RRA INBOUND BRAZIL SCCs

LGPD SCCs

To the extent that these RRA Inbound EU SCCs are intended for use in connection with personal data to which the LGPD (as defined in the Engagement Letter and Addendum thereto) applies, the parties hereby agree to the following:

 

Section I - General Information

CLAUSE 1. Identification of the Parties

1.1. By this contractual instrument, the Exporter and the Importer (hereinafter, Parties), identified below, agree to adopt the standard contractual clauses (hereinafter Clauses) approved by the Brazilian Data Protection Authority (ANPD), to govern the International Data Transfer described in Clause 2, in accordance with the provisions of Brazilian Legislation.

Exporter

Importer

Name: The entity identified as Client in the Engagement Letter.

Name: The RRA entity identified in the Engagement Letter.

Address: ‌ The address identified in the Engagement Letter.

Address: The address identified in the Engagement Letter.

Contact Person's Name, position and contact details: As set out in the Engagement Letter.

Contact Person's Name, position and contact details: Xander Menger, Global Privacy Counsel, xander.menger@russellreynolds.com, +39-340 746 89 82

Contact for the Data Subject: As set out in the Engagement Letter

Contact for the Data Subject: privacy@russellreynolds.com

Role: Controller

Qualification: Controller

Signature and date: As set out in the Engagement Letter

Signature and date: As set out in the Engagement Letter

 

CLAUSE 2. Object

2.1. These Clauses apply to the International Data Transfers from the Exporter to the Importer, as described below.

Description of the international data transfer

The personal data transferred will be processed in accordance with the Engagement Letter and this Addendum and may be subject to the following processing activities: (i) storage and other processing necessary to provide, maintain and improve the Services provided to Client; and (ii) disclosures in accordance with the Engagement Letter, or as compelled by law.

Main purposes of the international data transfers

To allow RRA to provide executive search and assessment services, and for the purpose of the providing the Services in accordance with the terms of the Engagement Letter (or as otherwise permitted in compliance with Applicable Data Protection Law).

Categories of personal data transferred:

Candidates:

  • Identification data: civil/marital status, first and last name, photograph, date and place of birth, nationality, corporate identifier, gender.

  • Contact details: address, telephone number (fixed and mobile), email address, fax number, emergency contact information.

  • Employment details: CV/résumé, job title, company name, grade, geographic location, employee performance and evaluation data; employee discipline information; information regarding previous roles and employment, employee benefits and prerequisite information; employment agreements and restrictive covenants with prior employers.

  • Academic and professional qualifications: degrees, certificates, titles, licenses, professional memberships, skills, language proficiency, training information.

  • Lifestyle preferences and personality profiles: prior military service, community involvement and memberships, hobbies, social activities, and/or individual's preferences, intellectual capacity, personality, behaviour and/or character traits.

  • Comments from third parties about candidate, including, without limitation, other employees, sources and/or referees.

Clients:

  • Identification data: first and last name, corporate identifier, gender.

  • Contact details: corporate address, telephone number (fixed and mobile), email address, fax number.

  • Role: Job title / role within the Client organization, scope of responsibilities, grade, geographic location.

  • Search parameters / specifications: information received from Clients in connection with the nature of their search requirements, including candidate specifications, preferences and opinions and feedback related to candidates.

Retention period (or, if not possible to determine, the criteria used to determine that period):

 

Duration of RRA's engagement under the Engagement Letter (subject to any legal requirement to retain the personal data for a longer period).

 

CLAUSE 3. Subsequent Transfers

3.1. The Importer may carry out Subsequent Transfers of the Personal Data subject to the International Data Transfer governed by these Clauses in the cases and under the conditions described below and provided that the provisions of Clause 18 are observed.

Main purposes of the international data transfers

To allow RRA and its affiliates to provide executive search and assessment services, and for the purpose of the providing the Services in accordance with the terms of the Engagement Letter (or as otherwise permitted in compliance with Applicable Data Protection Law).

Categories of personal data transferred:

Candidates:

  • Identification data: civil/marital status, first and last name, photograph, date and place of birth, nationality, corporate identifier, gender.

