Barco search

myBarco notifications

Unread

Read

You don't have any notifications.

Data processing addendum

LRC-TE-0047 V3 July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement governing Barco products and/or services (the “Agreement”).

WHEREAS in the performance of the Agreement, Barco (acting as Data Processor) may process Personal Data on behalf of End User;

WHEREAS End User (acting as Data Controller) engages Barco pursuant to article 28 GDPR;

WHEREAS transfers to third countries shall be governed by EC Standard Contractual Clauses (Commission Implementing Decision 914/2021/EU of 4 June 2021) as set out in appendix III;

WHEREAS this DPA sets out the terms ensuring compliance with Applicable Data Protection Laws.

 

1. Definitions

GDPR definitions apply. In addition,

“Affiliate” means any of Affiliate(s) of End User which (a) is subject to the data protection laws and regulations of the EEA, and (b) is permitted to use the Barco Product.

“Applicable Data Protection Law” means the Data Protection Laws applicable to the Data Controller or Data Processor as the case may be.

“Barco” means Barco NV, with registered office at President Kennedypark 35, 8500 Kortrijk Belgium and its subsidiaries.

“Barco Product” means the Barco products and/or services identified in the Agreement, and includes reference, as relevant, to the physical item (hardware component) generating data and capable of communication, the digital service (hardware, software and/or service component) enabling or enhancing the product’s function, the relating software, and the applicable cloud service.

“Data Controller” is a reference to End User.

“Data Processor” is a reference to Barco.

Data Protection Law” means the GDPR and the laws and regulations containing rules for the protection of Data Subjects with regard to the Processing of Personal Data.

“End User” is the person or entity on whose behalf this Exhibit DPA is accepted.

“End User Data” means Personal Data for which End User is the Data Controller.

“GDPR” means regulation 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

“Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. For the avoidance of doubt, a Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Personal Data (such as unsuccessful login attempts, pings, or port scans).

“Sub-Processor” means any Processor engaged by Barco that Processes End User Data.

 

2. Instructions

2.1 Barco shall Process End User Data only on documented instructions from Data Controller, including this DPA.

2.2 End User is obliged to ensure that any instruction given to Barco is in compliance with Applicable Data Protection Law. 

2.3 Where required by law, Barco may Process End User Data and shall inform Data Controller unless prohibited.

2.4 The Agreement and this DPA are Data Controller's complete and final instructions.

2.5 Barco shall inform Data Controller if an instruction conflicts with other legal or regulatory obligations or is technically impossible. 

 

3. Applicable law

Each party shall comply with Applicable Data Protection Laws.

 

4. Obligations of Data Controller

Data Controller: (i) ensures lawful collection and transfer of Personal Data; (ii) provides required transparency to data subjects and (iii) remains primary contact point for data subjects.

 

 5. Obligations of Barco

5.1 Security. Barco shall implement appropriate technical, physical and organisational security measures as specified in Appendix II.

5.2 Confidentiality. Barco shall ensure that all persons authorized to process End User Data are subject to an appropriate contractual or statutory duty of confidentiality.

 

6. Sub-Processors

6.1 Data Controller authorizes use of Sub-Processors. The Sub-Processors that are currently engaged by Barco are listed here: Product privacy statement - Barco.

6.2 Barco shall notify changes. Data Controller shall not unreasonably object to such changes. 

6.3 Sub-processing shall be governed by written agreements with equivalent data protection obligations.

 

7. Audit and compliance

7.1 Barco shall make the processing systems, facilities and supporting documentation relevant to the Processing of End User Data available for an audit by End User: (i) on reasonable notice and (ii) no more than once every two years.

7.2 Compliance is demonstrated through the audit rights in article 7.1.  Any additional information requests shall be reasonable and proportionate.

 

8. Notifications of Disclosures and Personal Data Breaches

8.1 Barco shall notify Data Controller as soon as reasonably possible if:

i)     it receives an inquiry, a subpoena or a request for inspection or audit from a competent public authority relating to the Processing, unless prohibited by law;

ii)    it intends to disclose Personal Data to any competent public authority; or

iii)   it becomes aware of a Personal Data Breach.

8.2 In the event of a Personal Data Breach, Barco shall take reasonable remedial measures to preserve the confidentiality of the End User Data. Furthermore, Barco shall provide Data Controller the information reasonably requested by End User regarding the Personal Data Breach.

