Skip to content

Data Processing Addendum

  1. 7.4.1. Upon Customer’s request, and subject to the confidentiality obligations set forth in the Agreement, Monte Carlo shall make available to Customer (or Customer’s independent, third-party auditor that is not a competitor of Monte Carlo) information demonstrating Monte Carlo’s compliance with the obligations set forth in this DPA in the form of the certifications and audit reports for the Service. Examples of potentially relevant certifications and audit reports include: SOC 2, SOC 3; ISO 27001 and ISO 27701; Binding Corporate Rules; APEC Cross Border Privacy Rules System; EU-U.S. and Swiss-U.S. Privacy Shields; industry codes of conduct or their successor frameworks. In the event Customer does not find the certifications and audit reports suitable, Monte Carlo will make its applicable premises and personnel available to Customer for audit upon request but no more than once annually and at Customer’s cost. Before the commencement of any such audit, Customer and Monte Carlo shall mutually agree upon the scope, timing, and duration of the audit in addition to the reimbursement rate for which Customer shall be responsible. All reimbursement rates shall be reasonable, taking into account the resources expended by Monte Carlo. Customer shall promptly notify Monte Carlo with information regarding any non-compliance discovered during the course of an audit and all findings during the audit shall be considered confidential information between Customer and Monte Carlo except as expressly required otherwise by Data Protection Laws and Regulations. If material non-compliance is discovered during Customer’s audit, Monte Carlo shall bear the costs.