  • Contact details: address, telephone number (fixed and mobile), email address, fax number, emergency contact information.

  • Employment details: CV/résumé, job title, company name, grade, geographic location, employee performance and evaluation data; employee discipline information; information regarding previous roles and employment, employee benefits and prerequisite information; employment agreements and restrictive covenants with prior employers.

  • Academic and professional qualifications: degrees, certificates, titles, licenses, professional memberships, skills, language proficiency, training information.

  • Lifestyle preferences and personality profiles: prior military service, community involvement and memberships, hobbies, social activities, and/or individual's preferences, intellectual capacity, personality, behaviour and/or character traits.

  • Comments from third parties about candidate, including, without limitation, other employees, sources and/or referees.

Clients:

  • Identification data: first and last name, corporate identifier, gender.

  • Contact details: corporate address, telephone number (fixed and mobile), email address, fax number.

  • Role: Job title / role within the Client organization, scope of responsibilities, grade, geographic location.

  • Search parameters / specifications: information received from Clients in connection with the nature of their search requirements, including candidate specifications, preferences and opinions and feedback related to candidates.

Retention period (or, if not possible to determine, the criteria used to determine that period):

 

Duration of RRA's engagement under the Engagement Letter (subject to any legal requirement to retain the personal data for a longer period).

 

CLAUSE 4. Responsibilities of the Parties

4.1. Without prejudice to the duty of mutual assistance and the general obligations of the Parties, the Designated Party below, in the capacity of Controller, shall be responsible for fulfilling the following obligations provided for in these Clauses:

a) Responsible for publishing the document provided for in Clause 14; (X) Exporter (X) Importer

b) Responsible for responding to data subject requests as provided for in Clause 15: (X) Exporter (X) Importer

c) Responsible for communicating security incidents as provided for in Clause 16(X) Exporter (X) Importer

4.2. For the purposes of these Clauses, if it is later verified that the Designated Party under item 4.1 acts as a Processor, the Controller shall remain responsible:

a) for fulfilling the obligations provided for in Clauses 14, 15, and 16 and other provisions established in Brazilian Legislation, especially in case of omission or non-compliance with the obligations by the Designated Party;

b) for complying with ANPD's determinations; and

c) for guaranteeing the Data Subjects’ rights and for repairing damages caused, as provided for in Clause 17.

 

Section II - Mandatory Clauses

CLAUSE 5. Purpose

5.1. These Clauses serve as a mechanism to enable the secure international personal data flow, establish minimum guarantees and valid conditions for the execution of International Data Transfers, and aim to ensure the adoption of appropriate safeguards to comply with the principles, Data Subject’s rights, and the data protection regime provided in Brazilian Legislation.

 

CLAUSE 6. Definitions

6.1. For the purposes of these Clauses, the definitions in Article 5 of Law No. 13,709, dated August 14, 2018, and Article 3 of the Regulation on International Data Transfers, without prejudice to other normative acts issued by ANPD, shall be considered. The Parties also agree to consider the terms and their respective meanings as outlined below:

a) Data processing agents: the controller and the processor;

b) ANPD: Brazilian Data Protection Authority;

c) Clauses: the standard contractual clauses approved by ANPD, which are part of Sections I, II, and III;

d) Linked Contract: a contractual instrument signed between the Parties or at least between one of them and a third party, including a Third-Party Controller, which has a common purpose, linkage, or dependency relationship with the contract governing the International Data Transfer;

e) Controller: Party or third party ("Third-Party Controller") responsible for decisions regarding the processing of Personal Data;

f) Personal Data: information related to an identified or identifiable natural person;

g) Sensitive Personal Data: personal data on racial or ethnic origin, religious belief, political opinion, membership in a union or organization of a religious, philosophical, or political nature, data concerning health or sexual life, genetic or biometric data when linked to a natural person;

h) Deletion: removal of data or a set of data stored in a database, regardless of the procedure used;

i) Exporter: data processing agent, located in the Brazilian territory or in a foreign country, who transfers personal data to an Importer.