8.3. Barco’s obligation to report or respond to a Personal Data Breach under this Section 8 is not and will not be construed as an acknowledgement by Barco any fault or liability of Barco with respect to the alleged Personal Data Breach.

 

9. Cooperation and assistance duty

9.1 Barco will reasonably assist Data Controller with data subjects requests.

9.2 Upon written request of Data Controller, Barco shall assist Data Controller in ensuring compliance with the obligations regarding security of the Processing, notification of Personal Data Breaches and mandatory data protection impact assessments (articles 32-36 GDPR).

9.3 Barco shall cooperate with the supervisory authorities in the performance of their duties.

 

10. Return and destruction of Personal Data

Upon termination, Barco shall – at a reasonable fee -, at the option of Data Controller expressed in writing, return and/or delete the End User Data and copies thereof, unless retention is required by law.

 

11. Affiliates

The parties acknowledge and agree that, by using the Barco Product, the End User enters into the DPA for its own account and, as applicable, in the name and on behalf of its or their Affiliates. All access to and use of the Barco Product by Affiliates must comply with the terms and conditions of the DPA and any violation of this DPA by an Affiliate shall be deemed a violation by End User.

 

12. Liability

12.1 Barco indemnifies Data Controller for all claims, losses or damages incurred by Data Controller and arising directly out of a breach by Barco of this DPA and/or the Applicable Data Processing Law provisions directed to Barco, unless Barco proves that it is not responsible for the event giving rise to the liability.

12.2 Data Controller indemnifies Barco and holds Barco harmless against all claims, losses or damages incurred by Barco and arising directly out of a breach of this DPA and/or the Applicable Data Protection Law by Data Controller, subject to applicable law.

12.3 Each party’s liability to the other party will be limited to foreseeable, direct and personal damage suffered, excluding indirect, incidental, special or consequential damage and regulatory fines, even if advised of the possibility thereof.

12.4 In any event and to the extent permitted by law, Barco’s aggregated maximum liability under this DPA will be limited to the amounts received for the provision of the Barco Product in the twelve months preceding the incident giving rise to liability.

 

13. Data transfer

Any transfer of Personal Data to a Non-Adequate Country shall be governed by the terms of the EC Standard Contractual Clauses (Appendix III) or other model clauses that have been approved by the EU commission or another competent public authority in accordance with the Applicable Data Protection Law.

 

14. Termination of the DPA

This DPA shall remain in force until the termination or expiration of the Agreement.

 

15. Entire Agreement

This Exhibit DPA is an integrating part of the Agreement. If there is a conflict between the Agreement and this DPA, the terms of this DPA will control.

 

 16.    Appendices

The following Appendices are attached hereto and made a part hereof:

Appendix I: Details of processing

Appendix II: Technical and organizational measures

Appendix III: EC Standard Contractual Clauses

 

Appendix I

Details of Processing

 

This Appendix 1 includes certain details of the Processing of End User Data as required by Article 28(3) GDPR. More specific details per Barco product are included in the product specific sections of Barco’s product privacy statement.

 Subject matter and duration of the Processing of End User Data

The subject matter of the Processing of the End User Data is set out in Barco’s product privacy statement on Product privacy statement - Barco and this DPA.

End User Data will be Processed for the duration of the provision of Barco Product for the benefit of the End User.

End User Data can be Processed outside the EEA by Barco Affiliates and/or Sub-Processors as indicated in Barco’s Product Privacy Statement.

The nature and purpose of the Processing of End User Data

Barco may process End User Data for various purposes including: managing the hosting environment on behalf of the Data Controller to enable the provision of the Barco Product and associated Cloud Services; delivering and maintaining the service; monitoring and ensuring quality, safety, and security; complying with legal obligations; gaining insight into Barco Product and associated Cloud Services and their use; conducting analytics, research, market evaluation, and fraud prevention; and developing, training, testing, improving, innovating, enhancing, and supporting Barco hardware and software, whether for existing or new products, services, or AI systems and underlying models; and for any purposes expressly agreed upon, for any other purposes defined in this Agreement or in other agreements.

