Printable Version

Last Revised: August 5, 2026

ENTERPRISEDB DATA PROCESSING ADDENDUM
& SUPPLIER SECURITY STANDARDS

This EnterpriseDB Data Processing Addendum & Supplier Security Standards (“DPA”) is published by EnterpriseDB Corporation, on behalf of itself and its Affiliates, located at 221 W 9th St., Suite 344, Wilmington, DE 19801, USA (“EnterpriseDB”), and is available at https://www.enterprisedb.com/vendor-data-processing-addendum, and is incorporated by reference in the EnterpriseDB Vendor Services Agreement (the “Agreement”).

 

1. Introduction

This DPA applies to EnterpriseDB and Vendor in Processing of Personal Data in connection with Services involving the same under the Agreement.

2. Definitions

In this DPA:

2021 EU Standard Contractual Clauses” or “2021 EU SCCs” mean the contractual clauses annexed to the EU Commission Decision 2021/914/EU or any successor clauses approved by the EU Commission.

Data Breach” shall mean any breach of security leading to unauthorized or unlawful destruction, loss, alteration or disclosure of Personal Data. 

Data Protection Laws” means all applicable law relating to data protection, privacy and security when processing Personal Data under the Agreement. This includes without limitation applicable international, regional, federal or national data protection, privacy, export or data security directives (e.g. directives of the European Union), laws, regulations, rulings, decisions and other binding restrictions of, or by, any judicial or administrative body, whether domestic, foreign or international.

Personal Data” shall mean personal data as defined in applicable Data Protection Laws, including that any information relating to an identified or identifiable individual (including, but not limited to, name, postal address, email address, telephone number, date of birth, Social Security number, driver’s license number, other government-issued identification number, financial account number, credit or debit card number, insurance ID or account number, health or medical information, consumer reports, background checks, biometric data, digital signatures, any code or password that could be used to gain access to financial resources, or any other unique identifier) that is processed by Vendor under the Agreement. 

Process” or “Processing” shall mean any operation, or set of operations, performed on Personal Data, by any means, such as by collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction. 

Sub-Processor” means any person appointed by or on behalf of Vendor to Process Personal Data on behalf of EDB in connection with the performance of Services (except in the context of Module Three of the 2021 EU SCCs, when Sub-processor refers to the data importer).

Swiss SCC Addendum” means adaptation of the 2021 EU SCCs to comply with the Swiss legislation in order to ensure an adequate level of protection for data transfers from Switzerland to a third country subject to the Swiss Federal Act on Data Protection (“FADP"). 

UK Data Protection Laws” means the UK GDPR and the Data Protection Act 2018, or any successor UK data protection laws as updated, amended or replaced from time to time. 

"UK SCC Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (vB1.0 or any subsequent version) issued by the UK Information Commissioner’s Office. 

The terms, "Commission", "Controller", "Member State", “Processor”, "Processing" and "Supervisory Authority" shall have the same meaning as under Applicable Law (e.g., the GDPR).

3. Processing Of Personal Data

Each party shall comply with its respective obligations as a Data Controller or Data Processor under the applicable Law when processing Personal Data. Each party will limit the other party’s access to Personal Data as necessary under the Agreement. Vendor shall (including ensuring that any person Processing Personal Data on Vendor’s behalf shall):

  • Process Personal Data only to perform the Services as specified by EDB’s documented instructions the Agreement, including this DPA, and its Annexes, or as otherwise provided in writing, and in accordance with applicable Law.
  • Comply with EDB’s reasonable instructions to obtain any required consents and to provide any required notices to Individuals on EDB’s behalf in the event that Vendor collects Personal Information directly from individuals on behalf of EDB (or its customers).
  • Provide reasonable assistance to EDB for the fulfillment of EDB’s obligations to respond to Individuals’ or EDB’s requests for exercising data subject rights within a reasonable time but at the latest within the time limits prescribed by Applicable Data Protection Law.
  • Cooperate and assist EDB or its customers and take steps reasonably requested to comply with any registration or other obligations applicable to EDB and/or its customers under applicable data protection law.
  • At EDB’s discretion, return or delete Personal Data after the termination of the Services or upon EDB’s request.

4. Compliance With Data Protection Laws

Vendor agrees to comply with the Data Protection Laws applicable to the processing of Personal Data and the terms and conditions of this Agreement.

