KSA Standard Contractual Clauses (Module 3 - Transfer Processor to Processor)
Capitalized terms used but not defined in these KSA Standard Contractual Clauses, including the Annexes which form an integral part of these KSA Standard Contractual Clauses, (together, the “KSA SCCs”), have the meanings given to them in the KSA Data Protection Law. If such terms are not defined in the KSA Data Protection Law or in these KSA SCCs, they shall have the meanings given to them in the agreement into which these KSA SCCs are incorporated (the “Agreement”).
KSA STANDARD CONTRACTUAL CLAUSES
Clause 1
- Purpose and Scope
- The purpose of these KSA SCCs is to ensure that any transfer of Personal Data to a country or international organization outside the Kingdom is subject to appropriate safeguards that ensure a level of protection for Personal Data equivalent to that required under the KSA Data Protection Law. The adoption of these KSA SCCs does not prejudice the Parties’ obligations under the KSA Data Protection Law when processing Personal Data.
- These KSA SCCs set out appropriate safeguards and cannot be amended except to add or update information in the Appendices. The Parties have the right to include any additional conditions related to the processing of Personal Data, provided that such additional conditions do not contradict and/or undermine any of the requirements of these KSA SCCs or the KSA Data Protection Law.
- The Parties:
- the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter “entity/ies”) transferring the Personal Data, as listed in Annex 1 (each, a “Data Exporter”); and
- the entity/ies in a country outside Kingdom receiving the Personal Data from the Data Exporter, directly or indirectly (via another entity also party to these KSA SCCs), as listed in Annex 1 (each, a “Data Importer”),
have agreed to these KSA SCCs.
- These KSA SCCs apply with respect to the transfer of Personal Data as specified in Annex 2.
- Any data importer or data exporter who is not a party to these KSA SCCs may join these KSA SCCs by completing and signing Annex 1, with the consent of the Parties. Such joining party shall thereafter assume the responsibilities under these KSA SCCs depending on the nature of the Personal Data processing and transfer operations that occurred on or after the date of joining and shall be entitled to exercise the rights and obligations corresponding to its role as defined in these KSA SCCs.
Clause 2
- Processing Instructions
- The Data Exporter has clarified to the Data Importer that it processes Personal Data as a Processor based on the instructions of, and on behalf of, its Controller. The Data Exporter confirms that these instructions are compatible and consistent with the instructions provided to it by the Controller.
- The Data Importer is obliged to process the transferred Personal Data only upon written instructions from the Data Exporter. The Data Importer is obliged to inform the Data Exporter if it is unable to follow these instructions without undue delay.
- The Data Importer shall notify the Data Exporter if it is unable to comply with the Data Exporter's instructions within twenty-four (24) hours from the time it becomes aware of this, provided that the Data Exporter shall notify the Controller within forty-eight (48) hours from the time it receives the Data Importer's notification.
- The Data Exporter confirms that it has imposed obligations on the Data Importer equivalent to those imposed on the Data Exporter by the Controller with respect to the processing of transferred Personal Data.
Clause 3
- Processing Restrictions
- The Data Importer shall process the transferred Personal Data in accordance with the purposes specified in Annex 1, unless otherwise directed in writing by the Data Exporter, provided that the Personal Data shall be processed in accordance with the provisions of the KSA Data Protection Law in all cases.
Clause 4
- Compliance with the Requests of the Competent Authority
- In order for the Competent Authority to exercise its powers under the KSA Data Protection Law, the Parties shall provide a copy of these KSA SCCs to the Competent Authority upon request and without undue delay. The Competent Authority may request any additional information regarding transfers of Personal Data.
- Each party agrees to comply with any requests made by the Competent Authority in relation to these KSA SCCs or the processing of the transferred data.
- Upon request, the Data Importer (either directly or through the Data Exporter or the Controller) shall disclose its identity, contact information, and the categories of Personal Data being processed to the Data Subject and provide a copy of these KSA SCCs.
Clause 5
- Accuracy and Quality of Personal Data
- If the Data Importer realizes that any transferred Personal Data is inaccurate or not up-to-date, it shall inform the Data Exporter in writing without undue delay, provided that the Data Exporter shall inform the Controller within forty-eight (48) hours from the time the Data Importer notifies the Data Exporter to request a written directive requesting the destruction or correction of the Personal Data.
Clause 6
- Duration of Personal Data Processing and Destruction or Recovery
- The processing shall be carried out by the Personal Data Importer only for the period specified in Annex 1. After completion of the purpose of the processing, the Personal Data Importer shall destroy all Personal Data processed on behalf of the Personal Data Exporter and notify the Personal Data Exporter accordingly, unless otherwise directed by the Personal Data Exporter in the following cases:
- Return all processed Personal Data to the Personal Data Exporter and delete the copies held by the Data Importer;
- If the regulations in force in the Kingdom require the retention of the transferred Personal Data for an additional period of time;
- To retain the minimum amount of Personal Data necessary for the establishment, prosecution, or defense of legal proceedings; and
- Retain the minimum amount of transferred Personal Data necessary to protect the Data Subject's life or vital interests or to prevent, examine, or treat an infection.
