Effective date: 01 September 2026.
For the prior version, please click here.
This Data Processing Addendum (“DPA”) forms part of the Kissflow Terms of Service or any other written master services or subscription agreement between the parties (in each case, the “Agreement”). It is entered into between the Customer entity identified in the Agreement or Quote (“Customer”) and the Kissflow contracting entity identified in the Agreement (Kissflow Inc. for non-Indian Customers; OrangeScape Technologies Private Limited for Indian Customers) (“Kissflow”).
This DPA forms part of, and is subject to, the Agreement. It is effective from the effective date of the Agreement (or, if executed later, the date of last signature on this DPA) and remains in force for as long as Kissflow Processes Personal Data on Customer's behalf under the Agreement. Capitalised terms used but not defined in this DPA have the meanings given in the Agreement.
1. Definitions
1.1. “Applicable Data Protection Law” means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including those addressed in Schedule 4.
1.2. “Controller”, “Processor”, “Sub-processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the EU General Data Protection Regulation 2016/679. Where Applicable Data Protection Law uses an equivalent term, that term is read accordingly (see the equivalent terms set out in the relevant country table in Schedule 4).
1.3. “Instructions” means the written or documented instructions issued by Customer to Kissflow directing Kissflow to perform specific or general actions in connection with the Processing of Personal Data, including the Agreement, this DPA, the configuration and admin controls of the services used by Customer, and any further written instructions reasonably required for Customer's use of the services.
1.4. “Security Incident” means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer's Personal Data. A Personal Data Breach is a Security Incident.
1.5. “Sensitive Personal Data” means special categories of personal data under Article 9 GDPR, criminal offence data under Article 10 GDPR, sensitive personal data under DPDPA, and the equivalent categories under other Applicable Data Protection Laws.
2. Scope and Roles
2.1. Customer is the Controller and Kissflow is the Processor of the Personal Data described in Schedule 1. Where Applicable Data Protection Law uses different terminology, the equivalent terms set out in the relevant country table in Schedule 4 apply.
2.2. Nothing in this DPA relieves either party of its own obligations under Applicable Data Protection Law.
3. Controller Obligations
3.1. Customer is solely responsible for: (a) the lawfulness of its Instructions; (b) having a valid lawful basis (including any necessary consents) for the Processing it instructs Kissflow to perform; (c) its own transparency and notice obligations to Data Subjects; and (d) informing Kissflow without undue delay of any errors or irregularities in the Personal Data it provides.
3.2. If Customer issues Instructions that, in Customer's reasonable view, will impose data protection obligations on Kissflow beyond those assumed in this DPA (for example, because Customer is deploying the services to Data Subjects in a jurisdiction not addressed in Schedule 4), Customer will notify Kissflow in advance. Kissflow will then either confirm the existing terms cover it, propose an amendment with any additional commitments or fees, or decline the Processing if the obligations cannot reasonably be met. Customer remains solely responsible as Controller for compliance with any local law obligation attaching to it for such Processing.
4. Processor Obligations
4.1. Kissflow Processes Personal Data only on Customer's documented Instructions, unless required to do otherwise by law to which Kissflow is subject, in which case Kissflow will inform Customer of that legal requirement before Processing (to the extent permitted by law).
4.2. Kissflow will promptly inform Customer if, in Kissflow's reasonable opinion, an Instruction infringes Applicable Data Protection Law.
4.3. Following a notice under Section 4.2, Kissflow may suspend the Processing affected by the infringing Instruction. If Customer does not provide updated Instructions to cure the infringement within ten (10) days of Kissflow's notice, Kissflow may, on written notice to Customer, terminate this DPA or the affected portion of the services without liability to Customer (other than refund of any prepaid fees attributable to the suspended or terminated services).
4.4. Kissflow ensures that personnel authorised to Process Personal Data are bound by appropriate confidentiality obligations and have received privacy and security training appropriate to their role.
4.5. Kissflow implements and maintains the technical and organisational measures set out in Schedule 2 to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure.
4.6. Kissflow will not use Personal Data for any purpose other than the provision of the services under the Agreement. Without limiting the foregoing, and certifying its understanding of the requirements under Applicable Data Protection Laws (including the CCPA), Kissflow will not: (a) sell or share Personal Data; (b) retain, use or disclose Personal Data for any commercial purpose other than providing the services under the Agreement; (c) receive Personal Data as consideration for any services it provides to Customer; or (d) combine Personal Data received from or on behalf of Customer with Personal Data received from or on behalf of any other person, except as expressly permitted by Applicable Data Protection Law for purposes ancillary to the services.
