Last Updated: July 2, 2026


This Data Processing Addendum, including its Schedules (“DPA”) is a part of the Rippling Customer Terms of Service Agreement (and are hereby incorporated into the Rippling Customer Terms of Service Agreement by reference), available at https://app.rippling.com/legal. Capitalized terms used but not otherwise defined in the DPA will have the meanings set forth in the Customer Terms of Service Agreement. Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name of and on behalf of its Authorized Affiliates, if and to the extent Rippling processes Customer Personal Data for which such Authorized Affiliates qualify as the Controller. For the purposes of this DPA, and except where indicated otherwise, the term “Customer” will include Customer and Authorized Affiliates. “Rippling” refers to Rippling and its Affiliates. Rippling and Customer are each a “Party” and together are the “Parties.” All terms of the Rippling Customer Terms of Service Agreement, including all disclaimers, limitations of liability, agreements and indemnities (collectively, to the extent any of the foregoing is applicable, the “Agreement”), apply to this DPA. In the event of any conflict between the Customer Terms of Service Agreement and this DPA, this DPA will govern.

1. Definitions

1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” and its cognates for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.


1.2 “Authorized Affiliate” means any of Customer's Affiliate(s) which (a) is subject to the Data Protection Laws, and (b) is permitted to use the Rippling Services pursuant to the Agreement between Customer and Rippling.


1.3 “Customer Personal Data” means any Customer Data (as defined in the Customer Terms of Service available at https://app.rippling.com/legal) that comprises the categories of Personal Data described in Schedule 1(B)(1)-(2) of this DPA. For the avoidance of doubt, Customer Personal Data excludes information about Users provided to Rippling in connection with the creation or administration of a Rippling Account, as well as Personal Data that Rippling processes for the provision of services as a Controller under the EOR Terms of ServicePEO Terms of Service, and Broker Services Additional Terms


1.4 “Data Protection Laws” means any applicable laws, regulations, or other binding obligations (including any and all legislative and/or regulatory amendments or successors thereto), each as updated from time to time, of the European Union, the EEA, Switzerland, the United Kingdom, the United States, Canada, Australia, Hong Kong, the Philippines, or any other jurisdiction that govern or otherwise apply to Personal Data processed under the Agreement.


1.5 “FADP” means the Swiss Federal Act on Data Protection of 25 September 2020.


1.6 “GDPR” means, to the extent applicable: (i) the European Union Regulation 2016/679 and any relevant implementing measure in each relevant Member State, and (ii) the "UK GDPR" as defined in the UK Data Protection Act of 2018.


1.7 “Personal Data” includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by Data Protection Laws.


1.8 “process” and its cognates “processing”, “processed”, etc. mean any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.


1.9 “Security Incident” means any accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.


1.10 “Standard Contractual Clauses” ("SCCs") refers to any and all of the following:

(a) The “EU SCCs” means the SCCs issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as set forth herein.


(b) The “UK Addendum” means the United Kingdom International Data Transfer Addendum to the EU Commission SCCs, located at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf and completed as set forth herein.

(c) The “Guernsey Addendum” means the Bailiwick of Guernsey (“Guernsey”) Addendum to the EU SCCs available at https://www.odpa.gg/guidance/transferring-peoples-data-outside-bailiwick and completed as set forth herein.

(d) The “Jersey Addendum” means the Bailiwick of Jersey (“Jersey”) Addendum to the EU SCCs located at https://jerseyoic.org/media/guidance-downloads/bailiwick-of-jersey-addendum-scc.pdf and completed as set forth herein.


(e) The “ADGM Addendum” means the Abu Dhabi Global Market Approved Addendum, being the template Addendum 1.0 issued by the Commissioner in accordance with Section 49(2)(j) of the DPR 2021 on 1 Nov 2023, as it may be revised under Section ‎‎17 of those Mandatory Clauses, located at https://www.adgm.com/operating-in-adgm/office-of-data-protection/guidance#addendum-to-the-eu-standard-contractual-clauses and completed as set forth herein.


(f) The “DIFC SCCs” means the SCCs for Compliance with Article 27 DIFC Law No 5 of 2020, located at https://www.difc.ae/business/registrars-and-commissioners/commissioner-of-data-protection/data-export-and-sharing and completed as set forth herein.


(g) The  “Turkish SCCs” means the SCCs issued in accordance with the guidelines and regulations of the Turkish Data Protection Authority ("Turkish Authority") under the Turkish Data Protection Law No. 6698, as updated or amended, and decision no. 2024/959 and dated 4/6/2024 held by the Turkish Authority for the transfer of personal data to third countries or international organizations, available at https://www.kvkk.gov.tr/Icerik/7991/Standard-Contracts and completed as set forth herein.


(h) The “Brazilian SCCs” means the SCCs approved by the Resolution CD/ANPD No. 19, August 23, 2024, available at https://www.in.gov.br/en/web/dou/-/resolucao-cd/anpd-n-19-de-23-de-agosto-de-2024-580095396 and completed as set forth herein. 


1.11 “Sub-processor” means any third-party that Rippling engages to process Customer Personal Data.


