---
title: "Data Protection Addendum"
canonical: "https://docs.pbs.org/space/PMSSO/4111920/Data%20Protection%20Addendum"
format: markdown
---
This Data Protection Addendum (“*Addendum*”) forms part of the Identity Authentication Services Terms of Use (“*Terms*”) and reflects the parties’ agreement about the Processing of Personal Data (as those terms are defined below). To the extent any term, requirement, or provision in this Addendum is deemed to be inconsistent or in direct conflict with any other term, requirement, or provision contained in the Terms, the terms of this Addendum shall control and govern. Service Recipient and PBS may each be referred to as a “*Party*” or collectively as the “*Parties*" in this Addendum.

1. **Definitions. **For purposes of this Addendum, the terms below have the meanings set forth below. Capitalized terms used but not otherwise defined in this Addendum have the meanings ascribed to them in the Terms.
  “*PBS User*” means an end-user of PBS’s digital products and services.
  “*PBS User ID Information*” means the User ID Information of a PBS User that is provided to or may be accessed by Service Recipient on behalf of PBS in connection with the Services.
  “*Privacy Laws*” means all applicable data privacy and security laws, rules and regulations applicable to the collection, use, and protection of Personal Data described in the Terms.
  "*Service Provider*” means Service Recipient or PBS when acting as a Processor as described in this Addendum.
  “*Service Recipient*” means a public media entity who integrates PBS-provided SSO Services into of the Service Recipient’s digital products and services.
  “*Service Recipient User ID Information*” means the User ID Information of an Authorized User or End-User (that is provided to or may be accessed by PBS on behalf of Service Recipient in connection with the Services.
  “*Sub-Processor*” has the meaning ascribed to it in Section 8.1 of this Addendum.
  The Privacy Laws define the terms “*Controller*”, “*Data Subject*”, “*Personal Data*”, “*Processor*”, “*Processing*”, and “*Third Party*.”
  The word “include” will be construed to mean “include without limitation”.
2. **Processing of Data.**
  1. **Roles and Responsibilities.**
    1. Service Recipient is and shall remain the Controller with respect to Service Recipient User ID Information; provided, however, that PBS is a Controller of Service Recipient User ID Information and Service-related session activity when Processed in connection with Authorized Users and End-User’s access to and use of PBS’s digital products and services. For the avoidance of doubt, PBS is and shall remain the Controller with respect to PBS User ID Information, and Service Recipient is a Service Provider when Processing PBS User ID Information. Controller maintains the rights and obligations to determine the purposes for which its User ID Information is processed (which includes but is not limited to, collection, recording, storage, use, access, transmission, and the means by which User ID Information may be transferred to a third country or international organization, if applicable). Nothing in this Addendum shall restrict or limit in any way a Controller’s rights or obligations to the User ID Information for such purposes. Controller and Service Provider shall comply with the obligations applicable to it under Privacy Laws with respect to the Processing of User ID Information for the SSO Services, as more particularly described in the Terms.** **Any reference in this Addendum to a Party as a Controller should not be construed as a concession or admission that any particular statute, law, regulation, or other legal act applies to that Party.
    2. Where an applicable Privacy Law requires Service Provider to Process User ID Information under terms other than those of this Addendum or other written instructions of Controller, Service Provider shall immediately notify Controller of such legal requirement before Processing in accordance with the legal requirement unless applicable law prohibits such disclosure. In addition, Service Provider shall notify Controller immediately if, in Service Provider's assessment, any of Controller's instructions infringe applicable law, including but not limited to applicable Privacy Laws.
    3. Upon request, Service Provider shall provide reasonable cooperation and assistance to Controller in ensuring compliance with data security obligations, as well as in carrying out any data protection impact assessment or similar activity, including but not limited to providing a systemic description of the envisaged Processing operations, reasonable assistance with an assessment of the risks to the rights and freedoms of the data subjects to whom the User ID Information relates, and/or reasonable assistance with an assessment of the necessity and proportionality of the Processing operations in relation to the underlying purpose. Service Provider shall also reasonably cooperate and provide any assistance or information reasonably requested and needed for Controller to engage in consultations with regulatory authorities or otherwise respond to requests for information from such authorities.
