Logo

DATA PROCESSING AGREEMENT BETWEEN GAI AND GROUPAUTO REGIONS / MEMBERS

GROUPAUTO INTERNATIONAL (hereinafter “GAI”) is a leader in the distribution of aftermarket parts. As such, GAI manages networks with members in charge of the distribution of parts.

GAI has developed a project allowing its GROUPAUTO Listed Suppliers to contact the members of the GROUPAUTO networks to propose their products and services to all members of the networks.

In the frame of this project, GAI, the GROUPAUTO Regions, and GROUPAUTO Listed Suppliers will process personal data regarding the Regions, Distributors, and Workshops for different purposes, depending on nature of the processed personal data and the concerned data subjects.

This data processing agreement (“Agreement”) intends to set forth the obligations of GAI as well the Members and Regions in the processing of personal data referring to Members, Regions, Distributors and Workshops.

The Parties agree that GAI may amend the Appendix 1 and 2 of the Agreement from time to time. If so, GAI will inform the Entities in due time of such changes.

If provisions of the Agreement are contrary to any other contractual document relating to the processing of Personal Data listed in Appendix 2, the provision of this Agreement shall prevail upon any other document.

For this purpose, GAI and the Regions and Members will comply with the obligations set out in the Agreement for the processing of these personal data in France.

1. Definitions
  • 1.1. CNIL: means the Commission Nationale pour l'Informatique et les Libertés (CNIL), the independent French administrative authority responsible for ensuring compliance with the Personal Data Regulations in France and/or any locally competent authority in this area for the territory concerned by the Agreement.
  • 1.2. Data Breach: means any event resulting in the accidental or unlawful destruction, loss, modification, disclosure, or unauthorized access of the Data Subject's Personal Data
  • 1.3. Data Controller: has the meaning given by the Regulation on Personal Data.
  • 1.4. Data subject: means the natural person whose Personal Data is collected and processed for marketing purposes under the Agreement, and which are employees of Entities, Workshops or Distributors member of GAI’s networks.
  • 1.5. Distribution Agreement: designate the agreement concluded between GAI and the Entity and under which GAI proposes its distribution services to the Entity.
  • 1.6. Distributors: means parts distributors who are members of the national GROUPAUTO Region.
  • 1.7. Entity:means both Regions and/Members, as their obligation under the Agreement are the same.
  • 1.8. Mandatory Information: means all the information that must be communicated by the Data Controller to the Data Subject, in accordance with the Agreement and the Personal Data Regulations.
  • 1.9. GROUPAUTO REGION: means the regions designated by GAI which consist of Members and Non-Member entities which are part of GROUPAUTO based on a GROUPAUTO Member Agreement or an affiliation with a GROUPAUTO Member Agreement.
  • 1.10. Recipient: has the meaning given by the Regulation on Personal Data.
  • 1.11. Regulation on Personal Data: means the (i) Law no. 78-17 of 6 January 1978 on data processing, data files and individual liberties, as last amended by Order no. 2018-1125 of 12 December 2018 and commonly referred to as the "Loi Informatique et Libertés, (ii) the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, commonly known as the General Data Protection Regulation or "GDPR" and (iii) the guidelines and recommendations of the CNIL and/or the European Data Protection Committee, in the form of opinions and guidelines.
  • 1.12. Party(ies): means GAI and/or the Entity.
  • 1.13. Personal Data: has the meaning given by the Regulation on Personal Data, which are collected and processed under the Contract.
  • 1.14. Specific Rights: means the rights granted to Data Subjects by the Personal Data Regulation and in particular: the right of access, the right of rectification, the right to erasure, the right to limitation of processing, the right to portability, the right to object, the right to give post-mortem instructions, the right not to be subject to an automated individual decision (including profiling) and the right to lodge a complaint with the CNIL.
  • 1.15. GROUPAUTO Listed Suppliers: means the suppliers of GAI and its members who will send marketing emails and more generally contact and propose products and services.
  • 1.16. Workshop Network Member: means a member of the local EUROGARAGE or TOP TRUCK which is managed by the national GROUPAUTO MEMBER.
2. Purpose of the Agreement

The purpose of the Agreement is to determine the rights, obligations, and liabilities of each Party in the processing of Data Subjects’ Personal Data by the GROUPAUTO MEMBER and GAI in order to allow the collection and communication of Data Subject’s Personal Data to GROUPAUTO Listed Suppliers allowing them to perform marketing operations towards Distributors and Workshops.

