Compliance Obligations

  1. Vendor/Contractor will not make or cause to be made, or receive or seek to receive, any offer, gift or payment, consideration or benefit of any kind or value, which would or could be construed as an illegal or corrupt practice, either directly or indirectly to: 

    1. Any person or firm employed by, or acting for or on behalf of, any customer or potential customer, whether private or governmental, for the purposes of inducing or rewarding favorable action by the customer or potential customer in any commercial transaction or any arrangement or provision of funds in relation to this Agreement;

    2. Any person or firm employed by, or acting for or on behalf of, any governmental entity (including state-owned or controlled entities or public international organizations) for the purposes of inducing or rewarding any action, or the withholding of any action, by such entity in any governmental matter; and

    3. Any governmental official or employee (including employees of state-owned or controlled entities or public international organizations), political party or official of such party, or any candidate for political office, for the purposes of inducing or rewarding favorable action (or the withholding of action) or the exercise of influence by such official, party, or candidate in any commercial transaction or in any governmental matter. 

  1. Vendor/Contractor must not engage in any fraudulent activity, which means dishonestly obtaining a benefit, or causing a loss, by deception or other means, and includes incidents of attempted, alleged, suspected, or detected fraud.  

  1. Neither Vendor/Contractor, nor any of its Personnel is engaged either directly or indirectly in terrorism, or in the finance or support to terrorists. 

  1. Vendor/Contractor will undertake its best effort to ensure that payments under this Agreement do not provide direct or indirect support or resources to entities and individuals as may be proscribed under the relevant international and national counter-terrorism legislation and regulations and are not diverted to support drug trafficking. 

  1. Vendor/Contractor shall maintain commercially reasonable Know Your Customer Procedures and shall not knowingly transact with persons or entities on applicable sanctions lists, including SDN, US, UK, or UN sanctions lists. 

  1. Vendor/Contractor and its Personnel will not engage in or support trafficking activities, procuring of commercial sex acts, or using forced labor; are aware of regulatory prohibitions in the jurisdictions they are engaged; and agrees to develop project specific Trafficking in Persons (TIP) Compliance Plans where government regulations mandate. 

  1. Vendor/Contractor explicitly acknowledges and agrees that the GIIN may use any and all information provided to conduct screening, including screening undertaken, prepared, or produced by a third party, to ensure legal and regulatory compliance, including screening relating to regulations promulgated by any local, state, or federal governmental, quasi-governmental or regulatory authority. 

  1. Vendor/Contractor is aware that the GIIN is committed to upholding the values and purpose of the UN Convention on the Rights of the Child, which requires that Children will be protected from performing any work that is likely to be hazardous, interfere with a Child’s education, or are harmful to a Child’s physical, mental, spiritual, moral or social health.  

  1. Vendor/Contractor is aware of the GIIN’s zero tolerance of modern slavery and its commitment to the principle that modern slavery is a crime and a violation of fundamental human rights, and that all humans have the right to be free from violence, abuse, and exploitation of any kind. Vendor/Contractor will not engage in modern slavery and will undertake its best effort to ensure that modern slavery is not taking place within the businesses of its suppliers, vendors, or partners. 

  1. Vendor/Contractor is committed to maintaining a work environment in which all employees are treated with respect and dignity and is free from all forms of harassment and discrimination. Any form of attempted or threatened exploitation, abuse, and harassment (including sexual abuse, sexual exploitation, and sexual harassment) are prohibited and will not be tolerated. 
     

  1. Unless otherwise disclosed in writing to the GIIN, neither the Vendor/Contractor, nor individuals employed by it, nor its immediate family members, are Public Officials. Public Official shall mean any elected or appointed officer, employee, or agent of a government or any political or regulatory subdivision including a public employee of any regulatory agency. The Vendor/Contractor shall immediately notify the GIIN in advance if any of the above become a Public Official. 

