DATA PROCESSING AGREEMENT
This Data Processing Agreement (this “DPA“) is made between Amadeus and Customer. Customer acknowledges and agrees that it will be acting as the Data Controller of Personal Data processed by Amadeus in the provision of Services under the Agreement(s) between the Parties as amended from time to time, and Amadeus will be acting as Data Processor.
1.DEFINITIONS
1.1.For the purposes of this DPA, the following terms shall have the following meanings: “Cross Border Transfer” means any transfer of Personal Data by Amadeus or a Subprocessor from one jurisdiction to a recipient located in a different jurisdiction in connection with the provision of the Services; “Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data; “Data Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller; “Data Protection Legislation” means all laws and regulations relating to the Processing of Personal Data and privacy, including the European Union’s General Data Protection Regulation (2016/679/EC) (“GDPR”) and Directive 2002/58/EC (“e-Privacy Directive”), and all laws and regulations implementing or made under them and any amendment or re-enactment of them, as applicable to each party; “Data Subject” means an identified or identifiable natural person; “Personal Data” means any information that relates to an identified or identifiable living individual; “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed as a result of the services provided under this DPA; “Processing” of Personal Data means the use, collection, storage, processing, modification, transfer, blocking or erasure of Personal Data; “Services” means the services, activities and functions provided or made available by Amadeus to the Customer pursuant to the Agreement; “Standard Contractual Clauses” means the Standard Contractual Clauses as approved by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council; and “Subprocessor“ means a Data Processor engaged by another Data Processor in the Processing of Personal Data.
2.SUMMARY OF PROCESSING
2.1In the provision of the Services, Amadeus may Process Personal Data on behalf of Customer. This Processing includes such activities as specified in the service description under the Agreement which shall determine the duration and the subject-matter of the Processing, the nature and purpose of the Processing, the type of Personal Data and the categories of natural persons to which the Personal Data relates, as further detailed in Annex 1 (Data Processing Details).
2.2Each party will comply with its obligations related to the Processing of Personal Data under Data Protection Legislation.
3.OBLIGATIONS OF PROVIDER AS DATA PROCESSOR
3.1Amadeus shall:
3.1.1only Process Personal Data in accordance with the documented instructions of Customer. These instructions are documented in the Agreement, including in the relevant service descriptions, (collectively, the “Instructions”);
3.1.2ensure that any Personnel authorized by Amadeus to access the Personal Data are subject to a duty of confidentiality in respect of the Personal Data;
3.1.3Amadeus will implement and maintain technical, organisational, and physical measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as described in Annex 2 (Amadeus Technical and Organizational Security Measures) .
3.1.4at the choice of Customer, delete or return (including by making available) all Personal Data to Customer after the end of the provision of the Services involving the Processing, unless Amadeus is required to retain the Personal Data under applicable Law.
4.INTERNATIONAL TRANSFERS OF PERSONAL DATA
4.1Customeracknowledges that in the provision of the Services, Amadeus may transfer Personal Data to locations outside the European Economic Area.
4.2In relation to any Personal Data that is transferred from Amadeus to any of its Data Processing Subprocessors in connection with the Services, from the European Economic Area (EEA) to a third country which is not deemed to have adequate safeguards in place within the meaning of Data Protection Legislation (‘’Third Countries’’), Amadeus will (i) procure that any international transfer to its Data Processing Subprocessors located outside the EEA will be made in accordance with a valid lawful transfer mechanism under the Data Protection Legislation, and (ii) where required, carry out the necessary transfer risk assessment so as to ensure any international transfers of Personal Data to Third Countries comply with Data Protection Legislation.
4.3In addition, Amadeus and Customer shall liaise in good faith with one another and shall undertake to complete the relevant schedules, appendices, and details of the Standard Contractual Clauses as soon as possible, in the event Standard Contractual Clauses are required to be signed as between Amadeus and Customer.
4.4Where Standard Contractual Clauses are required between Amadeus and Customer in connection with a specific Cross Border Transfer not otherwise covered under this Clause 4, Amadeus and Customer shall liaise in good faith and execute a separate Standard Contractual Clauses addendum incorporating the applicable module, annexes and transfer details as required under applicable Data Protection Legislation. Amadeus will make available a template SCC addendum upon request.