4.7. Kissflow will notify the Customer if Kissflow determines it can no longer meet its obligations under Applicable Data Protection Law. On such notification, Customer may, by written notice, direct Kissflow to take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data.
4.8. Where Kissflow becomes aware that Personal Data it Processes on Customer's Instructions is materially inaccurate or out of date, Kissflow will inform Customer without undue delay.
4.9. Where Customer Instructs Kissflow to de-identify or pseudonymise Personal Data, Kissflow will comply with the de-identification or pseudonymisation requirements under Applicable Data Protection Law, including the de-identification standard under the CCPA where applicable.
5. Sub-processors
5.1. Customer grants general written authorisation for Kissflow to engage the Sub-processors listed in Schedule 3 (which includes Kissflow group entities acting as intra-group Sub-processors).
5.2. Kissflow will give Customer at least ten (10) days' prior written notice of any intended addition or replacement of a Sub-processor. Customer may object on reasonable data protection grounds within the notice period. If Customer does not object within the notice period, Customer is deemed to have accepted the proposed Sub-processor and Kissflow may proceed to engage it. If Customer objects and the parties cannot resolve the objection in good faith, Customer may terminate the affected services without penalty (other than payment for services rendered up to the date of termination).
5.3. Kissflow will impose on each Sub-processor data protection obligations providing at least the same level of protection as those in this DPA, and remains liable to Customer for a Sub-processor's acts and omissions to the extent they result in a breach of Kissflow's obligations under this DPA or under Applicable Data Protection Law.
5.4. No Sub-processor may engage a further sub-processor in respect of Customer's Personal Data without Kissflow's prior written authorisation, and Kissflow will not grant such authorisation without first notifying Customer in accordance with Section 5.2.
6. Data Subject Rights
6.1. Kissflow provides Customer with functionality in the services to enable Customer to respond to Data Subject requests, including: (a) access; (b) rectification, correction or completion; (c) erasure or deletion; (d) restriction of Processing; (e) data portability; (f) objection to Processing; (g) withdrawal of consent; (h) opt-out of sale or share of personal information; (i) the right not to be subject to solely automated decisions producing legal or similarly significant effects; and (j) any equivalent rights under Applicable Data Protection Law.
6.2. If Kissflow receives a request directly from a Data Subject relating to Customer's Personal Data, Kissflow will forward the request to Customer within three (3) business days and will not respond to the Data Subject except on Customer's documented Instruction or as required by Applicable Data Protection Law.
6.3. Customer will reimburse Kissflow for the reasonable cost of assistance that materially exceeds standard support.
7. Security Incident Notification
7.1. Unless otherwise required by Applicable Data Protection Law, Kissflow will notify Customer without undue delay and in any event within forty-eight (48) hours after becoming aware of a Security Incident affecting Customer's Personal Data.
7.2. Kissflow will take reasonable steps to mitigate the Security Incident and assist Customer with its notification obligations to Supervisory Authorities and Data Subjects under Applicable Data Protection Law. Kissflow maintains a documented register of Security Incidents.
7.3. Kissflow's notification regarding, or response to, a Security Incident under this Section 7 shall not be construed as an acknowledgment by Kissflow of any fault or liability with respect to the Security Incident.
8. Data Protection Impact Assessments
8.1. Kissflow will provide reasonable assistance to Customer with data protection impact assessments (and the equivalent under Applicable Data Protection Law) and with prior consultations with Supervisory Authorities, in each case at Customer's reasonable request and taking into account the nature of the Processing and the information available to Kissflow.
9. Records of Processing
9.1. Kissflow maintains records of Processing activities carried out on behalf of Customer in accordance with Article 30(2) of the EU GDPR and the equivalent provisions under other Applicable Data Protection Laws. The records include the categories of Processing, transfers to third countries and the safeguards relied upon, and a general description of the technical and organisational measures in Schedule 2. The records are made available to Customer and to competent Supervisory Authorities on reasonable written request.
10. International Data Transfers
10.1. Where the Processing involves a transfer of Personal Data to a country or territory not benefiting from an adequacy or equivalent designation under Applicable Data Protection Law, the parties rely on the cross-border transfer mechanism set out in the relevant country table in Schedule 4. Where Schedule 4 refers to standard contractual clauses or any other published instrument, the parties incorporate them by reference with the elections set out in the relevant country table.
