BARRACUDA NETWORKS
Global Data Processing Addendum
This Global Data Processing Addendum (“Global DPA”) forms part of the agreement between Barracuda Networks, Inc. (“Barracuda”) and Customer, including Customer Affiliates (collectively, “Customer”) (the “Agreement”). This Global DPA applies to the processing of personal data by the Parties, to the extent such processing is subject to the Data Protection Laws.
1. PROCESSING OF CUSTOMER PERSONAL DATA
1.1 Roles of the Parties. Customer and Barracuda agree that Customer is the Controller or Processor of Customer Personal Data, and Barracuda is the Processor of such data. For purposes of the CCPA, Customer is a Business, and Barracuda is a Service Provider relevant to the Customer Personal Data. Data Processed by Barracuda as a Controller is processed in accordance with our Privacy Notice.
1.2 Barracuda Obligations. Barracuda will not Process Customer Personal Data other than: (a) as necessary to provide the Products and Services in accordance with Customer’s instructions, which include the terms of the Agreement, Customer’s use of the Services, and the terms of this Global DPA; or (b) as required to comply with laws to which Barracuda is subject. Barracuda will not retain, use, or disclose Customer Personal Data outside of the direct business relationship with Customer. Barracuda will comply with its obligations as to the Customer Personal Data under relevant Data Protection Laws, as applicable. Barracuda will inform Customer if it determines an instruction violates applicable Data Protection Laws. Barracuda may suspend the provision of Services until such time as Customer’s instructions become compliant with applicable Data Protection Laws.
1.3 Confidentiality. Barracuda takes reasonable steps to ensure that its employees who may have access to the Customer Personal Data are subject to confidentiality undertakings, or professional or statutory obligations, of confidentiality. Access to Customer Personal Data is reasonably limited.
1.4 Customer Obligations. Customer must comply with all Data Protection Laws with respect to its procurement and use of Barracuda Products and Services. Customer will not Process Personal Data, including Customer Personal Data, in any manner that violates or conflicts with the requirements of Data Protection Laws and Regulations. Customer’s instructions for the Processing of Customer Personal Data must comply with Data Protection Laws. Customer has sole responsibility and liability for the accuracy, quality, and legality of Customer Personal Data including the way Customer collects such Customer Personal Data.
1.4.1 Customer warrants that it has or will obtain all legally required consents and provide all legally required notices for the Processing of Customer Personal Data by Barracuda.
1.4.2 Customer warrants that all Customer Personal Data provided to and Processed by Barracuda is collected and Processed by the Customer in accordance with Data Protection Laws including without limitation: (a) ensuring that all notifications to and approvals from regulators that are required by Data Protection Laws are made and maintained by the Customer; and (b) ensuring that all Customer Personal Data is collected and Processed fairly and lawfully and is accurate and current.
1.4.3 Details of the Processing. The details of the Processing of Customer Personal Data, including the duration, subject matter, nature and purpose, categories of Data Subjects, and types of Customer Personal Data, are provided in Attachment 1.
2. LOCAL DATA PROTECTION LAWS
Attachment 1 details requirements specific to certain jurisdictions, supplementing this DPA as applicable for compliance.
3. SECURITY
Barracuda will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing of the Customer Personal Data as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, as further provided in Attachment 1 of this Global DPA.
4. SUBPROCESSING
4.1 Authorization. Customer authorizes Barracuda to subcontract the Processing of Customer Personal Data to Subprocessors who in each case are subject to terms between Barracuda and the Subprocessor that are no less protective of Personal Data than those set forth in this Global DPA. The list of Subprocessors currently engaged by Barracuda is available on the Barracuda website (as referred to in Section 6.2 below). Barracuda will provide Customer with further details about such Subprocessors upon written request from the Customer.