j) Importer: a data processing agent located in a foreign country or an international organization that receives personal data transferred by the Exporter;

k) Brazilian Legislation: the set of Brazilian constitutional, legal, and regulatory provisions regarding the protection of Personal Data, including Law No. 13.709, of August 14, 2018, the International Data Transfer Regulation, and other normative acts issued by the ANPD;

l) Arbitration Law: Law No. 9.307, of September 23, 1996;

m) Security Measures: technical and administrative measures adopted to protect personal data from unauthorized access and accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination;

n) Research Entity: a body or entity of direct or indirect public administration or a non-profit private legal entity legally constituted under Brazilian laws, headquartered and domiciled in the country, which includes in its institutional mission or social or statutory objective the basic or applied research of a historical, scientific, technological, or statistical nature;

o) Processor: a Party or third party, including a Subcontractor, that processes Personal Data on behalf of the Controller;

p) Designated Party: the Party to the contract designated, under Clause 4 ("Option A"), to fulfill specific obligations related to transparency, data subject rights, and security incident communication as the Controller;

q) Parties: Exporter and Importer;

r) Access Request: a mandatory request, by law, regulation, or public authority determination, to grant access to Personal Data subject to the International Data Transfer governed by these Clauses;

s) Subcontractor: a data processing agent contracted by the Importer, without a link to the
Exporter, to process Personal Data after an International Data Transfer;

t) Third-Party Controller: the Controller of Personal Data who provides written instructions for the execution, on its behalf, of the International Data Transfer between Processors governed by these Clauses, under Clause 4 ("Option B");

u) Data Subject: the natural person to whom the Personal Data subject to the International Data
Transfer governed by these Clauses refers;

v) Transfer: a processing modality whereby a data processing agent transmits, shares, or provides access to Personal Data to another data processing agent;

w) International Data Transfer: the  transfer of Personal Data to  a foreign country or an international organization of which the country is a member; and

x) Subsequent Transfer: an International Data Transfer originating from an Importer and destined for a third party, including a Subcontractor, provided it does not constitute an Access Request.

 

CLAUSE 7. Applicable Law and ANPD Oversight

7.1. The International Data Transfer subject to these Clauses is governed by Brazilian Legislation and supervised by the ANPD, including the power to apply preventive measures and administrative sanctions to both Parties, as applicable, as well as to limit, suspend, or prohibit international transfers arising from these Clauses or a Linked Contract.

 

CLAUSE 8. Interpretation

8.1. Any application of these Clauses must occur according to the following terms:

a) these Clauses must always be interpreted most favorably to the Data Subject and in accordance with the provisions of Brazilian Legislation;

b) in case of doubt about the meaning of terms in these Clauses, the meaning that most aligns with Brazilian Legislation applies.

c) no item of these Clauses, including a Linked Contract and the provisions set forth in Section IV, may be interpreted with the aim of limiting or excluding the liability of any of the Parties concerning obligations under Brazilian Legislation; and

d) the provisions of Sections I and II shall prevail in case of a conflict of interpretation with additional Clauses and other provisions set forth in Sections III and IV of this instrument or Linked Contracts.

 

CLAUSE 9. Possibility of third-party adherence

9.1. By mutual agreement between the Parties, it is possible for a data processing agent to adhere to these Clauses as an Exporter or Importer by filling out and signing a written document, which will become part of this instrument.

9.2. The adhering party shall have the same rights and obligations as the original Parties, depending on the position assumed as Exporter or Importer and in accordance with the corresponding category of data processing agent.

 

CLAUSE 10. General Obligations of the Parties

10.1. The Parties commit to adopting and, when necessary, demonstrating the adoption of effective measures capable of proving compliance with the provisions of these Clauses and Brazilian Legislation, including the effectiveness of these measures, and in particular:

a) use Personal Data only for the specific purposes described in Clause 2, without the possibility of subsequent processing incompatible with these purposes, observing, in  any case, the limitations, guarantees, and safeguards provided in these Clauses;

b) ensure the compatibility of the data processing with the purposes informed to the Data
Subject, according to the context of the data processing;

c) limit the data processing to the minimum necessary to achieve its purposes, encompassing relevant, proportional, and non-excessive data concerning the purposes of Personal Data processing;

d) ensure to Data Subjects, observing the provisions in Clause 4:

