Careers

Contact Us

Integrity Services Data Cooperation Addendum v1

Integrity Services Data Cooperation Addendum

(the “DCA”)

1. Definitions and Interpretations

1.1. For the purposes of this DCA, capitalised terms shall have the following meanings, unless defined elsewhere in this DCA or in the Agreement:

Agreement” shall mean any agreement in which this DCA is referenced or to which it is attached;

Anti-Doping Personal Data” shall have the meaning given to it in Annex 2 to this DCA;

Business Day” shall mean any day except any Saturday, Sunday or a public holiday in the respective countries of incorporation of the Parties to the Agreement;

CCPA” shall mean the US California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CPRA”) and as may further be amended from time to time;

Children’s Personal Data” means any Personal Data relating to a Data Subject who has not yet reached the age threshold under the applicable Data Protection Legislation (e.g., 16 years under the GDPR, or any other age prescribed by national law);

Competent Data Protection Authority” shall mean the supervisory authority for data protection in the respective countries of the Parties which, by way of example, could be the Austrian Data Protection Authority [die österreichische Datenschutzbehörde];

Data Protection Legislation” shall mean all applicable data protection legislation, including the GDPR, the UK GDPR, the FADP, the LGPD, the PIPL, the US State Data Protection Laws, any national data protection legislation, and any regulations, guidelines or any other documents issued by a Competent Data Protection Authority, each as amended from time to time;

GDPR” shall mean Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, as amended from time to time;

UK GDPR” shall mean the UK General Data Protection Regulation, as may be amended from time to time;

FADP” shall mean the Swiss Federal Act on Data Protection of 25 September 2020 [Bundesgesetz über den Datenschutz], as amended from time to time;

I&I Personal Data” shall have the meaning given to it in Annex 1 to this DCA;

Integrity Audit Personal Data” shall have the meaning given to it in Annex 2 to this DCA;

Integrity Education Personal Data” shall have the meaning given to it in Annex 2 to this DCA;

LGPD” shall mean the Brazilian General Data Protection Law as amended from time to time;

Personal Data” shall mean collectively the Anti-Doping Personal Data, the I&I Personal Data, the Integrity Audit Personal Data, the Integrity Education Personal Data, and the UFDS AI Personal Data;

PIPL” shall mean the Personal Information Protection Law of the People’s Republic of China, as amended from time to time;

UFDS AI Personal Data” shall have the meaning given to it in Annex 1 to this DCA;

US State Data Protection Laws” shall mean applicable US state comprehensive data protection laws, including the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the CCPA), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Montana Consumer Data Privacy Act, the Delaware Personal Data Privacy Act, the Iowa Consumer Data Protection Act, the New Jersey Data Privacy Act, and any other state data protection law that may become applicable, each as amended from time to time.

1.2. For the purposes of this DCA, the terms “controller”, “joint controllers”, “processor”, “data subject”, “personal data”, “process”, “processing” and “data breach” (and, as applicable, the related terms “business”, “service provider”, “consumer”, “sell”, “share” and “personal information”) shall have the meanings attributed to them in the Data Protection Legislation.

2. Purpose of the DCA and Roles of the Parties

2.1. The purpose of this DCA is to determine the roles and responsibilities of the Parties to the Agreement with respect to the processing of Personal Data in order to ensure the Parties’ compliance with the applicable Data Protection Legislation in connection with the provision of Services under the Agreement.

2.2. The types of Personal Data, the categories of data subjects to whom the processing relates, and the performed processing operations are further detailed in Annex 1 (Exchanged Personal Data Processing Description) and Annex 2 (Processor Personal Data Processing Description) to the DCA.

2.3. Clauses 1 – 3, 6 – 10 and Annex 1 apply where Sportradar provides I&I and/or UFDS AI. Clauses 1, 2, 4 – 10 and Annex 2 apply where Sportradar provides Integrity Education, Integrity Audit, and/or Anti-Doping.