4.2 Right to Object. The Barracuda website lists the Subprocessors (available at https://trust.barracuda.com/privacy/documentation/sub-processors-and-cricital-vendors) that are currently engaged by Barracuda to carry out Processing activities. Barracuda will use reasonable efforts to provide prior notice of any new Subprocessor to carry out Processing activities via the website. Customers may subscribe for updates via email. If Customer does not object in writing within fifteen (15) days of posting on the website, Customer is deemed to have accepted the new Subprocessor. If Customer does object in good faith and on reasonable data privacy grounds in writing within fifteen (15) days of posting on the website, Barracuda and Customer will discuss possible resolutions. If no agreement can be reached, Customer may, at its option, terminate the Agreement to the extent the Products or Services cannot be provided without the objected-to Subprocessor, before the end of the notice period. Customer must provide written notice of termination and otherwise comply with the termination provisions in the Agreement, along with an explanation of the grounds for non-approval.
4.3 Subprocessing Liability. Barracuda will be liable for the acts and omissions of its Subprocessors to the same extent Barracuda would be liable if performing the services of each Subprocessor directly under the terms of this Global DPA.
5. DATA SUBJECT REQUESTS
5.1 Notice to Customer. Barracuda will not independently respond to requests from Customer’s employees, agents or customers without Customer’s prior written consent, except where required by applicable law. Barracuda will, to the extent legally permitted, notify Customer as soon as reasonably practicable if Barracuda receives a formal request or communication from a Data Subject to exercise a right under applicable Data Protection Laws (“Data Subject Request”).
5.2 Assistance to Customer. Taking into account the nature of the Processing, Barracuda will assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer’s obligation to respond to a Data Subject Request under Data Protection Laws. In addition, to the extent Customer, in its use of the Products and Services, does not have the ability to address a Data Subject Request, Barracuda will, upon Customer’s request, provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request, to the extent Barracuda is legally permitted to do so and the response to such Data Subject Request is required under Data Protection Laws.
6. DATA BREACH
In the event of a Data Breach impacting the Customer Personal Data, Barracuda will notify Customer, without undue delay, after becoming aware of it, in compliance with the applicable Data Protection Laws. Barracuda will cooperate with Customer and take such reasonable commercial steps as requested by Customer to assist in the investigation, mitigation, and remediation of each such Data Breach.
7. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
Upon Customer’s request, taking into account the nature of the Processing and information available, Barracuda will provide reasonable cooperation and assistance to Customer to perform required data protection impact assessments or prior consultations with Supervisory Authorities related to the Processing of Customer Personal Data, to the extent Customer does not otherwise have access to the relevant information.
8. DELETION OR RETURN OF DATA
Barracuda will delete Customer Personal Data and instruct all Subprocessors to delete Customer Personal Data after termination of the Agreement or sooner, where possible, upon Customer’s written request. In the event Customer desires a return of such data, where available, it may elect to download a copy via the Services prior to termination of the Agreement. Barracuda may retain copies of data where required by any law to which it is subject.
9. AUDIT RIGHT
9.1 Barracuda conducts annual audits, such as SSAE 18 SOC audit. Barracuda will, upon request, provide Customer a valid report from the most recent audit covering the Services, subject to the confidentiality provisions in the Agreement. Customer agrees that the foregoing fulfils Barracuda’s audit obligations under applicable Data Protection Laws unless additional audits are subsequently required by a relevant data protection authority or regulatory body with authority over the Customer Personal Data. To the extent legally required by applicable Data Protection Laws, Barracuda will provide supplemental information necessary to demonstrate Barracuda’s compliance with this Global DPA and applicable Data Protection Laws.
9.2 If and to the extent required by Data Protection Laws, Barracuda will allow for and contribute to reasonable audits, including inspections, by Customer, or a third-party auditor mutually agreed upon by Customer and Barracuda, at Customer’s sole expense. Barracuda will not provide or permit access to information concerning: (i) Barracuda’s internal pricing information; (ii) information relating to Barracuda’s other customers; or (iii) any of Barracuda’s non-public reports. All audit reports and information will be subject to confidentiality.