5. International Transfer of Personal Data

To the extent that the Services involve the International Transfer of Personal Data of a resident(s) of a country within the European Economic Area (“EEA”), Switzerland or United Kingdom (“UK”) to Vendor, a Vendor Affiliate or a Sub-processor located outside of the EEA, Switzerland or UK and the International Transfer is not covered by an Adequacy Decision and there is not another legitimate basis for the International Transfer of such Personal Data, then such transfers are subject to either the 2021 EU Standard Contractual Clauses, the UK SCC Addendum and/or Swiss SCC Addendum (as applicable) or other valid transfer mechanisms available under Applicable Law. For international transfers subject to: 

  • the GDPR, the parties hereby incorporate the 2021 EU SCCs in unmodified form (Module One where EDB is a Controller and Vendor is a Controller, Module Two where EnterpriseDB or Vendor is a Controller the receiving party is a Processor, and Module Three where EnterpriseDB and Vendor are both Processors;
  • the UK Data Protection Laws, the parties hereby incorporate by reference the UK SCC Addendum in unmodified form; and
  • The FADP, the parties hereby incorporate by reference the Swiss SCC Addendum.

The 2021 EU Standard Contractual Clauses shall be between EnterpriseDB and Vendor, irrespective of Vendor’s location. For such purposes, the party transferring Personal Data across EEA/UK/Swiss borders shall act as the Data Exporter, and the party receiving such Personal Data shall act as the Data Importer under the applicable Module except where parties each act as Controller in which case EnterpriseDB and Vendor act as data importers and data exporters. With respect to the 2021 EU SCCs, the parties agree to the following: (i) Clause 7 shall be omitted; (ii) Clause 9 shall be governed by Option 2 (General Authorization) and provide for a 14-day advance notice; and (iii) for Clauses 17 and 18, the parties choose the Netherlands and the Supervisory Authority of the Netherlands. Annexes I and II of the 2021 EU SCCs are attached hereto.

For purposes of the UK SCC Addendum, the parties (i) select the Approved EU SCCs, including the Appendix, in Table II and (ii) select both Importer and Exporter in Table 4. Annexes I and II of the 2021 EU SCCs are attached hereto and shall serve to provide the information required for Table 1 of the UK SCC Addendum.

For the purposes of the Swiss SCC Addendum, (i) the term “member state” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the 2021 EU SCCs; (ii) the references to the GDPR should be understood as references to the FADP insofar as the data transfers are subject to the FADP; (iii) the Federal Data Protection and Information Commissioner of Switzerland shall be the competent supervisory authority in Annex I.C under Clause 13 of the 2021 EU SCCs, where the transfer of Personal Data is subject to the FADP.

If there is a direct conflict between this Addendum and the 2021 EU Standard Contractual Clauses, the UK SCC Addendum and/or Swiss SCC Addendum, then the 2021 EU Standard Contractual Clauses, the UK SCC Addendum and/or the Swiss SCC Addendum (as applicable) shall prevail.

All other international transfers of Personal Data shall be subject to the terms of this Addendum. If additional terms are required to meet the requirements for International Transfers from a specific jurisdiction other than EEA, Switzerland, and UK, the parties agree to negotiate in good faith to amend this Addendum to include the required terms.

6. CCPA Service Provider Obligation

Where Vendor is Processing Data subject to the California Consumer Privacy Act of 2018 as amended and updated by the California Privacy Rights Act of 2020 (the “CCPA”), Vendor will comply with the applicable obligations required by the CCPA and will provide the Personal Data the level of privacy protection required by the CCPA.

In the context of performing the Services under the Agreement, Vendor shall not:

  • sell or share the Personal Data, as defined under the CCPA;
  • retain, use or disclose the Personal Data for any purpose other than (i) for the limited business purposes specified in the Agreement, and (ii) as permitted by the CCPA, including to comply with applicable law;
  • retain, use or disclose the Personal Data outside the direct business relationship between EDB and Vendor; or, combine the Personal Data that Vendor receives from Us, or on Our behalf, with Personal Data that it receives from, or on behalf of, another person or persons, provided that the Vendor may combine Personal Data to perform any business purpose and as permitted by applicable law.

Vendor grants Us the right to take the reasonable and appropriate steps detailed in the Agreement, including, the Data Processing Addendum and/or EDB Vendor Security Standards in Exhibit A, to help ensure that Vendor is using the Personal Data transferred in a manner consistent with the CCPA, including, upon notice to Vendor, to stop and remediate unauthorized uses of Personal Data.

Vendor shall notify EnterpriseDB if Vendor can no longer meet its obligations under the CCPA.

To the extent there is any inconsistency between these CCPA obligations and any other portion of the Agreement or this Addendum with respect to obligations under the CCPA, these CCPA obligations shall control.

7. Use of Subcontractors in Data Processing

If in the Agreement, or separately in writing, EnterpriseDB has agreed that Vendor may engage subcontractor(s) to process Personal Data, then

  • such engagement will be under a written contract, and
  • the subcontract will require the subcontractor(s) to comply with the same obligations, representations, warranties and requirements applicable to Vendor under the Agreement and the Data Protection Laws and will provide EnterpriseDB with the same rights as EnterpriseDB has towards Vendor.

Vendor shall remain fully liable for the acts and omissions of its subcontractors.