(d.1.) clear, precise, and easily accessible information about the data processing and the respective data processing agents, observing commercial and industrial secrecy;

(d.2.) facilitated and free consultation on the form and duration of the processing, as well as on the entirety of their Personal Data; and

(d.3.) the accuracy, clarity, relevance, and updating of Personal Data, according to the necessity and for the fulfillment of the purpose of their data processing;

e) adopt appropriate security measures compatible with the risks involved in the International
Data Transfer governed by these Clauses;

f) not process Personal Data for illicit or abusive discriminatory purposes;

g) ensure that any person acting under their authority, including subcontractors or any agent collaborating with them, whether free of charge or for a fee, processes data only following their instructions and the provisions of these Clauses; and

h) keep a record of the Personal Data processing operations subject to the International Data Transfer governed by these Clauses, and present the pertinent documentation to the ANPD when requested.

 

CLAUSE 11. Sensitive personal data

11.1. If the International Data Transfer involves sensitive Personal Data, the Parties shall apply additional safeguards, including specific security measures proportional to the risks of the data processing activity, the specific nature of the data, and the interests, rights, and guarantees to be protected, as described in Section III.

 

CLAUSE 12. Personal Data of Children and Adolescents

12.1. In the event that the International Data Transfer involves the Personal Data of children and adolescents, the Parties shall apply additional safeguards, including measures that ensure the data 
processing is carried out in their best interest, in accordance with Brazilian Legislation and relevant international law instruments.

 

CLAUSE 13. Lawful Use of Data

13.1. The Exporter guarantees that the Personal Data has been collected, processed, and transferred to the Importer in accordance with Brazilian Legislation.

 

CLAUSE 14. Transparency

14.1. The Designated Party shall publish, on its website, a document containing easily accessible information written in simple, clear, and precise language about the execution of the International Data Transfer, including at least information on:

a) the form, duration, and specific purpose of the international data transfer;

b) the destination country of the transferred data;

c) the identification and contact details of the Designated Party;

d) the shared use of data by the Parties and the purpose;

e) the responsibilities of the agents who will process the data;

f) the rights of the Data Subject and the means to exercise them, including an easily accessible channel provided for addressing their requests and the right to file a complaint against the Controller before the ANPD; and

g) Subsequent Transfers, including those related to the recipients and the purpose of the transfer.

14.2. The document referred to in item 14.1. may be made available on a specific page or integrated, prominently and easily accessible, into the Privacy Policy or an equivalent document.

14.3. Upon request, the Parties must provide the Data Subject with a copy of these Clauses free of charge, observing commercial and industrial secrecy.

14.4. All information provided to data subjects, under these Clauses, must be written in Portuguese.

 

CLAUSE 15. Data Subject’s Rights

15.1. The Data Subject has the right to obtain from the Designated Party, regarding the Personal Data subject to the International Data Transfer governed by these Clauses, at any time, and upon request, in accordance with Brazilian Legislation:

a) confirmation of the existence of data processing;

b) access to the data;

c) correction of incomplete, inaccurate, or outdated data;

d) anonymization, blocking, or deletion of unnecessary, excessive data, or data processed in non-compliance with these Clauses and Brazilian Legislation;

e) data portability to another service or product provider, upon express request, in accordance with ANPD regulations, observing commercial and industrial secrecy;

f) deletion of Personal Data processed with the Data Subject's consent, except in cases provided for in Clause 20;

g) information on public and private entities with which the Parties have shared data;

h) information on the possibility of not providing consent and the consequences of refusal;

i) revocation of consent through a free and facilitated procedure, with the processing carried out before the deletion request being ratified.

j) review of decisions made solely based on automated data processing that affect their interests, including decisions intended to define their personal, professional, consumer, and credit profile or aspects of their personality; and

k) information regarding the criteria and procedures used for automated decision-making, observing commercial and industrial secrecy.

15.2. The data subject may object to data processing carried out based on one of the consent waiver hypotheses, in case of non-compliance with the provisions of these Clauses or Brazilian Legislation.