  1. To the extent applicable, Vendor/Contractor shall comply with the United States Department of Justice’s Final Rule Prohibiting and Restricting Access to Bulk U.S. Sensitive Personal Data (effective January 8, 2025) and all related guidance. 

  1. Vendor/Contractor shall implement data protection measures meeting or exceeding all applicable laws, rules, and regulations, including appropriate security measures, necessary opt-out information, breach notification procedures, and privacy compliance. 

  1. The GIIN shall immediately be informed if the Vendor/Contractor becomes aware of any information indicating that any action in breach of stated compliance obligations has been committed or has been requested or otherwise suggested by any person, including a Public Official or private individual, in connection with this Agreement. 

  1. Vendor/Contractor shall conduct all activities related to this Agreement in a fair, honest, and transparent manner. 

  1. Vendor/Contractor shall include these, or substantially similar, provisions in all subcontracts or other agreements made in connection with this Agreement. 

  2. The GIIN is committed to adhering strictly to the letter and spirit of the antitrust laws and requires all members and all engaged or participating parties to comply with applicable antitrust laws. You shall not use any GIIN information, nor any information you access through GIIN (collectively, "GIIN Information"), nor anything in or at GIIN programs or events (collectively, "GIIN Events") to coordinate or reach any understanding or agreements, express or implied, which would tend to prevent, restrict, or distort competition or, in any way, impair the ability of other engaged or participating parties to exercise independent judgment regarding matters discussed in GIIN Information or at GIIN Events.

Any breach of these compliance guidelines shall entitle the GIIN to terminate the Agreement between the Parties, without liability for termination charges or any other liability of any kind to the GIIN. Vendor/Contractor agrees to indemnify, defend, and hold harmless the GIIN and its directors, officers, employees, and agents (collectively, “Indemnitees”) from and against any and all liability, damages, loss, or expense (including attorneys’ fees and expenses of litigation, arbitration, or mediation) whether at law or in equity, incurred by or imposed upon any Indemnitee in connection with any third party claims, suits, actions, demands, or judgements resulting from Vendor/Contractor’s breach of or failure to comply with any of the obligations set forth above.

Data Processing Agreement

This Data Processing Addendum (“DPA”) is between the GIIN and the Consultant that has executed the Agreement that incorporates this DPA by reference.

Under the Agreement, the Consultant may be required to carry out processing of personal data on behalf of the GIIN in order to provide the Services. This DPA sets out the conditions applicable to such data processing.

By providing the Services under an Agreement that incorporates this DPA, the Consultant agrees to comply with the Agreement, including this DPA.

1. DEFINITIONS

For the purposes of this DPA, the following terms shall have the meaning given to them below:

  • Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

  • Data Protection Laws” means (i) the European Regulation n° 2016/679 relating to the processing of personal data (the “GDPR”), (ii) the UK Data Protection Act 2018 and the GDPR as incorporated into UK Law pursuant to the European Union (Withdrawal) Act 2018 (the “UK GDPR”); (iii) all applicable United States state and federal privacy and consumer protection laws, including without limitation state data breach and comprehensive privacy laws as well as the Telephone Consumer Protection Act and the CAN-SPAM Act  ; and (iv) all other data protection legislations applicable to the processing carried out by the GIIN and the Consultant;

  • Data Subject” means an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

  • EEA” means the European Economic Area;

  • GIIN Personal Data” means any Personal Data (including but not limited to those related to GIIN’s employees, customers and/or suppliers, as applicable) for which the Consultant carries out a Processing under the Agreement;

  • Personal Data” means any information relating to Data Subjects;

  • Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, GIIN Personal Data transmitted, stored or otherwise processed;

  • Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

  • Processing Activities” refers to the processing activities described in the Agreement;

  • Processor” means the entity acting on behalf of the Controller;

  • Sub-processors” means any third party (including the Consultant’s affiliates) engaged by the Consultant to carry out its obligations under the Agreement.

  • Supervisory Authority” has the meaning set out in Data Protection Laws.