    4. Service Provider warrants that any persons authorized to Process Controller User ID Information have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
    5. Service Provider shall immediately notify Controller in writing of any request, complaint, claim, or other communication regarding User ID Information received by Service Provider, as well as by any Sub-Processors: (i) from a Data Subject; (ii) from any data protection/supervisory authority, law enforcement agency, or other government authority; and/or (iii) from Controller’s employees or any third parties, other than those set forth in this Addendum. Unless otherwise required by applicable law, Service Provider shall not disclose or share any User ID Information in response to such requests without first obtaining Controller’s written consent. Subject to applicable law, in the event Service Provider receives any request from a governmental authority in any jurisdiction that requires the disclosure of User ID Information to such governmental authority, Service Provider shall ask the governmental authority to request such User ID Information directly from Controller. Service Provider shall also cooperate with and provide reasonable assistance to Controller and its affiliates, agents, Sub-Processors, and representatives in responding to requests, inquiries, claims, and complaints regarding the Processing of Controller User ID Information.
  2. **Scope of Processing.**
    1. Service Provider shall act as a “Processor” or similar term under Privacy Laws. As such, Service Provider shall only Process Controller User ID Information in accordance with applicable Privacy Laws (i) to provide the Services; (ii) as required by applicable Privacy Laws; (iii) as authorized by the Terms and this Addendum; (iv) to permit access to the Controller User ID Information only to its employees, agents, contractors, or other personnel acting on its behalf who have a genuine need to know the information in order to fulfill the obligations set forth in the Terms; or (v) as further documented in any other reasonably requested and written instructions given by Controller in connection with the Terms (provided, however, that such instructions will not cause Service Provider to incur material incremental costs) (“<u>Processing Services</u>”). Service Provider will not (and will ensure that its employees, officers, contractors and agents do not): (a) retain, use, or disclose Controller User ID Information for any purpose other than for the business purpose(s) set forth in the Terms and in accordance with written instructions from the Controller or otherwise permitted by applicable Privacy Laws; (b) retain, use, or disclose Controller User ID Information for a commercial purpose other than providing the Services to the Controller; (c) “sell” or “share” Controller User ID Information, as defined under applicable Privacy Laws; (d) retain, use, or disclose Controller User ID Information outside of the direct business relationship between Controller and Service Provider: or (e) combine Controller User ID Information received from or on behalf of the Controller with User ID Information received from or on behalf of any other person or collected from Service Provider’s own interaction with a consumer, except as specifically allowed under applicable Privacy Laws.
    2. For avoidance of doubt, with the exception of Controller User ID Information or an Authorized User or End-User’s Service-specific session activity as described in the Terms, Controller shall not pass through any other types of Personal Data for Processing by the other Party.
3. **Data Security.** Service Provider shall implement and maintain appropriate organizational, technical, physical, and administrative security safeguards to comply with applicable requirements, including, as appropriate: (i) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services, including against unauthorized access, use, disclosure, alteration, or destruction of Controller User ID Information; (ii) the ability to timely restore the availability and access to Controller User ID Information in the event of a physical or technical incident or issue; and (iii) a process for regularly testing, assessing, and evaluating the effectiveness of the administrative, technical, organizational, and physical measures for ensuring the security of the Processing (collectively, “<u>Safeguards</u>”).
4. ** ****Security Incident. **Service Provider shall protect against a breach, loss, misuse, theft of, or unauthorized access to, Controller’s User ID Information stored in the SSO Services by any Third Party or unauthorized individual (“<u>Security Incident</u>”).
  Service Provider shall inform Controller within 48 hours (but in any case, as soon as possible, and if not within 48 hours as soon thereafter as practicable) after it learns that a Security Incident has occurred. Service Provider will reasonably cooperate with Controller as needed to investigate, remediate, and prosecute any such occurrence. If any Security Incident results from the acts or omissions of Service Provider, Service Provider shall use commercially reasonable measures and actions as are appropriate to mitigate the effects of such Security Incident.
5. ** ****Audit**. Service Provider shall keep full and accurate records relating to its Processing of Controller User ID Information as part of the Processing Services and shall conduct periodic audits of its compliance with applicable Privacy Laws. Controller may reasonably request, upon thirty (30) days’ written notice to Service Provider, a virtual audit, through itself or through an independent third-party auditor, or request Service Provider provide all information necessary to demonstrate its compliance with applicable Privacy Laws as it relates only to the Processing Services. The audit may be carried out once in any calendar year, unless otherwise required by applicable Privacy Laws or government authority. Audits shall be subject to all applicable confidentiality obligations agreed to by Controller and Service Provider and shall be conducted making all reasonable efforts to minimize any disruption of Service Provider's performance of services and other normal operations.