11. Sensitive Personal Data
11.1. Customer is solely responsible for ensuring it has the additional lawful basis required by Applicable Data Protection Law before uploading any Sensitive Personal Data to the services, and for applying any additional safeguards that the Applicable Data Protection Law requires of the Controller for such data. Customer will notify Kissflow in writing in advance of any intended upload of Sensitive Personal Data so that the parties may agree to any additional safeguards reasonably required of Kissflow.
11.2. Kissflow has no obligation to inspect Customer's uploads for Sensitive Personal Data and is not liable for the Processing of Sensitive Personal Data uploaded by Customer without prior written notice under Section 11.1, nor for any failure to apply Controller-side safeguards that Kissflow could not reasonably have known were required.
12. Data Protection Officer and Privacy Contact
12.1. Kissflow's single point of contact for all privacy and data protection matters across all jurisdictions is Rini Mathew, Data Protection Officer, privacy@kissflow.com. Enquiries received at this contact are routed to the applicable jurisdiction-specific representative or local data protection officer.
13. Government Access and Law Enforcement Requests
13.1. If Kissflow receives a binding request from a government, law enforcement, judicial or regulatory authority for access to or disclosure of Personal Data Processed under this DPA, Kissflow will: (a) review the request carefully for legal validity and lawful basis; (b) challenge any request that is overly broad, lacks proper legal authority, or appears unlawful, including by seeking provisional measures and pursuing available appeals; (c) disclose only the minimum Personal Data necessary to comply with a legally binding request; and (d) where permitted by law, notify Customer of the request without undue delay before any disclosure so that Customer may seek protective measures.
13.2. Where Kissflow is legally prohibited from notifying Customer, Kissflow will use commercially reasonable efforts to seek a waiver of the prohibition.
14. Data Retention and Deletion
14.1. Personal Data is retained only for the duration of the Agreement and for up to thirty (30) days following termination or expiry.
14.2. On termination or expiry, Kissflow will, at Customer's election, securely delete the Personal Data and certify deletion in writing, or return it to Customer in a commonly used machine-readable format and thereafter delete all copies. Kissflow may retain Personal Data beyond these periods only where required by law, and will inform Customer of any such requirement.
15. Audit Rights
15.1. Kissflow makes available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
15.2. Audits will take place at reasonable intervals, on at least thirty (30) days' prior written notice, subject to confidentiality undertakings, during normal business hours, at Customer's cost, and may be conducted remotely at Kissflow's reasonable election. Audits will take place no more than once per twelve (12) months unless a Security Incident has occurred or a Supervisory Authority requires an additional audit.
15.3. Kissflow may satisfy its audit obligations by providing current SOC 1, SOC 2 Type II, and SOC 3 reports, ISO 27001 certificates, or equivalent third-party audit reports, provided these are no more than twelve (12) months old.
15.4. Nothing in this Section 15 requires Kissflow to disclose to Customer or to any auditor, or to allow access to: (a) data of any other Kissflow customer or Kissflow's own data Processed in its capacity as Controller; (b) Kissflow's internal accounting or financial information; (c) any trade secret or confidential information of Kissflow or its affiliates; (d) any information that, in Kissflow's reasonable opinion, could compromise the security of any Kissflow systems or breach Kissflow's obligations to third parties; or (e) any information that is sought for a purpose other than the good-faith fulfilment of Customer's obligations under Applicable Data Protection Law. No hands-on or intrusive access to Kissflow's IT systems or infrastructure is permitted.
15.5. All information disclosed by Kissflow under this Section 15, and the contents of any audit report, are Kissflow's Confidential Information and are subject to the confidentiality terms of the Agreement (or a separate non-disclosure agreement where Kissflow reasonably requires one).
16. Automated Decision-Making
16.1. Where Customer's configuration of the services involves Processing that produces legal effects concerning a Data Subject or similarly significantly affects the Data Subject, Customer is responsible for ensuring it has a valid lawful basis for such Processing and for providing the required information to and rights of the Data Subject under Applicable Data Protection Law (including GDPR Article 22 and equivalents). Kissflow will assist Customer with these obligations on reasonable request, using the services' standard functionality.