8. Safeguards

Vendor shall Implement and maintain appropriate administrative, technical, and organizational measures designed to protect against any misuse or accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data that the vendor may transmit store or otherwise Process in its provision of Services to EDB. Vendor shall at a minimum, comply with the EDB technical and organizational security measures specified in Exhibit A, the “EDB Vendor Security Standards”.

Vendor shall maintain and promptly provide EnterpriseDB with up-to-date information regarding its data processing activities as EnterpriseDB may reasonably request to meet its obligations under Data Protection Laws. Such information shall include at least a description of (i) supplier name and contact details, and data protection officer where applicable, (ii) the categories of Processing activities performed on behalf of EDB, (iii) if applicable, the countries to which Transfers occur, (iv) if applicable, the identity of any authorized Sub-processors and the Processing activities subcontracted to such Sub-processors, and (v) the technical and organizational measures designed to protect Personal Data against any misuse, accidental, unlawful or unauthorized destruction, loss, alteration, disclosure, acquisition, or access. EnterpriseDB shall have the right to audit the facilities and processing activities of Vendor under this DPA to examine the level of protection and security provided for Personal Data processed under the Agreement, or under this DPA, and to assess the compliance of Vendor and its subcontractors with the Agreement or this DPA. Vendor shall procure for EnterpriseDB the same rights of audit with respect to Vendor’s subcontractors. Each party shall bear its own costs for any such audit.

Vendor (or its authorized third-party auditor) shall regularly audit business processes and procedures that involve the Processing of Personal Data under the Agreement for compliance with the Agreement. A copy of the audit results shall be provided free of charge to EDB upon EDB’s request. Vendor shall complete a security and privacy assessment questionnaire related to Services, upon EDB’s written request. Such a questionnaire may include questions seeking confirmation of compliance with the Agreement and Applicable Data Protection Law. Upon request by EDB, Vendor will also supply a copy of its and its Sub-processors most recent third-party audit report or attestation, such as an ISO 27001, SOC report, NIST or similar assessment, if Vendor has had such an assessment which may be shared with EDB Affiliates or any relevant Supervisory Authority.

9. Security Incidents

Vendor shall follow the process outlined in section 6.0, “Incident Management”, of EDB Vendor Security Standards.

10. Cooperation Obligations

EnterpriseDB or Vendor may have obligations under the Data Protection Laws to provide access to individuals’ Personal Data or to allow modification, correction, blockage or deletion of Personal Data processed by the Vendor or to provide information regarding the processing of an individual’s Personal Data. If requested by EnterpriseDB, Vendor shall, at no additional cost:

  • promptly provide EnterpriseDB with a copy of individuals’ Personal Data under Vendor’s control in tangible form or, at EnterpriseDB discretion, provide access at any time to the Personal Data,
  • promptly modify, correct, block or delete Personal Data under Vendor’s control in a manner consistent with the Agreement or as required by Data Protection Laws,
  • provide EnterpriseDB with or make available to individuals information regarding the processing by providing, for example, privacy notices or requesting consents and waivers on behalf of EnterpriseDB, and
  • assist EDB in the filing process by providing accurate information in a timely manner about the processing practices of Personal Data by Vendor and its subcontractors.

11. Handling Government Requests

Subject to what is permitted under the Data Protection Laws, (a) if Vendor receives a request from a governmental authority or body (“Authority”) regarding any EnterpriseDB Personal Data, Vendor shall immediately notify EnterpriseDB in writing identifying the Authority, the scope of the requested and grounds presented for the request, and (b) Vendor shall respond to such Authority request only after consultation with EnterpriseDB and EnterpriseDB prior approval of the response in writing.

12. Registration of Data Processing

If requested by EnterpriseDB in order for EnterpriseDB to comply with the Data Protection Laws, Vendor shall, at no additional cost, assist EnterpriseDB in the filing process by providing accurate information in a timely manner about the processing practices of Personal Data by Vendor and its subcontractors. Further Vendor is under the obligation to inform EnterpriseDB if any information relevant for the registration of data processing has changed and needs to be updated.

13. Miscellaneous

To the extent that Personal Data is processed by, or for, Vendor, for whatsoever reason, after the termination or expiration of the Agreement, this DPA shall continue to apply to such processing for as long as such processing is carried out. The parties agree that to the extent of any conflict between the terms of this DPA and the Agreement, the provisions of this DPA shall prevail. EDB may update this DPA from time to time by publishing a revised version at https://www.enterprisedb.com/vendor-data-processing-addendum.

 

 

2021 EU SCC ANNEXES

ANNEX I

A. List of Parties

Data exporter(s):

Name: EnterpriseDB

Address:221 W 9th St. Suite 344, Wilmington, DE 19801, USA

Contact person’s name, position and contact details: privacy@enterprisedb.com

Activities relevant to the data transferred under these Clauses:  The transfer of Relevant Personal Data from data exporter to data importer in the context of the Agreement.

