LGPD SCCs
To the extent that these RRA Inbound EU SCCs are intended for use in connection with personal data to which the LGPD (as defined in the Engagement Letter and Addendum thereto) applies, the parties hereby agree to the following:
Section I - General Information
CLAUSE 1. Identification of the Parties
1.1. By this contractual instrument, the Exporter and the Importer (hereinafter, Parties), identified below, agree to adopt the standard contractual clauses (hereinafter Clauses) approved by the Brazilian Data Protection Authority (ANPD), to govern the International Data Transfer described in Clause 2, in accordance with the provisions of Brazilian Legislation.
|
Exporter |
Importer |
|
Name: The entity identified as Client in the Engagement Letter. |
Name: The RRA entity identified in the Engagement Letter. |
|
Address: The address identified in the Engagement Letter. |
Address: The address identified in the Engagement Letter. |
|
Contact Person's Name, position and contact details: As set out in the Engagement Letter. |
Contact Person's Name, position and contact details: Xander Menger, Global Privacy Counsel, xander.menger@russellreynolds.com, +39-340 746 89 82 |
|
Contact for the Data Subject: As set out in the Engagement Letter |
Contact for the Data Subject: privacy@russellreynolds.com |
|
Role: Controller |
Qualification: Controller |
|
Signature and date: As set out in the Engagement Letter |
Signature and date: As set out in the Engagement Letter |
CLAUSE 2. Object
2.1. These Clauses apply to the International Data Transfers from the Exporter to the Importer, as described below.
|
Description of the international data transfer |
The personal data transferred will be processed in accordance with the Engagement Letter and this Addendum and may be subject to the following processing activities: (i) storage and other processing necessary to provide, maintain and improve the Services provided to Client; and (ii) disclosures in accordance with the Engagement Letter, or as compelled by law. |
|
Main purposes of the international data transfers |
To allow RRA to provide executive search and assessment services, and for the purpose of the providing the Services in accordance with the terms of the Engagement Letter (or as otherwise permitted in compliance with Applicable Data Protection Law). |
|
Categories of personal data transferred: |
Candidates:
Clients:
|
|
Retention period (or, if not possible to determine, the criteria used to determine that period):
|
Duration of RRA's engagement under the Engagement Letter (subject to any legal requirement to retain the personal data for a longer period). |
CLAUSE 3. Subsequent Transfers
3.1. The Importer may carry out Subsequent Transfers of the Personal Data subject to the International Data Transfer governed by these Clauses in the cases and under the conditions described below and provided that the provisions of Clause 18 are observed.
|
Main purposes of the international data transfers |
To allow RRA and its affiliates to provide executive search and assessment services, and for the purpose of the providing the Services in accordance with the terms of the Engagement Letter (or as otherwise permitted in compliance with Applicable Data Protection Law). |
|
Categories of personal data transferred: |
Candidates:
Clients:
|
|
Retention period (or, if not possible to determine, the criteria used to determine that period):
|
Duration of RRA's engagement under the Engagement Letter (subject to any legal requirement to retain the personal data for a longer period). |
CLAUSE 4. Responsibilities of the Parties
4.1. Without prejudice to the duty of mutual assistance and the general obligations of the Parties, the Designated Party below, in the capacity of Controller, shall be responsible for fulfilling the following obligations provided for in these Clauses:
a) Responsible for publishing the document provided for in Clause 14; (X) Exporter (X) Importer
b) Responsible for responding to data subject requests as provided for in Clause 15: (X) Exporter (X) Importer
c) Responsible for communicating security incidents as provided for in Clause 16(X) Exporter (X) Importer
4.2. For the purposes of these Clauses, if it is later verified that the Designated Party under item 4.1 acts as a Processor, the Controller shall remain responsible:
a) for fulfilling the obligations provided for in Clauses 14, 15, and 16 and other provisions established in Brazilian Legislation, especially in case of omission or non-compliance with the obligations by the Designated Party;
b) for complying with ANPD's determinations; and
c) for guaranteeing the Data Subjects’ rights and for repairing damages caused, as provided for in Clause 17.
Section II - Mandatory Clauses
CLAUSE 5. Purpose
5.1. These Clauses serve as a mechanism to enable the secure international personal data flow, establish minimum guarantees and valid conditions for the execution of International Data Transfers, and aim to ensure the adoption of appropriate safeguards to comply with the principles, Data Subject’s rights, and the data protection regime provided in Brazilian Legislation.