9.3 Unless otherwise required by a supervisory authority, audit requests must adhere to the following requirements: (a) Customer will give Barracuda at least thirty (30) days written notice of any request to conduct an audit and will not perform audits more frequently than once in any twelve (12) month period; (b) The parties will discuss and agree upon the audit plan and scope; (c) The audit will be conducted during normal business hours; (d) Audits will not include any hosting service providers (e.g., AWS, Microsoft) or penetration testing of Barracuda SaaS Services; (e) Audit materials including reports or other documentation will be marked CONFIDENTIAL and subject to a separate Non-Disclosure Agreement.
10. CROSS-BORDER DATA TRANSFERS
Personal data may be processed in the United States or other countries in which Barracuda and its Subprocessors operate. Customer transfers personal data to Barracuda, and Barracuda may perform onward transfers of personal data in accordance with these terms. For jurisdiction specific terms for cross border transfers of data, refer to the appropriate sections on Exhibit B.
11. MISCELLANEOUS CLAUSES
11.1 Governing Law and Venue. The governing law and venue applicable to this Global DPA is the same as those indicated between the parties in the Agreement.
11.2 Severability. If any part of this Global DPA is found invalid or unenforceable, the rest remains in effect. Such provisions will be amended to ensure validity and enforceability, reflecting the parties’ intentions as closely as possible, or treated as if they were never included.
11.3 Customer Affiliate Claims. Customer Affiliates will not bring a claim directly against Barracuda. Any such claims are considered made by Customer and are subject to any liability restrictions set forth in the Agreement.
11.4 Hierarchy. As to the subject matter and scope, if the Legal Terms and Conditions conflict with this Global DPA, the Global DPA prevails. If the Global DPA conflicts with applicable Model Clauses, the Model Clauses prevail for their subject matter and scope; otherwise, the Global DPA prevails.
12. DEFINITIONS
In this Global DPA, the capitalized terms are defined below. Capitalized terms not defined in this section have the meaning given to them in the agreement.
12.1 “ASEAN MCCs” means the ASEAN Model Contractual Clauses published and endorsed by the 2nd ASEAN Digital Senior Officials’ Meeting (ADGSOM), January 2021 applicable to transfers of data from Customers subject to Data Protection Laws in Indonesia, Singapore, the Philippines, Malaysia, and Thailand.
12.2 “Barracuda Affiliate” means an entity that owns or controls, is owned or controlled by, or is or under common Control with Barracuda, where “Control” is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
12.3 “Customer Affiliate” means an entity that owns or controls, is owned or controlled by, or is or under common control with Customer.
12.4 “Customer Personal Data” means any Personal Data Processed by Barracuda or its Subprocessor on behalf and at the instruction of Customer, in connection with the Agreement. Customer Personal Data does not include data processed by Barracuda as a Controller.
12.5 “Data Protection Laws” means applicable regulations, laws, or statutes that regulate the processing of personal data or personally identifiable information in a relevant jurisdiction, including but not limited to, the Australian Privacy Act 1988 (Cth) (including the Australian Privacy Principles), the California Consumer Privacy Act, as amended by the CPRA (the “CCPA”), the EU General Data Protection Regulation 2016/679 (the “GDPR”) together with applicable national legislation implementing or supplementing the same or otherwise relating to the processing of Personal Data of natural persons, Japan’s Act on the Protection of Personal Information, Act No. 57 of May 30, 2003 (the “APPI”), the New Zealand Privacy Act 2020, Singapore’s Personal Data Protection Commission (the “PDPC”), the Swiss Federal Act on Data Protection (the “FADP”), the United Kingdom GDPR as it forms part of United Kingdom law pursuant to Section 3 of the European Union (Withdrawal) Act 2018, and the UK Data Protection Act 2018 (collectively, the “UK GDPR”), all as may be amended from time to time.
