Global Privacy Notice
HQ Royal Signals and RSTL Data Protection and Privacy Policy
Dated June 2026
How we will use your information when you give your data to HQ Royal Signals
HQ Royal Signals and the Royal Signals Charity takes active decisions in the processing of data subjects’ personal data and is bound by the Data Protection Act 2018, UK GDPR and the Data Usage Act 2026 legislation.
This policy explains why we ask for your personal information, how we store and use it, who we may share it with, and what your rights are.
This policy covers the following data collection reasons:
- You sign up to a membership or subscription.
- You book onto an event run by the Royal Signals Charity, Royal Signals Association or Royal Signals Institution.
- You submit a story for one of our publications or social media platforms.
- You request a moral and efficiency grant.
- You request benevolence assistance.
Why we ask for your personal information
We want you to be part of our Corps family throughout your career and beyond. We want to be able to contact you about Corps events and support you if you require benevolence assistance.
By consenting to us holding your information, we can administer any memberships and subscriptions and you can be the first to know about exciting events.
How we collect personal data
We collect personal information when you:
- Register online, request information or submit an application through our website.
- Complete a printed form, questionnaire or coupon.
- Contact us by phone, post, email or text message.
- Visit our websites. Information is automatically captured each time you visit. We use cookies and collect IP addresses to track visitors to our websites and prepare management reports.
Your personal data: the legal basis and what we collect
We will need to collect personal data in some cases to carry out a service with you. In other cases, we will tell you if providing personal data is optional.
Consent
We will ask for your consent to collect your personal information for the following:
- To send you newsletters and information about events.
- To include you in photography or filming taking place at events.
- To enable the collection of Gift Aid.
Contract
We may collect your personal information to perform a contract with you for the following services:
- Membership and subscription renewals.
- Online bookings and enquiries.
- Collection of payments through Direct Debit or other chosen forms of payment, including direct through wages for Days Pay Giving.
- Publishing an article that has been submitted to us.
Legal obligation
We will collect your personal information to comply with a legal obligation, such as:
- Requests made under data protection law.
We will also hold personal data of people who have written to us or left comments in the Last Post.
When we ask you to provide your personal information, we will let you know why we are asking, how we will use your data, and direct you towards this policy for more information.
How we use your data
Days Pay Giving – Serving Only
Being part of Days Pay Giving entitles you to a host of support and financial grants.
Corps Funds support welfare and benevolence for serving and retired members of the Corps, their relatives and dependants. It also supports Sport and Adventurous Training (AT) and other morale and efficiency activities.
Data collected for Days Pay Giving
- Rank
- Name
- Service Number
- Amount paying
- Unit address
- Length of Service
- Service Type
- Date of Birth
Data collected for AT, sports and other morale/efficiency grants
- Rank
- Name
- Service Number
- Amount paying
- Unit address
Royal Signals Association (RSA)
The Association exists to serve all members and ex-members of the Corps. It aims to foster comradeship within the Corps family and promotes the charitable work of the Royal Signals Benevolent Fund (RSBF).
Data collected
- Rank on leaving service
- Name
- Service Number
- Amount paying
- Postal and email addresses
- Phone numbers
- Gift Aid status
- Length of Service
- Service Type
Royal Signals Institution (RSI)
The Royal Signals Institution fosters professional development amongst serving and retired personnel of the Royal Corps of Signals and their close colleagues in Defence and Industry.
Membership of the Institution entitles you to two copies of The Journal a year and invitations to lectures and events held throughout the year.
Data collected
- Rank on leaving service
- Name
- Service Number
- Amount paying
- Postal and email addresses
- Phone numbers
- Gift Aid status
- Length of Service
- Service Type
Benevolence
Serving or former Royal Signals personnel are entitled to benevolence from the Royal Signals Benevolent Fund.
Information from case workers from associated charities such as the Royal British Legion and SSAFA is shared with us so the RSBF can assess eligibility for financial assistance.
We hold this information on our secure database for six years to comply with financial regulations.
