Common use of Security Procedures; Compliance Clause in Contracts

Security Procedures; Compliance. Apple shall use industry-standard measures to safeguard Personal Data during the transfer, processing, and storage of Personal Data as part of the Service. As part of these measures, Apple will use commercially reasonable efforts to encrypt Personal Data at rest and in transit; ensure the ongoing confidentiality, integrity, availability and resilience of the Service; in the event of an issue, restore the availability of Personal Data in a timely manner; and regularly test, assess, and evaluate the effectiveness of such measures. Apple will take appropriate steps to ensure compliance with security procedures by its employees, contractors and Sub-processors, and Apple shall ensure that any persons authorized to process such Personal Data comply with applicable laws regarding the confidentiality and security of Personal Data with regards to the Service. Encrypted Personal Data may be stored at Apple’s geographic discretion. To the extent Apple is acting as a data processor, Apple will assist You with ensuring Your compliance, if applicable, with the following: (a) Article 28 of the GDPR (by allowing for and contributing to audits; provided, that Apple’s ISO 27001 and ISO 27018 certifications shall be considered sufficient for such required audit purposes); (b) Article 32 of the GDPR (by implementing the security procedures set forth in this Section 9.3 and by maintaining the ISO 27001 and ISO 27018 Certifications); (c) Articles 33 and 34 of the GDPR or other equivalent obligations under law (by assisting You with providing required notice of a Data Incident to a supervisory authority or data subjects); (d) laws requiring Institution to conduct data protection impact assessments or to consult with a supervisory authority prior to processing; and (e) an investigation by a data protection regulator or similar authority regarding Personal Data.

Appears in 3 contracts

Samples: Apple Business Manager Agreement, Apple Business Manager Terms and Conditions, Apple Business Manager Terms and Conditions

Security Procedures; Compliance. Apple shall use industry-standard measures to safeguard Personal Data during the transfer, processing, and storage of Personal Data as part of the Service. As part of these measures, Apple will use commercially reasonable efforts to encrypt Personal Data at rest and in transit; ensure the ongoing confidentiality, integrity, availability and resilience of the Service; in the event of an issue, restore the availability of Personal Data in a timely manner; and regularly test, assess, and evaluate the effectiveness of such measures. Apple will take appropriate steps to ensure compliance with security procedures by its employees, contractors and Sub-processors, and Apple shall ensure that any persons authorized to process such Personal Data comply with applicable laws regarding the confidentiality and security of Personal Data with regards to the Service. Encrypted Personal Data may be stored at Apple’s geographic discretion. To the extent Apple is acting as a data processor, Apple will assist You with ensuring Your compliance, if applicable, with the following: (a) Article 28 of the GDPR or other equivalent obligations under law (by making available all necessary information; by allowing for and contributing to audits; audits (provided, that Apple’s ISO 27001 and ISO 27018 certifications shall be considered sufficient for such required audit purposes); (b) Article 32 of the GDPR (by implementing the security procedures set forth in this Section 9.3 and by maintaining the ISO 27001 and ISO 27018 Certifications); (c) Articles 33 and 34 informing You, as required by applicable law, if, in Apple’s opinion, any of Your instructions infringes the GDPR or other equivalent obligations under law (by assisting You with providing required notice of a Data Incident to a supervisory authority European Union or data subjects); (d) laws requiring Institution to conduct European Union Member State data protection impact assessments or to consult with a supervisory authority prior to processing; and (e) an investigation by a data protection regulator or similar authority regarding Personal Data.provisions);

Appears in 1 contract

Samples: Apple Business Manager Terms and Conditions