12.6 “IDTA” means the UK International Data Transfer Addendum B1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022.
12.7 “Data Breach” means an event leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
12.8 “Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council annexed to the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
12.9 “Subprocessor” means any person appointed by or on behalf of Barracuda or any Barracuda Affiliate to Process Personal Data on behalf of any Customer in connection with the Agreement.
12.10 The terms, “Business,” “Control,” “Controller,” “Data Subject,” “Member State,” “Personal Data,” “Process,” “Processing,” “Processor,” “Service Provider,” and “Supervisory Authority” have the same meaning as in the applicable Data Protection Laws, and their cognate terms are construed accordingly. In the event of a conflict between these terms under applicable Data Protection Laws, the definition which confers the highest level of protection to the relevant Customer Personal Data applies.
The parties hereto hereby execute this Global Data Processing Addendum by persons authorized.
Attachment A
Details of processing activities
Description of the Parties
Customer, as identified in the Order
Barracuda Privacy Contact: Amanda Osorio, Senior Director, Data Protection & AI Counsel privacy@barracuda.com
Duration of the processing
The duration of the Processing is for the term designated under the Agreement.
Subject matter of the processing
The subject matter of the Processing is limited to Customer Personal Data.
Nature of the processing
The nature of the Processing includes recording, organization, storing, consulting, using, and deleting Customer Personal Data.
Purpose of the processing
The purpose of Processing Customer Personal Data is the provision of Services per the Agreement.
Categories of data subjects
Categories of data subjects are natural persons whose Personal Data is provided to Barracuda for Processing in accordance with the Services and this Global DPA. These may include Customers’ clients, employees, contractors, suppliers, customers, prospects, and other related third parties whose data Customer provides to Barracuda.
Type of Personal Data
Types of Customer Personal Data are determined by Customer and are provided by Customer in accordance with the Agreement. Customer understands that Barracuda has no control over which data Customer provides to Barracuda.
Authorized Sub-Processors
https://trust.barracuda.com/privacy/documentation/sub-processors-and-cricital-vendors.
Technical & Organizational Measures
Barracuda implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing of the Customer Personal Data as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. The technical and organizational measures implemented by Barracuda are further described in detail in the documentation published to Barracuda’s Trust Center as updated from time to time and as available to the Customer upon request by going to the Trust Center, https://trust.barracuda.com/security.
Exhibit A
Local Data Protection Compliance
Where applicable, pursuant to Local Data Protection Laws, the following terms apply.
California Consumer Privacy Act of 2018, as Amended by CPRA (the “CCPA”)
Where Barracuda Processes Customer Personal Data subject to CCPA, the following supplemental terms apply:
A. Purpose Limitation. To the extent that Customer discloses, shares, or otherwise makes available Customer Personal Data to Barracuda, Customer does so for the limited and specified purposes as described in the Agreement and other valid legal purposes under relevant laws.
B. Selling and Sharing. Barracuda will not Sell or Share Customer Personal Information as those terms are defined under applicable US Data Protection Laws, particularly the CCPA.
C. Deidentified Data. To the extent that Customer discloses or otherwise makes available Deidentified Data to Barracuda, or Barracuda deidentifies Customer Personal Data, Barracuda agrees to: (i) take reasonable measures to ensure that the Deidentified Data cannot be associated with an individual or household; (ii) publicly commit to maintain Deidentified Data in a deidentified form; and (iii) contractually obligate any further recipient to comply with all provisions of this Section.
12.11 Combining Personal Information. Barracuda will not combine Customer Personal Data regarding an individual that Barracuda receives from, or on behalf of, Customer with Personal Data that it receives from, or on behalf of, another person, or collects from Barracuda’s own interaction with the individual except as allowed under applicable Data Protection Law; including to perform a business purpose as defined in regulations adopted pursuant to Cal. Civ. Code 1798.185(a)(10).