2.4. For the purposes of processing I&I Personal Data and UFDS AI Personal Data, the Parties shall act as joint controllers. For the purposes of processing Integrity Education Personal Data, Integrity Audit Personal Data, and Anti-Doping Personal Data, Sportradar shall act as a data processor and the Client shall act as a data controller.

2.5. The Client acknowledges and agrees that Sportradar shall be entitled to independently process I&I Personal Data and UFDS AI Personal Data, along with any associated data (including personal data) obtained in the course of the provision of the Services under the Agreement, for its own (or third parties’) legitimate interests, namely (a) safeguarding the integrity of sport, and (b) providing services and products to clients and partners.

2.6. Where Safe Sport Services are provided in whole or in part by third parties (“Safe Sport Third-Party Providers”), Sportradar does not act as controller or processor with respect to any personal data processed by the Safe Sport Third Party Providers. Safe Sport Third Party Providers process personal data as processors on behalf of the Client (acting as controller), subject to their respective data processing terms, and the Client acknowledges and agrees that it may be required to enter into separate data processing arrangements with the relevant Safe Sport Third Party Provider. For the avoidance of doubt, where Sportradar performs I&I Services in connection with Safe Sport matters, any processing of personal data shall be governed by the provisions applicable to I&I Personal Data.

2.7. Processing of personal data in connection with Athlete Wellbeing Workshops and/or Education Consultancy shall be governed by the provisions applicable to Integrity Education Personal Data.

3. Obligations of the Parties regarding the I&I Personal Data and UFDS AI Personal Data

3.1. The Client shall (a) ensure that it has a lawful basis under the Data Protection Legislation for the collection, processing, and sharing of I&I Personal Data and UFDS AI Personal Data, and (b) comply with all applicable transparency requirements under the Data Protection Legislation in connection with the collection and processing of such Personal Data under the Agreement and this DCA. Without limiting the foregoing, the Client shall ensure that its privacy notices and any other communications relating to the collection and processing of such Personal Data: (a) are clear and provide sufficient information to data subjects to understand what personal data is collected and processed under the Agreement and this DCA, the purposes for processing, and the circumstances in which it will be shared with other recipients; (b) include an explicit reference to Sportradar as an entity with whom personal data is shared for the purposes under the Agreement and this DCA; and (c) include a link to Sportradar’s Privacy Notice, available at https://sportradar.com/privacy-notice/.

3.2. The Parties shall cooperate in responding to data subject requests to exercise privacy rights under the Data Protection Legislation. The Client is responsible for complying with such requests. Each Party shall provide reasonable and prompt assistance to the other (within 5 (five) Business Days of a request for assistance) as necessary to enable compliance with data subject requests and to respond to any related queries or complaints from data subjects.

3.3. In the event of a dispute or claim brought by a data subject or a Competent Data Protection Authority concerning the processing of I&I Personal Data and/or UFDS AI Personal Data against either or both Parties to the Agreement, the Parties shall inform each other about any such disputes or claims without delay and shall cooperate with a view to settling them amicably in a timely manner.

3.4. To the extent that Sportradar is required to process Children’s Personal Data in connection with the Services, the Client shall:

a) implement, document, and maintain a lawful basis for such processing, including verifiable parental consent where required;
b) ensure that any profiling or automated decision-making involving Children’s Personal Data is carried out only where strictly necessary and with appropriate safeguards; and
c) complete any child-specific risk or impact assessments required under the Data Protection Legislation.

3.5. The Client acknowledges and agrees that Sportradar shall be entitled to disclose I&I Personal Data and UFDS AI Personal Data directly to sport federations, governing bodies, regulatory authorities, and law enforcement agencies for the purpose of safeguarding the integrity of sport, including identifying and combating sport manipulation.

4. Obligations of Sportradar regarding the Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data

4.1. Sportradar shall process Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data only for the purposes under the Agreement. Sportradar may not process Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data for its own purposes. Where Sportradar processes Anti-Doping Personal Data, Sportradar will act as a Third-Party Agent (as defined in article 3.3 of the International Standard for the Protection of Privacy and Personal Information (ISPPPI) issued by the World Anti-Doping Agency (WADA), or as defined in any successor standard issued by WADA, as applicable).