CLAUSE 6. Definitions
6.1. For the purposes of these Clauses, the definitions in Article 5 of Law No. 13,709, dated August 14, 2018, and Article 3 of the Regulation on International Data Transfers, without prejudice to other normative acts issued by ANPD, shall be considered. The Parties also agree to consider the terms and their respective meanings as outlined below:
a) Data processing agents: the controller and the processor;
b) ANPD: Brazilian Data Protection Authority;
c) Clauses: the standard contractual clauses approved by ANPD, which are part of Sections I, II, and III;
d) Linked Contract: a contractual instrument signed between the Parties or at least between one of them and a third party, including a Third-Party Controller, which has a common purpose, linkage, or dependency relationship with the contract governing the International Data Transfer;
e) Controller: Party or third party ("Third-Party Controller") responsible for decisions regarding the processing of Personal Data;
f) Personal Data: information related to an identified or identifiable natural person;
g) Sensitive Personal Data: personal data on racial or ethnic origin, religious belief, political opinion, membership in a union or organization of a religious, philosophical, or political nature, data concerning health or sexual life, genetic or biometric data when linked to a natural person;
h) Deletion: removal of data or a set of data stored in a database, regardless of the procedure used;
i) Exporter: data processing agent, located in the Brazilian territory or in a foreign country, who transfers personal data to an Importer.
j) Importer: a data processing agent located in a foreign country or an international organization that receives personal data transferred by the Exporter;
k) Brazilian Legislation: the set of Brazilian constitutional, legal, and regulatory provisions regarding the protection of Personal Data, including Law No. 13.709, of August 14, 2018, the International Data Transfer Regulation, and other normative acts issued by the ANPD;
l) Arbitration Law: Law No. 9.307, of September 23, 1996;
m) Security Measures: technical and administrative measures adopted to protect personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination;
n) Research Entity: a body or entity of direct or indirect public administration or a non-profit private legal entity legally constituted under Brazilian laws, headquartered and domiciled in the country, which includes in its institutional mission or social or statutory objective the basic or applied research of a historical, scientific, technological, or statistical nature;
o) Processor: a Party or third party, including a Subcontractor, that processes Personal Data on behalf of the Controller;
p) Designated Party: the Party to the contract designated, under Clause 4 ("Option A"), to fulfill specific obligations related to transparency, data subject rights, and security incident communication as the Controller;
q) Parties: Exporter and Importer;
r) Access Request: a mandatory request, by law, regulation, or public authority determination, to grant access to Personal Data subject to the International Data Transfer governed by these Clauses;
s) Subcontractor: a data processing agent contracted by the Importer, without a link to the
Exporter, to process Personal Data after an International Data Transfer;
t) Third-Party Controller: the Controller of Personal Data who provides written instructions for the execution, on its behalf, of the International Data Transfer between Processors governed by these Clauses, under Clause 4 ("Option B");
u) Data Subject: the natural person to whom the Personal Data subject to the International Data
Transfer governed by these Clauses refers;
v) Transfer: a processing modality whereby a data processing agent transmits, shares, or provides access to Personal Data to another data processing agent;
w) International Data Transfer: the transfer of Personal Data to a foreign country or an international organization of which the country is a member; and
x) Subsequent Transfer: an International Data Transfer originating from an Importer and destined for a third party, including a Subcontractor, provided it does not constitute an Access Request.
CLAUSE 7. Applicable Law and ANPD Oversight
7.1. The International Data Transfer subject to these Clauses is governed by Brazilian Legislation and supervised by the ANPD, including the power to apply preventive measures and administrative sanctions to both Parties, as applicable, as well as to limit, suspend, or prohibit international transfers arising from these Clauses or a Linked Contract.
CLAUSE 8. Interpretation
8.1. Any application of these Clauses must occur according to the following terms:
a) these Clauses must always be interpreted most favorably to the Data Subject and in accordance with the provisions of Brazilian Legislation;
b) in case of doubt about the meaning of terms in these Clauses, the meaning that most aligns with Brazilian Legislation applies.
c) no item of these Clauses, including a Linked Contract and the provisions set forth in Section IV, may be interpreted with the aim of limiting or excluding the liability of any of the Parties concerning obligations under Brazilian Legislation; and
d) the provisions of Sections I and II shall prevail in case of a conflict of interpretation with additional Clauses and other provisions set forth in Sections III and IV of this instrument or Linked Contracts.
CLAUSE 9. Possibility of third-party adherence
9.1. By mutual agreement between the Parties, it is possible for a data processing agent to adhere to these Clauses as an Exporter or Importer by filling out and signing a written document, which will become part of this instrument.