Data collected
- Rank on leaving service
- Name
- Service Number
- Amount of grant awarded
- Reason for award
- Length of Service
Donations
Where you are currently serving, ex-Corps or a family member and would like to donate to the RSBF without belonging to another subscription or membership, we collect the following information to process your donation.
Data collected
- Name
- Postal and email addresses
- Phone numbers
- Gift Aid status
- Amount paying
If serving or ex-Corps, we may also collect the following to see if we already hold a record for you:
- Service Number
- Rank on leaving service
- Service Dates
- Commission Type
- RSA Membership Number
Corps event registration
Data collected
- Full name
- Service Number
- Postal and email addresses
- Phone numbers
- Car registration and nationality, if the function is on Blandford Camp
- Full name of additional attendees
- Dietary requirements
Publications and social media
HQ Royal Signals collects your data in order to reference who has submitted an article for use on our digital channels.
This could be for publication in The Wire or The Journal, or on one of our social media platforms.
The information enables us to identify you, contact you if we require further information about your article and/or accompanying photographs, and obtain consent for the use of the article and accompanying photographs.
Data collected
- Name
- Service Number
- Unit Address
- MOD email address
- Contact telephone number
You may withdraw consent for this processing before an article is published by contacting socialmedia@royalsignals.org.
We will remove articles from social media and online publications where practicable. However, we are unable to withdraw material from printed publications.
Who your data is shared with
The data collected is shared with HQ Royal Signals and the organisations that fall under Royal Signals Trustees Limited.
These organisations are:
- The Royal Signals Benevolent Fund
- The Royal Signals Association
- The Royal Signals Institution
These organisations support you through your service and retirement and offer events, publications and subscriptions that may be of interest.
A small amount of marketing is used, inviting you to events and supplying you with information we believe you may be interested in.
Publications
If you subscribe to a publication, your address details are given to the publishers in order to send you the publication.
We have a strict agreement with the publishers about how they must treat your information. It is only held there until the publication is distributed.
Events
If an event is held on Blandford Garrison, the event organiser will share the following information with the Guardroom to allow access onto the site:
- Title, first name, family name and nationality of the registrant.
- Car registration number if using the on-site car park.
How we store your information
The personal information you consent to give us is stored on our customer relationship management database.
This database is used by members of HQ Royal Signals and the Royal Signals Charity, the Royal Signals Benevolent Fund, the Royal Signals Association and the Royal Signals Institution.
This is a fully managed system and procedures and policies are in place to keep your information protected from misuse in accordance with data protection regulations.
How long we keep your information
Your information is kept in accordance with our retention policy.
If you have a subscription and pay us money every year, we will hold your data for six years after this service has stopped.
If you have consented for us to contact you about future events, we will maintain your record until you tell us you would like us to delete it.
We will therefore retain your data:
- Until you inform us that you no longer wish the Charity to communicate with you.
- While you are a member of any association or membership or have a subscription.
- As required under UK law; for seven years in the case of financial transactions.
Your rights
When we ask you for information, we will keep to the law, including the Data Protection Regulations 2018 and UK General Data Protection Regulations.
At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
Right of access
You have the right to request a copy of the information that we hold about you.
Right of rectification
You have the right to correct data that we hold about you that is inaccurate or incomplete.
Right to be forgotten
In certain circumstances, you can ask for the data we hold about you to be erased from our records.
Right to restriction of processing
Where certain conditions apply, you have the right to restrict processing.
Right of portability
You have the right to have the data we hold about you transferred to another organisation.
Right to object
You have the right to object to certain types of processing, such as direct marketing.
Right to object to automated processing, including profiling
You have rights in relation to the legal effects of automated processing or profiling.
Right to judicial review
In the event that Royal Signals Trustee Ltd refuses your request under rights of access, we will provide you with a reason why.
You have the right to see the information that we hold about you at any time by submitting a Subject Access Request (SAR) in writing to the Data Protection Adviser.
How to opt out
You may request to opt out of any of these services or have your details deleted from the database at any time by contacting the Data Protection Adviser in writing and letting us know your preferences.