1.12 “Supervisory Authority” means an independent public authority which is established by an EU Member State, UK or Switzerland, or in other applicable jurisdictions pursuant to Data Protection Laws.


1.13 The terms “Business”, “Consumer”, “Controller”, “Data Subject”, “Processor”, and “Service Provider” have the meanings given to them in Data Protection Laws, or, where not specifically defined, the meanings of analogous terms under Data Protection Laws. For the avoidance of doubt, “Controller” is deemed to also refer to “Business”, and “Processor” is deemed to also refer to “Service Provider”. “Data Subject” is deemed to include “Consumer”.

2. Data Processing

2.1 Scope. This DPA applies when and to the extent Customer Personal Data is processed by Rippling in connection with the provision of the Services to the Customer under the Agreement. For the avoidance of doubt, this DPA does not apply to Personal Data that Rippling processes for the provision of services as a Controller under the Rippling EOR Terms of ServicePEO Terms of Service, and Broker Services Additional Terms.


2.2 Role of the Parties. With regard to the processing of Customer Personal Data, Rippling acts as a Processor on behalf of Customer, which may act either as a Controller or a Processor. Rippling or its Affiliates may engage Sub-processors pursuant to the requirements set out in this DPA.


2.3 Compliance with Laws. Each Party will comply with all laws, rules and regulations applicable to it and binding on it in the performance of this DPA, including Data Protection Laws.


2.4 Details of Processing. The subject matter of processing of Customer Personal Data under this DPA is the performance of the Rippling Services pursuant to this Agreement. The duration of the processing, the nature and purpose of the processing, the types of Personal Data and categories of Data Subjects processed under this DPA are further specified in Schedule 1 to this DPA.


2.5 Instructions for Processing. Rippling will process Customer Personal Data on behalf of and only in accordance with Customer's documented instructions regarding Rippling’s processing of Customer Personal Data as follows: (a) processing in accordance with the Agreement and applicable Order Form(s); (b) processing initiated by Users as authorized by Customers in the use of the Rippling Services; and (c) processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement. Customer authorizes Rippling to transfer Customer Personal Data identifying an individual User (e.g. personal email, personal address) to a subsequent employer of that User, to the extent the subsequent employer is a Rippling customer, and provided that such Customer Personal Data does not contain elements identifying the Customer. 


2.6 Rippling’s Obligations. Rippling will:


(a) inform Customer immediately if (i) in its opinion, an instruction from Customer violates Data Protection Laws and/or (ii) Rippling is unable to comply with Data Protection Laws or Customer’s instructions for the processing of Customer Personal Data; 


(b) not “sell” or “share” Customer Personal Data, or process Customer Personal Data for purposes of targeted advertising, as such terms are defined under Data Protection Laws;


(c) not retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and Rippling or as permitted by Data Protection Laws; and


(d) treat Customer Personal Data as Confidential Information under the Agreement. If a governmental body sends Rippling a demand for Customer Personal Data, Rippling will attempt to redirect the governmental body to request that data directly from Customer. As part of this effort, Rippling may provide Customer’s basic contact information to the governmental body. If compelled to disclose Customer Personal Data to a governmental body, then Rippling will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless Rippling is legally prohibited from doing so.


2.7 Third-Party Disclosures Comprising Part of Our Services. Customer acknowledges that, as part of the provision of the Rippling Services, Rippling will disclose Customer Personal Data to certain third-party vendors acting as Controllers (including professional advisers such as lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance and accounting services). 


2.8 Customer Rights. Customer retains the right, upon reasonable notice to Rippling, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

3. Rippling Personnel and Data Protection Officer 

3.1 Rippling Personnel. Rippling will ensure that its personnel engaged in the processing of Customer Personal Data are informed of the confidential nature of the Customer Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements. Rippling will also: (a) take commercially reasonable steps to ensure the reliability of any Rippling personnel engaged in the processing of Customer Personal Data; and (b) ensure that Rippling's access to Customer Personal Data is limited to those personnel performing Rippling Services in accordance with the Agreement.


3.2 Data Protection Officer. Rippling has appointed a data protection officer for certain jurisdictions. The appointed person may be reached at privacy@rippling.com

4. Customer Responsibilities

Customer will, in its use of the Rippling Services, process Customer Personal Data in accordance with the requirements of Data Protection Laws, including any applicable requirement to provide notice to Data Subjects of the use of Rippling as Processor. For the avoidance of doubt, Customer's instructions for the processing of Customer Personal Data will comply with Data Protection Laws. Customer will have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data. Customer specifically acknowledges and agrees that its use of the Rippling Services will not violate the rights of any Data Subject, including those that have opted-out from sales or other disclosures of Customer Personal Data, to the extent applicable under the Data Protection Laws. 

5. Assistance to Customer

5.1 Data Subject Requests. Rippling will, to the extent legally permitted, promptly notify Customer of any complaint or request it receives from a Data Subject with respect to the processing of their Personal Data covered by this DPA (each such request being a “Data Subject Request”). Customer authorizes on its behalf, and on behalf of its Controllers when Customer is acting as a Processor, Rippling to respond to any Data Subject who makes a Data Subject Request to Rippling, to confirm that Rippling has forwarded the request to Customer. To the extent Customer, in its use of the Rippling Services, does not have the ability to address a Data Subject Request, Rippling will upon Customer's request provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request, to the extent Rippling is legally permitted to do so and the response to such Data Subject Request is required under Data Protection Laws. To the extent legally permitted, Customer will be responsible for any costs arising from Rippling's provision of such assistance.