It is agreed by Parties that each of them determines its own purposes and means in the processing of the Distributors and Workshops’ Personal Data listed in Appendix 1 and act as independent Data Controllers.

In application of the Agreement, GAI will act as sole Data Controller in the processing of Personal Data of Entities’ Data Subjects listed in Appendix 2.

3. Entry into force – Duration

The Agreement enters into force as the last date between (i) the release of the Agreement on GAI Intranet or (ii) the date of entry into force of the Distribution Agreement. The Agreement will remain into force for the duration of the Distribution Agreement.

4. Data processing of Distributors and Workshops Personal Data

The Personal Data of Data Subjects part of Distributors and Workshops is collected by the Entity directly from Data Subjects as part of the process of adding them to the local GROUPAUTO Distributor or Workshop network.

  • 4.1. Obligations of GAI
  • The Personal Data of Workshops and Distributors collected will be retained by GAI or the GROUPAUTO Listed Suppliers for the duration of the subscription of the Workshop or Distributor to GAI’s network and will then be destroyed.

    GAI guarantees to process all Personal Data of Distributors and Workshops in accordance with the Regulation on Personal Data and undertakes in particular to take all necessary precautions in order to:

    • Preserve the security of and access to the Personal Data collected.
    • Prevent the said Personal Data from being distorted, damaged or communicated to unauthorized persons.
    • To ensure that persons authorized to process Personal Data collected in this way undertake to respect confidentiality or are subject to an appropriate legal or contractual obligation of confidentiality.
    • Not to transfer Personal Data outside the European Economic Area unless one of the specific guarantees imposed by the Personal Data Regulations has been adopted and formalized with the Recipient(s) of the Personal Data concerned.
    • To share Personal Data only with Recipients, including the GROUPAUTO Listed Suppliers, who comply with the Regulation on Personal Data.
    • Not to use the Personal Data processed for purposes other than those specified by GAI under the Distribution Agreement and the Agreement.

    GAI guarantees to use the Personal Data in accordance with the Agreement, within the limits of the Mandatory Information given to the Data Subject by the Entity and within the limits of the consent obtained by the Entity, subject to the latter's compliance with its contractual obligations relating to this Agreement and its legal obligations relating to the Personal Data Regulations in this respect.

    GAI shall provide the Entity with all necessary information, in a timely manner, to enable the Entity to comply with its Mandatory Information obligations to Data Subjects and to obtain their consent in order to perform the Distribution Agreement in accordance with the Agreement.

    GAI will provide, upon request from the Entity sent to the address 147 Avenue Charles de Gaulle, 92200, Neuilly sur Seine, France, all information requested by the latter in order to ensure compliance with the Regulation on Personal Data when processing Personal Data by GAI such as, in particular, the security measures put in place to ensure the protection of Personal Data, the identity of the Recipients.

  • 4.2. Obligations of the Entity
  • The Entity declares and guarantees to provide the Mandatory Information to Data Subjects and in particular:

    • The precise purposes of the processing of their Personal Data collected by the Entity, in accordance with the purposes communicated by GAI.
    • The Data Processors linked to the processing of their Personal Data. If necessary, the Entity will decide whether or not to update the information communicated to the Data Subjects depending on the extent of the updates to the information to be provided and after consulting GAI and obtaining its comments, and will bear the consequences of such an update.
    • Informing the Data Subjects of their right and ability to object, at any time, to the processing of their Personal Data and to receive marketing operations.
    • The broad outlines of this Agreement.
    • The possibility of consenting or refusing or modifying the choice already made, in the same way, by a clear positive act, independently and specifically for each distinct purpose or category of purposes of Personal Data processing.