2. GENERAL OBLIGATIONS OF THE CONSULTANT

  1. The Consultant acknowledges that the protection of GIIN Personal Data is of high importance to the GIIN, in particular considering the impact that any breach of Consultant’s obligations in relation to GIIN Personal Data could have on GIIN’s image, reputation, and assets.

  2. Each Party shall comply with their respective obligations under Data Protection Laws. 

  3. With respect to GIIN Personal Data, the GIIN shall act as a Controller and the Consultant shall act as a Processor. The Consultant shall thus carry out any Processing of GIIN Personal Data only in accordance with GIIN’s documented instructions and for no other purposes than the ones expressly defined and approved by the GIIN, unless required to do so by European Union or Member State law. In such a case, the Consultant shall inform the GIIN of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

  4. The Consultant guarantees to the GIIN that it has in place and will implement and maintain throughout the term of the Agreement appropriate technical, organizational and contractual safeguards to ensure the security, confidentiality, and integrity of GIIN Personal Data and to prevent unauthorized or unlawful Processing of GIIN Personal Data and against accidental loss or destruction of, or damage to, GIIN Personal Data.

  5. Such technical, organizational and contractual measures to be defined by the Consultant shall (i) take into account the nature of GIIN Personal Data, the risks that are presented by the Processing Activities, the harm that might result from unauthorized or unlawful Processing or accidental loss or destruction of, or damage to, GIIN Personal Data, as well as the state of the art, the best practices and the highest technical standards; (ii) be designed to implement data protection principles in an effective manner and to integrate the necessary safeguards into the Processing in order to meet the requirements of Data Protection Laws; and (iii) ensure that, by default, only GIIN Personal Data which are necessary are processed for the purposes defined by the GIIN. On request, the Consultant shall provide the GIIN with a then current written description of the security measures being taken. In any event, the Consultant shall not decrease the security level during the term of the Agreement.

  6. The Consultant shall ensure that persons authorized to Process GIIN Personal Data have committed themselves to confidentiality.

  7. Where the processing of the GIIN Personal Data is subject to the GDPR and/or the UK GDPR, the Consultant shall also:
    1. notify the GIIN about any request of communication of GIIN Personal Data it may receive from third parties, public authorities or jurisdictions, as well as about any action and/or measures instigated by such third parties, authorities or jurisdictions regarding the Processing of GIIN Personal Data;
    2. promptly notify the GIIN about Data Subjects’ request and/or complaints it may receive in relation to GIIN Personal Data and assist the GIIN to investigate and deal with such request and/or complaint. In any case, the Consultant shall not revert to Data Subjects about GIIN Personal Data unless otherwise instructed by the GIIN;
    3. immediately notify the GIIN of any change that may impact the Processing of GIIN Personal Data;
    4. provide assistance to the GIIN in ensuring compliance with its obligations to (i) implement technical and organizational security measures to ensure the security of the Processing, (ii) comply with any obligation to conduct a Data Protection Impact Assessment (“DPIA”) in connection with the Services, and (iii) consult the competent Supervisory Authority prior to Processing where a DPIA indicates that such Processing would result in a high risk in the absence of measures taken by GIIN to mitigate the risk, to the extent required by Data Protection Laws.
    5. actively cooperate with the GIIN to enable it to comply with Data Protection Laws and to assess and document the compliance of the Processing of GIIN Personal Data with Data Protection Laws and this DPA, including by providing to the GIIN any information that the GIIN may need or that may be necessary to demonstrate such compliance; and
    6. immediately inform the GIIN in writing if it believes that GIIN’s instructions with respect to the Processing of GIIN Personal Data infringes any EU Data Protection Laws and include sufficient details for the GIIN to assess the basis of such belief.