5.2 DPIAs and Consultations with Authorities. Customer agrees that Rippling’s then-current SOC 1 and SOC 2 audit reports (or comparable industry-standard successor reports) and/or Rippling’s ISO 27001 and ISO 27018 Certifications available at trust.rippling.com will be used by Customer to carry out its data protection impact assessments (“DPIAs”) and prior consultations. To the extent Customer requires additional assistance to meet its obligations under Articles 35 and 36 of the GDPR to carry out a DPIA and prior consultation with the competent Supervisory Authority related to Customer’s use of the Service, Rippling will, taking into account the nature of processing and the information available to Rippling, provide reasonable assistance to Customer. 

6. Sub-processors

6.1 Appointment of Sub-processors. Customer acknowledges and agrees that Rippling may engage Sub-processors in connection with the provision of the Rippling Services. Rippling will enter into a written agreement with each Sub-processor containing data protection obligations not less protective than those in this DPA to the extent applicable to the nature of the Rippling Services provided by such Sub-processor.


6.2 Sub-processor Lists. The current list of Sub-processors for the Rippling Services can be found on Rippling's Security and Trust Center webpage at trust.rippling.com. Customer may subscribe to notifications of new Sub-processors by emailing privacy@rippling.com.


6.3 Objecting to New Sub-processors. Customer may object to Rippling's use of a new Sub-processor by notifying Rippling promptly in writing within thirty (30) days after being notified of a new Sub-processor. In the event Customer objects to a new Sub-processor, Rippling will use commercially reasonable efforts to make available to Customer a change in the Rippling Services or recommend a commercially reasonable change to Customer's configuration or use of the Rippling Services to avoid processing of Customer Personal Data by the objected-to Sub-processor without unreasonably burdening Customer. If Rippling is unable to make available such change within thirty (30) days, Customer may, via written notice to Rippling, terminate the applicable Order Form(s) with respect only to those Rippling Services which cannot be provided by Rippling without the use of the objected-to Sub-processor.


6.4 Liability. Rippling will be liable for the acts and omissions of its Sub-processors to the same extent Rippling would be liable if performing the services of each Sub-processor directly under the terms of this DPA, except as otherwise set forth in the Agreement.

7. Security

7.1 Controls for the Protection of Customer Personal Data. Rippling has implemented and will maintain the technical and organizational measures outlined in Schedule 2 to this DPA to protect the confidentiality and integrity of Customer Personal Data, and to protect Customer Personal Data against Security Incidents. Rippling may update or change these measures from time to time, but will not materially decrease the overall security of the Rippling Services during a Subscription Term. Customer is solely responsible for making an independent determination as to whether the technical and organizational measures set forth in this DPA meet Customer’s requirements.


7.2 Third-Party Certifications and Audits. Rippling uses external auditors to verify the adequacy of its security measures, and has obtained the third-party certifications and audits set forth in Schedule 2 of this DPA. Upon Customer's written request at reasonable intervals, and subject to the confidentiality obligations set forth in the Agreement, Rippling will make available to Customer that is not a competitor of Rippling (or Customer's independent, third-party auditor that is not a competitor of Rippling) a copy of Rippling's then most recent third-party audits or certifications, as applicable.


7.3 Audit and Reasonable Exercise of Rights. Customer agrees that Rippling’s then-current SOC 1 and SOC 2 audit reports (or comparable industry-standard successor reports) and/or Rippling’s ISO 27001 and ISO 27018 Certifications will be used to satisfy any audit or inspection requests by or on behalf of Customer, and Rippling will make such reports available to Customer. In the event that Customer, a regulator, or a Supervisory Authority requires additional information, including information necessary to demonstrate compliance with this DPA, or an audit related to the Service, such information and/or audit will be made available, provided that any such on-site audit of Rippling’s processing activities covered by this DPA (“On-Site Audit”) may only be conducted when: (i) the information available pursuant to Section 7.2 is not sufficient to demonstrate compliance with the obligations set out in this DPA; (ii) Customer has received a notice from Rippling of a Security Incident; or (iii) such an audit is required by Data Protection Laws or by Customer’s competent Supervisory Authority. Any On-Site Audits will be limited to Customer Personal Data processing and storage facilities operated by Rippling or any of Rippling’s Affiliates. Customer acknowledges that Rippling operates a multi-tenant cloud environment. Accordingly, Rippling will have the right to reasonably adapt the scope of any On-Site Audit to avoid or mitigate risks with respect to, and including, service levels, availability, and confidentiality of other Rippling customers’ information. An On-Site Audit will be conducted by Customer: (a) acting reasonably, in good faith, and in a proportional manner, taking into account the nature and complexity of the Rippling Services used by Customer; (b) up to one (1) time per year with at least four (4) weeks’ advance written notice. If an emergency justifies a shorter notice period, Rippling will use good faith efforts to accommodate the On-Site Audit request; and (c) during Rippling’s normal business hours, under reasonable duration and without unreasonably interfering with Rippling’s day-to-day operations. An On-Site Audit can be conducted through a third-party independent contractor that is not a competitor of Rippling (“Third-Party Auditor”) if, prior to the On-Site Audit, the Third-Party Auditor enters into a non-disclosure agreement containing confidentiality provisions no less protective than those set forth in the Agreement to protect Rippling’s proprietary information, and the costs of the Third-Party Auditor are at Customer’s expense. Before any On-Site Audit commences, Customer and Rippling will mutually agree upon the scope, timing, and duration of the audit and the reimbursement rate for which Customer will be responsible. All reimbursement rates will be reasonable, taking into account the resources expended by or on behalf of Rippling. Customer must promptly provide Rippling with information regarding any actual or suspected non-compliance discovered during the course of an On-Site Audit.