Signature and date: Execution of the Agreement that incorporates this DPA by reference is deemed execution of these Clauses

Role (controller/processor): Controller for Module One; Processor for Module Two and Three

Data importer(s):

Name: Vendor as defined in the Agreement

Address: As specified in the Agreement

Contact person’s name, position and contact details: As provided in the agreement.

Activities relevant to the data transferred under these Clauses:  The transfer of Relevant Personal Data from data exporter to data importer in the context of the Agreement.

Signature and date: Execution of the Agreement that incorporates this DPA by reference is deemed execution of these Clauses

Role (controller/processor): Controller for Module One; Processor for Module Two and Three

B. Description of Transfer

Categories of data subjects whose personal data is transferred

As needed by Vendor to perform the Services, which may include:

  • Employees and applicants
  • Customers, prospective customers and end users
  • Vendors, agents and contractors

Categories of personal data transferred

As needed in order for Vendor to perform the Services, which may include:

  • Direct identifiers such as first name, last name, date of birth, and home address
  • Communications data such as home telephone number, cell telephone number, email address, postal mail, and fax number
  • Family and other personal circumstance information such as age, date of birth, marital status, spouse or partner, and number and names of children
  • Employment information such as employer, work address, work email and phone, job title and function, salary, manager, employment ID, system usernames and passwords, and performance information
  • Details of user’s interaction with the data importer’s systems and with systems for which the data importer provides computing services including device identifiers, online profiles, and IP address
  • Other Personal Data to which the parties provide to each other in connection with the provision of the Services

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

Personal Data transferred is determined and controlled by the data exporter and may include sensitive data such as government identifier, religious affiliation, or any other sensitive data necessary to be Processed in order to perform the Services

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

Transfers on a continuous basis as needed to perform the Services.

Nature of the processing

Personal Data will be subject to automated and manual processing operations by the data importer as necessary to perform the Services under the Agreement.

Purpose(s) of the data transfer and further processing

To perform Services under the Agreement and the Addendum.

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

Retained for the duration of the Services.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

For the subject matter, nature and duration as identified above

C. Competent Supervisory Authority

Pursuant to Clause 13, the supervisory authority of the EEA country where (i) the data exporter is established; or where (ii) the EU representative of the data exporter is established; or where (iii) the data subjects whose personal data are transferred under these Clauses in relation to the offering of goods or services to them, or whose behaviour is monitored, are located. Where the processing is subject to UK Data Protection Laws or the Swiss FADP, the competent authority shall be the UK Information Commissioner's Office (ICO) or the Swiss Federal Data Protection and Information Commissioner (FDPIC), respectively.

 

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

The technical and organizational security measures are specified in the EDB Vendor Security Standards (“Security Standards”) specified in Exhibit A.

 

Exhibit A: EDB Vendor Security Standards

These Vendor Security Standards (the “Standards”) list the minimum security controls that EnterpriseDB Vendors are required to adopt and meet when (a) accessing EnterpriseDB or EnterpriseDB Facilities and/or Information Systems, or (b) Processing EnterpriseDB Data. Vendor is responsible for compliance with these Standards by its Personnel. Additional security compliance requirements may be specified in individual statements of work.

Defined terms shall have the meaning set out in the Agreement or in Section 8, Definitions, below.

1.0 Information Security Program and Personnel Security Management

1.1 Information Security Program

Vendor shall implement comprehensive written policies, procedures and standards to establish effective safeguards for the protection of Data and to identify, protect against, detect, respond to, and recover from Security Incidents (collectively, “Information Security Program” or “ISP”). The ISP must be aligned with relevant industry standards (e.g., NIST CSF, ISO 27001, COBIT) and must be reviewed every year and updated as necessary in light of changes to business practices, applicable legal requirements or security risks.

1.2 Personnel Security

  • Vendor must perform criminal and employment background checks, consistent with local laws and regulations, for all Personnel. The level of verification performed must be proportional to risk correlated to Personnel’s respective roles.
  • Personnel must be made aware of their obligations under the ISP to protect Data, as well as the acceptable use of all Information Systems, and must agree in writing to comply with the requirements of the ISP.
  • Personnel must receive information security training appropriate to their roles at time of hiring and at least every two years, or more frequently as required by applicable law, regulation or standard.
  • Vendor will maintain a formal disciplinary procedure for violations of the ISP and take appropriate disciplinary actions based upon the nature and gravity of a violation.
  • Upon termination of Personnel employment, Vendor must promptly remove access to Information Systems and confirm Personnel have not retained any Data.

1.3. Subcontractors

To the extent Vendor is authorized to use subcontractors for provision of the Services:

  • Vendor is responsible for and contractually binds any subcontractor to comply with terms consistent with those set forth in the Agreement and this Standard.
  • Vendor must maintain and regularly update a list specifying its subcontractors that Process Data, including the countries where Data may be Processed, and provide that list to EnterpriseDB upon request. EnterpriseDB reserves the right to reject the use of a subcontractor or require reasonable steps to address objections to a subcontractor, where EDB believes in its reasonable judgment that the subcontractor is unable to meet the requirements of the Agreement or this Standard.

