This International Data Transfer Addendum ("Transfer Addendum") forms part of the Sento International Data Processing Agreement whenever Customer Personal Data is subject to a restricted international transfer under applicable law.
1. General rule
The transfer mechanism is determined by the actual exporter, importer, roles, source jurisdiction, destination, processing locations and applicable law. This Transfer Addendum does not substitute for an official mandatory transfer instrument.
Where an adequacy or comparable recognition validly covers a transfer, the parties may rely on it. Otherwise the parties use the legally required contractual or other safeguard.
2. European Union / EEA
For a restricted transfer subject to GDPR Chapter V, the parties use the mechanism permitted by the GDPR for the actual transfer.
Where Commission Implementing Decision (EU) 2021/914 applies, the parties incorporate and complete the official Standard Contractual Clauses (EU SCCs) using the module that matches the actual roles. Controller-to-processor transfers generally use Module 2; processor-to-subprocessor transfers generally use Module 3; another module is used where the facts require it.
Selectable options, annexes, competent supervisory authority, governing Member State law and Subprocessor authorization option are completed from the actual transfer facts. The official SCCs prevail over this Transfer Addendum and are not modified except as the SCCs expressly permit.
The parties perform a transfer impact assessment and adopt supplementary measures where required by applicable law and the circumstances of the transfer.
3. United Kingdom
For a restricted transfer under the UK GDPR, the parties use a valid UK transfer mechanism, including adequacy regulations where available or, as applicable, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
The parties complete any transfer risk assessment/data protection test required by current UK law and guidance. The official UK instrument prevails over inconsistent terms of this Transfer Addendum.
4. Switzerland
Where the Swiss Federal Act on Data Protection applies to a restricted international transfer, the parties use a mechanism permitted by Swiss law and make the Swiss adaptations required for any SCC-based transfer.
5. Brazil
Where the LGPD applies to an international transfer, the parties use a mechanism permitted by the LGPD and the current ANPD international-transfer rules, including adequacy, ANPD standard contractual clauses or another lawful mechanism as applicable.
If ANPD standard contractual clauses apply, the official clauses are incorporated/completed as required and prevail over inconsistent terms of this Transfer Addendum.
6. Australia
Where Australian Privacy Principle 8 applies, the relevant APP entity takes the reasonable steps required in the circumstances to protect Personal Information disclosed to an overseas recipient and applies the accountability rules and exceptions provided by Australian law.
7. New Zealand
Where Information Privacy Principle 12 applies, an overseas disclosure is made only where the recipient is covered by a permitted comparable-protection route, appropriate contractual safeguards or another basis permitted by the Privacy Act 2020.
8. Singapore
Where the Singapore PDPA transfer limitation applies, Sento and the relevant transfer party ensure that the overseas recipient is subject to a standard of protection comparable to that required by the PDPA or another permitted route applies.
9. Canada
Where Canadian privacy law applies, Sento remains accountable for Personal Information transferred to a third party for processing to the extent required by applicable law, uses appropriate contractual/organizational safeguards and provides required transparency concerning third-party processing.
10. United States
General US state privacy laws do not create one uniform international-transfer mechanism comparable to GDPR Chapter V. Sento applies contractual safeguards, security obligations and any sector-specific or state-specific localization/transfer requirement that actually applies to the relevant processing.
11. Government access and supplementary safeguards
For a restricted transfer, Sento and the relevant transfer party apply the safeguards required by the official transfer mechanism and the transfer risk. Measures may include access limitation, encryption or pseudonymization where appropriate, logging/monitoring, data minimization, retention controls and procedures for government requests.
Where lawful and required by the applicable transfer instrument, Sento reviews government demands for legal validity, seeks clarification or narrowing where appropriate, challenges unlawful or disproportionate demands where reasonably possible, and provides transparency to the exporter unless prohibited by law.
12. Transfer-specific record
The applicable Order Form, DPA annex, Subprocessor record or other transfer record identifies the facts required for the specific transfer, including:
- exporter and importer identity/contact details;
- controller/processor/subprocessor roles;
- categories of data subjects and Personal Data;
- purpose, nature and frequency of transfer;
- source and destination countries/processing locations;
- retention period or criteria;
- Subprocessors involved;
- relevant technical and organizational measures;
- applicable adequacy decision, SCC module, UK instrument, ANPD clauses or other mechanism; and
- competent authority/governing-law selections required by the official instrument.
Where an official transfer instrument requires signed or otherwise binding annexes, the parties complete and bind themselves to those annexes before relying on that instrument. Electronic acceptance or incorporation may be used where legally effective.
13. Precedence
An official mandatory transfer instrument and non-waivable transfer law prevail over inconsistent terms of the Agreement or this Transfer Addendum.
Questions about international transfers may be sent to [LEGAL_EMAIL].