8. Security Incident Management

8.1 Notification. Rippling will notify Customer without undue delay after becoming aware of a Security Incident. Rippling will make reasonable efforts to identify the cause of such Security Incident and take those steps as Rippling deems necessary and reasonable in order to remediate the cause of such a Security Incident to the extent the remediation is within Rippling's reasonable control. The obligations herein will not apply to Security Incidents that are caused by Customer or Customer's Users.


8.2 Assistance. To enable Customer to notify a Security Incident to Supervisory Authorities or Data Subjects (as applicable), Rippling will cooperate with and assist Customer by including in the notification under Section 8.1 such information about the Security Incident as Rippling is able to disclose to Customer, taking into account the nature of the processing, the information available to Rippling, and any restrictions on disclosing the information, such as confidentiality. 

9. Return and Deletion of Customer Personal Data

Upon Customer's request on or prior to termination of the Agreement, Rippling will reasonably cooperate with Customer to facilitate an export of such Customer Personal Data from Rippling's systems and thereafter may delete any and all remaining Customer Personal Data from the same, unless further preservation is required or otherwise prohibited by law.

10. Data Transfers

10.1 Cross-border Transfers. Customer acknowledges that the Rippling Services may involve cross-border transfers of Customer Personal Data. Rippling will comply with Data Protection Laws if it engages in any cross-border processing of Customer Personal Data, or transmits any Customer Personal Data to any country outside of the country from which such Customer Personal Data was provided to it. To the extent required by Data Protection Laws, Rippling will ensure that a lawful data transfer mechanism is in place prior to engaging in any onward transfers of Customer Personal Data from one country to another and, to the extent that they apply to the transfer, the specific jurisdiction’s provisions set forth in Schedule 3.


10.2 Transfers from the EEA. To the extent legally required, by entering into this DPA, the Parties are deemed to have signed the EU SCCs, which form part of this DPA and are deemed completed as follows:


10.2.1 Module 2 of the EU SCCs applies to transfers of Customer Personal Data from Customer (as a Controller) to Rippling (as a Processor), and Module 3 of the EU SCCs applies to transfers of Customer Personal Data from Customer (as a Processor) to Rippling (as a Sub-processor).


10.2.2 Clause 7 (the optional docking clause) is not included.


10.2.3 Clause 9 (Use of sub-processors): The Parties select Option 2 (General written authorization). The initial list of Sub-processors is available to Customer, and Rippling will propose an update to that list, as set forth in Section 6.2 of this DPA. The Parties agree that any objections to new Sub-processors shall be handled as set forth in Section 6.3 of this DPA.


10.2.4 Clause 11 (Redress): The optional language requiring that Data Subjects be permitted to lodge a complaint with an independent dispute resolution body is not included.


10.2.5 Clause 17 (Governing law): The Parties choose Option 1 (the law of an EU Member State that allows for third-party beneficiary rights) and select the law of the Republic of Ireland.


10.2.6 Clause 18 (Choice of forum and jurisdiction): The Parties select the courts of the Republic of Ireland.


10.2.7 Annex I (List of Parties) of the EU SCCs shall be deemed completed with the information set out in Schedule 1 of this DPA.


10.2.8 Annex II (Technical and organizational measures) of the EU SCCs shall be deemed completed with the information set out in Schedule 2 of this DPA.


10.2.9 Annex III (List of sub-processors) is not applicable because the Parties have chosen General Authorization under Clause 9.


10.3 Transfers from the UK. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the UK Addendum, which forms part of this DPA and takes precedence over the rest of this DPA as set forth in the UK Addendum. The Tables within the UK Addendum are deemed completed as follows:


10.3.1 Table 1: The Parties’ details will be the Parties and their affiliates to the extent any of them is involved in such transfer, and the Key Contact will be the contacts set forth in Schedule 1 of this DPA.


10.3.2 Table 2: The Approved EU SCCs referenced in Table 2 will be the EU SCCs as executed by the Parties and completed in Section 10.2 of this DPA.


10.3.3 Table 3: Annexes I and II are set forth in Schedules 1 and 2 of this DPA. Annex III is inapplicable.


10.3.4 Table 4: Neither Party may end this DPA as set out in Section 19 of the UK Addendum.


10.4. Transfers from Guernsey. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the Guernsey Addendum, which forms part of this DPA and takes precedence over the rest of this DPA as set forth in the Guernsey Addendum.

