Version 1.1 – 1st January 2023 - 31st December 2025
1. DATA PROTECTION LAWS
1.1 Travelport and Participant shall comply with the Data Protection Laws at all times during the Term.
1.2 Travelport and Participant will each be independent Data Controllers of Personal Data in the processing of Personal Data in relation to the services each Party respectively provides. Each Party will, to the extent practicable and reasonable in the circumstances and in relation to its respective processing of Personal Data, cooperate with the other Party where necessary or appropriate to respond to Data Subject requests and provide information necessary for other communications required by Data Protection Laws. Participant will notify Travelport of their contact details and will keep such contact information updated from time to time. The current contact details for Travelport for queries regarding Personal Data are as follows:
Attn:
Data Protection Officer
Travelport
One Axis Park, 10 Hurricane Way
Langley, Berkshire SL3 8AG
United Kingdom
Email: Privacy@travelport.com
1.3 In their capacity as a Data Controller, each of Travelport and Participant shall process Personal Data fairly and lawfully in accordance with Data Protection Laws and for: (a) the limited and specified purposes consistent with the consent provided by the Data Subject; and/or (b) any other lawful basis provided under Data Protection Laws or other applicable laws.
2. USE OF PROCESSORS
2.1 Both Parties may appoint third party processors to Process Personal Data but shall comply with the relevant provisions of the Data Protection Laws in making any such appointments and shall remain liable for the acts and/or omissions of any Processor they appoint with respect to their Processing of Personal Data.
3. TECHNICAL AND ORGANIZATIONAL MEASURES
3.1 Each Party confirms that it has in place (and shall implement on an ongoing basis at its own cost) appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, and which provide a level of security appropriate to the risk represented by its Processing of Personal Data and the nature of the Personal Data to be protected. Each Party confirms that it has in place (and shall implement on an ongoing basis) procedures so that any third party it authorises to have access to the Personal Data, including Processors, will respect and maintain the confidentiality and security of the Personal Data. To the maximum extent permitted by law, any person acting under the authority of a Party, including a Processor, shall be obligated to process the Personal Data only on instructions from that Party.
3.2 Travelport has implemented the technical and organizational measures set out in Annex II to the SCCs. and these technical and organizational measures are applied to all Personal Data Processed by Travelport under the Agreement, not just Personal Data subject to the SCCs. Travelport shall keep such security measures under review and shall carry out such updates as it determines appropriate throughout the Term of the Agreement.
3.3 Travelport will maintain an information security program designed to provide at least the same level of protection as the following:
(a) the ISO/IEC 27001:2013 – Information Security Management Systems – Requirements; and
(b) Payment Card Industry Data Security Standard (PCI-DSS).
3.4 It is the responsibility of each Party to ensure that its staff members are appropriately trained to handle and process Personal Data and have entered into confidentiality obligations relating to the Processing of Personal Data.
4. DATA BREACHES
4.1 In the event that a Party becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Participant Personal Data that is likely to result in a risk to the rights and freedoms of natural persons (each a “Data Breach”), the Party that has suffered such Data Breach shall notify the other Party without undue delay. The Parties agree that unsuccessful attempts to compromise or access the security of Personal Data shall not be considered a Data Breach and shall not be subject to notification in accordance with this clause 4.1, including, without limitation, unsuccessful denial of service attacks, unsuccessful log in attempts, unsuccessful attacks on firewalls or other systems or similar incidents.
4.2 The Party that has suffered the Data Breach shall provide relevant information regarding such breach to the other Party, including the nature of the Data Breach, categories of Personal Data involved, the scope of the breach, and remediation plans. The Parties shall coordinate on responsive actions prior to notifying the Data Subjects and/or regulatory or supervisory authorities, unless as otherwise required under the Data Protection Laws. The parties agree to provide reasonable assistance as is necessary to each other to facilitate the handling of any Data Breach in an expeditious and compliant manner.
5. DATA SUBJECT RIGHTS
5.1 In the event of a dispute, complaint or claim brought by a Data Subject or a regulator concerning the handling of Participant Personal Data against either or both Parties, the Parties will inform each other about any such disputes, complaints or claims, and will cooperate with a view to settling them amicably in a timely fashion.
6. INTERNATIONAL DATA TRANSFERS
6.1 Participant acknowledges and accepts that Travelport may process Personal Data relating to Bookings outside of the United Kingdom or the European Economic Area including without limitation in the United States.