9.2. The adhering party shall have the same rights and obligations as the original Parties, depending on the position assumed as Exporter or Importer and in accordance with the corresponding category of data processing agent.
CLAUSE 10. General Obligations of the Parties
10.1. The Parties commit to adopting and, when necessary, demonstrating the adoption of effective measures capable of proving compliance with the provisions of these Clauses and Brazilian Legislation, including the effectiveness of these measures, and in particular:
a) use Personal Data only for the specific purposes described in Clause 2, without the possibility of subsequent processing incompatible with these purposes, observing, in any case, the limitations, guarantees, and safeguards provided in these Clauses;
b) ensure the compatibility of the data processing with the purposes informed to the Data
Subject, according to the context of the data processing;
c) limit the data processing to the minimum necessary to achieve its purposes, encompassing relevant, proportional, and non-excessive data concerning the purposes of Personal Data processing;
d) ensure to Data Subjects, observing the provisions in Clause 4:
(d.1.) clear, precise, and easily accessible information about the data processing and the respective data processing agents, observing commercial and industrial secrecy;
(d.2.) facilitated and free consultation on the form and duration of the processing, as well as on the entirety of their Personal Data; and
(d.3.) the accuracy, clarity, relevance, and updating of Personal Data, according to the necessity and for the fulfillment of the purpose of their data processing;
e) adopt appropriate security measures compatible with the risks involved in the International
Data Transfer governed by these Clauses;
f) not process Personal Data for illicit or abusive discriminatory purposes;
g) ensure that any person acting under their authority, including subcontractors or any agent collaborating with them, whether free of charge or for a fee, processes data only following their instructions and the provisions of these Clauses; and
h) keep a record of the Personal Data processing operations subject to the International Data Transfer governed by these Clauses, and present the pertinent documentation to the ANPD when requested.
CLAUSE 11. Sensitive personal data
11.1. If the International Data Transfer involves sensitive Personal Data, the Parties shall apply additional safeguards, including specific security measures proportional to the risks of the data processing activity, the specific nature of the data, and the interests, rights, and guarantees to be protected, as described in Section III.
CLAUSE 12. Personal Data of Children and Adolescents
12.1. In the event that the International Data Transfer involves the Personal Data of children and adolescents, the Parties shall apply additional safeguards, including measures that ensure the data
processing is carried out in their best interest, in accordance with Brazilian Legislation and relevant international law instruments.
CLAUSE 13. Lawful Use of Data
13.1. The Exporter guarantees that the Personal Data has been collected, processed, and transferred to the Importer in accordance with Brazilian Legislation.
CLAUSE 14. Transparency
14.1. The Designated Party shall publish, on its website, a document containing easily accessible information written in simple, clear, and precise language about the execution of the International Data Transfer, including at least information on:
a) the form, duration, and specific purpose of the international data transfer;
b) the destination country of the transferred data;
c) the identification and contact details of the Designated Party;
d) the shared use of data by the Parties and the purpose;
e) the responsibilities of the agents who will process the data;
f) the rights of the Data Subject and the means to exercise them, including an easily accessible channel provided for addressing their requests and the right to file a complaint against the Controller before the ANPD; and
g) Subsequent Transfers, including those related to the recipients and the purpose of the transfer.
14.2. The document referred to in item 14.1. may be made available on a specific page or integrated, prominently and easily accessible, into the Privacy Policy or an equivalent document.
14.3. Upon request, the Parties must provide the Data Subject with a copy of these Clauses free of charge, observing commercial and industrial secrecy.
14.4. All information provided to data subjects, under these Clauses, must be written in Portuguese.
CLAUSE 15. Data Subject’s Rights
15.1. The Data Subject has the right to obtain from the Designated Party, regarding the Personal Data subject to the International Data Transfer governed by these Clauses, at any time, and upon request, in accordance with Brazilian Legislation:
a) confirmation of the existence of data processing;
b) access to the data;
c) correction of incomplete, inaccurate, or outdated data;
d) anonymization, blocking, or deletion of unnecessary, excessive data, or data processed in non-compliance with these Clauses and Brazilian Legislation;
e) data portability to another service or product provider, upon express request, in accordance with ANPD regulations, observing commercial and industrial secrecy;
f) deletion of Personal Data processed with the Data Subject's consent, except in cases provided for in Clause 20;
g) information on public and private entities with which the Parties have shared data;
h) information on the possibility of not providing consent and the consequences of refusal;
i) revocation of consent through a free and facilitated procedure, with the processing carried out before the deletion request being ratified.
j) review of decisions made solely based on automated data processing that affect their interests, including decisions intended to define their personal, professional, consumer, and credit profile or aspects of their personality; and
k) information regarding the criteria and procedures used for automated decision-making, observing commercial and industrial secrecy.