17. Liability
17.1. Each party is liable to the other for damages arising from its breach of this DPA, subject to the limitations of liability in the Agreement. Customer holds Kissflow harmless from fines, penalties or claims arising from Customer's failure to comply with its obligations as Controller under Applicable Data Protection Law (including the lawfulness of its Instructions and the adequacy of Data Subject consents).
18. Term and Termination
18.1. This DPA remains in force for as long as Kissflow Processes Personal Data on behalf of Customer under the Agreement. Provisions that by their nature should survive termination (including Sections 7, 13, 14, 15 and 17) will so survive.
19. General
19.1. Governing law: this DPA is governed by the law of the Agreement, except as specified in Schedule 4 for jurisdiction-specific transfer mechanisms which carry their own governing law.
19.2. Order of precedence: incorporated standard contractual clauses prevail over Schedule 4, which prevails over this DPA body, which prevails over the Agreement, in each case only to the extent of the conflict and only as to the Processing of Personal Data.
19.3. Amendments: amendments require a writing signed by both parties. Kissflow may update Schedule 2 (Technical and Organisational Measures) and Schedule 3 (Sub-processors) in accordance with this DPA, provided that updates to Schedule 2 are no less protective than the measures in place at the date of signing.
19.4. Entire agreement: this DPA (with its Schedules) is the entire agreement between the parties as to the Processing of Personal Data under the Agreement, and supersedes all prior agreements on this subject matter.
Schedule 1 — Description of Processing
| Item | Detail |
| Subject matter | Provision of the Kissflow platform and associated services to Customer, involving the Processing of Personal Data. |
| Duration | The term of the Agreement plus up to 30 days after termination. |
| Nature and purpose | Hosting, Processing, and storage of Personal Data uploaded by Customer to enable workflow automation, process management and related platform functionality. |
| Types of Personal Data | Customer-controlled. Typically business identifiers, contact data, navigational and system usage data, and content uploaded by Customer or its end users into Customer's workflows. |
| Categories of Data Subjects | Customer-controlled. Typically Customer's employees, contractors, customers, prospects, suppliers, and other end users of the platform. |
| Sensitive Personal Data | Customer is solely responsible. Kissflow does not inspect uploads for Sensitive Personal Data. See Section 11. |
| Frequency of transfer | Continuous during the Agreement term. |
| Retention | As in Section 14. |
Schedule 2 — Technical and Organisational Measures
Detailed and current measures are maintained in the Kissflow Trust Center. Summary as at the date of this DPA:
| Measure | Description |
| Encryption | AES-256 at rest; TLS 1.2 or higher in transit. |
| Access control | Least-privilege; multi-factor authentication on production access; role-based access control; quarterly access reviews. Kissflow personnel do not have routine access to Customer workflow content; production access is via documented break-glass procedure, logged immutably, and notified to Customer's designated point of contact. |
| Availability and resilience | Multi-region cloud deployment on Google Cloud Platform and Amazon Web Services with MongoDB Atlas as the data layer. Customer data pinned to the Customer-selected region with intra-jurisdictional backup. Documented disaster recovery procedures; daily backups tested annually. |
| Physical security | Cloud infrastructure hosted by AWS, GCP and MongoDB Atlas with physical security controls delegated to and warranted by the underlying providers. Kissflow office access controlled, logged and monitored. |
| Event logging | Application and infrastructure audit logs maintained per defined log management standards; logs analysed for anomalous activity. |
| System hardening | Industry-standard benchmarks; continuous vulnerability and patch management; annual third-party penetration testing. |
| ISMS | ISO 27001-certified information security management system; dedicated Information Security team; risk register maintained; policies reviewed at least annually. |
| Certifications and audits | ISO 27001 certified. SOC 1, SOC 2 Type II, and SOC 3 attestations completed by an independent external auditor. Internal audits semi-annually. |
| HR security | Confidentiality undertakings on hire; background checks where permitted by local law; security and privacy training on hire and annually. |
| Sub-processor management | Documented due diligence; contractual flow-downs; ongoing monitoring; exit planning. |
| Incident response | Documented plan; tabletop exercises at least annually. |
| Data portability and deletion | Customers may export Personal Data; all Customer data deleted from servers within 30 days of service termination. |
Schedule 3 — Authorised Sub-processors
Authorised at the date of this DPA. The current list is maintained at the Kissflow Trust Center and updated in accordance with Section 5. Each Sub-processor's published data processing terms are hyperlinked below; Kissflow is not responsible for the maintenance of third-party links, and Customer should verify currency at the source on the date of use.