6. ** ****Data Subject Rights. **Service Provider shall provide reasonable assistance to Controller in responding to applicable Data Subjects' requests relating to their rights, including but not limited to requests regarding: (i) access; (ii) rectification/modification; (iii) erasure/deletion; (iv) restriction of Processing; (v) data portability; (vi) objection to Processing; and (vii) opting out of automated individual decision-making, including profiling. Controller reserves the right to determine whether or not a Data Subject has a right to exercise any Data Subject rights referenced above or under applicable Privacy Laws, and to give instructions to Service Provider to the extent any such assistance is required. Upon notice of a request for deletion or correction of Controller User ID Information, Service Provider will delete or correct (as applicable) the Data Subject’s User ID Information from its systems and records, and notify Service Provider’s service providers, contractors,** **subcontractors, or Sub-Processors to delete or correct the User ID Information (as applicable).
7. ** ****Privacy Policy. **Controller has the necessary rights and licenses, consents, permissions, waivers and releases to collect, use, disclose, or otherwise process Controller User ID Information. Service Provider shall have its own privacy policy or privacy notice that is made available to its Users prior to Users’ provision of any User ID Information to Service Provider or Sub-Processors.
8. ** ****Sub-Processors.**
  1. **Consent to Sub-Processor Engagement**. Service Provider has authorization to utilize affiliates and subsidiaries, agents, subcontractors, or other third parties to assist Service Provider in providing the Services (“*Sub-Processors*”), such as Akamai.
  2. **Requirements for Sub-Processor Engagement**. Service Provider shall provide a current list of its Sub-Processors upon request. Service Provider shall inform Controller if there any changes concerning the addition or replacement of such Sub-Processors, to which changes Controller has the right to object. Service Provider shall remain at all times responsible for and liable to Controller for its Sub-Processors’ performance of its obligations. When engaging any Sub-Processor, Service Provider shall ensure that each Sub-Processor is capable of providing the level of protection for User ID Information required by this Addendum and will enter into a written agreement with such Sub-Processor containing data protection obligations no less protective than those in the Terms (including this Addendum) with respect to the protection of User ID Information to the extent applicable to the nature of the Services provided by such Sub-Processor.
9. ** ****Data Transfers. **The following is applicable to the extent that Service Provider processes Personal Data of residents of the European Economic Area or the United Kingdom:
  1. **Cross Border Transfer Mechanisms**. Service Provider will not, other than in accordance with Controller’s instructions, transfer any Personal Data to any country or territory outside the European Economic Area unless that country or territory has been declared to provide an adequate level of protection for Personal Data by the European Commission. Where Controller does consent or has consented to the transfer or processing of Personal Data outside of the European Economic Area, the parties shall comply with the applicable provisions of the Privacy Laws relating to the transfer of Personal Data outside of the European Economic Area and undertake to take steps necessary to comply with those provisions or to provide and make use of Service Provider’s services without making such transfers.
  2. **Alternate Mechanisms**.** **To the extent that the parties are relying on a specific statutory mechanism to normalize international data transfers that is subsequently modified, revoked, or held in a court of competent jurisdiction to be invalid, the parties agree to cooperate in good faith to promptly terminate the transfer or to pursue a suitable alternate mechanism that can lawfully support the transfer.
10. **Post-Termination. **Notwithstanding any other provision of the Terms or this Addendum to the contrary, when Service Provider (including any Sub-Processors) ceases to perform the Processing Services upon termination of the Terms or otherwise (e.g., at the request or explicit instruction of Controller), Service Provider shall, upon reasonable request: (i) return User ID Information (and all media containing copies of Controller User ID Information) to Controller; and/or (ii) securely purge, delete, and destroy Controller User ID Information to the extent practicable, unless applicable law to which Service Provider is subject prevents it from returning or destroying all or part of the Controller User ID Information transferred. Service Provider shall communicate in writing the legal basis preventing it from returning or destroying Controller’s User ID Information, and warrant that it shall guarantee the confidentiality of the Controller User ID Information and shall not actively Process the Controller User ID Information. Electronic media containing Controller User ID Information shall be disposed of in a manner that renders Controller User ID Information unrecoverable.
11. **Analytics. **Controller acknowledges and agrees that the Service Provider may use Controller User ID Information to improve its products and services, but only to the extent such Controller User ID Information is anonymized and/or aggregated.
12. **Duration of Addendum. **This Addendum shall survive so long as either Party has obligations pursuant to applicable Privacy Laws.
13. **Additional Privacy Terms. **If and to the extent required by applicable Privacy Laws, the Parties shall make all commercially reasonable efforts to make necessary amendments to this Addendum. The Parties will agree on the necessary changes in good faith, taking into account the obligation to carry out this contractual relationship in compliance with applicable Privacy Laws.