4.2. Sportradar shall process Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data in accordance with the instructions of the Client and in compliance with the Data Protection Legislation. Sportradar shall inform the Client in writing if Sportradar believes that any of the instructions of the Client violate the Data Protection Legislation.

4.3. Sportradar shall not disclose Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data to third parties, unless with the express prior written consent of the Client or where required by law. For the avoidance of doubt, Sportradar’s subsidiaries shall not be considered ‘third parties’ and Sportradar may disclose Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data to its group affiliates and subsidiaries and to other processors engaged by the Client solely in connection with the provision of the Services under the Agreement.

Where Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data shall be accessed and processed from outside the European Economic Area (“EEA”), the United Kingdom (“UK”) or Switzerland, Sportradar shall ensure that an appropriate data transfer mechanism is in place as required by the applicable Data Protection Legislation. If Sportradar shall transfer Integrity Education Personal Data, Integrity Audit Personal Data and/or Anti-Doping Personal Data to a third country or international organisation, pursuant to applicable European Union or Member State law, Sportradar shall inform the Client of that legal requirement beforehand, unless the law prohibits this on important grounds of public interest.

4.4. The Client authorises Sportradar to appoint – and permit each sub-processor appointed in accordance with this clause to appoint – sub-processors. Sportradar may continue to use those sub-processors already engaged by Sportradar as at the date of this DCA.

If any processing operation shall be further subcontracted, Sportradar shall notify in writing the Client thirty (30) Business Days in advance, indicating the processing operations to be subcontracted and clearly and unequivocally identifying the subcontractor and its contact details. If, within thirty (30) days of receipt of the notice, the Client notifies Sportradar in writing of any objections on reasonable grounds to the proposed appointment:

a) Sportradar shall work with the Client in good faith to make available a commercially reasonable change in the provision of the data processing component of the Services agreed under the Agreement;
b) where such a change cannot be made within ninety (90) days as of the receipt of the Client’s notice by Sportradar, the Client may, by written notice to Sportradar, terminate with immediate effect the Agreement to the extent that it relates to the integrity services which require the use of the proposed sub-processor.

Sportradar shall ensure that any sub-processor engaged under this DCA is bound by data protection obligations materially equivalent to those set forth herein, including compliance with Client instructions, appropriate security measures, and data subject rights protections. Sportradar shall remain liable for the acts and omissions of its sub-processors.

Sportradar shall maintain and make available to the Client upon request a current list of all sub-processors engaged in the processing of Integrity Education Personal Data, Integrity Audit Personal Data, and Anti-Doping Personal Data.

4.5. Sportradar shall maintain the duty of secrecy regarding the Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data after the termination of the Agreement.

4.6. Sportradar shall ensure that individuals authorised to process Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data are bound by appropriate confidentiality obligations and are informed of any relevant security measures.

4.7. Sportradar shall assist the Client in meeting its obligations in relation to data subjects’ requests to exercise data protection rights under the Data Protection Legislation. The Client shall reimburse Sportradar for its reasonable charges for such assistance. When data subjects exercise their data protection rights before Sportradar, Sportradar shall notify the Client immediately but in any event not later than five (5) Business Days following the receipt of the request. The notification shall be accompanied, where appropriate, by other information that may be relevant to resolve the request.

4.8. Sportradar shall notify the Client without undue delay of any confirmed personal data breach affecting Integrity Education Personal Data, Integrity Audit Personal Data, or Anti-Doping Personal Data. Such notification shall include all information required under article 33(3) of the GDPR, to the extent available. Where complete information is not immediately available, Sportradar shall provide it in phases without undue delay.

4.9. Sportradar shall support the Client in sending prior consultations to Competent Data Protection Authorities, when appropriate.

4.10. Sportradar shall support the Client in conducting data protection impact assessments, when appropriate.

4.11. Sportradar shall provide the Client with all reasonable information necessary to demonstrate compliance with its obligations under the Data Protection Legislation and shall allow audits and inspections to be carried out by an independent auditor mutually agreed by the Client and Sportradar at the cost of the Client, once per calendar year.

