ROKT® Australian Data Processing Agreement for Advertisers
This Data Processing Agreement (“DPA”) is effective as of the date You agree to the underlying Rokt Terms for Advertisers (“Terms”) covering the applicable Services (as defined therein) between You and Rokt (inclusive of any and all schedules, attachments, addendums, amendments, exhibits, order forms and statements of work, the “Agreement”), or by otherwise accepting or using the Services described therein.
1. Background
1.1 If: (i) the Advertiser is established in Australia, (ii) any data handled in the provision of the Services contains any Personal Information of individuals in Australia, or (iii) if Australian Privacy Law otherwise applies to such Personal Information (“Australian Personal Information”), then the provisions of this DPA shall apply and will take priority over any privacy- related provisions of the Agreement if and to the extent only of any conflict or inconsistency between them.
1.2 The Advertiser will use the Services pursuant to the Agreement, and in connection with such usage and with Rokt’s provision of the Services, Rokt will have access to and handle certain Australian Personal Information. The Australian Personal Information that Rokt will handle in providing the Services is described in Annex A to this DPA.
1.3 Each party shall comply with its obligations under Australian Privacy Law and this DPA with respect to the Australian Personal Information that it handles and according to its role (as described in clause 1.4) in relation to the relevant Australian Personal Information. The parties acknowledge that Australian Privacy Law does not use the concepts of “controller” and “processor”; the parties adopt those terms in this DPA as a contractual construct only, to describe their respective handling of Australian Personal Information, without prejudice to their status as APP Entities under the Privacy Act.
1.4 The parties agree that: (a) the Advertiser shall be a “controller” (as a contractual construct) with regard to Australian Personal Information, described in Annex A, constituting Advertiser Data (as defined in the Agreement), that is handled in connection with the Services (“Advertiser Australian Personal Information”); (b) Rokt shall be a “processor” (as a contractual construct) with regard to Advertiser Australian Personal Information; and (c) Rokt shall be a “controller” (as a contractual construct) with regard to Rokt Data.
1.5 This DPA shall be governed by the laws of New South Wales, Australia, to the extent that this DPA applies to Australian Personal Information.
1.6 The parties shall submit to the non-exclusive jurisdiction of the courts of New South Wales, Australia, in respect of any dispute arising out of or in connection with this DPA.
2. Security
Rokt shall implement appropriate technical and organisational measures designed to protect the Advertiser Australian Personal Information from misuse, interference, loss, unauthorised or unlawful access, use, modification or disclosure, or accidental destruction (a “Security Incident”). Such measures shall have regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of handling as well as the risk of varying likelihood and severity for the rights and interests of individuals, and shall include the security measures described in Annex B (Minimum Security Measures) to this DPA. Without limitation, Rokt shall ensure that only authorised personnel have access to Advertiser Australian Personal Information and that access credentials are held securely at all times. Rokt shall take reasonable steps to continuously monitor (or if this is not practicable, to frequently check) the systems on which it holds Advertiser Australian Personal Information for events that could amount to Eligible Data Breaches.
3. Controller obligations
3.1 Whenever a party is acting in a capacity as a controller in relation to Australian Personal Information, it shall comply in all respects with Australian Privacy Law, including by handling such data fairly and lawfully and in accordance with the Australian Privacy Principles, providing any legally required privacy notices and collection notifications, and obtaining any legally required consents for the handling of Personal Information.
3.2 A controller shall provide assistance reasonably requested by the other party (and at that other party’s cost) in order for that other party to comply with Australian Privacy Law, including with respect to individual access and correction requests under APP 12 and APP 13, notifications of collection under APP 5, and open and transparent management of Personal Information under APP 1.
3.3 The parties agree that they do not intend to act as “joint controllers” with respect to any Australian Personal Information. However, if and to the extent that the parties are acting jointly in determining the purposes and means of handling any Australian Personal Information, and the provisions of the Agreement and this DPA do not enable material compliance with the obligations of either or both parties under Australian Privacy Law, they shall each provide all assistance reasonably requested by the other party in order for that other party to comply with its obligations under Australian Privacy Law, including with respect to individual access and correction requests, and cooperate to ensure that each individual is given any notices that are required under Australian Privacy Law with respect to the handling that each of the parties undertakes.