12.12 Inability to Meet Data Protection Obligations. Barracuda will notify Customer if Barracuda reasonably determines that it can no longer meet its obligations under applicable US Data Protection Laws.
12.13 Unauthorized Use of Customer Personal Data. Customer may, upon reasonable notice to Barracuda, take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
United States - SEC Regulation S-P
Privacy of Consumer Financial Information and Safeguarding Customer Information. When Processing Customer Personal Data as a Service Provider of an entity regulated under Regulation S-P (17 CFR 248.30), Barracuda will notify Customer within 72 hours of becoming aware of a relevant security breach in accordance with 17 CFR 248.30(a)(5).
Exhibit B
Cross-Border Transfers - Jurisdiction Specific Terms
Restricted Transfers Subject to the Standard Contractual Clauses (EEA)
In accordance with Section 12 of the Global DPA, for transfers of Personal Data where Customer is located in the EEA or the Personal Data is otherwise subject to the Data Privacy Laws of the EEA and where Personal Data is transferred to a jurisdiction without an Adequacy Decision by the ECC (a “Restricted Transfer”), the Parties agree to be bound by the Standard Contractual Clauses (the “SCCs”), completed as follows:
A. Where the Customer is acting as a Controller, Module 2 applies. Where Customer is acting as a Processor, Module 3 applies.
B. Clause 7, the “Docking Clause (Optional)”, will be deemed incorporated.
C. Under Clause 9 (Use of sub-processors), the Parties select Option 2 (general authorization), and the time period for submitting requests for the addition or replacement of Sub-Processors is set forth in Section 5 of the Global DPA.
D. Under Clause 11 (Redress), the optional requirement that Data Subjects be permitted to lodge a complaint with an independent dispute resolution body does not apply.
E. Under Clause 17 (Governing law), the Parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights). The Parties select the law of Ireland.
F. Under Clause 18 (Choice of forum and jurisdiction), the Parties select the courts of Ireland.
G. For Annexes I-III, see the information provided in Attachment 1.
Restricted Transfers Subject to UK GDPR
Regarding any Restricted Transfers of Personal Data subject to the UK GDPR, the SCCs, as completed above apply as between the parties, subject to the IDTA thereto. The IDTA available here is incorporated here in and completed as follows:
A. In Table 1 of the IDTA the Parties is defined as set out in Annex I below.
B. In Table 2 of the IDTA, the EU Standard Contractual Clauses referenced are the Standard Contractual Clauses as completed herein and executed by reference between the Parties.
C. In Table 3 of the IDTA, the Annexes to the Standard Contractual Clauses are set out below.
D. In Table 4 of the IDTA, Barracuda may end the Addendum as set out in Section 19.
E. Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
F. By entering this Global DPA, the parties are deemed to execute the IDTA to the Standard Contractual Clauses as indicated herein.
Restricted Transfers Subject to Swiss Data Protection Law
If any personal data subject to the federal act on data protection (the “FADP”) is transferred out of Switzerland, the SCCs, completed as indicated above apply and is amended, for transfers subject to FADP only, as follows:
A. The competent supervisory authority in Annex I.C under Clause 13 is the Swiss Federal Data Protection and Information Commissioner (the “FDPIC”) insofar as the data transfer is governed by the FADP.
B. Applicable law for contractual claims under Clause 17 is Swiss law or the law of a country that allows and grants rights as a third-party beneficiary for contractual claims regarding data transfers pursuant to the FADP.
C. References to a “Member State” and “EU Member State” will not be read to prevent data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland).
D. References to the GDPR should be understood as references to the FADP insofar as the data transfers are subject to the FADP.
Transfers Subject to the ASEAN Model Contractual Clauses
In accordance with Section 12 of the Global DPA, for transfers of Personal Data from Singapore, Malaysia, Indonesia, the Philippines, and Thailand, the parties agree that the ASEAN MCCS are incorporated by reference and completed as follows:
A. For data transfers of Customer Personal Data from Customer to Barracuda where Barracuda acts as a data Processor, Module 1, sections 1-3 apply.
