Skip to content

Commit e36880c

Browse files
committed
Record new changes of Google Analytics Data Controller Agreement
This version was recorded after extracting from snapshot mongo://contrib/open-terms-archive/snapshots/64d6810858708d77293df126
1 parent 9516579 commit e36880c

File tree

1 file changed

+7
-7
lines changed

1 file changed

+7
-7
lines changed

Google Analytics/Data Controller Agreement.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -326,18 +326,18 @@ The Google End Controllers are: (i) for European Controller Personal Data proces
326326
**5.7 Data Deletion on Termination**. To the extent that:
327327

328328
* (a) Google LLC acts as data importer and Customer acts as data exporter under the Controller SCCs; and
329-
* (b) Customer terminates the Agreement in accordance with Clause 16(c) of the Controller SCCs, then for the purposes of Clause 16(d) of the Controller SCCs, Customer directs Google to delete Controller Personal Data, and, unless European Laws require storage, Google will facilitate such deletion as soon as is reasonably practicable, to the extent such deletion is reasonably possible (taking into account that Google is an independent Controller of such data, as well as the nature and functionality of the Controller Services).
329+
* (b) Customer terminates the Agreement in accordance with Clause 16(c) of the Controller SCCs, then for the purposes of Clause 16(d) of the Controller SCCs, Customer directs Google to delete Controller Personal Data, and, unless European Laws require storage, Google will facilitate such deletion as soon as is reasonably practicable, to the extent such deletion is reasonably possible (taking into account that Google is an independent Controller of such data, as well as the nature and functionality of the Measurement Services).
330330

331331
### 6\. Liability if Controller SCCs Apply.
332332

333333
If Controller SCCs apply under paragraph 5 (Controller SCCs) of this Appendix 1A, then the total combined liability of:
334334

335335
* (a) Google, Google LLC and Google Ireland Limited towards Customer; and
336-
* (b) Customer towards Google, Google LLC and Google Ireland Limited, under or in connection with the Agreement and the Controller SCCs combined will be subject to Section 6 (Liability). Clause 12 of the Controller SCCs will not affect the previous sentence.
336+
* (b) Customer towards Google, Google LLC and Google Ireland Limited, under or in connection with the Agreement and the Controller SCCs combined will be subject to Section 5 (Liability). Clause 12 of the Controller SCCs will not affect the previous sentence.
337337

338338
### 7\. Third-Party Beneficiaries
339339

340-
Where Google LLC and/or Google Ireland Limited are not a party to the Agreement but are a party to the applicable Controller SCCs in accordance with paragraph 5 (Controller SCCs) of this Appendix 1A, Google LLC and/or Google Ireland Limited (as applicable) will be a third-party beneficiary of Section 4.3 (End Controllers), paragraphs 3 (Google End Controllers), 5 (Controller SCCs) and 6 (Liability if Controller SCCs Apply) of this Appendix 1A. To the extent this paragraph 7 (Third-Party Beneficiaries) conflicts or is inconsistent with any other clause in the Agreement, this paragraph 7 (Third-Party Beneficiaries) will apply.
340+
Where Google LLC and/or Google Ireland Limited are not a party to the Agreement but are a party to the applicable Controller SCCs in accordance with paragraph 5 (Controller SCCs) of this Appendix 1A, Google LLC and/or Google Ireland Limited (as applicable) will be a third-party beneficiary of Section 4.4 (End Controllers), paragraphs 3 (Google End Controllers), 5 (Controller SCCs) and 6 (Liability if Controller SCCs Apply) of this Appendix 1A. To the extent this paragraph 7 (Third-Party Beneficiaries) conflicts or is inconsistent with any other clause in the Agreement, this paragraph 7 (Third-Party Beneficiaries) will apply.
341341

342342
### 8\. Precedence
343343

@@ -351,13 +351,13 @@ Where Google LLC and/or Google Ireland Limited are not a party to the Agreement
351351

352352
**1\. Introduction**
353353

354-
Google may offer and Customer may enable certain in-product settings, configurations or other functionality for the Controller Services relating to restricted data processing, as described in supporting documentation available at [business.safety.google/rdp](https://business.safety.google/rdp), as updated from time to time (“**Restricted Data Processing**”). This Appendix 1B reflects the parties’ agreement on the processing of Customer Personal Data and Deidentified Data (as defined below) pursuant to the Agreement in connection with the US State Privacy Laws, and is effective solely to the extent each US State Privacy Law applies.
354+
Google may offer and Customer may enable certain in-product settings, configurations or other functionality for the Measurement Services relating to restricted data processing, as described in supporting documentation available at [business.safety.google/rdp](https://business.safety.google/rdp), as updated from time to time (“**Restricted Data Processing**”). This Appendix 1B reflects the parties’ agreement on the processing of Customer Personal Data and Deidentified Data (as defined below) pursuant to the Agreement in connection with the US State Privacy Laws, and is effective solely to the extent each US State Privacy Law applies.
355355