Data Protection Adviser
DPA
HQ Royal Signals
Griffin House
Blandford Camp
Dorset
DT11 8RH
Email: commandengagement@royalsignals.org
Data Controller
Our Data Controller is the Secretary to the Board of Trustees:
Corps Secretary
Griffin House
Blandford Camp
Dorset
DT11 8RH
Email: rsignalshq-corpssec-seo@mod.gov.uk
How to complain if you are not happy
If you are unhappy with any aspect of this privacy notice or how your personal information is being processed, please initially contact:
DPA
HQ Royal Signals
Griffin House
Blandford Camp
Dorset
DT11 8RH
Email: commandengagement@royalsignals.org
We will acknowledge the complaint within 30 days and respond without undue delay.
If you are not satisfied with the response to the complaint, you can contact:
MOD Information Rights Team
Ground Floor, Zone D
Main Building
Whitehall
London
SW1A 2HB
Email: cio-dpa@mod.gov.uk
For independent advice about data protection, privacy and data-sharing issues, you can contact:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Phone: 08456 30 60 60
Fax: 01625 524510
Website: www.ico.gov.uk
Annex A – Website Cookies
Use of our website and cookies
To improve your experience and make this website simpler to use, we sometimes place small amounts of information on your computer, mobile phone or device. These include small files known as cookies.
The cookies used on this website improve your experience by:
- Recognising your settings, so you don't need to keep re-entering them whenever you visit a new page.
- Remembering information that you've given, such as your username and password, so you don't need to keep entering it.
- Measuring how you use our website so we can make improvements that meet your needs.
- Tracking the websites that you use so advertising using third-party networks is better targeted and more relevant to you.
Our cookies contain anonymous information such as a unique identifier, but this information is not used to identify you personally.
Types of cookies
The cookies used on this website can be grouped into the following categories:
1. Strictly necessary cookies
Required to enable you to move around the website and use essential features.
2. Performance cookies
Collect information about how you use our website and help us improve performance and provide a better user experience.
3. Functionality cookies
Enhance the functionality of the website by storing your preferences.
4. Targeting cookies
Used by advertising networks to track your browsing across the internet whilst enabling us to enhance our website with services provided by third parties.
Some cookies are set directly by the website. Others are set by third parties when you visit the website.
Third-party cookies include those set by advertising networks, partners we use for web analytics, and external websites delivering embedded content and videos, such as YouTube.
Cookies are stored on your computer for different lengths of time depending on what they are used for.
Session cookies are temporary cookies and are only stored until you leave the website or close your web browser.
Persistent cookies last for a fixed period of time, defined within the cookie, and allow the website to recognise the device and track repeat visits.
We do not sell the information collected by cookies.
How can I control cookies?
If you don't want to receive cookies, you can change your browser settings to reject new cookies or delete those that have already been set.
You can choose to accept or reject functionality and targeting cookies set by the Royal Signals website on the cookie settings page and can change these settings at any time.
You will also be given the opportunity to change your cookie settings when you first visit our website.
You can accept or reject functionality or targeting cookies at any time by changing your cookie settings, although third-party advertising networks may continue to use information previously collected through targeting cookies.
If you create an online account, you may be asked to accept cookies required for the online application when you register or log in.
You can also opt out of tracking and targeting cookies by following instructions provided on the appropriate third-party websites.
To learn more about cookies in general and how to manage them, visit www.aboutcookies.org.
Strictly necessary cookies
Strictly necessary cookies enable you to move around the website and use essential features. These cookies don't collect information that is used to identify you personally.
Strictly necessary cookies listed in the policy
ASP.NET_SessionId
Used to maintain an anonymous user session to enable navigation around the website and use of an account.
cookiePolicyAccept
Used to remember the cookie settings for your account.
Performance cookies
Performance cookies collect information about how you use our website and help us improve performance and provide a better user experience.
Cookies of this type collect information about the pages you visit, which videos you watch and whether you experience any errors.
The information collected is anonymous and is used to help improve how the website works and understand what interests users.
We may use independent web analytics companies to measure and report on the performance of our website. As a result, some performance cookies may be set by third parties.
Performance cookies listed in the policy
Google Analytics – _ga
Used to collect information about how you use our website. This data is shared with Google Analytics, which provides analysis and reporting services.