4.12. Sportradar shall implement appropriate technical and organisational measures to:

a) ensure a level of security appropriate to the risk involved in order to protect the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data from unauthorized use, alteration, access or disclosure, loss, theft, and damage;
b) ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
c) restore the availability and access to the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data in a timely manner in the event of a physical or technical incident;
d) test, assess and evaluate the effectiveness of technical and organisational measures implemented for ensuring the security of the processing of the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data;
e) pseudonymise and encrypt the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data, as appropriate;
f) prevent a personal data breach.

4.13. Sportradar shall promptly delete all Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data provided by the Client in its entirety from its systems and destroy any copies it made of the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data after completing the Services under the Agreement, unless and to the extent that Sportradar is required to retain copies in accordance with the applicable legislation or as otherwise agreed in writing (e-mail shall suffice) between the Parties.

4.14 Service Provider Certification (US State Data Protection Laws)

4.14.1. For any Personal Information governed by US State Data Protection Laws that Sportradar processes on behalf of the Client in its capacity as a Service Provider, Sportradar:

a) certifies that it will not Sell or Share such Personal Information;
b) will not retain, use, or disclose such Personal Information (1) for any purpose other than for the specific purpose of performing the Services, or (2) outside the direct business relationship between the Parties, except as otherwise permitted by US State Data Protection Laws;
c) will not combine such Personal Information with Personal Information obtained from another source except to the extent permitted by applicable law; and
d) will promptly notify the Client if Sportradar determines it can no longer meet its obligations under this clause 4.14 or any US State Data Protection Laws.

4.14.2. Sportradar grants the Client the right to take reasonable and appropriate steps to ensure that Sportradar uses Personal Information in a manner consistent with the Client’s obligations under US State Data Protection Laws and to stop and remediate any unauthorised use of Personal Information.

5. Obligations of the Client regarding Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data

5.1. The Client shall provide or otherwise make the Integrity Education Personal Data, the Integrity Audit Personal Data and the Anti-Doping Personal Data available to Sportradar.

5.2. The Client shall, at the time when Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data are processed, provide the data subjects with all information about the collection and processing of the Integrity Education Personal Data, the Integrity Audit Personal Data, respectively the Anti-Doping Personal Data and collect consent as required by any applicable Data Protection Legislation or any other applicable laws or regulations (including national and international anti-doping regulations) for the data collection and processing.

6. International Data Transfers

6.1. To the extent that Sportradar transfers Anti-Doping Personal Data, the I&I Personal Data, the Integrity Audit Personal Data, the Integrity Education Personal Data and the UFDS AI Personal Data from the EEA, the UK or Switzerland to Client, the Parties will be deemed to have entered into the standard contractual clauses approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 available at http://data.europa.eu/eli/dec_impl/2021/914/oj (“Clauses”) in respect of such transfer, whereby:

a) Sportradar is the “data exporter” and Client is the “data importer”;
b) Module One applies for transfers of I&I Personal Data and UFDS AI Personal Data, Module Two applies for transfers of Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data, and Module Four applies for transfers of Integrity Education Personal Data, Integrity Audit Personal Data and Anti-Doping Personal Data from Sportradar (as processor) back to the Client (as controller);
c) Module Three, the footnotes, Clause 11(a) Option and Clause 17 Option 1 are omitted, the applicable annexes are completed respectively with the information set out in the Agreement and this Agreement;
d) the “competent supervisory authority” is that in the country where the data exporter is established;
e) the Clauses are governed by the law of the country where the data exporter is established;
f) any dispute arising from the Clauses shall be resolved by the courts of the country where the data exporter is established;
g) if there is any conflict between the terms of the Agreement and the Clauses or the remaining provisions of this DCA and the Clauses, the Clauses will prevail.