1.4 Business Continuity

Vendor must have a Disaster Recovery (DR) program and maintain a documented organizational Business Continuity Plan (BCP). The DR program and BCP must be designed to prevent the loss of Data and to ensure the Vendor can continue to function through operational interruption and continue to provide Services as specified in the Agreement and this Standard. Vendor will provide EDB written summaries of its DR program and BCP upon request. The BCP must be tested at least annually and material gaps remedied promptly.

2.0 Physical Security

2.1 Physical Security

Vendor’s Facilities must have physical protection that meets or exceeds industry standards. This includes:

  • Vendor will maintain a physical security plan to protect Facilities that address internal and external threats. This plan must be reviewed and updated at least annually.
  • Facilities must have secure entry points that restrict access and protect against unauthorized access. Access to all locations must be limited to authorized Personnel and approved visitors. All visitors must be logged and be escorted by Vendor Personnel at all times. Security guards, intrusion detection, and/or CCTV cameras must be used to monitor building entry points, loading and shipping docks, and public access areas. All visitors must be required to sign a visitor register.
  • Reception areas must be manned by a receptionist or security guard. Off hours access must be monitored, recorded and controlled. Logs detailing access must be stored for a period of at least 90 days.
  • Vendor Personnel and authorized visitors must be issued identification cards. Visitor identification cards must be distinguishable from Vendor Personnel identification.
  • Access cards and keys that provide access to secure areas and information processing Facilities such as Data Centers must be monitored and limited to authorized Personnel. Regular reviews of access rights to Facilities must be performed.
  • Off-site removal of Information Systems, servers and Network Devices must be restricted, approved and authorized by appropriate security Personnel.
  • A clear desk policy must be enforced in areas where EDB Data is stored. Documents that contain EDB Data must be secured when not in use.

2.2 EDB Facilities

Vendor Personnel are required to abide by EDB security requirements and direction when working at EDB Facilities. The security measures employed at EDB Facilities (e.g., use and placement of security cameras, use and placement of other physical and logical security controls) are EDB Confidential Information. Personnel may not photograph or otherwise record EDB Facilities or infrastructure, unless required for the performance of Services and EDB approves in advance.

3.0 Information Systems

This Article 3 applies where the supplier processes EDB data on Vendor Information Systems.

3.1 System Configuration

Vendor Information Systems will be implemented and maintained in accordance with industry standards. This includes:

  • Versions/Patching. Vendor will maintain all applicable Information Systems components at version and patch levels that reasonably protect Data from Vulnerabilities.
  • Change Control. Vendor will implement an effective change control policy which ensures that any changes to the Information Systems are controlled and documented, including the submission, recording, analysis, decision making, and approval of the change. Change requests will be managed to ensure minimal risk of disruption to the Information Systems.
  • Backups. Vendor will create, maintain and securely store backups of Data in encrypted form. Vendor will create, secure, manage and maintain all information necessary to restore the Data promptly upon EDB’s request.

3.2 Network Security

The Information Systems network perimeter must be protected by firewall systems and maintain segmentation based on security zones. Vendor will establish port, protocol and IP address restrictions that limit the network inbound and outbound protocols to the minimum required and ensure Data is encrypted. All inbound traffic must be routed to specific authorised destinations. Vendor shall: (i) implement intrusion detection and prevention solutions for all connectivity to the Information Systems from the Internet with regularly updated signatures to generate alerts for known and new threats; (ii) configure perimeter systems with redundant connections, i.e., there are no single points of failure, and (iii) maintain and enforce security procedures in operating the Information Systems consistent with industry standards.

3.3 Access Control

Vendor will employ the following controls for access to Vendor Information Systems.