Annex B – Royal Signals Institution Corporate Membership
Data Collection and Privacy Notice
Who is the Data Controller?
Director Royal Signals Institution, a permanent employee of Royal Signals Trust Limited (RSTL).
Why we ask for your personal information
The Institution asks for personal information for the following reasons.
Process membership donations
Membership donations are collected annually for current and new Corporate Members.
In doing so, we collect and hold a business point-of-contact email address for each member company. This is stored alongside the amount donated, invoice number and payment date and is then held to trigger annual renewal.
Event administration
Corporate, serving and retired members may attend lectures, seminars and the RSI Dinner and Awards ceremony.
To administer these events, the RSI must collect contact details and personal information such as dietary requirements and vehicle registrations.
Information requirements vary depending on the event and the information is destroyed once the event is completed.
Information will only be shared with operationally essential personnel. For example, this includes security staff for access control purposes and caterers to capture dietary requirements.
Legal basis for processing
Consent
Information we collect
Membership information
- Business point-of-contact full name
- Postal address
- Email address
RSI event administration for attendees
- Name
- Role
- Organisation
- Contact email address
- Contact mobile number
- Vehicle registration
- Any special dietary requirements
How we will use your information
Membership administration
We use the information to contact the business point of contact to complete membership administration, set up payments and communicate information covering events.
RSI event administration
We use attendee data to complete event planning and administration.
This includes issuing invitations, planning catering and managing access control to various sites. Requirements vary between military locations and civilian corporate locations.
The Journal of the Royal Corps of Signals
Corporate members' physical addresses are used to distribute printed copies of The Journal.
Who your data is shared with
- Membership donation invoices are shared with the RSTL accountant only. No membership information is shared.
- Event attendee information may be shared with security staff for entry to military and corporate sites.
- Dietary information will be shared with catering staff.
How we store your information
Information is stored electronically on MODNet and is subject to security protection as MOD OFFICIAL SENSITIVE documentation.
Physical addresses of corporate members are also stored on the charity database held on a MOD system to support distribution of printed copies of The Journal.
How long we keep your information
- Membership information will be stored for the duration of an organisation's RSI membership and for one year after membership ceases.
- Financial information is retained for seven years after membership ceases.
- Event-related information is stored for the duration of event planning, execution and closure. This will vary and is typically several months, after which it is deleted from the IT system.
Your rights
You have rights concerning access, rectification, erasure, restriction of processing, portability, objection, automated processing and profiling.
You may submit a Subject Access Request (SAR) in writing to the Data Protection Adviser using the contact details given in the main Privacy Policy.
For further information or to make a complaint, you may also contact the Information Commissioner's Office.
Annex C
Emerald City (including its affiliates and subsidiaries, "Emerald City" or "We") value your privacy and is committed to protecting it. This Privacy Notice explains how we collect, use, share, and store personal information about you. It also outlines your rights regarding your personal data and how to exercise them.
This privacy notice applies to personal data we collect through #INSERT THIS URL or other websites that Emerald City operates that link to this policy ("collectively Websites"), as well as through our products and related service offerings. If you have any questions or concerns about how we handle your personal data, please contact us using the contact information provided at the end of this document.
The personal information we may collect falls into the following categories:
Information You Provide Voluntarily: Certain areas of our websites may require you to provide personal information willingly, such as when you register for an account, request technical support, subscribe to marketing communications, sign up for events, access content, or submit enquiries. We will clearly inform you of the data we collect and the reasons for collecting it at the point of collection.
Information Collected Automatically: When you visit our websites, we may automatically collect certain information from your device. In some jurisdictions, including those in the European Economic Area, this information may be considered personal data under applicable data protection laws. This information may include your IP address, device type, unique device identifiers, browser type, broad geographic location (country or city level), and other technical data. We may also collect information about how your device interacts with our websites, such as the pages you access and links you click.
Collecting this information allows us to better understand who visits our websites, where they come from, and which content they find most relevant. We use this information for internal analytics and to improve the quality and relevance of our websites for our visitors. Some of this information may be collected using cookies and similar tracking technologies.