    In the absence of prior consent from the Data Subject to the processing of its Personal Data, where applicable after consent, no Personal Data must be processed by the Entity and transferred to GAI.

    The Entity must be able to provide certain, individual and time-stamped proof of the collection of consent from the Data Subjects and to demonstrate that the mechanism put in place, where applicable by a third party, has all the characteristics required to collect valid consent (free, specific, informed and unambiguous) and complies with the Entity's contractual obligations under this Agreement and the Entity's legal obligations under the Regulation on Personal Data.

5. Data processing of Entities

GAI will process the Personal Data of Entities’ Data Subjects for the purpose of allowing the sending to them of commercial and marketing operational by GROUPAUTO Listed Suppliers, on the basis of either the execution of the contractual relationships between GAI and Entities or the consent of Data Subjects.

The Personal Data collected will be retained by GAI or the GROUPAUTO Listed Suppliers for the duration of the subscription of the Entities to GAI’s network and will then be destroyed.

Personal Data will only be shared with the GROUPATUO Listed Suppliers to allow them to carry out marketing operations towards Entities.

GAI guarantees to process all Personal Data of Entities in accordance with the Regulation on Personal Data and undertakes in particular to take all necessary precautions in order to:

  • Preserve the security of and access to the Personal Data collected.
  • Prevent the said Personal Data from being distorted, damaged or communicated to unauthorized persons.
  • To ensure that persons authorized to process Personal Data collected in this way undertake to respect confidentiality or are subject to an appropriate legal or contractual obligation of confidentiality.
  • Not to transfer Personal Data outside the European Economic Area unless one of the specific guarantees imposed by the Personal Data Regulations has been adopted and formalized with the Recipient(s) of the Personal Data concerned.
  • To share Personal Data only with Recipients, including the GROUPAUTO Listed Suppliers, who comply with the Regulation on Personal Data.
  • Not to use the Personal Data processed for purposes other than those specified by GAI under the Distribution Agreement and the Agreement.
6. Specific Rights of the Data Subject

Each Data Subject of Entities, Workshops and Distributors may exercise the Specific Rights conferred upon it by the Regulation on Personal Data with regard to and against each of the Data Controllers, and the Parties shall communicate to each other any request from a Data Subject based on these Specific Rights, as soon as it is received, provided that it relates to the processing of Personal Data carried out within the framework of the Distribution Contract.

The Parties shall jointly examine and analyze the Data Subject's request within a maximum of five (5) working days and, within the same period, shall jointly designate the Party that will respond to the Data Subject. It is agreed that the exercise of their Specific Rights by Entities’ Data Subjects will be managed by Entities in priority, except if specific circumstances justify that GAI manages such request.

The Party concerned will process the request in accordance with the Regulation on Personal Data and will report to the other Party on the follow-up to the Data Subject's request.

7. Data breach and communication

The Parties undertake to notify each other as soon as possible of any Data Breach, within a period which may not exceed 36 hours from the time of becoming aware of it, which endangers or has consequences for the Personal Data.

In order, in particular, to enable the Parties to control their communications, each of the Parties undertakes not to inform third parties, including the Data Subjects or the CNIL, with the exception of the GROUPAUTO Listed Suppliers concerned where applicable, of a Data Breach in the context of the Agreement of which it has become aware without having obtained the prior written consent of the other Party within a period of forty-eight (48) hours. Failing to obtain such prior written consent from the other Party, each Party may inform third parties without its direct or indirect liability being incurred in any way whatsoever by the other Party as a result.

The Parties will jointly designate the Party or Parties authorized to communicate on the Data Breach, it being specified that GAI will be given priority for any Data Breach originating in the processing of Personal Data operated by GAI and/or an Entity in the execution of the Agreement.