10.5. Transfers from Jersey. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the Jersey Addendum, which forms part of this DPA and takes precedence over the rest of this DPA as set forth in the Jersey Addendum.

10.6. Transfers from Switzerland. For transfers of Customer Personal Data that are subject to the FADP, the EU SCCs form part of this DPA as set forth in Section 10.2 of this DPA, but with the following differences to the extent required by the FADP:


10.6.1 References to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR, and references to personal data in the EU SCCs also refer to data about identifiable legal entities until the entry into force of FADP revisions that eliminate this broader scope.


10.6.2 The term “member state” in EU SCCs will not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs.


10.6.3 The relevant Supervisory Authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the Supervisory Authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).


10.7 Transfers from the ADGM. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the ADGM Addendum, which forms part of this DPA and takes precedence over the rest of this DPA as set forth in the ADGM Addendum. The Tables within the ADGM Addendum are deemed completed as follows:


10.7.1 Table 1: The Parties’ details will be the Parties and their affiliates to the extent any of them is involved in such transfer, and the Key Contact will be the contacts set forth in Schedule 1 of this DPA.


10.7.2 Table 2: The Approved EU SCCs referenced in Table 2 will be the EU SCCs as executed by the Parties and completed in Section 10.2 of this DPA.


10.7.3 Table 3: Annexes I and II are set forth in Schedules 1 and 2 of this DPA. Annex III is inapplicable.


10.7.4 Table 4: Either Party may end this DPA as set out in Section 19 of the ADGM Addendum.


10.8 Transfers from the DIFC. As set out in Section 10.2 of this DPA regarding transfers of Customer Personal Data to a jurisdiction outside of the DIFC that is not yet considered adequate by the DIFC Commissioner of Data Protection or relevant Supervisory Authority, the DIFC SCCs are deemed to be appended to this DPA. Annexes I and II within the DIFC SCCs are deemed completed as set forth in Schedules 1 and 2 of this DPA, and Annex III is inapplicable.


10.9 Transfers from Turkey. To the extent legally required, by entering into this DPA, the Parties are deemed to have agreed to comply with the Turkish SCCs, which form part of this DPA and take precedence over the rest of this DPA as set forth in the Turkish SCCs. The Turkish SCCs are deemed completed as follows:


10.9.1 The Standard Contract for the Transfer of Personal Data Abroad - 2 (Controller to Processor) applies to transfers of Customer Personal Data from Customer (as a Controller) to Rippling (as a Processor), and the Standard Contract for the Transfer of Personal Data Abroad - 3 (Processor to Processor) applies to transfers of Customer Personal Data from Customer (as a Processor) to Rippling (as a Sub-processor).


10.9.2 Clause 8 (Sub-Processors): The Parties select Option 2 (General written authorization). The initial list of Sub-processors is available to Customer, and Rippling will propose an update to that list, as set forth in Section 6.2 of this DPA.  The Parties agree that any objections to new Sub-processors shall be handled as set forth in Section 6.3 of this DPA.


10.9.3 Clause 10 (Redress): The optional language requiring that Data Subjects be permitted to lodge a complaint with an independent dispute resolution body is not included.


10.9.4 Clause 16 (Notification of the Contract to Authority): The Parties agree that Customer will be responsible for notifying the Turkish Authority of use of the Turkish SCCs within five (5) business days following the finalization of all signatures.


10.9.5 Annex I (List of Parties) of the Turkish SCCs shall be deemed completed with the information set out in Schedule 1 of this DPA.


10.9.6 Annex II (Technical and organizational measures) of the Turkish SCCs shall be deemed completed with the information set out in Schedule 2 of this DPA.


10.9.7 Annex III (List of sub-processors) is not applicable because the Parties have chosen General Authorization under Clause 8.


10.10 Transfers from Brazil. To the extent legally required, by entering into this DPA, the Parties are deemed to have agreed to comply with the Brazilian SCCs, which form part of this DPA and take precedence over the rest of this DPA as set forth in the Brazilian SCCs. The Brazilian SCCs are deemed completed as follows:


10.10.1 Clause 1: The Parties shall be Exporter and Importer, as appropriate, with the respective details set out in Schedule 1 of this DPA.


10.10.2 Clause 2 of the Brazilian SCCs shall be deemed completed with the information set out in Schedule 1 of this DPA. 


10.10.3 Clause 3: The Parties select Option A.


10.10.4 Clause 4: For transfers of Customer Personal Data from Customer (as a Controller) to Rippling (as a Processor), the Parties select Option A, and the Parties agree that, except as otherwise provided for under the DPA, Customer is responsible for the compliance obligations addressed in Clauses 4.1(a)-(c) of the Brazilian SCCs. For transfers of Customer Personal Data from Customer (as a Processor) to Rippling (as a Sub-processor), the Parties select Option B, and Customer is responsible for making a list of applicable Controllers available to Rippling.


10.10.5 Schedule III of the Brazilian SCCs shall be deemed completed with the information set out in Schedule 2 of this DPA.