15.3. The deadline for responding to requests provided for in this Clause and item 14.3. is 15 (fifteen) days from the date of the data subject's request, except in cases where a different deadline is established in specific ANPD regulations.

15.4. If the data subject's request is directed to the Party not designated as responsible for the obligations provided for in this Clause or in item 14.3., the Party must:

a) inform the data subject of the service channel provided by the Designated Party; or

b) forward the request to the Designated Party as soon as possible to enable a response within the deadline provided in item 15.2.

15.5. The Parties must immediately inform the Data Processing Agents with whom they have shared data of the correction, deletion, anonymization, or blocking of the data, so that they can repeat the same procedure, except in cases where this communication is proven to be impossible or involves disproportionate effort.

15.6. The Parties must promote mutual assistance to meet the data subjects' requests.

 

Clause 16. Security Incident Reporting

16.1. The Designated Party must notify the ANPD and the data subjects within 3 (three) business days of the occurrence of a security incident that may pose a risk or significant harm to the data subjects, in accordance with Brazilian Legislation.

16.2. The Importer must keep a record of security incidents as per Brazilian Legislation.

 

Clause 17. Liability and Compensation for Damages

17.1. The Party that, due to the exercise of personal data processing activities, causes property, moral, individual, or collective damage, in violation of the provisions of these Clauses and Brazilian Legislation, is obliged to repair it.

17.2. The data subject may seek compensation for the damage caused by any of the Parties due to the violation of these Clauses.

17.3. The defense of the data subjects' interests and rights may be sought in court, individually or collectively, as provided in the relevant legislation regarding individual and collective protection instruments.

17.4. The Party acting as the Processor is jointly liable for damages caused by the data processing when it fails to comply with these Clauses or when it has not followed the lawful instructions of the Controller, except as provided in item 17.6.

17.5. Controllers directly involved in the data processing that resulted in damages to the data subject are jointly liable for these damages, except as provided in item 17.6.

17.6. The Parties will not be held liable if it is proven that:

a) they did not carry out the data processing attributed to them;

b) although they carried out the data processing attributed to them, there was no violation of these Clauses or Brazilian Legislation; or

c) the damage is due to the exclusive fault of the data subject or a third party who is not a recipient of Subsequent Transfer or subcontracted by the Parties.

17.7. Under Brazilian Legislation, the judge may reverse the burden of proof in favor of the Data Subject when, in their judgment, the allegation is plausible, there is insufficiency for the purpose of producing evidence, or when the production of evidence by the Data Subject would be excessively burdensome.

17.8. Actions for reparation of collective damages aimed at accountability under this Clause can be collectively exercised in court, in accordance with the relevant legislation.

17.9. The Party that compensates the damage to the data subject has the right of recourse against the other responsible parties, to the extent of their participation in the harmful event.

 

CLAUSE 18. Safeguards for Subsequent Transfer

18.1. The Importer may only carry out Subsequent Transfers of Personal Data subject to the International Data Transfer governed by  these  Clauses if  expressly authorized, according to  the hypotheses and conditions described in Clause 3.

18.2. In any case, the Importer must:

a) ensure that the purpose of the Subsequent Transfer is compatible with the specific purposes described in Clause 2;

b) guarantee, through a written contractual instrument, that the safeguards provided in these Clauses shall be observed by the third-party recipient of the Subsequent Transfer; and

c) for the purposes of these Clauses, and in relation to the transferred Personal Data, be considered responsible for any irregularities committed by the third-party recipient of the Subsequent Transfer.

18.3.  The  Subsequent Transfer may  also  be  carried  out  based  on  another valid  mechanism of International Data Transfer provided in the Brazilian Legislation, regardless of the authorization referred to in Clause 3.

 

CLAUSE 19. Notification of Access Request

19.1. The Importer shall notify the Exporter and the Data Subject about an Access Request related to the Personal Data subject to the International Data Transfer governed by these Clauses, except in cases where notification is prohibited by the law of the country where the data is processed.

19.2. The Importer shall take appropriate legal measures, including judicial actions, to protect the rights of the Data Subjects whenever there is a suitable legal basis to question the legality of the Access Request and, if applicable, the prohibition of making the notification referred to in item 19.1.

