BidSwitch
Data Processing Addendum
This Data Processing Addendum was updated on June 2026 and applies to all Customers irrespective of the Effective Date of the Term Sheet.
![]()
-
- The terms and conditions in this Data Processing Addendum (“DPA“), are entered into between Criteo S.A., as the parent company for the Criteo entity providing services to Customer (“BIDSWITCH“); and You (“Customer“), pursuant to the terms of the Agreement (defined below).
- This DPA together with the Agreement, constitutes a legally binding agreement between the parties and governs Your use of the BIDSWITCH Services and the parties’ processing of any personal data under the Agreement. Customer agrees that this DPA is like any written negotiated agreement signed by Customer and agrees to enter into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws, in the name and on behalf of any group companies or affiliates that use the Services. All capitalized terms not defined herein shall have the meaning set forth in the Agreement.
3. Background
3.1. BIDSWITCH and Customer have entered into a master services agreement, together with one or more connected service orders and/or agreements (collectively the “Agreement“), pursuant to which BIDSWITCH has agreed to provide the Services.
3.2. The parties wish to define their respective data protection obligations relating to BIDSWITCH’s provision of Services to Customer.
4. Definitions
4.1. In this DPA, the following terms shall have the following meanings:
(a) “Controller“, “processor“, “data subject“, “personal data“, “processing” (and “process“), “personal data breach”, “business”, “service provider” and “special categories of personal data” shall have the meanings given in Applicable Data Protection Laws.
(b) “Applicable Data Protection Laws” means any and all applicable international, national, federal and state laws and regulations relating to data protection, privacy and the Processing of personal data, including but not limited to: (a) the General Data Protection Regulation (“EU GDPR”), (b) the ePrivacy Directive and any national law implementing it, (c) the UK Data Protection Act (“UK GDPR”), (d) the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”), (e) any other U.S. state data protection or privacy law, including but not limited to laws in Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Indiana, Kentucky, Maryland, Minnesota, Rhode Island and Tennessee, and any future or amended state laws; (vi) the Brazilian Lei Geral de Proteção de Dados (“LGPD”); (vii) the Japan Act on the Protection of Personal Information (“APPI”); and (viii) the Korean Personal Information Protection Act (“PIPA”), in each case as implemented in the relevant jurisdiction, and any amending or replacement legislation (or similar) from time to time. For the sake of clarity, Applicable Data Protection Law also includes all legally binding requirements issued by the competent data Regulatory Authorities i) governing the Processing and security of information relating to individuals and providing rules for the protection of such individuals’ rights and freedoms with regard to the processing of data relating to them, ii) specifying rules for the protection of privacy in relation to data Processing and electronic communications, or iii) enacting rights for individuals which are enforceable towards organizations with respect to the processing of their personal data, including rights of access, rectification and erasure. Any Applicable Data Protection Law listed herein only apply to the Customer to the extent this is provided for under the criteria set by law.
(c) “Data subject” as used herein shall also refer to “consumer” as that term is defined under Applicable Data Protection Laws.
(d) “Personal data” means any information that identifies, relates to, describes, is capable of being associated with, or can reasonably be linked, directly or indirectly, to an identified or identifiable natural person or household, and that is Processed in connection with the Agreement.
(e) “Regulatory Authority” means any competent public authority, supervisory authority or government agency responsible for supervising compliance with Applicable Data Protection Laws, including, where applicable, the French CNIL, the UK Information Commissioner’s Office, the California Privacy Protection Agency and U.S. state attorneys general.
(f) “Services” has the meaning given to it in the Agreement or if not set forth in the Agreement, means the services provided by BIDSWITCH to Customer in accordance with and as described in the Agreement.
(g) “Standard Contractual Clauses” means, as applicable, the Module Two (controller-to-processor) standard contractual clauses approved by the European Commission, together with the UK Addendum approved by the competent UK authority, in each case as may be amended, replaced or superseded from time to time. The Standard Contractual Clauses as at the date of this DPA are set out at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and the UK Addendum is set out at: https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf.