5.ASSISTANCE
5.1Amadeus will, in a manner consistent with the functionality of the Services and Amadeus’ role as a Data Processor, provide reasonable support to Customer that may reasonably be required to respond to a Data Subject requests to exercise their rights under the Data Protection Legislation (‘’Data Subject Requests’’) For the avoidance of doubt, Customer is responsible for responding to Data Subject Requests. If Amadeus receives a Data Subject Request addressed to the Customer or its Affiliates, Amadeus will inform the Data Subject to contact the Data Controller directly (i.e., Customer or its Affiliates).
5.2Amadeus will provide reasonable assistance to Customer in respect of the Customer’s obligations concerning data security, breach notification, data protection impact assessments and prior consultations with supervisory authorities as expressly required by Data Protection Legislation, considering the nature of the Processing undertaken by Amadeus and the information available to Amadeus.
5.3Audits.
5.3.1Amadeus shall make available to Customer information reasonably necessary to demonstrate compliance with Amadeus’ Personal Data Processing obligations under this Agreement by making available documentation, or certifications and/or reports of audits performed by qualified, independent third-party auditors, such as Amadeus’ ISO 27001, PCI DSS certifications and/or SOC 1 and SOC 2 audit reports (or comparable industry-standard successor reports) (“Amadeus Reports”). Customer acknowledges that Amadeus Reports will be used to satisfy any audits or inspection requests by or on behalf of Customer. Amadeus will allow Customer to perform audits, including on-site audits, as required under Data Protection Legislation, of Amadeus’ control environment and security practices relevant to the Personal Data Processed under this Agreement for Customer (“Customer Audits”). Customer Audits will be subject to the following:
5.3.2unless otherwise required at the written request of a competent authority or regulatory body with jurisdiction over Customer (in which case Customer shall only be required to give as much advance notice as possible), such audit will be (i) limited to once in any twelve (12) months period, and (ii) Customer shall provide Amadeus with reasonable advance notification (at least forty-five (45) days). The date, time and place of the Customer Audit will be mutually agreed upon between Customer and Amadeus and it will be conducted during normal business hours and in a manner that avoids any disruption to Amadeus’ operations;
5.3.3the audit will be conducted in accordance with Amadeus’ security-related policies and procedures to protect the security and confidentiality of Customer Data and the data of Amadeus’ other customers. For the avoidance of doubt, Customer’s auditor will not have access to any data of other customers of Amadeus or any systems or facilities not used in the provision of the Services;
5.3.4the auditor shall be required to sign an appropriate confidentiality agreement with Amadeus and comply with Amadeus’ on-site security policies. Without limiting the other provisions of this sub-clause (c), Amadeus may reject the auditor appointed by Customer if the auditor is a competitor of Amadeus;
5.3.5The Parties will agree on the scope of the audit;
Customer will provide Amadeus with a copy of the auditor’s report. The Amadeus Reports as well as any information and documentation provided by Amadeus pursuant to this Clause will be treated or will request to be treated, by Customer as Confidential Information of Amadeus provided that where such Amadeus Reports and documents are directly relevant to a regulator of the Customer, the Customer shall be entitled to make disclosure of such parts of the Amadeus Reports and documents as are reasonably required by their regulator.
5.3.6Amadeus may charge fees (based on Amadeus’ then current man day rates) for any support provided pursuant to Clauses 5.1, 5.2 and 5.3.1 (including the costs of providing the certification and/or report).
6.PERSONAL DATA BREACH
6.1Amadeus shall notify Customer without undue delay, of any Personal Data Breach after having established the nature of the Personal Data Breach and the fact that Personal Data transmitted, stored or otherwise Processed by Amadeus in connection with this Agreement has been affected, including, to the extent reasonably available, information to assist Customer to comply with its obligations as Data Controller, in accordance with applicable Data Protection Legislation, in notifying competent supervisory authorities and individuals.
6.2Customer shall notify Amadeus of any Personal Data Breaches as specified in the Agreement. Amadeus’ notification of or response to a Personal Data Breach under this Clause 6 shall not be construed as an acknowledgment by Amadeus of any fault or liability with respect to the Personal Data Breach.
7.SUBPROCESSORS
7.1Customer hereby, grants Amadeus and its Affiliates a general written authorization to engage Subprocessors in the Processing of Personal Data in accordance with the provisions set out in this Clause 8. If a Subprocessor fails to meet its data protection obligations, Amadeus will remain liable to Customer for ensuring the performance of those obligations. Amadeus shall inform Customer of any such changes to the Subprocessors made after the Effective Date of the Agreement by notifying Customer as specified in the Agreement.