The types of End User Data to be Processed is set out in Barco’s product privacy statement on Product privacy statement - Barco

The categories of Data Subjects to whom the End User Data relates

·    End User’s employees (including End User’s agents, advisors, freelancers and consultants) and End User’s representatives (who are natural persons)

·    Customers of the End User, its employees and representatives

·    Customers of the End User’s customers, its employees and representatives

·    Users of the Barco Product authorized by the End User to use the products

 

Appendix II

Technical and organisational measures

1.    The pseudonymisation and encryption of personal data; (art. 32, par. 1, lit. a, GDPR)

a.     based on a risk assessment (and if required an additional DPIA) Barco will ensure a level of security appropriate to the risk, including inter alia as appropriate:

                                      i.    Pseudonymization

                                     ii.    Encryption, conform Cryptographic Controls policy

2.    Ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (art. 32, par. 1, lit. b, GDPR)

a.     Barco is verified under ISO/IEC 27001:2022 covering the business processes and  infrastructure that relate  to the hard-&software design and development; manufacturing execution system, sales, deployment, and support of the products listed on the certificate: Certificates - Barco

b.    Security and privacy by design

c.    Compliance with the security policies in place at Barco, covering

                                      i.    Code of Ethics

                                     ii.    Code of Digital Conduct

                                    iii.    Information Security Top Policy

                                    iv.    Acceptable Use Policy

                                     v.    Third Party Security Policy

                                    vi.    Identify and Access Management Policy

                                   vii.    Information Security Incident Management Policy

                                  viii.    Cryptography and key management Policy

                                    ix.    Disposal – destruction and reuse policy

                                     x.    Backup policy

                                    xi.    Anti-malware policy

                                   xii.    Secure Development Life Cycle Policy

                                  xiii.    Phyiscal and environmental security policy

                                  xiv.    Network Protection Policy

                                   xv.    IT Operations Policy

                                  xvi.    Secure support and service policy

                                 xvii.    Disposal and Destruction

 

3.    The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (art. 32, par. 1, lit. c, GDPR)

Compliance with the security policies in place at Barco, covering

                                      I.    Backup and Recovery

                                     II.    IT Operations

4.    Process for regular testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the data processing (art. 32, par. 1, lit. d, GDPR)

a.    Product Security Incident Response teams (psirt): https://www.barco.com/psirt

b.    Barco Security Organization operates in three lines of defense, covering operations, governance and internal audit.

c.    Regular evaluations by independent third parties (e.g. penetration testing, audit, …)

d.    Integration of automated security scanning tools during the development process (Secure SDLC) and operations

 

Appendix III

EC Standard Contractual Clauses

The 2021 Standard Contractual Clauses are incorporated into the DPA by reference, and will apply in the following manner:

Module Two (Controller to Processor) will apply where End User is a controller of Personal Data and Barco is a processor of Personal Data.

For this Module:

i)     Clause 7 will not apply;

ii)    in Clause 9(a), Option 2 will apply, and the time period for prior notice of Sub-Processor changes will be as set forth in Section 6 of the DPA;

iii)   in Clause 11(a), the optional language will not apply;

iv)   in Clause 17, Option 1 will apply, and the Standard Contractual Clauses will be governed by the laws of Belgium;

v)    in Clause 18(b), disputes will be resolved by the courts of Belgium;

vi)   Annex I.A (List of parties)

The End User (as defined under Section 1 of the DPA) acts as data exporter and Barco (as defined under Section 1 of the DPA), on behalf of Barco’s (Sub-)Processors located in a Third Country, acts as data importer for the construction of these 2021 Standard Contractual Clauses.  Further contact details are part of the DPA and Appendix I.

vii)  Annex I.B (Description of Transfer)

The Parties agree that Appendix I to the DPA (as well as Section of DPA in respect of transfers to (sub-processors) describe the transfer as required under the 2021 Standard Contractual Clauses.

viii)  Annex I.C (Competent Supervisory Authority)

The competent supervisory authority is the supervisory authority that has primary jurisdiction over the data exporter.

ix)   Annex II (Technical and Organizational Measures – Security of the Data)

Described in Appendix II to the DPA

x)    Annex III (List of Sub-processors)

The Data Controller has authorised the use of the sub-processors mentioned in Barco’s product privacy statement (Product privacy statement - Barco)