(h) “Supplementary Measures” means the provisions set out in Appendix 2 to this DPA.
(i) “Sub-processor” means a party appointed by a processor or service provider to Process Personal data on behalf of that processor or service provider or on behalf of another processor/service provider, as applicable, in connection with the provision of the Services.
5. Details of the processing. The subject matter of BIDSWITCH’s processing of personal data is the processing necessary to perform the Services as outlined in the Agreement. The duration of the processing is for the Term of the Agreement. The nature and purpose of the processing are to provide the Services, as defined in the Agreement, the types of personal data are information unique to internet user(s), used by advertisers to present advertising to that internet user(s) and categories of data subjects processed under this DPA are the aforementioned internet users. If the Agreement is materially deficient in respect of the subject matter of this Clause 5, the parties may supplement the Agreement with additional information.
6. Data Protection Obligations
6.1. Relationship of the parties: Customer acting either as the controller in its own right or as the processor on behalf of one or more third party controller(s), appoints BIDSWITCH as a processor (or sub-processor, as the case may be) to Process Personal data described in the Agreement (the “Data“) for the purposes described in the Agreement (or as otherwise agreed in writing by the parties) (the “Permitted Purpose“). Each party shall comply with the obligations under Applicable Data Protection Laws. If BIDSWITCH becomes aware that Processing for the Permitted Purpose infringes an Applicable Data Protection Laws, it shall promptly inform Customer. Customer remains solely responsible for ensuring the accuracy, lawfulness, and quality of the Personal Data and for ensuring that the disclosure and Processing entrusted to BIDSWITCH has an valid legal basis and complies with Applicable Data Protection Laws.
6.2. Customer Instructions: BIDSWITCH shall process Personal Data for the Services only on Customer’s documented instructions, unless otherwise required to do so by applicable law to which BIDSWITCH is subject, in which case BIDSWITCH shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. Customer shall not instruct BIDSWITCH to Process Personal Data in a manner that is incompatible with the Agreement, this DPA or Applicable Data Protection Laws. BIDSWITCH shall promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws , or if such instructions are incompatible with the Services or more generally with the Agreement.
6.3. Service provider limitations: Customer is a business and BIDSWITCH is a service provider as those terms are defined under the Applicable Data Protection Laws. BIDSWITCH shall not: (a) sell, share, or otherwise process Data for purposes of targeted advertising other than the Permitted Purpose; (b) retain, use, or disclose personal data for any purpose other than for the Permitted Purpose; (c) retain, use, or disclose personal data for a commercial purpose other than for the Permitted Purpose; or (d) retain, use, or disclose personal data outside of the direct business relationship between BIDSWITCH and Customer. BIDSWITCH certifies that it understands these restrictions and will comply with them.
6.4. Security: BIDSWITCH shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
6.5. Prohibited data: Customer shall not disclose or provide (and shall not permit any data subject to disclose) any special categories of personal data or sensitive data to BIDSWITCH for processing.
6.6. Transfers of Personal Data: BIDSWITCH shall not transfer the Data outside of the European Economic Area (“EEA“) or the United Kingdom (“UK“) unless it has taken such measures as are necessary to ensure that the transfer complies with Applicable Data Protection Laws.
6.7. Where BIDSWITCH Processes Personal Data (i) relating to individuals located in the EEA in a territory outside of the EEA that does not benefit from an adequacy decision of the European Commission; or (ii) relating to individuals located in the UK in a territory outside of the UK that does not benefit from adequacy regulations or other recognised transfer mechanism under applicable UK Data Protection Laws, the Standard Contractual Clauses shall be incorporated by reference into this DPA and shall apply in relation to such Personal Data, together with the Supplementary Measures.