Information Obtained from Third Parties: Occasionally, we may receive personal information about you from third-party sources, such as lead generation providers, partners, content syndication providers, third-party enrichment tools, or meeting maker vendors. We only collect information from third parties that have your consent or are otherwise legally permitted to share it with us. The types of information we collect from third parties include name, contact information, job title, Emerald City data, and internet activity. We use this information to market our services to you.
Sensitive Personal Data: We may collect sensitive personal data, or special category personal data, from our customers in the course of providing our services. We do not use sensitive personal data for any other commercial purpose, we do not sell sensitive personal data, and we do not share sensitive personal data for online advertising.
We are committed to protecting your personal data. We implement appropriate technical and organisational security measures to protect your personal data from unauthorised access, use, disclosure, alteration, destruction, or accidental loss.
Who do Emerald City Share Your Personal Data With?
We may share your personal data with the following categories of recipients:
Our group companies and third-party service providers: We may share your data with our affiliated companies and external service providers who assist us in providing our services and products, supporting our websites, or enhancing their security.
Our partners: We may share your data with our partners who collaborate with us in selling or distributing our products and services, or engaging in joint marketing activities, subject to your marketing preferences. We will not share text messaging originator opt-in data and consent with any third parties.
Law enforcement, regulatory bodies, and government agencies: We may disclose your data to competent law enforcement bodies, regulators, government agencies, courts, or other third parties when we believe disclosure is necessary to comply with applicable laws or regulations, enforce our legal rights, protect your vital interests or those of others, or investigate potential wrongdoing.
Other third parties with your consent: We may disclose your data to other third parties with your explicit consent. We may share this data with the following categories for business purposes or for commercial purposes, including sale/online advertising:
Emerald City Knowledge of Personal Data Sales
Emerald City has no actual knowledge that it sells or shares the personal information of individuals under 16 years of age.
Legal Basis for Processing Personal Data
The foundation upon which we collect and utilise the personal information described above is contingent on the specific data type and the context in which it is obtained. Typically, we will gather your personal information only if:
We need the data to fulfil our obligations under a contract we have with you.
Our legitimate interests dictate it: Processing personal data is essential to operate our platform and communicate with you as needed. For instance, when responding to your enquiries, analysing platform usage, improving our services, marketing to existing customers within legal limits, and identifying or preventing illegal activities.
You consent: You have granted us explicit authorisation to process your personal data.
In certain situations, we may also be legally obligated to collect your personal information or require it to safeguard your or someone else's vital interests. If we request your personal information to comply with a legal obligation or fulfil a contract, we will clearly inform you at the appropriate time and advise you whether providing your personal information is necessary or not (along with the possible consequences of not providing such data).
If we collect and utilise your personal information based on our legitimate interests (or those of any third party), it will typically be to operate our platform and communicate with you as required. For example, responding to your enquiries, analysing platform usage and improving our services, undertaking marketing activities for existing customers within legal limits, and detecting or preventing illegal activities. We may have other legitimate interests, and we will inform you at the relevant time what those interests are. We rely on these legal bases to process data for the following purposes: to assist in providing services (e.g., customer support and usage data) and to market our services to you within legal limits.
If you have any questions or require further information regarding the legal basis upon which we collect and utilise your personal information, please contact us using the contact information provided under the "How to contact us" heading at the bottom of this notice.
Emerald City Use of Cookies and Similar Tracking Technology
Cookies are small data files that are placed on your computer or mobile device when you visit a website. Website owners can utilise cookies for various purposes, including enabling their websites to operate effectively, providing personalised content and advertising, and generating website analytics.
Our website utilises first-party and third-party cookies for various purposes. Essential cookies are crucial for operating our site, while additional cookies enhance user experience by providing personalised content and advertising. First-party cookies gather standard information like browser type, language, access times, and the previous website visited. They also collect IP address, clickstream behaviour, and product information. Third-party advertising networks, contracted by Emerald City collect non-personal and personal data through our website, emails, and third-party websites. These networks track online activities to deliver tailored ads about products and services across the web. This process also aids in monitoring marketing effectiveness.