  • Least Privilege. Vendor will limit its access by its Personnel to Information Systems based upon a principle of least privilege.
  • Access Review. Vendor will implement a secure mechanism to periodically review access of its Personnel to Confidential Information.
  • Account Credentials. Vendor will ensure that every distribution and reset of Account credentials will be conditioned upon the Account credential owner first providing verification information from at least two (2) different categories: something you are, something you have and something you know. Account credentials must be communicated through a channel accessible only to the Account credential owner that is an existing part of the Account profile (i.e., is not supplied at the time of reset request).
  • Revocation of Access. Vendor will revoke access privileges of a User within twenty-four (24) hours after access is no longer required, or within one (1) hour in emergency or priority situations including termination for cause.
  • Remote Administration. All remote administration of the Information Systems shall require MFA from two (2) different categories (something you are, something you have and something you know) and use encrypted channels.
  • Records Vendor shall maintain a record of: (i) the approval for the creation, modification, privilege escalation and deletion of each Account; (ii) Account credential owner; and (iii) Account additions, removals, and modification including traceability of the executor of the action for ninety (90) days.
  • Timing Out. Vendor shall ensure that the Information Systems lock an Account after (at most) five (5) consecutive access attempts. Vendor shall require Account Credentials to gain access to any Information Systems used to Process Data, and such access will terminate after a reasonable period of inactivity, which shall not exceed 20 minutes.
  • Reviews Vendor will conduct a full review of all User Accounts with access to Data annually. Review shall include: (i) validate current User role and rights in the Information Systems; (ii) review a User access table (read, write, execute) to ensure "Principle of Least Privilege"; and (iii) validate that the User role has not been combined with other roles.
  • Account Single User. Account activities must be attributable to a single User.
  • Training. All Account holders must be adequately trained with respect to the limitations on the use of Accounts and the consequences for misuse of Accounts.
  • Logs. Vendor will maintain logs sufficient to definitively attribute access to Processing and actions performed using Data. Such logs shall be kept for at least ninety (90) days after the event logged. The details logged for each event at minimum must capture the following types of information: (i) timestamp; (ii) event, status, and/or error codes; (iii) service/command/application name; (iv) User Account associated with an event; and (v) device used (e.g., source and destination IP addresses, terminal session ID, web browser, etc.).
  • Unauthorised Code. Vendor will configure and use up-to-date anti-malware and anti-virus software to protect the Information Systems and other systems that interface with EDB Systems. Anti-virus and anti-malware signatures must be updated at least every twenty-four (24) hours. Vendor will not knowingly incorporate or introduce Unauthorised Code into the Information Systems or EDB Systems.
  • Penetration Testing. Vendor must perform independent testing on at least an annual basis to verify that the Information Systems are free of Vulnerabilities, including those that may be used: (i) to inject Unauthorised Code; (ii) to gain unauthorised access to the Information Systems; or (iii) to gain unauthorised access to the Data. Independent Testing should include, but not be limited to, firewalls, routers, intrusion detection and prevention, web filtering, malware detection, databases, and applications. All Vulnerabilities must be remediated promptly, in no event greater than 30 days following completion of the testing.

3.4 Passwords, Passphrases, PINS and Account Secrets

Passwords must follow a password policy consistent with industry standards. This includes:

  • passwords must meet minimum password length and complexity requirements (e.g., no dictionary words, use a mix of alpha, numeric characters, require special characters, etc.);
  • passwords may not be reused and default passwords must be changed prior to use;
  • users must not hardcode any usernames/passwords in scripts or clear text files such as system shell scripts, batch jobs, or word processing documents;
  • passwords must have a defined expiration period not to exceed 90 days; alternatively, password practices may follow all requirements for memorized secrets found in National Institute of Standards and Technology (NIST) Special Publication 800-53B. 5.7.4;
  • passwords must be distributed separately from account information, in a manner that ensures confidentiality of information;
  • passwords must be encrypted when transmitted between Information Systems, Network Devices and Applications and when stored; and
  • multi-factor authentication must be used for all personnel accessing non-public network resources, or any environments processing EDB data.

4.0 Software Development

This Section 4 applies where Vendor develops, hosts, deploys computer software or code for EDB or otherwise offers Products to EDB.

4.1 Software Development Lifecycle

Vendor will implement a formal written software development lifecycle that follows industry standards, such as NIST or ISO, that provides for change control and configuration management and verifies that all security configurations are in place prior to the use of any component of the Information Systems in a production environment. Within the software development lifecycle, Data will not be used in non-production environments such as environments for software evaluation, training, or development.

4.2 Secure Coding

Vendor shall design and build software using industry-standard secure coding practices and address security appropriately throughout the development life-cycle. This includes, without limitation, employing security development requirements, test plans, code reviews, security testing and quality assurance. The Product’s processes, direct capabilities, and other necessary actions shall comply with Applicable Law, including but not limited to laws addressing privacy and information security obligations.

4.3 Application Vulnerabilities

Vendor will take reasonable steps to ensure that all applications allowing for access to the Information Systems (“Applications”), are free of critical weaknesses, malware and Vulnerabilities, and will test for weaknesses and Vulnerabilities prior to each delivery or to providing access. In addition Vendor shall:

  • Use limited application privileges. not use or require administrator, system administrator, database administrator, root, “super user” or other similar rights to execute applications;
  • Validate all User input. Ensure Applications and all software validates information before use and un-validated User-supplied or client application supplied input is not used in any filename, database query, or other function;

4.4 Vulnerability Remediation

Vendor shall remediate vulnerabilities in Products offered to EDB at the Vendor’s expense and as a top priority. Vendor must remediate a Vulnerability by correcting or removing any contributing factors within fourteen (14) days for critical Vulnerabilities and thirty-five (35) days for high Vulnerabilities; provided that, in the event the Vendor determines a Vulnerability cannot be remediated within the identified time, Vendor must escalate the issue to executive management and continue to work on the issue on an urgent basis until resolved. All vulnerability patches and fixes must be provided to EDB promptly upon release.