6.8. For the purposes of the Standard Contractual Clauses:
- Customer acts as a controller and “data exporter” and BIDSWITCH is the “data importer” and Module Two (controller to processor) shall apply;
- In Clause 9, the parties choose Option 2 and agree that the notice period shall be at least ten (10) days in advance;
- The optional language in Clause 11(a) shall be deleted;
- Clause 13 (a) shall be completed with the French CNIL as the competent supervisory authority;
- In Clause 17, the parties choose Option 1 and the governing law shall be the laws of France ;
- Clause 18(b) shall be the courts of Paris, France;
- Annex I to the Standard Contractual Clauses shall be completed with the information set out in Appendix 1 to this DPA;
- Annex II to the Standard Contractual Clauses shall be completed with the information set out in Appendix 2 to this DPA; and
- Where applicable, the UK Addendum shall be deemed completed as follows:
- Table 1 shall be deemed completed with the parties’ details from the Agreement;
- Tables 2 and 3 shall be deemed completed with the information set out in this clause 6.6, Appendix 1 and Appendix 2; and
- in Table 4, the parties choose the option “neither Party”.
6.9. Sub-processing: Subject to Clause 9 of the Standard Contractual Clauses, Customer may object to BIDSWITCH’s appointment or replacement of a Sub-processor prior to BIDSWITCH’s engagement of such Sub-processor, provided such objection is based on reasonable grounds relating to data protection. In such event, BIDSWITCH shall either not appoint or replace the relevant Sub-processor or, if this is not reasonably possible, Customer may suspend or terminate the affected Services or the Agreement, without prejudice to any fees incurred by Customer prior to suspension or termination.
6.10. Cooperation and data subjects’ rights: Taking into account the nature of the Processing, BIDSWITCH shall provide reasonable assistance to Customer, to the extent legally required and subject to operational feasibility (at Customer’s expense) to enable Customer to respond to: (i) any request from a Data Subject to exercise any of its rights under Applicable Data Protection Laws (including its rights of access, correction, objection, erasure and data portability, as applicable); and (ii) any other correspondence, enquiry or complaint received from a Data Subject, Regulatory Authority or other third party in connection with the Processing of the Personal Data under the Agreement.
6.11. Data Protection Impact Assessment: Upon Customer’s request, at Customer’s cost, and to the extent required under Applicable Data Protection Laws, BIDSWITCH shall assist Customer in complying with any required data protection impact assessment on Customer’s request, considering the information available to BIDSWITCH. To the extent required under Applicable Data Protection Laws, BIDSWITCH shall provide reasonable assistance to Customer in its cooperation or prior consultation with a Regulatory Authority in the performance of its tasks.
6.12. Audit: Customer acknowledges that BIDSWITCH is audited against ISO 27001, standards by independent third-party auditors. Upon request, BIDSWITCH shall supply a summary copy of its audit report(s) to Customer, which shall be subject to the confidentiality provisions of the Agreement. BIDSWITCH shall also respond to any written audit questions submitted to it by Customer, provided that Customer shall not exercise this right more than once per year.
Appendix 1
A. List of Parties
Data exporter: the organisation identified as Customer. Customer’s contact information is specified in the Agreement.
Customer’s activities are as described in the Agreement and, in relation to the relevant Processing, Customer acts as either a data controller or a data processor.
Data importer: the Criteo entity providing the Services to Customer and identified in this DPA as BIDSWITCH. BIDSWITCH’s contact information is specified in the Agreement. BIDSWITCH’s activities are as described in the Agreement and, in relation to such activities, BIDSWITCH acts as a data processor.
B. Description of Transfer
Categories of data subjects whose personal data is transferred: the categories of data subjects identified in clause 5.1 of the DPA.
Categories of personal data transferred: the personal data identified in clause 5.1 of the DPA.
Sensitive data transferred (if applicable): no special categories of personal data or sensitive data are transferred.
Frequency of the transfer: on a continuous basis depending on Customer’s use of the Services.