The website may incorporate third-party social media features and widgets. These components may collect IP addresses, visited pages, and set cookies for proper functioning. Interaction with these elements is governed by the respective provider's privacy policy.
Learn More About Cookies
If you want to learn more about cookies, or how to control, disable, or delete them, please visit http://www.allaboutcookies.org for detailed guidance.
Detailed information about first- and third-party cookies served and their purposes may be found on our cookie settings page.
Cookie Control
Users have the choice to accept or reject cookies. Cookie preferences can be managed in the cookie settings page. Our cookie consent tool automatically honours Google Consent.
Web browser controls can be configured to accept or reject cookies. While rejecting cookies may restrict site functionality, it's still possible to access the website. Refer to browser help menus for specific instructions. Targeted advertising opt-out options are available through most advertising networks. Visit
http://www.aboutads.info/choices
http://www.youronlinechoices.com
http://www.youronlinechoices.eu
Data Security
Emerald City employs appropriate technical and organisational measures to safeguard personal data collected and processed. These measures aim to provide a security level commensurate with the risk associated with handling personal data.
Emerald City resides on leading cloud service providers (linked on our security page) utilising industry-standard security protocols to protect personal data. Personal data is stored on private servers within a secure security group. End-user to server connections are encrypted using SSL, and server software is updated regularly with the latest security patches.
Data Transfers
Your personal data may be transferred to, and processed in, countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country. However, we have taken appropriate safeguards to ensure that your personal data will remain protected in accordance with this Privacy Notice.
Emerald City is committed to safeguarding the privacy of personal data transferred from the European Union, United Kingdom, and Switzerland. To ensure compliance with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF"), Emerald City has certified that our data processors are compliant with the DPF. These DPA agreements may be referenced here - https://webflow.com/legal/dpa
Emerald City is accountable for the personal data it receives under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, even if it is subsequently transferred to a third party. This means that Emerald City remains responsible and liable if these third-party agents process the personal data in a manner inconsistent with the principles of the DPFs, unless Emerald City can demonstrate that it is not at fault for the resulting harm.
Data Retention
We retain your personal data as long as we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with legal requirements). When we no longer have a legitimate business need to process your personal data, we will either delete or anonymise it, or if this is not possible, securely store it and isolate it from any further processing.
Your Data Protection Rights
You have the following data protection rights:
Access your personal data Correct or update your personal data Request deletion of your personal data Object to the processing of your personal data Restrict the processing of your personal data Request portability of your personal data Opt out of marketing communications Withdraw your consent (if you have given it) Opt out of the sale of your personal data
You can exercise these rights by contacting us using the contact details provided under the "How to contact us" heading at the bottom of this notice.
Sensitive Personal Data
We do not use or disclose your sensitive personal data, except for the purposes of providing services to our customers.
Non-discrimination
We will not discriminate against you for exercising your data protection rights.
Authorised Agent
You can authorise another person to make a data privacy request on your behalf. To do this, you will need to provide us with a written authorisation that includes the specific data protection request you want the authorised agent to make.
Data Protection Authority
You have the right to complain to a data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority.
Appealing Our Decision
If you are not satisfied with our response to your data privacy request, you have the right to appeal our decision. To do this, please contact us using the contact details provided under the "How to contact us" heading at the bottom of this notice. If you are not satisfied with the result of the appeal, you have the right to contact your respective attorney general depending on where you reside.
Verifying Data Protection Requests
We verify data protection requests to ensure that they are legitimate and to prevent unauthorised access to your personal data. Our verification process is based on matching personal data provided by the requestor with personal data that we have on file with the requestor. The personal data points matched vary based on what Emerald City has on the requestor, but Emerald City uses multiple personal data points for verification. During the verification process, Emerald City aims to avoid collecting additional personal data from the requester that has not been previously collected by Emerald City.
Updates to this Privacy Notice
We may update this Privacy Notice from time to time in response to changing legal, technical or business developments. When we update our Privacy Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy Notice changes if and where this is required by applicable data protection laws. You can see when this Privacy Notice was last updated by checking the "last updated" date displayed at the top of this Privacy Notice.