356356
**2\. Additional Definitions and Interpretation.**
357357

358358
In this Appendix 1B:
359359

360-
* (a) “**Customer Personal Data**” means personal data that is processed by Google on behalf of Customer in Google’s provision of Controller Services.
360+
* (a) “**Customer Personal Data**” means personal data that is processed by Google on behalf of Customer in Google’s provision of Measurement Services.
361361
* (b) “**Deidentified Data**” means data information that is “deidentified” (as that term is defined by the CCPA) and “de-identified data” (as defined by other US State Privacy Laws), when disclosed by one party to the other.
362362
* (c) “**Instructions**” means, collectively, Customer’s instructions to Google to process Customer Personal Data only in accordance with US State Privacy Laws: (a) to provide the RDP Services and any related technical support; (b) as further specified through Customer’s use of the RDP Services (including in the settings and other functionality of such RDP Services) and any related technical support; (c) as documented in the form of the Agreement, including this Appendix 1B; (d) as further documented in any other written instructions given by Customer and acknowledged by Google as constituting instructions for purposes of this Appendix 1B; and (e) to process Customer Personal Data as permitted under US State Privacy Laws for service providers and processors.
363363
* (d) “**RDP Services**” means Controller Services operating under Restricted Data Processing.
@@ -455,7 +455,7 @@ In this Appendix 1B:
455455

456456
**4\. US State Privacy Law Terms**
457457

458-
**4.1 Deidentified Data.** With respect to Customer Personal Data processed with or without Restricted Data Processing enabled, and to the extent that one or more of the US State Privacy Laws applies to the processing of Customer Personal Data, each party will comply with the requirements for processing Deidentified Data set out in the US State Privacy Laws, with respect to any Deidentified Data it receives from the other party pursuant to the Agreement. For purposes of this paragraph 4.1 (Deidentified Data), Customer Personal Data means any personal data that is processed by a party under the Agreement in connection with its provision or use of the Controller Services.
458+
**4.1 Deidentified Data.** With respect to Customer Personal Data processed with or without Restricted Data Processing enabled, and to the extent that one or more of the US State Privacy Laws applies to the processing of Customer Personal Data, each party will comply with the requirements for processing Deidentified Data set out in the US State Privacy Laws, with respect to any Deidentified Data it receives from the other party pursuant to the Agreement. For purposes of this paragraph 4.1 (Deidentified Data), Customer Personal Data means any personal data that is processed by a party under the Agreement in connection with its provision or use of the Measurement Services.
459459

460460
**5.Google’s CCPA Obligations.**
461461

@@ -472,7 +472,7 @@ In this Appendix 1B:
472472

473473
5.2 With respect to Customer Personal Data processed without Restricted Data Processing enabled, and to the extent that CCPA applies to the processing of Customer Personal Data:
474474

475-
* (a) Google will process such Customer Personal Data for the specific purpose of performing the Controller Services, as applicable, as further described in the Agreement and supporting documentation (e.g., help center articles), or as otherwise permitted under the CCPA, and the parties agree that Customer is making such Customer Personal Data available to Google for such purposes;
475+
* (a) Google will process such Customer Personal Data for the specific purpose of performing the Measurement Services, as applicable, as further described in the Agreement and supporting documentation (e.g., help center articles), or as otherwise permitted under the CCPA, and the parties agree that Customer is making such Customer Personal Data available to Google for such purposes;
476476
* (b) Google will allow audits to verify Google’s compliance with its obligations under this Appendix 1B in accordance with paragraph 3.3.3(c) (Customer’s Audit Rights) herein;
477477
* (c) Google will notify Customer if Google makes a determination that it can no longer meet its obligations under the CCPA;
478478
* (d) If Customer reasonably believes that Google is processing Customer Personal Data in an unauthorized manner, Customer has the right to notify Google of such belief via the methods described at [privacy.google.com/businesses/processorsupport](https://privacy.google.com/businesses/processorsupport), and the parties will work together in good faith to remediate the allegedly violative processing activities, if necessary; and

0 commit comments

Comments
 (0)