International Data Transfer Addendum — postal.ID

This addendum describes contractual safeguards for international transfers where required. It is intended to be attached to the DPA / MSA.

1

1. DIFC data exports

Transfers of Personal Data from the DIFC to a recipient outside the DIFC will be handled in accordance with DIFC Data Protection Law requirements, including adequacy or appropriate safeguards.

2

2. EU/EEA transfers (GDPR)

Where EU/EEA personal data is transferred to a non-adequate country, the parties may incorporate:

  • the EU Standard Contractual Clauses (SCCs) (2021/914), module(s) appropriate to the transfer.
3

3. UK transfers (UK GDPR)

Where UK personal data is transferred to a non-adequate country, the parties may incorporate:

  • the UK International Data Transfer Agreement (IDTA), or
  • the EU SCCs plus the UK Addendum.
4

4. Transfer Impact Assessment (TIA)

Where required, parties will conduct and document a transfer risk assessment and implement supplementary measures as appropriate.

5

5. Data residency options (optional)

If Customer purchases a data residency option, processing locations are defined in the Order Form.

6

Schedules

  • Schedule A: EU SCCs (attach executed SCCs)
  • Schedule B: UK IDTA or UK Addendum (attach executed document)
  • Schedule C: DIFC SCCs (if used; attach executed clauses)