Data Processing Agreement
DPA — Standard Contractual Clauses under Article 28 GDPR
Version 1.0 — Effective from 2026-05-28
This Data Processing Agreement (the “DPA”) sets out the terms governing Supplier’s processing of personal data on behalf of Customer in connection with the Services provided by Supplier under the relevant agreement between the Parties. The DPA is incorporated into that agreement by reference.
For the purposes of Article 28(3) of Regulation (EU) 2016/679 (the GDPR) for the processing of personal data by the processor.
Parties
Between Customer (as specified in the relevant Agreement) — the data controller — and Retail Media Networks ApS (as specified in the relevant Agreement) — the data processor, each a “Party” and together “the Parties.”
The Parties have agreed on the following Contractual Clauses (the “Clauses”) in order to meet the requirements of the GDPR and to ensure the protection of the rights of the data subject.
Preamble
These Clauses set out the rights and obligations of the data controller and the data processor when processing personal data on behalf of the data controller.
The Clauses have been designed to ensure the Parties’ compliance with Article 28(3) of the GDPR.
In the context of the provision of the Services as described in the relevant Agreement between the Parties, the data processor will process personal data on behalf of the data controller in accordance with the Clauses.
The Clauses take priority over any similar provisions contained in other agreements between the Parties.
Four appendices are attached to the Clauses and form an integral part of the Clauses.
- Appendix A contains details about the processing of personal data, including the purpose and nature of the processing, types of personal data, categories of data subject and duration of the processing.
- Appendix B contains the data controller’s conditions for the data processor’s use of sub-processors and a list of sub-processors authorized by the data controller.
- Appendix C contains the data controller’s instructions with regard to the processing of personal data, the minimum security measures to be implemented by the data processor, and how audits of the data processor and any sub-processors are to be performed.
- Appendix D contains provisions for other activities not covered by the Clauses.
The Clauses along with appendices are retained in writing, including electronically, by both Parties. The Clauses do not exempt the data processor from obligations to which the data processor is subject pursuant to the GDPR or other legislation.
1. Rights and obligations of the data controller
The data controller is responsible for ensuring that the processing of personal data takes place in compliance with the GDPR, applicable EU or Member State data protection provisions, and the Clauses.
The data controller has the right and obligation to make decisions about the purposes and means of the processing of personal data.
The data controller is responsible, among other things, for ensuring that the processing of personal data which the data processor is instructed to perform has a legal basis.
2. The data processor acts according to instructions
The data processor processes personal data only on documented instructions from the data controller, unless required to do so by Union or Member State law to which the processor is subject. Such instructions are specified in Appendices A and C. Subsequent instructions may be given by the data controller throughout the duration of the processing of personal data, and such instructions must always be documented and kept in writing, including electronically, in connection with the Clauses.
The data processor must immediately inform the data controller if, in the opinion of the data processor, an instruction contravenes the GDPR or applicable EU or Member State data protection provisions.
3. Confidentiality
The data processor grants access to the personal data being processed on behalf of the data controller only to persons under the data processor’s authority who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and only on a need-to-know basis. The list of persons with access is kept under periodic review; access is withdrawn where no longer necessary.
The data processor at the request of the data controller demonstrates that the concerned persons are subject to confidentiality.
4. Security of processing
Article 32 GDPR requires that, considering the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and processor implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
The data controller evaluates the risks to the rights and freedoms of natural persons inherent in the processing and implements measures to mitigate those risks. Such measures may include:
- Pseudonymization and encryption of personal data;
- the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures.
The data processor independently evaluates the risks and implements measures to mitigate them. The data controller provides the data processor with all information necessary to identify and evaluate such risks.
The data processor assists the data controller in ensuring compliance with the data controller’s obligations pursuant to Article 32 GDPR, by providing information about the technical and organizational measures already implemented by the data processor along with other information necessary for the data controller to comply with its obligations.
5. Use of sub-processors
The data processor meets the requirements specified in Article 28(2) and (4) GDPR in order to engage another processor (a sub-processor).
The data processor does not engage another processor (sub-processor) without the prior general written authorization of the data controller.
The data processor has the data controller’s general authorization for the engagement of sub-processors. The data processor informs the data controller in writing of any intended changes concerning the addition or replacement of sub-processors at least thirty (30) days in advance, giving the data controller the opportunity to object. The list of authorized sub-processors is set out in Appendix B.