3. DISCLOSURE OF GIIN PERSONAL DATA

  1. The Consultant is authorized to disclose GIIN Personal Data to the Sub-Processors listed in the Agreement. When disclosing GIIN Personal Data, the Consultant shall:
     
    1. specifically inform in writing the GIIN of any intended changes of the list of authorized Sub-processors at least thirty (30) days in advance, thereby giving the GIIN sufficient time to be able to object to such changes prior to the engagement of the concerned Sub-processor(s). The Consultant shall provide the GIIN with the information necessary to enable the GIIN to make an informed decision in relation to potentially exercising such right to object;
    2. ensure that its personnel and the one of the Sub-processors are duly trained on their privacy and confidentiality obligations when Processing GIIN Personal Data;
    3. ensure that the Sub-processors which carry out Processing of GIIN Personal Data are committed, in substance, to the same data protection obligations as the ones applying to the Consultant, in particular providing sufficient guarantees to implement appropriate measures in such a manner that the Processing will meet the requirements of Data Protection Laws;
    4. provide to the GIIN a copy of the contract with the Sub-processors which carry out Processing of GIIN Personal Data or, failing that, a description of the essential elements of the contract, including the obligations related to the protection of GIIN Personal Data.

  2. In any event, the Consultant shall remain fully liable to the GIIN for the performance of the Sub-processors as if any act or omission of the Sub-processors were conducted by the Consultant.

4. TRANSFER OF GIIN PERSONAL DATA

  1. Provisions applicable where the Consultant is established within the EEA/United Kingdom
    • Where the Consultant transfers GIIN Personal Data, either directly or via onward transfer, from the EEA or the UK to a recipient in a country not recognized by the European Commission or the UK (as applicable) as providing an adequate level of protection for Personal Data, the Consultant shall implement appropriate safeguards in accordance with Data Protection Laws (including but not limited to the Module 3 (processor to processor) of the European Union Standard Contractual Clauses adopted by the European Commission 2021/914/EU (the “EU SCCs”), as amended, where required, by the International Data Transfer Addendum to the EU SCCs (the “UK Addendum”)), provided the conditions for the use of those safeguards are met.

  2. Provisions applicable where the Consultant is established outside the EEA/United Kingdom
    • Considering that the provision of the Services involves a transfer of GIIN Personal Data within the meaning of Data Protection Laws, the following terms shall apply: 
      • If the processing of the GIIN Personal Data by the Consultant involves a transfer subject to the GDPR, the EU SCCs shall apply and are incorporated herein by reference, and, with respect thereto, (i) Module 2 (controller to processor) shall apply, (ii) Clause 7 (Docking Clause) does not apply, (iii) Clause 9(a) option 2 shall apply and the time period shall be thirty (30) days, (iv) the option in Clause 11(a) (Redress) does not apply, (v) regarding Clause 17, the parties agree that these SCCs shall be governed by the law of Ireland, and per Clause 18(b) disputes arising under the SCCs shall be resolved in the courts of Ireland, (vi) the description of the transfer provided under the Agreement shall serve as Annexes I and II to the SCCs, (vii) Annex III to the SCCs should be completed as to indicate that the Irish Data Protection Commission is the competent Supervisory Authority.
      • If the processing of GIIN Personal Data by the Consultant involves a transfer subject to the UK GDPR, the EU SCCs shall be read in accordance with, and deemed amended by, the provisions of Part 2 (Mandatory Clauses) of the UK Addendum, and the parties agree that (i) details required by Tables 1-3 under Part 1 (Tables) of the UK Addendum are set out in the Agreement, and that the UK Information Commissioner’s Office shall act as competent Supervisory Authority for the purposes of this UK Addendum, (ii) with respect to Table 4 under Part 1 (Tables) of the UK Addendum, the Parties select the “neither Party” option.
      • In the event of a conflict between the provisions herein and the EU SCCs and/or the UK Addendum, the EU SCCs and/or the UK Addendum shall prevail. 