11. Authorized Affiliates

11.1 Contractual Relationship. The Parties acknowledge and agree that, by executing the Agreement, Customer enters into the DPA on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates, thereby establishing a separate DPA between Rippling and each such Authorized Affiliate subject to the provisions of the Agreement and this Section 11 and Section 12. Each Authorized Affiliate agrees to be bound by the obligations under this DPA and, to the extent applicable, the Agreement. For the avoidance of doubt, an Authorized Affiliate is not and does not become a party to the Agreement, and is only a party to the DPA. All access to and use of the Rippling Services and Content by Authorized Affiliates must comply with the terms and conditions of the Agreement and any violation of the terms and conditions of the Agreement by an Authorized Affiliate will be deemed a violation by Customer.


11.2 Communication. The Customer that is the contracting party to the Agreement will remain responsible for coordinating all communication with Rippling under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Authorized Affiliates.


11.3 Rights of Authorized Affiliates. Where an Authorized Affiliate becomes a party to the DPA with Rippling, it will to the extent required under applicable Data Protection Laws be entitled to exercise the rights and seek remedies under this DPA, subject to the following:


11.3.1 Except where applicable Data Protection Laws require the Authorized Affiliate to exercise a right or seek any remedy under this DPA against Rippling directly by itself, the Parties agree that (i) solely the Customer that is the contracting party to the Agreement will exercise any such right or seek any such remedy on behalf of the Authorized Affiliate, and (ii) the Customer that is the contracting party to the Agreement will exercise any such rights under this DPA not for each Authorized Affiliate individually, but in a combined manner for itself and all of its Authorized Affiliates together.


11.3.2 The Parties agree that the Customer that is the contracting party to the Agreement will, when carrying out an On-Site Audit of the procedures relevant to the protection of Customer Personal Data, take all reasonable measures to limit any impact on Rippling and its Sub-Processors by combining, to the extent reasonably possible, several audit requests carried out on behalf of itself and all of its Authorized Affiliates in one single audit.

12. Limitation of Liability

To the extent permitted by Data Protection Laws, each Party's and all of its Affiliates' liability, taken together in the aggregate, arising out of or related to this DPA, and all DPAs between Authorized Affiliates and Rippling, whether in contract, tort or under any other theory of liability, is subject to the Limitation of Liability section of the Rippling Customer Terms of Service Agreement, and any reference in such section to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and all DPAs together. For the avoidance of doubt, Rippling's and its Affiliates' total liability for all claims from Customer and all of its Authorized Affiliates arising out of or related to the Agreement and all DPAs will apply in the aggregate for all claims under both the Agreement and all DPAs established under this Agreement, including by Customer and all Authorized Affiliates, and, in particular, will not be understood to apply individually and severally to Customer and/or to any Authorized Affiliate that is a contractual party to any such DPA.


SCHEDULE 1

ANNEX I TO THE EU SCCS: DESCRIPTION OF THE TRANSFER AND PROCESSING

 

A. LIST OF PARTIES


Data exporter(s)


Data importer(s)


B. DESCRIPTION OF THE TRANSFER AND PROCESSING


  1. Categories of Data Subjects: Customer Personal Data relating to the following categories of Data Subjects, without limitation:


  1. Categories of personal data: The Customer determines and controls the extent and types of Customer Personal Data it submits to or makes accessible through the Rippling Services. Depending on the nature of the Rippling Services used by the Customer, Customer Personal Data may include: 


  1. Sensitive data transferred and processed and applied restrictions or safeguards: Customer Personal Data may include personal data revealing racial or ethnic origin, gender identity, sexual orientation, political opinions or philosophical beliefs, or trade-union membership, the processing of biometric data, and health-related data (e.g., health insurance benefits and claims information, including family status and information about dependents), and data from which membership in a protected group may be inferred (e.g., meal preferences, assisted services requests, or accessibility accommodations), for the purpose of effectuating the Rippling Services as directed by Customer. 


The applicable security measures are outlined in Schedule 2 to this DPA as updated from time to time, or as otherwise made reasonably available by Rippling.


  1. The frequency of the transfer and processing: Continuous basis depending on the use of the Rippling Services by Customer.


  1. Nature of the processing: The nature of processing of Customer Personal Data by data importer is the performance of the Rippling Services pursuant to the Agreement or an applicable Order Form.


  1. Purpose(s) of the transfer and further processing: The purpose of the transfer to Rippling and processing of Customer Personal Data by Rippling is Rippling’s performance of the Rippling Services pursuant to the Agreement or an applicable Order Form, or as further instructed by Customer in its use of the Rippling Services. In particular, Rippling will process Customer Personal Data to:


  1. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Subject to Section 9 of the DPA, Rippling will process Customer Personal Data for as long as necessary to perform the Rippling Services pursuant to the Customer Terms of Service Agreement or an applicable Order Form.


  1. For transfers to (sub-)processors, also specify the subject matter, nature and duration of the processing: The subject matter, nature, and duration of the processing for any transfers to Sub-processors are the same as those above for transfers to Rippling. 


C. COMPETENT SUPERVISORY AUTHORITY


To the extent legally permissible, the competent Supervisory Authority is the Irish Data Protection Commission.