- The Data Importer remains bound by these KSA SCCs until the Personal Data is deleted or recovered.
Clause 7
- Personal Data Security and Personal Data Breach Notifications
- The Parties shall ensure that the organizational, administrative, and technical measures specified in Annex 3 provide a sufficient level of protection for the transferred Personal Data to comply with the requirements of Article (19) of the PDPL and Article (23) of the Implementing Regulations.
- The Data Importer shall implement the security measures specified in Annex 3 and apply those measures to all transferred Personal Data to ensure the security and protection of Personal Data against any violation that may result in damage to the Data Subject, unlawful action, loss, alteration, disclosure, or unauthorized access.
- The Data Importer must periodically review the security measures stipulated in Annex 3 to ensure that they are being implemented as required and update them as needed to ensure compliance with Article (19) of the PDPL and Article (23) of the Implementing Regulations.
- If the Data Importer becomes aware of a data breach incident that could harm the transferred personal data or the data subjects, or conflict with their rights or interests, the Data Importer must immediately take appropriate and necessary measures to contain the incident to minimize any risks or negative consequences and ensure that it does not recur. The Data Exporter must be notified within twenty-four (24) hours of the breach or upon becoming aware of it. This notification shall include a description of the incident, its causes, the measures taken or planned to contain the incident and prevent its recurrence and contact details for follow-up by the Data Exporter. The Data Exporter must notify the Controller within twenty-four (24) hours of receiving the notification from the Data Importer. The Controller must then notify the Competent Authority in accordance with the requirements set forth in Article (24) of the Implementing Regulations.
Clause 8
- Sensitive Data
- Without prejudice to any restrictions related to Sensitive Data as stipulated in the KSA Data Protection Law, the Data Exporter must ensure that the Data Exporter adopts additional protection measures appropriate to the nature of the Sensitive Data and ensures its protection from any risks during processing, while also ensuring the application of the restrictions and additional safeguards outlined in Annex 1.
Clause 9
- Subsequent Transfer
- The Data Importer shall not transfer or disclose the transferred Personal Data to a third party outside the Kingdom unless that party has acceded to these KSA SCCs.
- Without prejudice to the provisions of Articles (8) and (15) of the PDPL and (17) of the Implementing Regulations, the provisions of the KSA Data Protection Law shall apply to Personal Data that has been previously transferred or disclosed to an entity outside the Kingdom.
- The Controller shall be responsible for verifying that the Data Exporter and Data Importer comply with the above obligations, and the Controller may appoint an independent third party to review and verify compliance on its behalf. In all cases, if the Data Exporter and Data Importer violate the instructions issued by the Controller or the agreement concluded with it regarding the processing of the transferred Personal Data, the Data Exporter and Data Importer shall be considered as the Controller and shall be responsible for violating the KSA SCCs and the provisions of the KSA Data Protection Law before the Competent Authority.
Clause 10
- Sub-Processor Appointment
- If there is a need for the Data Importer to appoint a Sub-Processor, the Data Exporter is required to obtain prior written consent from the Controller at least 30 days before appointing any Sub-Processor.
- If a Sub-Processor is appointed, this shall be done through a written agreement that imposes the same obligations as on the Data Importer under these KSA SCCs. The Data Importer shall, at the request of the Data Exporter, provide a copy of this written agreement and any subsequent amendments thereto to the Data Exporter.
Clause 11
- Compliance with these KSA SCCs
- The Data Importer shall respond to all inquiries and requests of the Data Exporter or the Controller within the specified period and provide all information requested by the Data Exporter and Controller, in addition to providing the Data Exporter or the Controller with all information it may request regarding the processing of the transferred Personal Data, including any information necessary to enable the Controller to prove its compliance with the requirements contained in these KSA SCCs or the provisions stipulated in the KSA Data Protection Law before the Competent Authority.
- Each party is responsible for proving that all obligations under these KSA SCCs have been fulfilled before the Competent Authority upon request, and in all cases, if the Data Exporter and Data Importer violate the instructions issued by the Controller or the agreement concluded with it regarding the processing of the transferred Personal Data, the Data Exporter and Data Importer shall be considered as the Controller and shall be responsible for the violation of the KSA SCCs and the provisions of the KSA Data Protection Law before the Competent Authority.
- The Data Importer shall allow, without undue delay, the Data Exporter or the Controller or their appointed representatives to audit the Data Importer's processing of Personal Data at the request of the Data Exporter or the Controller.
- The Controller must provide the information revealed by the audit when requested by the Competent Authority.
- The right of audit does not grant the Data Exporter or the Controller or their representative’s access to any confidential information of the Personal Data Importer as long as this information is not closely related to the processing of the transferred Personal Data.
Clause 12
- Rights of Data Subjects
- The Data Importer shall notify the Data Exporter within twenty-four (24) hours of receipt of any request received from the Data Subject, provided that the Data Exporter shall notify the Controller within twenty-four (24) hours of receipt of the Data Importer's notification, provided that the Data Importer and the Data Exporter shall not respond to the request unless the Controller authorizes it to do so.
