Data Controller: [Transit Operator Company Name], a company incorporated under the laws of [Country], with registered office at [Address] ("Controller")
Data Processor: BusCommand Enterprise, a company providing SaaS fleet management services, with registered office at [Address] ("Processor")
This Data Processing Agreement ("DPA") is entered into pursuant to Article 28 of the General Data Protection Regulation (GDPR) and governs the processing of personal data by the Processor on behalf of the Controller.
Subject Matter: The Processor shall provide fleet management, dispatch operations, driver shift scheduling, and related transit operational services to the Controller through the BusCommand SaaS platform.
Duration: This DPA shall commence on the Effective Date and shall remain in force for the duration of the main service agreement between the parties, plus a period of twelve (12) months following termination of such agreement to allow for data export and deletion.
Categories of Data Subjects: The processing shall involve personal data of the following categories of data subjects:
Categories of Personal Data: The Processor shall process the following categories of personal data:
Purpose of Processing: The personal data shall be processed for the following purposes:
Processing on Controller's Behalf: The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by European Union or Member State law to which the Processor is subject. In such case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Confidentiality: The Processor shall ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Security Measures: The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate:
Subprocessor Engagement: The Processor shall not engage another processor without prior specific or general written authorization from the Controller. The Processor shall provide the Controller with a list of subprocessors already engaged, and shall inform the Controller of any intended changes concerning the addition or replacement of subprocessors, thereby giving the Controller the opportunity to object to such changes.
Assistance to Controller: The Processor shall assist the Controller, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
Data Subject Rights: The Processor shall assist the Controller in ensuring compliance with the following data subject rights:
Encryption: The Processor shall implement the following encryption measures:
Data Residency: All personal data shall be stored and processed within the European Union. The Processor shall ensure that cloud infrastructure is hosted in the europe-west3 region (Frankfurt, Germany) unless otherwise agreed in writing by the Controller.
Multi-Tenant Isolation: The Processor shall implement strict multi-tenant isolation to ensure that data of one Controller is not accessible to another Controller or any unauthorized party.
Access Control: The Processor shall implement role-based access control (RBAC) ensuring that personnel have access only to data necessary for their roles.
Audit Logging: The Processor shall maintain comprehensive, immutable append-only audit logs for all data processing operations for a minimum period of 24 months.
Right to Disconnect: The Processor shall ensure that the platform does not collect telemetry, location data, or any monitoring data outside of active shift periods. GPS tracking or continuous surveillance of drivers is not implemented or permitted.
Working Time Compliance: The platform shall assist the Controller's compliance with EU working time regulations and EU Regulation 561/2006 on drivers' hours by recording shift start/end times and flagging shifts with less than the statutory minimum daily rest for dispatcher review. This is a dispatcher decision-support aid; it does not replace a certified tachograph or working-time compliance system, and final compliance responsibility remains with the Controller.
Off-Duty Privacy: Drivers and other data subjects shall not be monitored or tracked outside of their assigned working hours. The platform shall not collect or process personal data during periods when the data subject is not actively engaged in work duties.
Authorized Subprocessors: The Processor is authorized to engage the following subprocessors for the provision of the services:
| Subprocessor | Services | Data Location |
|---|---|---|
| Google Cloud Platform | Cloud infrastructure, database hosting, computational services | Frankfurt, Germany (europe-west3) |
Subprocessor Agreement: The Processor shall ensure that each subprocessor provides sufficient guarantees to implement appropriate technical and organizational measures in such a manner that processing will meet the requirements of the GDPR and ensure the protection of the rights of the data subject.
Subprocessor Changes: The Processor shall notify the Controller of any intended addition or replacement of subprocessors at least 30 days prior to such change, providing the Controller with the opportunity to object to such changes.
Deletion or Return: Upon termination of the services, the Processor shall, at the Controller's choice, delete or return all personal data processed on behalf of the Controller, and delete existing copies unless European Union or Member State law requires the storage of the personal data.
Data Export: The Processor shall provide the Controller with the ability to export all personal data in a commonly used machine-readable format prior to termination of services.
Verification: The Processor shall provide written confirmation to the Controller that all personal data has been deleted or returned in accordance with this Article 8.
Notification to Controller: The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. The notification shall at least:
Documentation: The Processor shall maintain a record of all personal data breaches, including the facts relating to the personal data breach, its effects, and the remedial action taken.
Audit Rights: The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
Compliance Certifications: The Processor shall maintain and provide evidence of relevant compliance certifications, including but not limited to ISO 27001, SOC 2 Type II, and GDPR compliance assessments.
This DPA shall be governed by the laws of [European Union Member State] and shall be subject to the exclusive jurisdiction of the courts of [European Union Member State]. Any disputes arising under or in connection with this DPA shall be resolved in accordance with such laws.
In the event of any conflict between the provisions of this DPA and the main service agreement, the provisions of this DPA shall prevail to the extent of such conflict.
Entire Agreement: This DPA constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and representations, whether written or oral.
Amendments: Any amendment or modification to this DPA shall be in writing and signed by authorized representatives of both parties.
Severability: If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
|
For and on behalf of the Data Controller: [Transit Operator Company Name] ___________________________ Signature ___________________________ Name: ___________________________ Title: ___________________________ Date: |
For and on behalf of the Data Processor: BusCommand Enterprise ___________________________ Signature ___________________________ Name: ___________________________ Title: ___________________________ Date: |