15.2. The data subject may object to data processing carried out based on one of the consent waiver hypotheses, in case of non-compliance with the provisions of these Clauses or Brazilian Legislation.
15.3. The deadline for responding to requests provided for in this Clause and item 14.3. is 15 (fifteen) days from the date of the data subject's request, except in cases where a different deadline is established in specific ANPD regulations.
15.4. If the data subject's request is directed to the Party not designated as responsible for the obligations provided for in this Clause or in item 14.3., the Party must:
a) inform the data subject of the service channel provided by the Designated Party; or
b) forward the request to the Designated Party as soon as possible to enable a response within the deadline provided in item 15.2.
15.5. The Parties must immediately inform the Data Processing Agents with whom they have shared data of the correction, deletion, anonymization, or blocking of the data, so that they can repeat the same procedure, except in cases where this communication is proven to be impossible or involves disproportionate effort.
15.6. The Parties must promote mutual assistance to meet the data subjects' requests.
Clause 16. Security Incident Reporting
16.1. The Designated Party must notify the ANPD and the data subjects within 3 (three) business days of the occurrence of a security incident that may pose a risk or significant harm to the data subjects, in accordance with Brazilian Legislation.
16.2. The Importer must keep a record of security incidents as per Brazilian Legislation.
Clause 17. Liability and Compensation for Damages
17.1. The Party that, due to the exercise of personal data processing activities, causes property, moral, individual, or collective damage, in violation of the provisions of these Clauses and Brazilian Legislation, is obliged to repair it.
17.2. The data subject may seek compensation for the damage caused by any of the Parties due to the violation of these Clauses.
17.3. The defense of the data subjects' interests and rights may be sought in court, individually or collectively, as provided in the relevant legislation regarding individual and collective protection instruments.
17.4. The Party acting as the Processor is jointly liable for damages caused by the data processing when it fails to comply with these Clauses or when it has not followed the lawful instructions of the Controller, except as provided in item 17.6.
17.5. Controllers directly involved in the data processing that resulted in damages to the data subject are jointly liable for these damages, except as provided in item 17.6.
17.6. The Parties will not be held liable if it is proven that:
a) they did not carry out the data processing attributed to them;
b) although they carried out the data processing attributed to them, there was no violation of these Clauses or Brazilian Legislation; or
c) the damage is due to the exclusive fault of the data subject or a third party who is not a recipient of Subsequent Transfer or subcontracted by the Parties.
17.7. Under Brazilian Legislation, the judge may reverse the burden of proof in favor of the Data Subject when, in their judgment, the allegation is plausible, there is insufficiency for the purpose of producing evidence, or when the production of evidence by the Data Subject would be excessively burdensome.
17.8. Actions for reparation of collective damages aimed at accountability under this Clause can be collectively exercised in court, in accordance with the relevant legislation.
17.9. The Party that compensates the damage to the data subject has the right of recourse against the other responsible parties, to the extent of their participation in the harmful event.
CLAUSE 18. Safeguards for Subsequent Transfer
18.1. The Importer may only carry out Subsequent Transfers of Personal Data subject to the International Data Transfer governed by these Clauses if expressly authorized, according to the hypotheses and conditions described in Clause 3.
18.2. In any case, the Importer must:
a) ensure that the purpose of the Subsequent Transfer is compatible with the specific purposes described in Clause 2;
b) guarantee, through a written contractual instrument, that the safeguards provided in these Clauses shall be observed by the third-party recipient of the Subsequent Transfer; and
c) for the purposes of these Clauses, and in relation to the transferred Personal Data, be considered responsible for any irregularities committed by the third-party recipient of the Subsequent Transfer.
18.3. The Subsequent Transfer may also be carried out based on another valid mechanism of International Data Transfer provided in the Brazilian Legislation, regardless of the authorization referred to in Clause 3.
CLAUSE 19. Notification of Access Request
19.1. The Importer shall notify the Exporter and the Data Subject about an Access Request related to the Personal Data subject to the International Data Transfer governed by these Clauses, except in cases where notification is prohibited by the law of the country where the data is processed.
19.2. The Importer shall take appropriate legal measures, including judicial actions, to protect the rights of the Data Subjects whenever there is a suitable legal basis to question the legality of the Access Request and, if applicable, the prohibition of making the notification referred to in item 19.1.