6.2. In relation to transfers of Anti-Doping Personal Data, the I&I Personal Data, the Integrity Audit Personal Data, the Integrity Education Personal Data and the UFDS AI Personal Data from the UK, the Clauses as implemented under clause 6.1. above will apply subject to the following modifications:

a) the Clauses are amended as specified by Part 2 of the international data transfer addendum to the European Commission’s standard contractual clauses issued under Section 119A of the UK Data Protection Act 2018, as may be amended or superseded from time to time (“UK Addendum”);
b) tables 1 to 3 in Part 1 of the UK Addendum are completed respectively with the information set out in the Agreement and this DCA (as applicable); and
c) table 4 in Part 1 of the UK Addendum is completed by selecting “neither party”.

6.3. In relation to transfers of Anti-Doping Personal Data, the I&I Personal Data, the Integrity Audit Personal Data, the Integrity Education Personal Data and the UFDS AI Personal Data from Switzerland, the Clauses as implemented under clause 6.1. above will apply subject to the following modifications:

a) references to “Regulation (EU) 2016/679” shall be interpreted as references to FADP;
b) references to specific articles of “Regulation (EU) 2016/679” shall be replaced with the equivalent article or section of the FADP;
c) references to “EU”, “Union”, “a Member State” and “Member State law” shall be replaced with references to “Switzerland” or “Swiss law”, as applicable;
d) the term “member state” shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of accessing their rights;
e) Clause 13(a) and Part C of Annex I are not used and the “competent supervisory authority” is the Swiss Federal Data Protection Information Commissioner;
f) the Clauses are governed by the law of Switzerland; and
g) any dispute arising from the Clauses will be resolved by the courts of Switzerland.

6.4 Data Localization Requirements

Where any applicable Data Protection Legislation imposes cross-border transfer, data localization or in-country storage/processing mandates (including, without limitation, laws in the Russian Federation, the People’s Republic of China, India, Indonesia, Vietnam, or any other relevant jurisdiction), the Client shall:

a) notify Sportradar in writing prior to transferring any Personal Data that is subject to such localization requirements;
b) ensure that it transfers to Sportradar, stores and/or otherwise processes the relevant Personal Data in compliance with those cross-border transfer and localization requirements; and
c) where such transfer would require Sportradar to store or process data in-country in order to comply with applicable localization requirements, not transfer such Personal Data to Sportradar unless either (i) the Parties have agreed in writing on appropriate arrangements for such in-country processing, or (ii) the transfer is necessary for Sportradar to provide the Services and the Client accepts full responsibility for ensuring compliance with the applicable localization requirements.

The Client represents and warrants that all Personal Data transferred to Sportradar under this DCA complies with applicable data localization requirements at the time of transfer. For the avoidance of doubt, Sportradar shall have no obligation to establish or maintain data processing infrastructure in any specific jurisdiction solely to comply with the Client’s data localization requirements.

6.5 Technical and Organisational Measures

To the extent that Sportradar transfers I&I Personal Data and/or UFDS AI Personal Data outside the EEA, the UK or Switzerland, the Client shall implement the technical and organisational measures set out in Annex 3 (Technical and Organisational Measures) to this DCA.

7. Term and Termination

This DCA shall commence on the effective date of the Agreement and shall continue in full force and effect until the expiry or termination of the Agreement. Any renewal or extension of the Agreement shall automatically renew or extend this DCA for the same period.

8. Indemnity and Limitation of Liability

8.1. Each Party (the “Indemnifying Party”) shall indemnify and hold harmless the other Party (the “Indemnified Party”) in respect of all costs, claims, fines, losses, damages or expenses incurred by the Indemnified Party, or for which the Indemnified Party may become liable, due to any failure by the Indemnifying Party to comply with any of its obligations set out in this DCA.

8.2. To the fullest extent permitted by law, neither Sportradar nor any of its affiliates, shall be liable to the Client under or in connection with this DCA for any indirect, special, or consequential losses or damages, loss of business or good will, profit or revenue. Sportradar’s total aggregate liability (including under clause 8.1. above) arising out of or in relation to this DCA, whether the liability arises because of a breach of contract, negligence or for any other reason, shall be strictly limited to the liability cap set forth in the Agreement.