| Sub-processor | Service | Region(s) | Type | DPA / Terms |
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure | US, EU, India, Australia | Third party | AWS DPA |
| Google LLC (Google Cloud Platform) | Cloud infrastructure | US, EU, India, Australia | Third party | GCP DPA |
| MongoDB Atlas (MongoDB, Inc.) | Managed database service | US, EU, India, Australia | Third party | MongoDB DPA |
| Chargebee Inc. | Subscription and billing | US | Third party | Chargebee DPA |
| Cloudflare, Inc. | DNS, CDN, security | Global | Third party | Cloudflare DPA |
| Intercom, Inc. | Customer chat support | US | Third party | Intercom DPA |
| Snowflake Inc. | Analytics | US | Third party | Snowflake DPA |
| OpenAI, L.L.C. | AI features (LLM) | US | Third party | OpenAI DPA |
| Anthropic, PBC | AI features (Claude LLM) | US | Third party | Anthropic DPA |
| Google LLC (Gemini) | AI features (Gemini LLM) | US | Third party | Google DPA |
| OrangeScape Technologies Private Limited | Engineering, customer support, customer success and operations touching Customer Personal Data globally | India | Intra-group | Kissflow Trust Center |
| Kissflow DIFC entity | Sales operations touching Customer admin and contact data | UAE (DIFC) | Intra-group | Kissflow Trust Center |
Schedule 4 — Applicable Data Protection Laws and Jurisdiction-Specific Terms
This Schedule sets out the Applicable Data Protection Laws addressed by this DPA, together with the jurisdiction-specific terms (equivalent terminology, cross-border transfer mechanism, and governing law of the transfer mechanism) for each. The body of this DPA applies in full. The country tables in this Schedule add only what is genuinely jurisdiction-specific; generic processor obligations are not repeated here.
Schedule 4 Index : Applicable Data Protection Laws
| Ref. | Applicable Data Protection Law | Jurisdiction |
|---|---|---|
| Ref. | Applicable Data Protection Law | Jurisdiction |
| 4.1 | EU General Data Protection Regulation (Regulation (EU) 2016/679) | European Union / EEA |
| 4.2 | UK GDPR + UK Data Protection Act 2018 (as amended by DUAA 2025) | United Kingdom |
| 4.3 | Federal Act on Data Protection (revFADP / nFADP, in force 1 Sept 2023) | Switzerland |
| 4.4 | Digital Personal Data Protection Act, 2023 (DPDPA) + DPDP Rules 2025 | India |
| 4.5 | California Consumer Privacy Act, as amended by California Privacy Rights Act (CCPA/CPRA) | California, USA |
| 4.6 | Lei Geral de Proteção de Dados, Law No. 13,709/2018 (LGPD) | Brazil |
| 4.7 | Personal Data Protection Act, B.E. 2562 | Thailand |
| 4.8 | Personal Data Protection Act 2012 (as amended 2020) | Singapore |
| 4.9 | Data Privacy Act 2012 (Republic Act No. 10173) | Philippines |
| 4.10 | Federal Decree-Law No. 45 of 2021 (Federal PDPL) and DIFC Data Protection Law No. 5 of 2020 (as amended 2025) | United Arab Emirates (incl. DIFC) |
| 4.11 | Act on the Protection of Personal Information (APPI) | Japan |
| 4.12 | Personal Information Protection Act (PIPA, as amended 2023) | South Korea |
| 4.13 | Personal Information Protection and Electronic Documents Act (PIPEDA) + Quebec Act respecting the protection of personal information in the private sector (Law 25) | Canada (incl. Quebec) |
| 4.14 | Personal Data Protection Law (PDPL) | Saudi Arabia |
| 4.15 | Protection of Personal Information Act 4 of 2013 (POPIA) | South Africa |
Schedule 4.1 : EU GDPR
| Item | Detail |
| Applicable law | Regulation (EU) 2016/679 (GDPR) and ePrivacy Directive 2002/58/EC as implemented in national law. |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Irish law (as elected in Clause 17 of the EU SCCs). |
Schedule 4.2 — UK GDPR
| Item | Detail |
| Applicable law | UK GDPR and the UK Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA). |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of England and Wales (UK Addendum default). |
Schedule 4.3 : Switzerland nFADP
| Item | Detail |
| Applicable law | Swiss Federal Act on Data Protection (revFADP / nFADP, in force 1 September 2023) and the Ordinance on Data Protection. |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. (Protection extends to legal entities to the extent FADP requires.) |
| Cross-border transfer mechanism |
|
| Governing law | Swiss law (as set out in the Swiss-adapted SCCs). |
Schedule 4.4 : India DPDPA
| Item | Detail |