19.3. To meet the requests of the ANPD and the Exporter, the Importer must keep a record of Access Requests, including the date, requester, purpose of the request, type of data requested, number of requests received, and legal measures taken.
CLAUSE 20. Termination of Processing and Data Deletion
20.1. The Parties must delete the Personal Data subject to the International Data Transfer governed by these Clauses after the end of data processing, within the scope and technical limits of the activities, with retention allowed only for the following purposes:
a) compliance with a legal or regulatory obligation by the Controller;
b) study by a Research Entity, ensuring, whenever possible, the anonymization of Personal Data;
c) transfer to a third party, provided that the requirements set forth in these Clauses and the Brazilian Legislation are respected; and
d) exclusive use by the Controller, with third-party access prohibited, and provided that the data is anonymized.
20.2. For the purposes of this Clause, the termination of processing is considered to occur when:
a) the purpose provided in these Clauses is achieved;
b) the Personal Data is no longer necessary or relevant to achieve the specific purpose provided in these Clauses;
c) the processing period has ended;
d) the request of the Data Subject has been fulfilled; and
e) determined by the ANPD, when there is a violation of the provisions in these Clauses or the Brazilian Legislation.
CLAUSE 21. Data Processing Security
21.1. The Parties must adopt security measures that ensure the protection of Personal Data subject to the International Data Transfer governed by these Clauses, even after its termination.
21.2. The Parties shall inform, in Section III, the Security Measures adopted, considering the nature of the information processed, the specific characteristics and purpose of the processing, the current state of technology, and the risks to the Data Subjects’ rights, especially in the case of sensitive personal data and data of children and adolescents.
21.3. The Parties must make the necessary efforts to adopt periodic evaluation and review measures to maintain an adequate level of security for the characteristics of the data processing.
CLAUSE 22. Law of the Data Recipient Country
22.1. The Importer declares that it has not identified any laws or administrative practices in the recipient country of the Personal Data that prevent it from fulfilling the obligations assumed in these Clauses.
22.2. In the event of a regulatory change that alters this situation, the Importer shall immediately notify the Exporter for an evaluation of the contract's continuity.
CLAUSE 23. Non-compliance with the Clauses by the Importer
23.1. In the event of a violation of the safeguards and guarantees provided in these Clauses or the impossibility of their compliance by the Importer, the Exporter must be immediately informed, notwithstanding the provisions of item 19.1.
23.2. Upon receiving the communication referred to in item 23.1 or verifying the Importer's non- compliance with these Clauses, the Exporter will take the necessary measures to ensure the protection of the Data Subjects' rights and the compliance of the International Data Transfer with the Brazilian Legislation and these Clauses, which may include, as appropriate:
a) suspending the International Data Transfer;
b) requesting the return of the Personal Data, its transfer to a third party, or its deletion; and c) terminating the contract.
CLAUSE 24. Choice of forum and jurisdiction
24.1. Brazilian legislation applies to these Clauses, and any dispute between the Parties arising from these Clauses shall be resolved before the competent courts of Brazil, observing, if applicable, the forum chosen by the Parties in Section IV.
24.2. Data Subjects may file lawsuits against the Exporter or the Importer, at their choice, before the competent courts in Brazil, including those located in their place of residence.24.3. By mutual agreement, the Parties may resort to arbitration to resolve conflicts arising from these Clauses, provided it is conducted in Brazil and in accordance with the provisions of the Arbitration Law.
Section III - Security Measures
As part of RRA’s efforts in establishing a first-class information security program, RRA has obtained an ISO/IEC 27001:2022 certification. RRA’s most recent certification (1077981-14) was issued on January 24, 2025 and expires on January 25, 2026. The security measures implemented by RRA to protect personal data are as follows:
1. Security Organization
RRA has a security framework which includes decision, reporting, responsibility, and escalation principles and procedures.
a. Risk Management
b. Business Continuity
c. Security incident Management
2. Physical Security
a. Physical Access control
b. Intrusion Detection System
c. Visitor Management
d. Server Room
3. Personnel Security
a. New and Departing Employees
b. Background Checks
4. Information Security
a. Acceptable Use
b. Authorization
c. Training
5. IT Security
RRA ensures all security mechanisms deny access until specifically granted.
a. Connectivity
b. User Account and Password Management
c. Remote Work
d. Malicious Code Protection
e. Backup Measures
f. Encryption
g. Monitoring
h. Patch management