    • Where the Consultant transfers GIIN Personal Data to a recipient in a country not recognized by the European Commission or the UK (as applicable) as providing an adequate level of protection for Personal Data, the Consultant shall implement appropriate safeguards in accordance with Data Protection Laws (including but not limited to the Module 3 (processor to processor) of the EU SCCs, as amended, where required, by the UK addendum), provided the conditions for the use of those safeguards are met.  

5. DATA PROTECTION AUDITS

  1. The Consultant shall allow the GIIN to perform audits in relation to the Processing of GIIN Personal Data. Such audit may be carried out by the GIIN or by an independent third party appointed by the GIIN. In this respect, the Consultant undertakes, at its expense, to provide full access to GIIN’s internal or external auditors to the relevant resources (including but not limited to premises, employees and information, as well as those of its Sub-processors) and all reasonable assistance in carrying out the audit. The GIIN will be responsible for any fees charged by any auditor appointed by the GIIN to perform such audit. 

  2. The Consultant also commits to audit on a regular basis its Sub-processors in relation to the Processing of GIIN Personal Data. The Consultant shall then provide to the GIIN a complete report of the conducted audits to demonstrate that GIIN Personal Data is processed in accordance with the obligations defined in this DPA and with the conditions defined and approved by the GIIN. 

6. PERSONAL DATA BREACH

  1. In the event the Consultant identifies or believes that there has been any Personal Data Breach, the Consultant shall promptly notify the GIIN and in any event shall inform the GIIN within twenty-four (24) hours after becoming aware of such Personal Data Breach. In such circumstances, the Consultant shall at least share the following information with the GIIN:  
     
    • the name and contact details of the data protection officer or other contact point where more information can be obtained;
    • the nature of the Personal Data Breach, including but not limited to the categories and number of Data Subjects and GIIN Personal Data concerned by the Personal Data Breach;
    • a description of the measures the GIIN could take to mitigate the possible adverse effects of the Personal Data Breach and to prevent from another potential Personal Data Breach;
    • the consequences of the Personal Data Breach;
    • the measures proposed or taken by the Consultant following the Personal Data Breach, including to prevent from any new occurrence.

  2. In any case, both Parties shall actively cooperate in order for the GIIN to comply with its legal obligations under Data Protection Laws to notify the Personal Data Breach to the competent Supervisory Authority and to the Data Subjects impacted, where required. The GIIN shall first approve any public communication and/or official notification to competent Supervisory Authority or to Data Subjects regarding such potential or actual Personal Data Breach.

7. RETURN OR DESTRUCTION OF GIIN PERSONAL DATA

  1. Upon the GIIN’s request and at any time during the term of the Agreement, the Consultant shall promptly provide to the GIIN a copy of GIIN Personal Data it processes in a format prescribed by the GIIN, in particular in order to ensure that the GIIN can access the Data Subjects’ request for portability of their Personal Data.

  2. Upon termination or expiry of the Agreement, the Consultant shall cease immediately any Processing of GIIN Personal Data and shall, upon GIIN’s request, return and/or delete GIIN Personal Data no later than one (1) month following GIIN’s request. In case of return to the GIIN, following GIIN’s issuance of a receipt of acknowledgement of the restitution, the Consultant shall destroy all GIIN Personal Data (including but not limited to any file containing GIIN Personal Data) within forty-eight (48) hours after the issuance of the above-mentioned GIIN’s receipt and prove to the GIIN that such destruction did take place. Should the law prevent the Consultant from deleting all or part of GIIN Personal Data, the Consultant shall inform the GIIN of such requirements and implement, at its costs, the relevant anonymization or pseudo-anonymization measures.

8. INDEMNIFICATION

  1. Notwithstanding anything to the contrary in the Agreement, the Consultant shall indemnify (including but not limited to attorney fees and costs), hold harmless and defend the GIIN against all third-party’s claims (including Data Subjects and authorities) brought against the GIIN related to GIIN Personal Data and/or compliance with the Data Protection Laws, arising from or in connection with the Consultant’s (or the Sub-processors’) Processing of GIIN Personal Data.