The Parties will then meet within twelve (12) working hours of notification of the Data Breach to determine whether:

  • The documentation required to notify the CNIL of this Data Breach within 72 hours, as well as any additional documentation to be sent to the CNIL after notification.
  • The forms and methods of notification.
  • Whether or not it is necessary to notify the data subjects of the data breach.
  • The documentation required to notify data subjects of the breach.
  • The forms and methods of notification.
8. Data register

Each Party undertakes to update, at least once a year, a data register of the processing operations it carries out under the Agreement.

The data register shall be maintained by the Data Protection Officer and/or a privileged contact of the Party and shall contain at least the following information:

  • The name and contact details of the Party and its DPO.
  • The purposes of the identified personal data processing operations.
  • A description of the categories of data subjects and categories of personal data.
  • The categories of recipients to whom the Personal Data has been and/or will be communicated, including recipients located outside the European Economic Area.
  • Where applicable, transfers of Personal Data to Recipients located outside the European Economic Area, identification of the third country or international organization and, in the case of such transfers, documents justifying the guarantees implemented in accordance with the Personal Data Regulations.

A general description of the technical and organizational security measures adopted.

9. GROUPAUTO Listed Suppliers

GAI shall ensure that it has a written agreement with the GROUPAUTO Listed Suppliers guaranteeing the compliance of the services provided by the latter with the Regulation on Personal Data Regulations and the proper performance of the Distribution Agreement and the Agreement.

10. Warranties and liability

In the event of a dispute, claim and/or action by a third party claiming that one of its rights has been infringed, or in the event of an inspection by the CNIL resulting in a fine, only the Party responsible for the element in question shall be liable, where applicable. In order to determine which Parties are liable and the proportion of their liability, the Parties may refer to the decision of the CNIL and/or any final court judgment.

In the event of mixed causality of a claim arising from elements provided by the Parties, their joint liability may be maintained to the extent of the causality.

Each Party therefore undertakes to indemnify the other Party for any damage of any nature whatsoever that the latter may suffer as a result of any challenge or sanction and, in any event, undertakes to pay any damages and interest that the other Party may be ordered to pay, as well as any costs resulting from any judicial or extrajudicial action brought by a third party or by the CNIL or resulting from a data breach.

No settlement agreement may be entered into without the consent of each of the Parties.

Each Party may only be held liable for compensation for actual, personal, and specific loss or damage suffered by the other Party, to the exclusion of any indirect loss or damage, such as loss of turnover, customers or reputation, suffered by the other Party as a result of the performance or non-performance, even partial, of this Agreement.

Each Party shall do everything in its power to minimize any damage it may suffer as a result of the application of this Agreement.

In no event shall either party be liable for the processing of personal data by the other Party for which it does not act as joint controller with the other party.

11. Collaboration

The Parties undertake to collaborate and co-operate actively and to provide each other or facilitate each other's consultation or transmission in good time of all the elements and/or documents that they may require for the proper performance of their obligations under the Agreement and to meet as soon as possible in the event of difficulties in its performance.

Each Party undertakes to behave at all times towards the other Party as a loyal partner acting in good faith and, in particular, to inform the other party without delay of any dispute or difficulty which it may encounter in the performance of the Agreement.

The Parties have appointed a Data Protection Officer and a single point of contact for all notifications provided for in this Agreement, whose contact details are set out below:

All notices required to be given under the terms of the Agreement shall be in writing and sent to the above addresses. All notices given in accordance with the provisions of this article shall be effective: (a) at the time of delivery, in the case of delivery by hand against a receipt; (b) on the date of the first presentation of the letter to the addressee by the services of La Poste, in the case of sending by registered mail with acknowledgement of receipt; or (c) on the date of sending the notice by electronic mail.

Appendix 1: Workshops’ and Distributors’ processed Personal Data

Personal Data of Workshops’ and Distributors’ Data Subjects are the following:

  • Contact Name
  • Contact Phone Number
  • Contact Email Address
Appendix 2: Entities processed Personal Data

Personal Data of Entities’ Data Subjects are the following:

  • Contact Name
  • Contact Phone Number
  • Contact Email Address