate:
At the end of the provision of services relating to the processing of this data, the subcontractor undertakes to return then to destroy all the personal data to the controller.
The return must be accompanied by the destruction of all existing copies in the information systems of the subcontractor.
As the subcontractor uses learning and automatic processing algorithms that he develops himself, he is authorized by the data controller to keep data for the purposes of improving said algorithms. The stored data is used by a dedicated team of the subcontractor, all of whose members have signed a specific confidentiality obligation. The stored data is not accessible outside the internal information system of the subcontractor.
Data protection officer: The processor communicates to the data controller the name and contact details of his data protection officer, if he has appointed one in accordance with Article 37 of the European data protection regulation.
Register of processing activity categories: The processor declares to keep in writing a register of all categories of processing activities carried out on behalf of the controller, including:
Documentation: The processor provides the data controller with the necessary documentation to demonstrate compliance with all its obligations and to allow audits, including inspections, to be carried out by the data controller or another auditor that it has mandated, and contribute to these audits.
The data controller undertakes to:
Provide the subcontractor with the data referred to in II of these clauses
Document in writing any instructions regarding the processing of data by the processor
Ensure, beforehand and throughout the duration of the processing, compliance with the obligations provided for by the European data protection regulation on the part of the processor
Supervise the processing, including performing audits and inspections on the processor