4.5 Custom Developed Product Security Notification

Vendor shall identify and notify EDB promptly, and in no case more than ten days, after learning of any security vulnerabilities in hosted environments, software or code developed for EDB.

5.0 Protection of EDB Data

5.1. Access and Use of Data

Vendor may access, use and EDB Data only on behalf of EDB and only for the purposes specified in the Agreement and these Standards.

5.2 Separation

EDB Data must be physically or logically separated (as applicable) from the Confidential Information of Vendor and any other customers.

5.3 Mobile Devices

EDB Data may not be stored on mobile devices or device media cards unless encrypted using 256-bit or higher encryption and devices are managed through centralized device management software, with the capability to remotely lock and wipe lost/stolen devices.

5.4 Media

Electronic Media containing EDB Data must be sanitized before disposal using a process that assures complete data deletion and prevents data from being reconstructed or read, as prescribed in industry standards such as NIST SP 800-88 Revision 1 and DoD 5220.22-M. Defective Electronic Media containing EDB Data must be physically destroyed.

5.5 Encryption

Vendor will encrypt all Data, including online, nearline and offline: (i) at rest; (ii) when transmitted over non-secure channels, including remote connectivity; (iii) when Processing Data; and (iv) when creating or storing backups. The encryption standards used shall be, at a minimum, AES 256 and TLS 1.2, as applicable.

5.6 Email Accounts

Vendor will not permit the use of personal email accounts for exchanging, processing or storing EDB Data.

5.7 Non-production environments

Vendor will not use production systems that store or process EDB Data for development, testing or staging purposes.

5.8 Back-up

Vendor must ensure Information Systems involved in the performance of the Services are backed up to online and/or offline storage. Backups must be tested in accordance with operational backup standards. If Vendor is storing EDB Data, Vendor must ensure daily backups, at a minimum.

5.9 Return and Deletion of EDB Data

Within 30 days following termination of a Statement of Work, and/or upon EDB’s written request, Vendor shall return all originals and copies of EDB Data, whether in logical, physical, or electronic form, including all backups and archived data. Following confirmation that Data has been received or upon EDB’s request, Vendor will delete or securely destroy any remaining copies of Data. Vendor may retain one copy of the foregoing materials, as required for regulatory retention purposes or by law, provided that any such copy is kept in encrypted format, is not used or accessed for any other purpose, and remains protected in accordance with the requirements of these Standards and is deleted promptly when no longer needed for such purpose.

5.10 EDB Information Systems

Vendor Personnel may not access EDB Systems unless expressly authorized by EDB and must follow EDB information security standards at all times. EDB Information Systems are monitored for compliance.

6.0 Incident Management

6.1 General

Vendor shall maintain documented standards and procedures for dealing with suspected and actual Security Incidents. The incident management standards and procedures must cover the reporting, analysis, monitoring and resolution of Security Incidents.

6.2 Security Incident Reporting

Reported Security Incidents must be handled by a dedicated information security response team and/or by personnel who are trained in assessing and handling Security Incidents. Vendor shall notify EDB as soon as reasonably practicable and in no case more than twenty-four (24) hours after confirmation of a Security Incident, by sending notice to security@enterprisedb.com. Such notice shall summarise in reasonable detail the cause of the incident, the effect and damage to Data, and the corrective actions taken or to be taken. Vendor shall promptly take appropriate corrective actions and shall cooperate fully with EDB to prevent, mitigate or rectify such Security Incident.

6.3 Remediation

Vendor shall remediate the Security Incident or Breach as soon as reasonably practicable at Vendor’s expense. Vendor shall notify EDB if the remediation cannot be performed fully within seven (7) days of the Security Incident or Breach and in such case, EDB may, in its discretion, terminate this Agreement. Vendor shall reimburse EDB for costs incurred by EDB in responding to and mitigating damages caused by a Security Incident or Breach. Vendor shall preserve all forensic evidence related to the Breach or Security Incident and make them available to EDB upon request

6.4 Notice of Investigation or Inquiry

Vendor shall promptly notify EDB of any investigations of its privacy or security practices by a government, regulatory or self-regulatory organisation. Further, unless prohibited by law, Vendor must promptly notify EDB in the event the Vendor receives a request for access to EDB Data or Information Systems and, unless prohibited by law, must act upon EDB’s instruction concerning such request.

6.5. Statements

Unless otherwise required by law or law enforcement, Vendor must not make any statements concerning a Security Incident identifying or concerning EDB without written authorization of EDB’s Legal Department.