4. Processor obligations
4.1 Purpose limitation: Rokt shall handle the Advertiser Australian Personal Information as necessary to perform its obligations under the Agreement, for such other purposes as may be described in this DPA (including Annex A) and in accordance with the documented instructions of the Advertiser (the “Permitted Purpose”), except where otherwise required by Australian law. Rokt shall inform the Advertiser if, in its opinion, an instruction infringes Australian Privacy Law.
4.2 Confidentiality of processing: Rokt shall ensure that any person that it authorises to handle the Advertiser Australian Personal Information (including Rokt’s staff, agents and subcontractors) (an “Authorised Person”) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any person access to Advertiser Australian Personal Information who is not under such a duty of confidentiality. Rokt shall take reasonable steps to ensure the reliability of any Authorised Person who has access to Advertiser Australian Personal Information.
4.3 Subprocessing: Rokt may subcontract its handling of Advertiser Australian Personal Information to a third party subprocessor without the prior written consent of the Advertiser. Rokt shall however inform the Advertiser when it adds to or removes the subprocessors (which may be done via a website link notified to the Advertiser) in order to give the Advertiser the opportunity to object to the appointment of the subprocessor. Notwithstanding anything to the contrary in the foregoing, the Advertiser consents and authorises Rokt to use the subprocessors listed at https://rokt.com/rokt-subprocessors/ in its provision of the Services. Rokt shall enter into a written agreement with each subprocessor imposing privacy and security obligations substantially equivalent to those set out in this DPA, and shall be solely responsible for fulfilling its obligations under this DPA despite the use of any subprocessors.
4.4 Cooperation and individual rights: Rokt shall (i) respond to any verified and valid request from an individual to exercise rights available under Australian Privacy Law (including access under APP 12 and correction under APP 13), to the extent the request concerns Advertiser Australian Personal Information held by Rokt; provided that Rokt may retain Personal Information as described in this DPA (including Annex A); and (ii) provide all reasonable and timely assistance (including by appropriate technical and organisational measures) to the Advertiser (at the Advertiser’s expense) to enable the Advertiser to respond to: (A) any verified and valid request from an individual to exercise any of its rights under Australian Privacy Law, including rights of access and correction; and (B) any written correspondence, enquiry or complaint received from the Commissioner or any other regulator in connection with the handling of the Advertiser Australian Personal Information. In the event that any such request, correspondence, enquiry or complaint is made directly to Rokt, Rokt shall promptly do either or both of the following: inform the Advertiser of the request, correspondence, enquiry or complaint; or direct the individual or regulator to contact the Advertiser.
4.5 Privacy Impact Assessment: If Rokt believes or becomes aware that its handling of Advertiser Australian Personal Information is likely to result in a high risk to the privacy rights or interests of individuals, it shall promptly inform the Advertiser and provide the Advertiser with all such reasonable and timely assistance (at the Advertiser’s expense) as the Advertiser may require in order to conduct a privacy impact assessment and, if necessary, consult with the Commissioner.
4.6 Security incidents and Eligible Data Breaches: (a) Upon becoming aware of a confirmed Security Incident (including any event that could amount to an Eligible Data Breach), Rokt shall inform the Advertiser without undue delay and shall provide all such timely information and cooperation as the Advertiser may reasonably require in order for the Advertiser to fulfil its obligations under Australian Privacy Law (including its obligations under Part IIIC of the Privacy Act 1988 (Cth)). (b) If Rokt determines, or the Advertiser determines and notifies Rokt, that an Eligible Data Breach has or may have occurred and Australian Privacy Law requires that the Eligible Data Breach be notified to the Commissioner, Rokt shall, as soon as practicable, provide the Advertiser with any information reasonably required for the Advertiser to prepare and issue any notification required under Part IIIC of the Privacy Act 1988 (Cth). (c) Rokt shall keep the Advertiser promptly informed of any investigation or other action taken by the Commissioner in connection with the actual or suspected Eligible Data Breach, to the extent relating to Advertiser Australian Personal Information. (d) This clause 4.6 does not affect either party’s independent obligations under Australian Privacy Law.