- The Data Importer shall take all necessary measures, in cooperation with the Data Exporter and the Controller, to respond to the requests of Data Subjects to exercise their rights under the provisions of the KSA Data Protection Law.
- The Data Importer is obliged to follow all instructions issued by the Data Exporter and the Controller in all matters relating to the processing of the transferred Personal Data.
- All statements made to the Data Subject must be presented in a clear, legible, and accessible format.
Clause 13
- Termination and Breach of KSA SCCs
- If, for any reason, the Data Importer is unable to fulfil its obligations under these KSA SCCs, it must inform the Data Exporter within twenty-four (24) hours from the time it becomes aware of this.
- In the event that the Data Importer violates these KSA SCCs or is unable to comply with them, the Data Exporter shall immediately cease the transfer of Personal Data to the Data Importer until the Data Importer ensures its return to compliance again, provided that the Data Importer shall be given a period of thirty (30) days, extendable for a similar maximum period, to prove its ability to comply with these KSA SCCs, and if the period expires without achieving this, the Parties shall agree to terminate the Agreement to the extent that it involves the transfer or processing of Personal Data subject to these KSA SCCs, without any liability for the Data Exporter or Controller, as the case may be.
- The Data Exporter or Controller, as the case may be, shall ensure that all Personal Data previously transferred to the Data Importer is fully destroyed before termination under Clause 13.2 above, and shall also ensure that any copies the Data Importer has of such Personal Data are destroyed. The Data Importer shall document the destruction of the data, and this documentation must be provided to the Data Exporter or Controller upon request.
Clause 14
- Governing Law and Jurisdiction
- These KSA SCCs shall be governed by the laws of the Kingdom of Saudi Arabia. Any dispute arising from the application of these KSA SCCs shall fall under the jurisdiction of the Kingdom and be vested in its courts. The Parties agree to submit themselves to the jurisdiction of such courts.
ANNEX 1
PARTIES’ DETAILS
| Particulars | Information of Data Exporter(s) | Information of Data Importer(s) |
| Name | Customer | SentinelOne, Inc |
| Address | As specified in the Agreement. | As specified in the Agreement. |
| Contact Information | As specified in the Agreement. | As specified in the Agreement. The data importer’s data protection team can be contacted at privacy@sentinelone.com. |
| Signature and Date | The parties agree that execution of the Agreement and certification by the data exporter in relation to the DPA shall constitute execution of these Clauses by both parties. | The parties agree that execution of the Agreement and certification by the data exporter in relation to the DPA shall constitute execution of these Clauses by both parties. |
| Role (i.e., controller/processor) | Processor | Processor |
ANNEX 2
DESCRIPTION OF THE TRANSFERRED PERSONAL DATA
Categories of Data Subjects whose Personal Data is transferred
Data subjects include the individuals about whom data is provided to SentinelOne via the Solutions by (or at the direction of) Customer.
Categories of transferred Personal Data
SentinelOne processes the Customer Personal Data described below in relation to the Solution(s) a Customer contracts for:
- Singularity. SentinelOne may process the following categories of Customer Personal Data in connection with Singularity:
- user and endpoint data: agent ID, endpoint name, customer active directory user ID, user name, installed applications – installation time, size, publisher and version, SMTP user name, configuration data related to active directory integration;
- full file path: will include personal data only if file name as named by Customer includes data;
- in cases of suspected threats, the SentinelOne agent collects for each process (file metadata, hash, file type, certificate, command line arguments, network access metadata (IP address, protocol), registry (created keys, deleted keys, modified key names);
- network data (internal network IP address, public IP address (if running cloud-based Management Console);
- threat information (file path, agent IDs, SMS messages content (which may include user names, IP addresses, file names);
- live network monitoring (URLs, URL headers, time stamps); and
- where Customer utilizes SentinelOne’s File Fetching feature: any Data contained in files fetched by Customer’s administrators.
- Dataset and XDR Ingest. SentinelOne may process the following categories of Customer Personal Data in connection with Dataset and/or XDR Ingest:
- data relating to individuals provided to SentinelOne by (or at the direction of) Customer in any data ingested by Customer to Dataset and/or XDR Ingest.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
Customer Personal Data does not include special categories of personal data or data related to criminal convictions or offenses, except where such data is uploaded by Customer in connection with the Dataset or XDR Ingest Services or accessed by Customer using the File Fetching feature of the SentinelOne Solutions.
The restrictions and safeguards specified in Annex II apply to these categories of personal data (if any).
Purpose of transfer
SentinelOne will process Customer Personal Data only to the extent reasonably necessary to provide Customer the Solutions and associated Support.
Retention Period/Criteria
The data importer will retain Customer Personal Data until its deletion in accordance with the provisions of the DPA.
ANNEX 3
TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
The data importer will implement and maintain security standards at least as protective as those set out in Appendix 2 of the DPA.
The technical and organisational measures to be taken by sub-processors are described in Section 4 (Subprocessing) of the DPA.