Nature of the processing: the nature of the processing identified in clause 5.1 of the DPA.
Purpose or purposes of the data transfer and further processing: the purposes of processing of personal data by the parties are as set out in clause 5.1 of the DPA.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: the Services have different automated retention and deletion periods for different types of data and settings, but in no event is personal data retained longer than is necessary.
Transfers to Sub-processors: BIDSWITCH maintains an up-to-date list of its Sub-processors in accordance with the DPA. The subject matter of processing by Sub-processors is the personal data processing required for performance of the Services pursuant to the Agreement. The nature of the processing is to provide the Services under the Agreement and the duration of the processing is for the Term of the Agreement.
C. Competent Supervisory Authority
The competent supervisory authority is the French CNIL.
Appendix 2
Description of the technical and organisational measures implemented by the data importer, including technical and organisational measures to ensure the security of the data:
1. The data importer shall implement and maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed, as required under Applicable Data Protection Laws and, where applicable, Article 32 GDPR.
2. Such measures shall include, as appropriate to the risk:
-
- measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- measures to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;
- access controls limiting access to personal data to authorised personnel on a need-to-know basis;
- network and transmission security measures, including encryption in transit where appropriate; and
- vendor management and Sub-processor due diligence measures designed to ensure an appropriate level of security.
3. Supplementary Measures. If BIDSWITCH receives an order or request to disclose personal data transferred under the Agreement (“Transferred Personal Data“) to a law enforcement, regulatory, judicial or governmental authority (an “Authority”), whether on a binding or voluntary basis, BIDSWITCH shall:
-
- promptly notify the Customer of such Authority’s data access request;
- inform the Authority that it is a processor of the Transferred Personal Data and that the Customer has not authorised BIDSWITCH to disclose that Transferred Personal Data to the Authority;
- inform the Authority that all requests or demands relating to the Transferred Personal Data should be notified to or served upon the Customer in writing; and
- not provide the Authority with access to Transferred Personal Data unless and until authorised by the Customer, save to the extent any such order, request or other legally binding obligation on BIDSWITCH requires BIDSWITCH to do otherwise.
4. In the event BIDSWITCH is under a legal prohibition or legal compulsion that prevents it from complying with paragraph 1 in full, BIDSWITCH shall use reasonable and lawful efforts to challenge such prohibition or compulsion, provided that such challenge may not always be reasonable or possible in light of the nature, scope, context and purposes of the intended Authority access request and the reasonable prospects and costs of successfully challenging the prohibition or compulsion.
5. Paragraphs 1 and 2 shall not apply where, considering the nature, scope, context and purposes of the intended Authority access to the Transferred Personal Data, BIDSWITCH has a reasonable and good-faith belief that urgent access is necessary to prevent an imminent risk of serious harm to any individual. In such event, BIDSWITCH shall notify the Customer as soon as practicable following such Authority access and provide the Customer with full details of the same, unless and to the extent BIDSWITCH is legally prohibited from doing so.
6. BIDSWITCH shall not knowingly disclose the Transferred Personal Data in a massive, disproportionate and indiscriminate manner that goes beyond what is necessary in a democratic society.
7. BIDSWITCH shall have in place, maintain and comply with a policy governing personal data access requests from Authorities which, at minimum, prohibits:
-
- massive, disproportionate or indiscriminate disclosure of personal data relating to data subjects in the EEA or the UK; and
- disclosure of personal data relating to data subjects in the EEA or the UK to an Authority without a subpoena, warrant, writ, decree, summons or other legally binding order that compels disclosure of such personal data.
8. BIDSWITCH shall have in place and maintain, in accordance with good industry practice, measures to protect the Transferred Personal Data from unauthorised interception, including in transit from the Customer to BIDSWITCH and between different systems and services. This includes maintaining network protection and encryption in transit designed to deny attackers the ability to intercept or read the Transferred Personal Data.