Where the data processor engages a sub-processor, the same data protection obligations as set out in the Clauses are imposed on that sub-processor by way of a contract or other legal act under EU or Member State law, providing sufficient guarantees that processing meets the requirements of the Clauses and the GDPR.
If the sub-processor does not fulfil its data protection obligations, the data processor remains fully liable to the data controller for fulfilment of the obligations of the sub-processor.
6. Transfer of data to third countries
Any transfer of personal data to third countries or international organizations by the data processor occurs only on the basis of documented instructions from the data controller and always in compliance with Chapter V GDPR.
As set out in Appendix C.5 and C.6, the data controller authorizes transfers to the sub-processors located outside the EEA listed in Appendix B, and to Supplier personnel who may access personal data from outside the EEA in the course of performing their duties. Such transfers rely on the EU-U.S. Data Privacy Framework for certified U.S. recipients and the Standard Contractual Clauses for any other authorized transfer. No other transfers to third countries are authorized unless and until the data controller provides documented instructions to that effect.
If transfers to third countries are required under EU or Member State law to which the data processor is subject, the data processor informs the data controller of that legal requirement prior to processing, unless that law prohibits such information on important grounds of public interest.
The Clauses are not standard data protection clauses within the meaning of Article 46(2)(c) and (d) GDPR, and cannot be relied upon as a transfer tool under Chapter V GDPR.
7. Assistance to the data controller
Taking into account the nature of the processing, the data processor assists the data controller by appropriate technical and organizational measures, insofar as possible, in the fulfilment of the data controller’s obligations to respond to requests for exercising data subjects’ rights laid down in Chapter III GDPR. This includes assistance with the rights to information, access, rectification, erasure, restriction of processing, data portability, objection, and not to be subject to a decision based solely on automated processing.
In addition, the data processor assists the data controller, taking into account the nature of the processing and the information available, in ensuring compliance with the data controller’s obligations relating to notification of personal data breaches to the supervisory authority and to data subjects, to carrying out data protection impact assessments, and to prior consultations with the supervisory authority.
8. Notification of personal data breach
In case of any personal data breach, the data processor notifies the data controller of the personal data breach without undue delay after becoming aware of it.
The data processor’s notification to the data controller takes place, if possible, within 24 hours after the data processor has become aware of the breach, to enable the data controller to comply with its obligation to notify the supervisory authority under Article 33 GDPR.
The data processor assists the data controller in obtaining the information required by Article 33(3) GDPR.
9. Erasure and return of data
On termination of the provision of personal data processing services, the data processor deletes all personal data processed on behalf of the data controller and certifies to the data controller that it has done so, unless Union or Member State law requires storage of the personal data.
10. Audit and inspection
The data processor makes available to the data controller all information necessary to demonstrate compliance with Article 28 and the Clauses, and allows for and contributes to audits, including inspections, conducted by the data controller or another auditor mandated by the data controller. Procedures for audits are specified in Appendix C.7 and C.8.
The data processor must provide the supervisory authorities, which pursuant to applicable legislation have access to the data controller’s and data processor’s facilities, with access to the data processor’s physical facilities on presentation of appropriate identification.
11. The Parties’ agreement on other terms
The Parties may agree other clauses concerning the provision of the personal data processing service specifying e.g. liability, as long as they do not contradict, directly or indirectly, the Clauses or prejudice the fundamental rights or freedoms of the data subject.
12. Commencement and termination
The Clauses become effective on the date of both Parties’ signature (which coincides with execution of the relevant Agreement).
Both Parties are entitled to require the Clauses renegotiated if changes to the law or inexpediency of the Clauses should give rise to renegotiation.
The Clauses apply for the duration of the provision of personal data processing services. The Clauses cannot be terminated unless other Clauses governing the provision of personal data processing services have been agreed between the Parties.
If the provision of personal data processing services is terminated and the personal data is deleted or returned to the data controller pursuant to Clause 9 and Appendix C.4, the Clauses may be terminated by written notice by either Party.
13. Contact information
The data processor’s contact:
Email: [email protected]
Appendix A — Information about the processing
The Solution is Retail Media Manager (RMM) — a software platform provided as a service. RMM may include modules for (a) webshop and order management; (b) advertiser portals; and (c) marketplace functionality. The Solution itself does not serve advertising impressions, does not track end consumers and does not perform real-time bidding. Ad-serving and ad-operational services, where included, are provided as Professional Services.