4.7 Deletion or return of Advertiser Australian Personal Information: Upon termination or expiry of the Agreement, Rokt shall (if the Advertiser so requests) destroy or return to the Advertiser all Advertiser Australian Personal Information (including all copies of the same) in its possession or control (including any Advertiser Australian Personal Information subcontracted to a third party for handling) for which Rokt is acting as a processor. This requirement shall not apply to the extent that Rokt is required by Australian law to retain some or all of that Australian Personal Information, or Rokt retains Advertiser Australian Personal Information for the purposes of establishment, exercise or defence of legal claims, in which event Rokt shall protect the Australian Personal Information from any further handling except to the extent required by such law. Without limiting the foregoing, Rokt shall take such steps as are reasonable in the circumstances to destroy or de-identify Advertiser Australian Personal Information that it no longer needs for any purpose for which the information may be used or disclosed under Australian Privacy Law, in accordance with APP 11.2.
4.8 Records: Where required by Australian Privacy Law, Rokt shall maintain a record of all categories of handling activities carried out on behalf of the Advertiser in respect of Advertiser Australian Personal Information (“Processing Records”) and Rokt shall make available the Processing Records to the Advertiser within ten (10) working days following receipt of a request for such Processing Records from the Advertiser.
4.9 Audit: Rokt shall permit the Advertiser (or its appointed third party auditors) to audit at the Advertiser’s own expense Rokt’s compliance with this DPA, and shall make available to the Advertiser all information, systems and staff reasonably necessary for the Advertiser (or its third party auditors) to conduct such audit. Rokt acknowledges that the Advertiser (or its third party auditors) may enter its premises for the purposes of conducting this audit, provided that the Advertiser gives Rokt 30 days’ prior written notice of its intention to audit, conducts its audit during normal business hours, and takes all reasonable measures to prevent unnecessary disruption to Rokt’s operations. The Advertiser will not exercise its audit rights more than once in any twelve (12) calendar month period, except (i) if and when required by instruction of the Commissioner or another competent regulator; or (ii) the Advertiser reasonably believes a further audit is necessary due to a Security Incident suffered by Rokt.
5. Cross-border disclosure of Personal Information
5.1 The parties acknowledge that the provision of the Services may involve the disclosure of Advertiser Australian Personal Information to Rokt and to its Affiliates and subprocessors located outside Australia. Any such cross-border disclosure shall be made in compliance with APP 8 of the Australian Privacy Principles.
5.2 Where Rokt discloses Advertiser Australian Personal Information to an overseas recipient (including any Affiliate or subprocessor), Rokt shall take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles (other than APP 1) in relation to that information. Without limitation, Rokt shall ensure that each overseas recipient is bound by written contractual obligations requiring it to handle Advertiser Australian Personal Information in a manner substantially equivalent to the obligations imposed on Rokt under this DPA.
5.3 The Advertiser consents and authorises Rokt to disclose Advertiser Australian Personal Information to the subprocessors and overseas recipients listed at https://rokt.com/rokt- subprocessors/ in its provision of the Services. This consent is given for the purposes of APP 8.2(b) and is acknowledged by the Advertiser to be informed consent to the disclosure.
5.4 If the Advertiser wishes to restrict the cross-border disclosure of any specific Advertiser Australian Personal Information beyond what is set out in this clause 5, the parties will discuss in good faith any operational changes that may be required and the allocation of any associated costs.
6. Definitions
In this DPA:
(i) “Advertiser Data” has the meaning given in the Agreement.
(ii) “APPs” or “Australian Privacy Principles” means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act 1988 (Cth).
(iii) “Australian Privacy Law” means the Privacy Act 1988 (Cth), including the Australian Privacy Principles, the Notifiable Data Breaches scheme in Part IIIC of that Act, and any binding code or determination made under that Act, together with any other applicable Australian laws relating to the handling of Personal Information
(iv) “Commissioner” means the Australian Information Commissioner and includes the Privacy Commissioner, in each case as established under the Australian Information Commissioner Act 2010 (Cth).
(v) “Eligible Data Breach” has the meaning given in section 26WE of the Privacy Act 1988 (Cth).
(vi) “Personal Information” has the meaning given in section 6 of the Privacy Act 1988 (Cth).
(vii) “Rokt Data” has the meaning given in the Agreement.
(viii) “Security Incident” has the meaning given in clause 2 of this DPA. All other capitalised terms that are used but not defined in this DPA shall have the meaning given to them in the Agreement.
ANNEX A TO DPA
Advertiser Australian Personal Information – Data Handling Description
ANNEX B TO DPA
Minimum Security Measures