SCHEDULE 2

ANNEX II TO THE EU SCCS: TECHNICAL AND ORGANIZATIONAL MEASURES


Rippling maintains an information security program designed to (a) secure Customer Personal Data against accidental or unlawful loss, access, or disclosure, (b) identify reasonably foreseeable risks to the security and availability of the Rippling Services, and (c) minimize physical and logical security risks to the Rippling Services, including through regular risk assessment and testing.  Rippling will designate one or more employees to coordinate and be accountable for the information security program. 


Rippling’s information security program includes the measures outlined here.


SCHEDULE 3

ADDITIONAL PROVISIONS FOR CERTAIN JURISDICTIONS


To the extent that Data Protections Laws apply to transfers of Customer Personal Data by Customers in any jurisdiction listed in this Schedule 3, the specific jurisdiction provisions of the relevant jurisdiction will also apply.


1. Canada    


(a) If Customer Personal Data originating in Quebec is accessed, stored, transferred or otherwise processed by Rippling outside of Quebec, Rippling will take reasonable steps to ensure that the Customer Personal Data receives adequate protection in accordance with applicable Data Protection Laws and that any transfer to a third-party is subject to a written agreement containing data protection obligations no less protective than those contained in this DPA, unless otherwise permitted by law. 


(b) Upon request by Customer, Rippling will provide Customer with information about the jurisdictions in which Customer Personal Data is accessed, stored, transferred or otherwise processed by Rippling, to the extent such information is reasonably available and necessary for Customer to comply with applicable Data Protection Laws or to respond to a request by a competent Supervisory Authority.


2. Israel


(a) For the avoidance of doubt, “Data Protection Laws” includes the Protection of Privacy Law 1981 including all regulations thereunder, including, but not limited to, Privacy Protection Regulations (Data Security), 5777-2017, and the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, as amended from time to time.


(b) The Parties agree that Customer will collect all consents from Data Subjects required by Data Protection Laws, and as required for the processing of Customer Personal Data under the DPA, including without limitation for the transfer of the Customer Personal Data outside of Israel.


(c) Rippling will: 


(i) take sufficient steps to ensure the privacy of the Data Subjects whose Personal Data is processed pursuant to this DPA; 


(ii) apply adequate data security requirements to applicable Customer Personal Data in accordance with Schedule 2


(iii) logically segregate the Customer Personal Data from information obtained from unaffiliated third-parties or information obtained for other purposes; 


(iv) appoint an officer responsible for data security; 


(v) periodically audit and make reports to Customer with respect to Customer Personal Data processing activities and compliance with this DPA upon Customer request and in accordance with Section 7.2


(vi) coordinate and permit periodic audits by the Customer (or a mutually agreed upon third-party who will execute a confidentiality agreement) in accordance with Section 7.3


(vii) conduct reasonable background checks for personnel with access to Customer Personal Data in accordance with Schedule 2; and


(viii) destroy or return Customer Personal Data in its possession in accordance with Section 9.


3. Japan


(a) Rippling will not process Customer Personal Data for purposes other than those specified in Schedule 1 (for the purpose of this section, the “Permitted Purposes”) without the prior written consent of Customer. Customer represents that it has notified all applicable Data Subjects of the Permitted Purposes to the extent required by Data Protection Laws.


(b) The Parties agree that Customer will collect all consents from Data Subjects required by Data Protection Laws, including without limitation for (1) the collection of any “Sensitive Personal Information” (as defined by Data Protection Laws) and (2) any disclosures of Customer Personal Data made by Rippling to third-parties, subject to Clause 4(g) below.


(c) Rippling will keep Customer Personal Data accurate and up-to-date within the scope necessary for the Permitted Purposes, and may delete it in accordance with Section 9.


(d) To the extent required by Data Protection Laws, upon request of the Data Subject, Rippling will disclose to the Data Subject information about its processing of the Data Subject’s Customer Personal Data required under Data Protection Laws, including (i) the contents of Customer Personal Data; (ii) the purpose for use of Customer Personal Data; (iii) the process for responding to a request from the Data Subject in relation to Customer Personal Data; and (iv) the contact information Data Subjects may use to submit questions or complaints about Rippling’s handling of Customer Personal Data, or a statement that it has determined it is not required to do so.


(e) Rippling will report to Customer, upon Customer's request, by a method specified by Customer such as in writing, the status of Rippling's compliance with its obligations under this DPA, and the existence and details of any processing that may affect Rippling's compliance with its obligations under this DPA.


(f) To the extent required by Data Protection Laws, if the Data Subject has shown that Rippling is using or has used such Customer Personal Data other than in compliance with all applicable laws or the Permitted Purposes, or such Customer Personal Data was acquired by improper means, upon Customer’s request, Rippling will delete or stop using the Customer Personal Data. Rippling is not under an obligation to comply with such a request where it would be unreasonably expensive or difficult to do so, and where the Data Subject’s interests can be protected by taking alternative action.


(g) To the extent required by Data Protection Laws, and upon Customer’s request, Rippling will stop disclosing Customer Personal Data to a third-party if the Data Subject has shown that Rippling has disclosed it to a third-party in violation of Data Protection Laws. Rippling is not under an obligation to comply with such a request where it would be unreasonably expensive or difficult to do so, and where the Data Subject’s interests can be protected by taking alternative action.