7.0 Compliance and Assessments

7.1 Regulatory Compliance

  • In the event that Vendor processes Data that is subject to additional regulatory requirements, including without limitation payment card data subject to the Payment Card Industry Security Standard, financial information subject to the Digital Operational Resilience Act, or health information covered under the Health Insurance Portability and Accountability Act of 1996, Vendor agrees to cooperate with EDB to comply, including negotiating in good faith additional agreements as required for such compliance.
  • Where needed to ensure compliance with Applicable Law, EDB may propose amendments to these Standards and the parties shall negotiate such amendments in good faith. If the parties cannot reach agreement, EDB may terminate the Agreement and associated Statements of Work.
  • Vendor must inform EDB in writing if, for any reason, Vendor is unable to meet the requirements of this Standard and/or Applicable Law, in which case EDB may terminate the Agreement and associated Statements of Work.

7.2 Reviews and Assessments

  • Audits. EDB may conduct written and/or in-person security assessments upon reasonable notice to verify compliance with the terms of these Standards. In-person assessments will take place during normal business hours and will not unreasonably interfere with Vendor’s business operations. Such Assessment may, in EDB’s discretion, require that Vendor work with a third-party chosen by EDB. EDB shall have the right to perform the Assessment once during each twelve-month period, and more frequently in the event of a Security Incident.
  • Data Flow Diagram. Upon request, Vendor shall provide a data flow diagram of Vendor’s Information Systems that includes the following information: (i) information about outputs and inputs of each entity involved in handling EDB data; and (ii) the process by which data flows from one system or network to another.

7.3 Remediation

Vendor must promptly remedy any material non-compliance found in such assessments. Further, if Vendor discovers non-compliance with the requirements of this Appendix, Vendor will promptly notify EDB of the non-compliance, and Vendor will remediate as soon as reasonably practicable, in no event to exceed 30 days.

8.0 Definitions

The following definitions apply to these standards Defined terms used but not otherwise defined in the Standards shall have the meanings given to such terms in the Agreement.

“Account”or “User Account” means User based access to the portion of Information Systems on which Confidential Information resides.

“Account Credentials” means a User ID and password necessary to access an Information System.

Applicable Law” means all laws, regulations, court orders and other governmental directive applicable to a party’s activities hereunder.

Data” means any and all of information, data, materials, works, expression, or other content, whether it is the information of EDB, its customers or other entities, that: (i) is Processed by Vendor; (ii) that is provided by EDB to Vendor, including through the Information Systems; or (iii) that is work product or other intellectual property that is owned by EDB, even when created by Vendor. For clarity, “Data” includes all Confidential Information, as defined under the Agreement, to which Vendor is provided access.

Data Center(s)” mean data center(s) owned, leased, utilised, or accessed by Vendor in which Data is created, received, Processed, maintained, stored, destroyed, or transmitted.

“EDB Systems” means the EDB’s platform, networks, databases, software, or architecture accessed by Vendor in the provision of Products.

“Facilities” means (a) any offices or data centers (whether owned or managed by EnterpriseDB, a EnterpriseDB customer, Vendor or a third-party) from which EnterpriseDB Confidential Information, Information Systems or Networks may be accessed. References in this document to (i) “EnterpriseDB Facilities” shall be deemed to include Facilities of EnterpriseDB customers, and (ii) “Vendor Facilities” shall be deemed to include third-party Facilities used by Vendor.

“Information Systems” means any platform, software, server or network that Vendor makes available to EDB, or that otherwise Processes Data.

“MFA” means multifactor authentication.

Personnel” means all Vendor employees, contractors, sub-contractors and agents who are provided access to Facilities, Networks, Information Systems and/or Confidential Information.

Process” or “Processing” or “Processed” means any operation or set of operations performed upon or any access to Data, whether by automatic means or not, such as creating, collecting, procuring, obtaining, recovering, organising, sorting, adapting, altering, retrieving, consulting, using, storing, disclosing or destroying Data.

Product” is any product, software, code or other deliverable developed or made available to EDB.

“Security Incident” means (a) actual or attempted unauthorized access to Confidential Information or Information Systems, or (b) the loss of confidentiality, integrity or availability of any Confidential Information.

Unauthorised Code” means: (i) a computer virus, harmful programs or data that destroys, erases, damages or otherwise disrupts the normal operation of EDB Systems, Data or Product, or allows for unauthorised access to EDB Systems, Data or Product; or (ii) worms, trap door, back door, timer, counter, software locks, password checking, CPU serial number checking or time dependency or other such limited routine, instruction that is designed to interrupt or limit the proper operation of EDB Systems, Data or the Product; or (iii) spyware/adware; or (iv) any other similar program, data or device that is being inserted for an improper purpose.

Update” or “Updated” means ongoing review and modification designed to ensure through use of commercially reasonable efforts the ongoing effective administrative, technical and physical safeguards and ongoing identification, protection, detection, response, and recovery from Security Incidents.

“Vulnerability” means a security vulnerability that is publicly reported or which the Vendor knew of or should have known of, and includes Harmful Code, or that otherwise adversely affects or has the potential to affect the confidentiality, integrity or availability of EDB Confidential Information.