9. Contact Point

Each Party shall nominate the following contact person within their organisation who can be contacted in respect of queries, complaints or notifications of any kind whatsoever regarding this DCA or the Data Protection Legislation:

For Sportradar:
E-mail: [email protected]

For the Client:
Email: As set forth in the Agreement.

10. Miscellaneous

10.1. In the event of any conflict between the terms of this DCA and the terms of the Annexes to this DCA, the Annexes shall take precedence. In the event of any conflict between the terms of this DCA and any provision of the Agreement and any other agreement between the Parties, this DCA shall take precedence.

10.2. This DCA shall be governed by and construed in accordance with the laws chosen by the Parties in the Agreement.

10.3. All disputes arising out of or in connection with this DCA shall be subject to the exclusive jurisdiction of the Austrian court(s). For contracts subject to US State Data Protection Laws, all disputes shall be subject to the exclusive jurisdiction of the courts of New York, USA.

10.4. The provisions of this DCA are severable. If any phrase, clause or provision is invalid or unenforceable in whole or in part, such invalidity or unenforceability shall affect only such phrase, clause or provision and the rest of this DCA shall remain in full force and effect.

10.5. Any amendment to this DCA must be made in writing upon mutual agreement by the Parties.

10.6. Clauses 1, 2.5, 4.5, 4.13, 6, 8, 10 and any other provisions which by their nature are intended to survive shall survive expiry or termination of the Agreement and this DCA.

 

Annex 1 – Exchanged Personal Data Processing Description to the DCA

Service I&I pursuant to the Agreement
Personal Data Name and surname, address, photographs, alias, date of birth, nationality, gender, ID card, job role and category level, employment and education history, contact details, geolocation data, performance data (statistics), social media information, adverse or relevant media, criminal, civil, court and financial records and information, declarations made related to criminal, civil, financial and sporting sanctions and information, open source information, reports containing some or all of the above data, and any other data which may be considered as personal data.
Data Subjects Athletes and other sports professionals (such as referees, judges, coaches, and individuals holding executive, managerial, or governance position within  teams or sporting organizations), and any other individuals, whether or not affiliated with a sporting organization, including those who may potentially pose a threat to the integrity of sport.
Processing Operations Receiving, collecting, recording, organising, structuring, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, combining, restricting, erasing, and storing I&I Personal Data, including but not limited to receiving personal data from the Client, collecting data from open sources and publicly available information, using already existing data, conducting research, analysis, profiling and risk assessment, cross-referencing with other data sources, and sharing data and reports with the Client.

 

Service UFDS AI pursuant to the Agreement
Personal Data Name and surname, photographs, alias, date of birth, nationality, gender, ID card, job role and category level, contact details, performance data (statistics), social media information, open source information, reports containing some or all of the above data, and any other data which may be considered as personal data.
Data Subjects  Athletes and other sports professionals (such as referees, judges, coaches, and individuals holding executive, managerial, or governance position within teams or sporting organizations), and any other individuals, whether or not affiliated with a sporting organization, including those who may potentially pose a threat to the integrity of sport.
Processing Operations Receiving, collecting, recording, organising, structuring, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, combining, restricting, erasing, and storing UFDS AI Personal Data (including through the use of machine learning models), including but not limited to receiving personal data from the Client, collecting data from open sources and publicly available information, using already existing data, conducting research, analysis, profiling and risk assessment, cross-referencing with other data sources, and sharing data and reports with the Client.

 

Annex 2 – Processor Personal Data Processing Description to the DCA

Service Integrity Audit pursuant to the Agreement
Personal Data Name and surname, contact details (such as email address and phone number, job role and organisational position, records relating to integrity breach reports, investigations, and disciplinary proceedings (which may include names of reporters, subjects of complaints, witnesses, and sanctioned individuals), any other data which may be considered as personal data contained in documents, records, or systems made available to Sportradar.
Data Subjects  Athletes, referees, coaches, team staff, club officials, integrity personnel, and other individuals whose personal data is contained in the Client’s integrity records, reports, investigation files, or disciplinary proceedings made available to Sportradar.
Processing Operations Receiving personal data from the Client, reviewing and analysing integrity policies, procedures, and case records, preparing audit findings and recommendations, and returning or deleting personal data upon completion of the audit.