B. For data transfers of personal data from Customer to Barracuda where Barracuda acts as a Controller, Module 2, sections 1-4 apply.
C. For both Modules, optional clause 2.2 is adopted; no other optional clauses are adopted.
D. For both Modules, the Addendum of Additional Terms to the ASEAN MCCs is not adopted.
E. The governing law for the contractual provisions related to the ASEAN MCCs is Singapore.
F. The venue applicable to the ASEAN MCCs in the event of a dispute is the same as those indicated between the parties in the Agreement.
Transfers of Personal Data from Japan
To the extent Customer discloses or transfers Personal Data subject to Japan's APPI to Barracuda for processing outside Japan into a country not recognized as adequate, the following applies:
A. Barracuda agrees that it has established and will maintain a system of data protection measures equivalent to those required under the APPI, including: (i) processing Personal Data only for Customer's instructed purposes; (ii) implementing and maintaining appropriate technical and organizational security measures; (iii) restricting onward transfers only to third parties that are bound by equivalent obligations; and (iv) cooperating with Customer to respond to data subject inquiries regarding overseas data protection measures.
B. Upon Customer’s written request, Barracuda will confirm annually that its APPI-equivalent safeguards remain in effect.
C. The obligations in this Section are in addition to, and do not replace, any other international transfer mechanisms (such as EU Standard Contractual Clauses) that may apply under this DPA.
Transfers of Personal Data from Australia
If Customer transfers Personal Data subject to the Australian Privacy Act 1988 (Cth) (including the APPs) to Barracuda for Processing outside Australia, the following applies:
D. Barracuda will Process the Personal Data under this Global DPA and maintain safeguards (including appropriate technical and organizational measures and access controls) intended to provide a level of protection consistent with the APPs, considering the nature of the Processing and the Services.
E. The Parties acknowledge that, under Australian privacy law, not all overseas Processing is a “disclosure,” including where Personal Data remains under Customer’s effective control and is accessed only to provide the Services.
F. Barracuda will not disclose or make Personal Data available to third parties (including Subprocessors) except as permitted by this Global DPA and under terms no less protective than this Global DPA.
G. Considering the nature of the Processing, Barracuda will provide commercially reasonable assistance for Customer to respond to access/correction requests and will notify Customer of any Data Breach affecting the Personal Data under Section 8, reasonably cooperating to support Customer’s Australian-law notification obligations.
H. The Parties acknowledge that, for APP 8 purposes, Customer determines whether a cross-border disclosure occurs and remains responsible for complying with applicable cross-border disclosure requirements under Australian law, except where a statutory exception applies.
Transfers of Personal Data from New Zealand
If Customer transfers Personal Data subject to the New Zealand Privacy Act 2020 (including IPP 12) to Barracuda for Processing outside New Zealand, the following applies:
I. Barracuda will Process the Personal Data under this Global DPA and implement safeguards designed to protect it in a manner comparable to the New Zealand Privacy Act 2020; the Parties agree these safeguards are a permitted mechanism for overseas disclosures under IPP 12 and Customer reasonably believes comparable protection is required.
J. Barracuda will not disclose or make Personal Data available to third parties (including Subprocessors) except as permitted by this Global DPA.
K. Considering the nature of the Processing, Barracuda will provide commercially reasonable assistance for Customer to respond to individuals’ requests under the New Zealand Privacy Act 2020 and will notify Customer of any Data Breach affecting the Personal Data under Section 8, reasonably cooperating to support New Zealand-law notification or regulatory obligations.
L. If Customer relies on an individual’s authorisation for an overseas disclosure under IPP 12(1)(a), Customer is responsible for informing the individual that the Personal Data may not be protected comparably to New Zealand law; nothing in this Global DPA requires Barracuda to provide such disclosures to individuals.