19.3. To meet the requests of the ANPD and the Exporter, the Importer must keep a record of Access Requests, including the date, requester, purpose of the request, type of data requested, number of requests received, and legal measures taken.

 

CLAUSE 20. Termination of Processing and Data Deletion

20.1. The Parties must delete the Personal Data subject to the International Data Transfer governed by these Clauses after the end of data processing, within the scope and technical limits of the activities, with retention allowed only for the following purposes:

a) compliance with a legal or regulatory obligation by the Controller;

b) study by a Research Entity, ensuring, whenever possible, the anonymization of Personal Data;

c) transfer to a third party, provided that the requirements set forth in these Clauses and the Brazilian Legislation are respected; and

d) exclusive use by the Controller, with third-party access prohibited, and provided that the data is anonymized.

20.2. For the purposes of this Clause, the termination of processing is considered to occur when:

a) the purpose provided in these Clauses is achieved;

b) the Personal Data is no longer necessary or relevant to achieve the specific purpose provided in these Clauses;

c) the processing period has ended;

d) the request of the Data Subject has been fulfilled; and

e) determined by the ANPD, when there is a violation of the provisions in these Clauses or the Brazilian Legislation.

 

CLAUSE 21. Data Processing Security

21.1. The Parties must adopt security measures that ensure the protection of Personal Data subject to the International Data Transfer governed by these Clauses, even after its termination.

21.2. The Parties shall inform, in Section III, the Security Measures adopted, considering the nature of the information processed, the specific characteristics and purpose of the processing, the current state of technology, and the risks to the Data Subjects’ rights, especially in the case of sensitive personal data and data of children and adolescents.

21.3. The Parties must make the necessary efforts to adopt periodic evaluation and review measures to maintain an adequate level of security for the characteristics of the data processing.

 

CLAUSE 22. Law of the Data Recipient Country

22.1. The Importer declares that it has not identified any laws or administrative practices in the recipient country of the Personal Data that prevent it from fulfilling the obligations assumed in these Clauses.

22.2. In the event of a regulatory change that alters this situation, the Importer shall immediately notify the Exporter for an evaluation of the contract's continuity.

 

CLAUSE 23. Non-compliance with the Clauses by the Importer

23.1. In the event of a violation of the safeguards and guarantees provided in these Clauses or the impossibility of  their  compliance by  the  Importer,  the  Exporter  must  be  immediately informed, notwithstanding the provisions of item 19.1.

23.2. Upon receiving the communication referred to in item 23.1 or verifying the Importer's non- compliance with these Clauses, the Exporter will take the necessary measures to ensure the protection of the Data Subjects' rights and the compliance of the International Data Transfer with the Brazilian Legislation and these Clauses, which may include, as appropriate:

a) suspending the International Data Transfer;

b) requesting the return of the Personal Data, its transfer to a third party, or its deletion; and c) terminating the contract.

 

CLAUSE 24. Choice of forum and jurisdiction

24.1. Brazilian legislation applies to these Clauses, and any dispute between the Parties arising from these Clauses shall be resolved before the competent courts of Brazil, observing, if applicable, the forum chosen by the Parties in Section IV.

24.2. Data Subjects may file lawsuits against the Exporter or the Importer, at their choice, before the competent courts in Brazil, including those located in their place of residence.24.3. By mutual agreement, the Parties may resort to arbitration to resolve conflicts arising from these Clauses, provided it is conducted in Brazil and in accordance with the provisions of the Arbitration Law.

 

Section III - Security Measures

As part of RRA’s efforts in establishing a first-class information security program, RRA has obtained an ISO/IEC 27001:2022 certification.  RRA’s most recent certification (1077981-14) was issued on January 24, 2025 and expires on January 25, 2026. The security measures implemented by RRA to protect personal data are as follows:

1. Security Organization

RRA has a security framework which includes decision, reporting, responsibility, and escalation principles and procedures.

a. Risk Management

  • RRA has formal Risk Management Committee (ISMS Committee) that manages and is responsible for enterprise security risk issues.
  • Security risk issues are reviewed regularly by considering the threats, possible business impacts and probabilities.

b. Business Continuity

  • RRA has a Disaster Recovery and Business Continuity Plan that covers technology, offices, and personnel.  This plan is reviewed bi-annually and engages personnel at all levels of the organization.

c. Security incident Management

  • RRA has a form Cyber Incident Response Plan designed to prevent further damages caused by Security Incidents.