 

Service Integrity Education pursuant to the Agreement
Personal Data Name and surname, email address, assessment results, performance data and score, user IP address, log-in password, league, club, organisation, role, position, and any other data which may be considered as personal data specified in writing by the Client.
Data Subjects  Athletes, other sports professionals (such as referees, coaches, team staff, club officials, integrity personnel) and any other individuals specified by the Client.
Processing Operations Some or all of the following processing operations, depending on the Integrity Education package selected by the Client: collection and registration of participant personal data, tracking and recording of participation, and completion status, assessment of participant performance and scoring, generation of participation and performance statistics and summary reports, storage and maintenance of learning records, and return or deletion of personal data upon completion of the Services or as instructed by the Client.

 

Service Anti-Doping I&I pursuant to the Agreement
Personal Data Name and surname, address, date of birth, gender, nationality, email address, phone number, IP address, domains and digital footprint, social media accounts and information, activity and connections, photographs, videos and media content, adverse or relevant media, criminal, civil, court and financial records and information, declarations made related to criminal, civil, financial and sporting sanctions and information, sporting results, statistics, history and affiliations, employment and education history, whereabouts information (including data stored in ADAMS), anti-doping testing and results history, medical and health data (including Doping Control Forms (DCF) and Therapeutic Use Exemptions (TUE)), evidence submitted or collected as part of an anti-doping investigation or disciplinary hearing, and any other data which may be considered as personal data.
Data Subjects  Athletes and other sports professionals specified by the Client.
Processing Operations Receiving, collecting, recording, organising, structuring, adapting, altering, retrieving, consulting, using, disclosing, disseminating, aligning, combining, restricting, erasing, and storing Anti-Doping Personal Data, including but not limited to receiving personal data from the Client and third parties, collecting data from open sources and publicly available information, conducting research, analysis, profiling and risk assessment, cross-referencing with other data sources, supporting investigations and disciplinary proceedings, preparing reports and recommendations, and sharing data and reports with the Client.

 

Annex 3 – Technical and Organisational Measures to the DCA

This Annex 3 sets out the technical and organisational measures to be implemented by the Client to protect I&I Personal Data and UFDS AI Personal Data when the Client is located outside the EEA, the UK or Switzerland.

