“Personal data“: any information relating to an identified or identifiable natural person (“data subject”).
A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the genetic, psychological, economic, cultural, or social identity of that person.
Annex 1 lists the Personal Data that the Processor will process in accordance with this agreement and the purposes for which the data are processed.
“Processing“: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Data Controller“: a natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor“: a natural or legal person which processes personal data on behalf of the data controller.
“Sub-processor“: the processor appointed by the processor to perform part of the processing activities on behalf of the data controller.
“Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed, also known as a “data leak“.
“GDPR“: the General Data Protection Regulation, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.