7.2If Customer, after having received notice in accordance with Clause 7.1 above:
(a)acting reasonably, objects to the use of a Subprocessor, on the grounds that such use would present a significant risk to the Data Subjects’ rights and freedoms; and
(b)Customer notifies Amadeus promptly in writing within fourteen (14) calendar days after receipt of Amadeus notice in accordance with Clause 7.1 above providing details of the evidence of such grounds,
then, subject to Clause 7.3.1, Amadeus shall use reasonable endeavours to resolve the reasons for Customer’s objections or to procure use of a different Subprocessor.
7.3If Amadeus:
7.3.1disputes the grounds notified to it under Clause 7.2, the dispute shall be referred to the Dispute Resolution Procedure; or
7.3.2is unable to or fails to resolve the reasons for Customer’s objections or to procure use of a different Data Processing Subprocessor within a reasonable period of time, Customer may terminate the Services which cannot be provided by Amadeus without the use of the Data Processing Subprocessor to which Customer objects by providing written notice to Amadeus, provided Customer will not be entitled to claim damages in respect such termination. Termination shall be in accordance with the Agreement’s termination for convenience provision or, if no such provision exists, by providing written notice to Amadeus.
8.DPA Management data
8.1The Personal Data derived from the management of this DPA (such as contacts) and those deriving from the Agreement between the Parties will be processed by each Party in order to comply with the purpose of the DPA and those agreements, and its processing is legitimated by the existence of such relationship. This Personal data will not be transferred to third parties except in cases where there is a legal obligation to do so, and will be kept for as long as the relationship is maintained or for as long as necessary in order to comply with applicable data protection laws. The corresponding Data Subjects may exercise, where applicable, their right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object and the right not to be subject to a decision based solely on automated processing by contacting the other Party at the address indicated in this DPA, as well as file a complaint with the appropriate Data Protection Authority. Additional information related to such data may be found in Amadeus’ Business Partners Privacy Notice available here: Amadeus’ Business Partners Privacy Notice.
9.GENERAL TERMS
9.1Precedence. The provisions of this DPA are supplemental to the relevant Agreement. In the event of inconsistencies between the provisions of this DPA and the provisions of the relevant Agreement the provisions of this DPA shall prevail.
9.2Compliance with Data Protection Laws. Each Party to this DPA shall comply with all applicable Data Protection Laws.
ANNEX 1
Customer instructs Amadeus to process personal data on Customer‘s behalf as set forth in this DPA and pursuant to the Agreement:
Processing of Personal Data required in the provision of the Services by Amadeus (as Processor) to Customer.
For the term of the Agreement and as required or permitted under the Agreement following the end of the term of the Agreement.
•Receiving data, including collection, accessing, retrieval, recording and data entry.
•Hosting data, including storage, organisation and structuring.
•Using and updating data in the provision of the Services (as further described in this Agreement) or in accordance with Amadeus’ policies.
•Protecting data, including restricting, encrypting, anonymizing and security testing.
•Sharing data, including disclosure, dissemination, allowing access or otherwise making available.
•Returning data to Customer.
•Erasing data, including destruction and deletion.
oProvision of Services related to the travel and tourism industry provided to the Customer by Amadeus type of Personal Data:
–Traveller/customer data of Customer and any Service Recipients that include: name, itinerary, booking number, passport details, loyalty scheme membership, booking history as required to provide the Services; and
–employees/contractors’ data of Customer that include: names and professional contact information Processed to provide the Services.
(iii)travellers/customers (including prospective travellers or customers) of Customer; and
(iv)employees/contractors of Customer.
ANNEX 2
1.GENERAL
1.1.Amadeus has implemented and will maintain the following measures for Customer Personal Data that is in the possession, control, or otherwise processed by and under the control and responsibility of Amadeus in accordance with the following security measures.
1.2.The Amadeus Technical and Organisational Security Measures are based on ISO 27001 controls and require Amadeus to implement and maintain physical, administrative, and technical safeguards designed to protect the confidentiality, integrity, availability and security of the products and services and security of Customer Personal Data processed in the provision of the services. Details of additional security measures and relevant exceptions that apply to a specific Service Module are available upon request.
2.SECURITY REQUIREMENTS
Amadeus shall maintain documented information security policies, processes, organization and controls (the ‘Processes’’), that are appropriate, taking into account the information security risks and where applicable, recognized industry standards. The Processes will be reviewed and, if required, updated by Amadeus at least on an annual basis, taking into account good industry practices.