(h) To the extent required by Data Protection Laws, and upon Customer’s request, Rippling will correct, add, or delete certain Customer Personal Data if the Data Subject has shown that the Customer Personal Data is incorrect.


(i) To the extent required by Data Protection Laws, and upon Customer’s request, Rippling will delete Customer Personal Data, or stop using or disclosing the Customer Personal Data to a third-party, if the Data Subject has shown that (i) the Customer Personal Data is no longer needed for the Permitted Purposes; (ii) a Security Incident has occurred; or (iii) there is a possibility that the rights or legitimate interest of the Data Subject may be harmed.


(j) Where Rippling receives a complaint or request relating to the processing of Customer Personal Data, Rippling will notify and assist the Customer in accordance with Section 5.1 of this DPA.


4. Korea


When processing Customer Personal Data provided by or on behalf of Customer, Rippling will: 


(a) limit access to Customer Personal Data to those personnel who reasonably require such access for the purposes of the processing, and establish and maintain the safeguards contained in Schedule 2 to this DPA, including: (i) internal procedures for secure handling of Customer Personal Data; (ii) measures to prevent illegal access to Customer Personal Data; (iii) measures to prevent falsification or alteration of access logs; (iv) measures to securely store and transmit Customer Personal Data (including use of encryption technology and secure server); (v) installation of intrusion detection software; (vi) the installation and regular updating of antivirus software for monitoring for and responding to intrusions by computer viruses, spyware or other malicious programs; (vii) the establishment and operation of access control procedures with respect to physical storage locations; and (viii) other measures for the protection of Customer Personal Data that may be required under relevant rules and regulations of Data Protection Laws from time to time (as applicable to an overseas transferee of Customer Personal Data); 


(b) not disclose or transfer to any third-party any Customer Personal Data without the consent of the relevant Data Subjects, or otherwise in accordance with applicable Data Protection Laws; 


(c) establish and implement appropriate procedures for (i) the handling of privacy-related complaints and (ii) the resolution of any disputes with Data Subjects; and


(d) be subject to (i) training and supervision by the Customer with respect to Rippling’s handling of the Customer Personal Data, and (ii) supervision and audit by relevant Supervisory Authorities.


5Mexico


(a) For the purposes of this Clause 6 of Schedule 3:

 

(i) “Privacy Notice” means a document in physical, electronic, or any other format, generated by the Controller, that is made available to the Data Subject prior to the processing of their Customer Personal Data, which provides the Data Subject with information regarding what Customer Personal Data is collected about them and for what purposes.


(ii) “Mexican Privacy Laws and Regulations” means the Federal Law on the Protection of Personal Data Held by Private Parties (“Ley Federal de Protección de Datos Personales en Posesión de los Particulares”) and all of its implementing regulations, including the Regulations of the Federal Law on the Protection of Personal Data Held By Private Parties (“Reglamento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares”) and the Privacy Notice Guidelines (“Lineamientos del Aviso de Privacidad”).


(iii) “Third-Party” means a third-party who is not a Processor or a Sub-processor.


(b) To the extent that any Customer acts as a Controller of Customer Personal Data collected within Mexico under this DPA the following provisions apply: 


(i) Rippling will process Customer Personal Data in accordance with the Customer’s Privacy Notice and Mexican Privacy Laws and Regulations. The Customer agrees that any processing of Customer Personal Data by Rippling in accordance with this DPA is deemed to be in accordance with the Customer’s Privacy Notice.


(ii) Rippling may only transfer Customer Personal Data to Third-Parties as necessary to comply with a valid request made by a competent legal authority, or after receiving the written authorization of the Customer to do so. The Customer agrees that, to the extent required, Section 2.7 of this DPA constitutes such written authorization.


(iii) Upon termination or expiration of the Agreement, Rippling will, at Customer's request, cease processing Customer Personal Data. 


(iv) Upon termination or expiration of the Agreement, Rippling will:


    (a) provide Customer with the opportunity to retrieve Customer Personal Data; and


    (b) upon Customer’s request, provide Customer with Customer Personal Data.


6. Singapore


Rippling will not transfer any Customer Personal Data out of Singapore unless the recipient of any such Customer Personal Data provides a written undertaking that such data will be protected at a standard that is comparable to that under the Personal Data Protection Act 2012 of Singapore.


7. South Africa


(a) For the avoidance of doubt, “Data Protection Laws” includes the Protection of Personal Information Act No. 4 of 2013, as amended from time to time, (“POPIA”) including any applicable supplementary legislation, regulations and/or standards, and any replacement, successor, amendment or re-enactment, to or of the foregoing. 


(b) Where Rippling is required to transfer any Customer Personal Data outside of South Africa, Customer will (i) transfer such Customer Personal Data to Rippling in compliance with Section 72 of POPIA and (ii) ensure that any transfer of “Special Personal Information” as defined in POPIA or Personal Data relating to individuals below the age of 18 years contained in the Customer Personal Data is in compliance with Chapter VI of POPIA, which requires prior authorization from the Information Regulator (the Supervisory Authority in South Africa).