Processing activities on behalf of the data controller include:
- Login and authorization
- User support
- Inventory, listing and pricing management
- Booking and order management
- Reporting
- Notifications
A.1 Purpose
The data processor uses the data from the data controller to (i) make the platform available via authentication and authorization mechanisms, (ii) provide customer support, (iii) provide the core functionality of the platform — listing and managing inventory, advertiser bookings and orders, (iv) provide bookings/sales/operational reporting, and (v) provide email and in-platform notifications.
A.2 Nature of the processing
Processing is limited to storage, retrieval, presentation, transmission within the Solution and (for notifications) outbound notification via email. The data processor does not use Customer Data to train machine-learning models for the benefit of any third party. Aggregated, de-identified usage statistics may be used to operate, secure and improve the Solution.
A.3 Types of personal data
Username, email address, name, role, client identifier, organization name, login timestamps, IP address, support correspondence content, booking details (which may include the name and contact details of advertiser/agency representatives provided by the data controller), notification content.
A.4 Categories of data subject
Employees and representatives of the data controller; representatives of advertisers, agencies and other end-users onboarded by the data controller.
A.5 Duration
From commencement of the Clauses until the end of the provision of the Solution, subject to the erasure and return obligations in Clause 9.
Appendix B — Authorized sub-processors
For the current list of authorized sub-processors, please contact [email protected].
The data processor’s notice of any planned addition or replacement of sub-processors must be received by the data controller no later than thirty (30) days before the change takes effect, insofar as possible. If the data controller has objections, the data controller notifies the data processor without undue delay before the change takes effect.
Appendix C — Instructions
C.1 The subject of / instruction for the processing
The processing is carried out in accordance with the relevant Agreement between the Parties and comprises the Processing Activities described in Appendix A.
C.2 Security of processing
The data processor implements appropriate security measures, including encryption in transit (TLS 1.2+), encryption at rest (AES-256 or equivalent for personal data in production databases and backups), role-based access control with least-privilege and multi-factor authentication for administrative access, audit logging retained for at least 12 months, regular backups encrypted and tested, vulnerability management with annual external penetration testing, target RTO/RPO of 24 hours, written confidentiality obligations and security training for personnel, and EU hosting of personal data.
C.3 Assistance to the data controller
The data processor assists the data controller as set out in Clauses 7 and 8.
C.4 Storage period / erasure
Upon termination, personal data is deleted or returned in accordance with Clause 9. Where the Parties have agreed transition assistance, deletion is postponed for the duration of the agreed transition period (not exceeding three months), and personal data is processed during that period solely for transition purposes.
C.5 Processing location
Personal data is hosted within the European Economic Area. Limited processing of personal data takes place by:
- approved sub-processors located outside the EEA (as listed in Appendix B); and
- Supplier personnel who may access personal data from outside the EEA in the course of performing their duties (for example during travel, or where Supplier engages personnel located outside the EEA). Such access is subject to written confidentiality obligations and, where applicable, the Standard Contractual Clauses or other valid transfer mechanism under Chapter V GDPR.
Such transfers rely on a valid transfer mechanism under Chapter V GDPR, including the EU-U.S. Data Privacy Framework for transfers to certified U.S. recipients, and the Standard Contractual Clauses under Article 46(2)(c) for any other transfer authorized by the data controller.
C.6 Transfer of personal data to third countries
Personal data may be transferred outside the European Economic Area in the ordinary course of providing the Services, to the extent set out in Appendix C.5. Such transfers rely on the EU-U.S. Data Privacy Framework for certified U.S. recipients and the Standard Contractual Clauses for any other authorized transfer. If the European Commission completes new Standard Contractual Clauses, the data processor is authorized to use the Standard Contractual Clauses in force from time to time.
C.7 / C.8 Audit procedures
The data controller may carry out audits by way of self-monitoring (questionnaires and review of documentation including risk assessment, IT security policy and contingency plans) or by written supervision / physical inspection at dates agreed with the data processor. The data processor regularly audits its sub-processors using a risk-based approach.
Appendix D — Other subjects
None, unless added by the Parties.
Changelog
- v1.0 — 2026-05-28 — Initial publication.