| Applicable law | Digital Personal Data Protection Act, 2023 (DPDPA) and the DPDP Rules 2025. |
| Equivalent terms | Controller: Data Fiduciary. Processor: Data Processor. Data Subject: Data Principal. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of India. |
Schedule 4.5 : California CCPA / CPRA
| Item | Detail |
| Applicable law | California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). |
| Equivalent terms | Controller: Business. Processor: Service Provider. Data Subject: Consumer. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the State of California. |
Schedule 4.6 : Brazil LGPD
| Item | Detail |
| Applicable law | Lei Geral de Proteção de Dados, Law No. 13,709/2018 (LGPD). |
| Equivalent terms | Controller: Controlador. Processor: Operador. Data Subject: Titular. |
| Cross-border transfer mechanism |
|
| Governing law | Brazilian law (as mandated by the ANPD SCCs). |
Schedule 4.7 : Thailand PDPA
| Item | Detail |
| Applicable law | Personal Data Protection Act, B.E. 2562 (Thailand PDPA). |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the Kingdom of Thailand. |
Schedule 4.8 : Singapore PDPA
| Item | Detail |
| Applicable law | Personal Data Protection Act 2012 (as amended 2020) and Personal Data Protection (Transfer of Personal Data Outside Singapore) Regulations 2014. |
| Equivalent terms | Controller: Organisation. Processor: Data Intermediary. Data Subject: Individual. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the Republic of Singapore. |
Schedule 4.9 : Philippines Data Privacy Act
| Item | Detail |
| Applicable law | Data Privacy Act 2012 (Republic Act No. 10173) and NPC implementing rules. |
| Equivalent terms | Controller: Personal Information Controller (PIC). Processor: Personal Information Processor (PIP). Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the Republic of the Philippines. |
Schedule 4.10 : United Arab Emirates (Federal PDPL and DIFC DPL)
| Item | Detail |
| Applicable law | (a) UAE Federal Decree-Law No. 45 of 2021 (Federal PDPL); and/or (b) DIFC Data Protection Law No. 5 of 2020, as amended by Amendment Law No. 1 of 2025 (DIFC DPL). |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Federal PDPL: UAE federal law / UAE courts. DIFC DPL: DIFC law / DIFC Courts. |
Schedule 4.11 : Japan APPI
| Item | Detail |
| Applicable law | Act on the Protection of Personal Information (APPI), as amended. |
| Equivalent terms | Controller: Personal Information Handling Business Operator (entrusting). Processor: Personal Information Handling Business Operator (entrusted). Data Subject: Principal. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of Japan. |
Schedule 4.12 : South Korea PIPA
| Item | Detail |
| Applicable law | Personal Information Protection Act (PIPA), as amended in 2023. |
| Equivalent terms | Controller: Personal Information Controller (outsourcer). Processor: Personal Information Processor (outsourcee). Data Subject: Information Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Korean law (as required by the PIPC Standard Contract). |
Schedule 4.13 : Canada PIPEDA and Quebec Law 25
| Item | Detail |
| Applicable law | Personal Information Protection and Electronic Documents Act (PIPEDA) (federal) and Quebec Act respecting the protection of personal information in the private sector, as amended by Law 25 (Quebec Law 25). |
| Equivalent terms | PIPEDA: Controller: Organisation; Processor: Service provider; Data Subject: Individual. Quebec: Controller: Person carrying on an enterprise; Processor: Person to whom information communicated for services; Data Subject: Person concerned. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the relevant Canadian province or territory; for federally regulated matters, the laws of Canada. |
Schedule 4.14 : Saudi Arabia PDPL
| Item | Detail |
| Applicable law | Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia and its Implementing Regulations. |
| Equivalent terms | Controller: Controller. Processor: Processor. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the Kingdom of Saudi Arabia. |
Schedule 4.15 : South Africa POPIA
| Item | Detail |
| Applicable law | Protection of Personal Information Act 4 of 2013 (POPIA). |
| Equivalent terms | Controller: Responsible Party. Processor: Operator. Data Subject: Data Subject. |
| Cross-border transfer mechanism |
|
| Governing law | Laws of the Republic of South Africa. |