2. Physical Security

a. Physical Access control

  • RRA has a physical access control system (or equivalent) which limits individuals’ access to buildings, rooms, and areas where personal data is maintained. Access control cards are granted to individuals (no collective or shared key cards are issued).

b. Intrusion Detection System 

  • RRA has an intrusion detection system covering the areas where personal data is stored and/or processed.

c. Visitor Management

  • RRA has a security system in place which limits physical and informational access by visitors where personal information is stored and/or processed.

d. Server Room

  • RRA has an electronic access control system which limits physical access to the server room only to authorized individuals.
  • Each server room has adequate fire protection such as a CO2 portable fire extinguisher or an automatic fire extinguishing system depending on the size and the criticality of the information stored on the servers.

3. Personnel Security

a. New and Departing Employees

  • RRA has security procedures in place for entry of new employees and exiting of departing personnel.

b. Background Checks

  • The reliability and professional aptitude of all RRA employees are verified before assigning roles in the organization.

4. Information Security

a. Acceptable Use

  • RRA’s has in place an Internet & Electronic Tool Acceptable Use Policy which restricts the use of electronic devices and RRA network resources. All employees, contractors, consultants, temporary workers, and visitors are subject to the policy.

b. Authorization

  • The number of people having access to personal data shall be restricted.
  • Access to personal data allowed only to such persons whose work-related tasks require access to personal data.
  • Sufficient audit trail collected of use of the access rights, including all changes made and, where appropriate given the nature of the personal data, views (e.g., who, what, when).
  • Access rights are granted in an organized manner according to agreed internal procedures.
  • Access rights are only granted by approved responsible managers (audit trail of approvals required).
  • Access to personal data is promptly terminated when an employee ceases employment.

c. Training

  • Employees are trained on the importance of IT and personal data security.
  • Yearly Information security training is conducted, and monthly phishing campaigns are performed to increase security awareness

5.  IT Security

RRA ensures all security mechanisms deny access until specifically granted.

a. Connectivity

  • RRA offices and data centers are connected over a secure private network via an encrypted connections.

b. User Account and Password Management

  • RRA maintains a process for user account management which defines policies for approving, creating, and terminating users’ access to RRA IT systems.
  • RRA’s policy for password management meets industry standards.
  • User accounts are locked after five unsuccessful attempts to gain access to the account.

c. Remote Work

  • RRA has remote network access capabilities and accompanying remote work policies and guidelines in place.
  • Remote access systems are properly guarded, equipped with firewalls, antivirus protection, and two factor authentication

d. Malicious Code Protection

  • RRA has automated an up-to-date malicious code protection (e.g., antivirus and antimalware system) to cover all workstations and servers.

e. Backup Measures

  • All e-mails are archived and replicated between our global data centers and stored for a period of one year. E-mails may also be tagged for longer retention by RRA employees and stored for a maximum of seven years or until deleted manually. 
  • All personal data stored in RRA proprietary applications for as long as necessary or until such earlier time as instructed by client to delete the data. 
  • Documents, memos, and other associated personal data are stored in a document management system for the lifetime of the data.  
  • All of the above personal data is replicated between multiple global data centers and backed up at each data center according to the retention policies below:
    • Daily Backups:
      • 30 Days for critical systems both on local disk and encrypted cloud storage
      • 15 days for non-critical systems both on local disk and encrypted cloud storage
    • Monthly Backups:
      • 7-years on to encrypted cloud storage

f. Encryption

  • Transport layer security (TLS) is used to encrypt information as it passes through the Internet, not only in e-mails, but also in Web browsing, instant messaging, and voice-over intellectual property.
  • All enpoints are encrypted to industry standards to maintain confidentiality of information

g. Monitoring

  • RRA conducts reasonable monitoring of its systems for unauthorized use of or access to personal data.

h. Patch management

  • RRA applies operating system and software patches on a timely basis