Category Technical and Organisational Measure
Information Security Policies · The Client shall maintain documented information security policies that are proportionate to the size and nature of its operations and aligned with a recognised industry standard (e.g., ISO 27001, NIST CSF, or an equivalent framework).
· Roles and responsibilities for information security shall be clearly defined and assigned to appropriately qualified personnel.
· 
Information security policies shall be reviewed and, where necessary, updated at least annually.
Risk Assessment and Management ·  The Client shall conduct periodic risk assessments to identify threats and vulnerabilities relevant to the personal data it processes.
·  Identified risks shall be documented in a risk register, together with the measures adopted to mitigate them.
·  Risk assessments shall be reviewed at least annually or following any material change in the Client’s processing activities or technical environment.
Business Continuity and Disaster Recovery ·  The Client shall maintain a business continuity plan that addresses the continued availability of critical systems and data following a disruptive event.
·  The Client shall maintain a disaster recovery plan that sets out procedures for restoring IT systems and data.
·  Business continuity and disaster recovery plans shall be tested at least annually and updated to reflect changes in technology, personnel, or business processes.
Incident Response ·  The Client shall maintain a documented incident response plan covering identification, containment, investigation, communication, and escalation of security and privacy incidents.
·  The Client shall notify the relevant data controller or supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with applicable data protection legislation.
·  The incident response plan shall be reviewed at least annually and tested periodically through tabletop or simulated exercises.
·  The Client shall implement appropriate monitoring and detection capabilities (e.g., intrusion detection/prevention, log monitoring) commensurate with the sensitivity of the data processed.
Employee Training and Awareness ·  All employees who handle personal data shall complete information security and data protection awareness training upon joining and at least annually thereafter.
·  Training shall cover, at a minimum, recognising common threats (e.g., phishing, social engineering), incident reporting procedures, and the Client’s data protection obligations.
·  The Client shall promote a culture of security awareness and encourage prompt reporting of suspected incidents.
Third-Party Management ·  The Client shall carry out proportionate due diligence on third-party vendors and service providers that process personal data on its behalf, to verify that they meet appropriate data protection and security standards.
·  The Client shall enter into data processing agreements with such vendors and service providers in compliance with applicable data protection legislation.
·  Third-party compliance with data protection and security requirements shall be reviewed on a periodic basis, using questionnaires, audits, or certifications as appropriate.
Access Control ·  Access to systems and data shall be granted on the basis of least privilege and need-to-know principles.
·  The Client shall implement role-based access controls and maintain a record of user access rights.
·  Multi-factor authentication shall be required for remote access and for access to systems that process sensitive or personal data.
·  Access rights shall be reviewed periodically and promptly revoked upon termination of employment or change of role.
·  The Client shall enforce strong password policies (e.g., minimum length, complexity requirements).
Encryption and Data Integrity ·  Personal data shall be encrypted in transit using TLS 1.2 or higher (or an equivalent protocol).
·  Personal data at rest shall be encrypted using a strong encryption standard (e.g., AES-256 or equivalent).
·  Encryption keys shall be stored securely and managed in accordance with documented key-management procedures.
·  Where appropriate, checksums or hashing shall be used to verify data integrity during transmission and storage.
Backup and Data Availability ·  The Client shall maintain regular, encrypted backups of personal data, stored in a secure location that is physically or logically separate from the primary environment.
·  Backup integrity shall be verified periodically, and restore tests shall be conducted at least annually to confirm the reliability of recovery processes.
Data Retention and Disposal ·  The Client shall maintain a data retention policy that specifies retention periods based on legal and business requirements, ensuring personal data is not retained longer than necessary.
·  Personal data that is no longer required shall be securely deleted or destroyed using methods appropriate to the storage medium (e.g., secure wiping, degaussing, physical destruction).
Physical Security ·  Facilities where personal data is stored or processed shall be protected by appropriate physical access controls (e.g., keycards, visitor logs) to restrict entry to authorised personnel.
·  Hardware and portable devices containing personal data shall be physically secured and tracked through asset management procedures.
·  Physical security measures shall comply with applicable local regulations.
Network Security ·  The Client shall implement and maintain network security controls, including firewalls, endpoint protection (anti-malware), and network segmentation appropriate to the sensitivity of the data.
·  All workstations shall be managed centrally, kept up to date with security patches, and protected with encrypted hard drives.
·  Remote access shall be secured through VPN or equivalent secure-access solutions.
Change and Patch Management ·  Changes to systems that process personal data shall be subject to a documented change management process, including testing and approval prior to deployment.
·  A periodic patch management process shall be in place to ensure that operating systems, applications, and firmware are updated with security patches in a timely manner.
·  Segregation of duties shall be observed so that the same individual does not both develop and approve a change.
Vulnerability Management and Penetration Testing ·  The Client shall conduct regular vulnerability scans and remediate identified vulnerabilities in a timely, risk-based manner.
·  Penetration testing of internet-facing applications and critical systems shall be carried out at least annually, preferably by a qualified independent third party.
Logging and Audit ·  Security-relevant events (e.g., authentication attempts, access to personal data, privilege changes) shall be logged and retained for a period sufficient to support incident investigation.
·  Logs shall be stored securely and protected against unauthorised modification.
·  Privileged-account activity shall be subject to periodic review.
Compliance and Legal Obligations ·  The Client shall monitor and ensure compliance with applicable data protection laws, regulations, and contractual obligations relevant to the international transfer of personal data.
·  Responsibility for data protection compliance shall be assigned to identified personnel or a dedicated function within the organisation.

 

Version 1 | July 2026

Contact Decorative Stadium background

GET IN TOUCH WITH OUR TEAM

Contact us