How to contact us
If you have any questions or concerns about our use of your personal data, please contact us at
#INSERT EMAIL
#INSERT COMPANY ADDRESS
Glossary of Terminology
1.1 "controller", "processor", "data subject", "personal data" and "processing" (and "process") will have the meanings given in EU/UK Data Protection Law;
1.2 "Applicable Data Protection Law" means all worldwide data protection and privacy laws and regulations applicable to the Personal Data in question, including, where applicable, EU/UK Data Protection Law, US Data Protection Law, Serbian Data Protection Law, Canadian Data Protection Law, and the Swiss DPA;
1.3 "Breach" means an accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access that is in violation of Emerald City's security obligations under this Agreement by Emerald City or its agents of which Emerald City becomes aware. Breach will not include an unsuccessful Breach, which is one that results in no unauthorised access to Personal Data or to any Emerald City equipment or facilities storing the Personal Data, and could include (without limitation) pings and other broadcast attacks of firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorised access to traffic data that does not result in access beyond headers) or similar incidents;
1.4 "Canadian Data Protection Law" means: (i) the Personal Information Protection and Electronic Documents Act S.C. 2000, c. 5; (ii) applicable provincial law; (iii) any and all applicable data protection laws made under, pursuant to or that apply in conjunction with any of (i) or (ii); in each case as may be amended or superseded from time to time;
1.5 "Data Privacy Framework" means the EU-US Data Privacy Framework, the UK extension to the EU-US Data Privacy Framework, and the Swiss-US Data Privacy Framework self-certification program operated by the US Department of Commerce;
1.6 "Data Privacy Principles" means the Data Privacy Framework principles (as supplemented by the Supplemental Principles);
1.7 "EU/UK Data Protection Law" means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the "EU GDPR"); (ii) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2018 (the "UK GDPR"); (iii) the EU e-Privacy Directive (Directive 2002/58/EC); and (iv) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (i), (ii) or (iii); in each case as may be amended or superseded from time to time;
1.8 "US Data Protection Law" means: (i) the California Consumer Privacy Act of 2018, including as amended by the California Privacy Rights Act of 2020, codified at Cal. Civ. Code §1798.100 et seq., upon the CPRA's enforcement date of July 1, 2023 (together with its implementing regulations) ("CPRA"); (ii) the Virginia Consumer Data Protection Act; (iii) the Colorado Privacy Act; (iv) the Connecticut Personal Data Privacy and Online Monitoring Act; (v) the Utah Consumer Privacy Act; (vi) the Iowa Consumer Data Protection Act; (vii) the Indiana Consumer Data Protection Act; (viii) the Tennessee Information Protection Act; (ix) the Montana Consumer Data Privacy Act; (x) the Texas Data Privacy and Security Act; (xi) the Oregon Consumer Privacy Act; (xii) the Delaware Personal Data Privacy Act; and (xiii) any and all applicable comprehensive state data protection laws and regulations that are or are not yet in effect as of the Effective Date; in each case as may be amended or superseded from time to time;
1.9 "Serbian Data Protection Law" means: Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti; Official Gazette of the Republic of Serbia, no 87/2018). In the case of a transfer of Personal Data to a Non-Adequate Country, by entering into this DPA, the Customer is entering into the Serbian Standard Contractual Clauses ("Serbian SCCs") as adopted by the "Serbian Commissioner for Information of Public Importance and Personal Data Protection", to provide an adequate level of protection. References to the Standard Contractual Clauses in this DPA will include the Serbian SCCs.
1.10 "Supplemental Principles" will have the meaning given in the Data Privacy Framework;
1.11 "Standard Contractual Clauses" means: (i) where the EU GDPR or Swiss DPA applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (ii) where the UK GDPR applies, standard data protection clauses adopted pursuant to or permitted under Article 46 of the UK GDPR ("UK SCCs"); and (iii) where Serbian Data Protection Law applies, the Serbian SCCs; and
1.12 "Swiss DPA" means the revised Swiss Federal Act on Data Protection enacted on September 25, 2020, and effective on September 1, 2023, as may be amended or superseded from time to time.