Security Ownership – Amadeus has a designated security official responsible for information security and control and implementation of the Processes.
Security Roles and Responsibilities – Amadeus personnel are subject to confidentiality obligations; Individuals for whom Amadeus is responsible will have documented security roles and responsibilities where relevant.
Risk Management Program – Amadeus will have in place a risk management process to perform risk assessments before and while providing the products and services..
Amadeus will screen Amadeus personnel as part of the hiring process in accordance with its policies and subject to limitations of applicable law.
During employment – Amadeus will make personnel aware of security rules and procedures through a documented security awareness and training program including informing personnel of consequences of breaching security rules and procedures.
Termination of employment – Amadeus will maintain the relevant processes, including the removal of system accesses after termination or change of employment.
Asset Inventory – Amadeus will maintain an inventory of where Customer Personal Data is stored.
Classification and labelling of Customer Personal Data – Amadeus will maintain access to Customer Personal Data that is appropriately restricted, according to the classification.
Acceptable use policy – Amadeus will have in place an acceptable use policy that applies to information and assets that contain Customer Personal Data.
Handling of assets and disposal of assets – Amadeus will have in place procedures for handling, management and secure disposal of information and assets.
Access Policy –Amadeus will maintain a record of access and security privileges of individuals having access to Customer Personal Data.
Access Authorization – Amadeus shall maintain a record of personnel’s accounts authorised to access information systems that contain Customer Personal Data, and individual personnel shall have separate identifiers or log ins.
Least Privilege – access to Customer Personal Data is restricted to those individuals who are required to access the Customer Personal Data to perform their job function on a need-to-know basis.
Application Security – Amadeus shall implement system and application access controls.
Authentication – Amadeus shall use industry standard practices to identify and authenticate users who attempt to access information systems. Where authentication measures are based on passwords, the passwords shall be renewed regularly and meet industry standard password protection practices.
Network Design – Amadeus shall logically have controls in place to avoid access to Customer Personal Data by individuals where they may not be authorised to access.
Physical Access to facilities – Amadeus shall limit access to facilities where Customer Personal Data is located or accessed from to identified authorised individuals.
Physical Access to components – Amadeus shall maintain records of the incoming and outgoing media containing Customer Personal Data, including the kind of media, the authorized sender/recipients, date and time, the number of media and the types of such data they contain.
Protection from disruption – Amadeus shall use industry standard systems to protect against loss of Customer Personal Data due to power supply failure or other disruptions.
Data deletion – Amadeus shall use industry standard practices to securely delete Customer Personal Data in accordance with the Agreement and applicable law.
Operational – Amadeus shall maintain documentation describing security measures, the relevant procedures and responsibilities of its personnel who have access to Customer Personal Data.
Environment Separation – Amadeus shall maintain separation of development, testing and production environments.
Data Recovery Procedures – Amadeus shall have in place data recovery procedures so that Customer Data can be recovered, including written business continuity and disaster recovery plans.
Malicious Software – Amadeus shall maintain reasonable and up-to-date anti-malware, anti-spam, and similar controls on networks, systems and devices.
Encryption and Other Security Measures – Strong cryptography and security protocols are deployed for or made available to protect Customer Personal Data while in transit and at rest.
Monitoring and Logging – Amadeus shall log access to information systems containing Customer Personal Data.
Technical Vulnerability Management – Amadeus will maintain a vulnerability management program addressing vulnerabilities in a timely manner based on risk assessments.
Amadeus shall only use third party suppliers who contractually agree to implement appropriate technical and organisational measures that are substantially similar to the Amadeus Technical and Organisational Security Measures.
Amadeus shall have contractual safeguards in place with its third-party suppliers and will carry out reasonable due diligence and monitoring of such third-party suppliers in connection with the provision of the services.
Incident Response Process – Amadeus has a written security incident response plan that includes procedures to be followed to identify, address and report any Security Incident. The plan is regularly tested and has procedures to notify impacted stakeholders.
Investigation and Cooperation in event of Security Incident – In the event of a Security Incident, Amadeus shall promptly take reasonable steps to contain, investigate and mitigate any Security Incident.
Business Continuity – Amadeus has processes, procedures and controls for business continuity that applies to the people, processes and facilities in which Amadeus processes Customer Personal Data. Amadeus shall review the processes, procedures and controls at regular intervals.
Last updated: October 2026