6.2 EU GDPR: In the absence of other appropriate safeguards or exemptions for the transfer of Personal Data pursuant to the Agreement and to which Chapter V of the GDPR applies, the Parties agree to be bound by Module 1 (controller to controller) of the standard contractual clauses pursuant for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as annexed to Commission Implementing Decision 2021/914 as currently set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (“SCCs”) which are incorporated by reference into this DPA. Where the SCCs identify optional provisions (or provisions with multiple options) the following shall apply:
(a) in Clause 7 (Docking Clause) – the Optional provision shall apply;
(b) in Clause 11(a) (Redress) – the Optional provision shall NOT apply;
(c) in Clause 17 (Governing law) – Where Participant is established in an EU Member State Option 2 shall apply and the law of the country where a Participant is established shall govern. Where Participant is not established in an EU Member State the laws of the Republic of Ireland shall apply;
(d) in Clause 18(b) (Choice of forum and jurisdiction) – Where Participant is established in an EU Member State the courts of the country where Participant is established shall have jurisdiction. Where Participant is not established in an EU Member State the courts of the Republic of Ireland shall have jurisdiction.
In the event that the SCCs are replaced or superseded the replacement version shall be incorporated into this DPA from the date of publication. For the avoidance of doubt the Parties agree that when the European Commission publishes standard contractual clauses for data importers who are already subject to the direct effects of EU GDPR pursuant to Article 3 of EU GDPR such standard contractual clauses should replace the SCCs from the date of publication and this DPA shall be amended accordingly.
6.3 Annex I and Annex II in Attachment 1 to this DPA shall constitute the completed Annexes I and Annex II to the SCCs.
6.4 UK GDPR: In the absence of other appropriate safeguards or exemptions for the transfer of Personal Data pursuant to the Agreement and to which Chapter 5 of the Data Protection Act 2018 (UK) applies, the Parties agree to be bound by the UK GDPR template Addendum B.1.0 issued by the UK ICO in force 21 March 2022 (“UK Approved Addendum”) which shall amend the SCCs in respect of such transfers and Part 1 of the UK Approved Addendum shall be populated as set out below:
(a) Table 1. The “start date” will be the date this DPA enters into force. The “Parties” are Travelport and Participant.
(b) Table 2. The “Addendum EU SCCs” are the modules and clauses of the SCCs selected in relation to a particular transfer in accordance with 6.2 of this DPA.
(c) Table 3. The “Appendix Information” is as set out in Annex 1 and Annex 2 to this DPA.
(d) Table 4. Neither party may end the UK Approved Addendum in accordance with its Section 19.
6.5 In respect of the SCCs and UK Approved Addendum each Party shall be both a “data exporter” and a “data importer” and be bound by its obligations and be afforded its rights under the SCCs or UK Approved Addendum as both “data exporter” and “data importer” depending upon whether it is exporting or importing the Personal Data as the case may be.
6.6 The SCCs and UK Approved Addendum will cease to apply if an alternative method of transferring Personal Data to a Third Country is later recognised by either the EU Commission or the UK Information Commissioners Office or UK Government.
7. TERM AND TERMINATION
7.1 This DPA shall continue during the term of the Agreement and for a period of 4 years following termination or expiry of the Agreement.
7.2 All provisions which expressly or by implication are intended to survive the termination or expiry of this DPA shall remain in full force and effect.
8. MISCELLANEOUS
8.1 To the extent permitted by law each Party’s liability under this DPA shall be limited to the Fees payable to Travelport by the Participant in the previous 12 months prior to the event that gave rise to the liability.
8.2 This DPA forms part of the Agreement.
8.3 Except as expressly amended, modified or supplemented in this DPA, all other provisions of the Agreement shall remain in full force and effect.
8.4 In the event of a conflict between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA shall take precedence.
9. DEFINITIONS AND INTERPRETATION
9.1 The following definitions shall apply to this DPA:
“DPA” means these Data Protection Terms;
“Agreement” means the TIGADA or TPA as applicable to a Participant;
“Data Controller” means a person or entity who determines the purpose and means of the processing of Personal Data;
“Data Protection Laws” means any legislation, rules and regulations worldwide in relation to the use and processing of Personal Data applicable to Travelport or Participant from time to time (including any relevant codes of practice) and shall include without limitation EU GDPR, UK GDPR, the Data Protection Act 2018 (UK) and any successor legislation;
“Data Subject” shall have the meaning given to it in EU GDPR;
“EU GDPR” means the General Data Protection Regulation (EU) 2016/679;
“EU Member State” means a member of the European Union;
“Fees” the Charges to be paid under a TPA or the fees and charges to be paid under a TIGADA by the Participant for use of the Travelport System (as applicable);
“Participant Personal Data” means Personal Data that relates to Bookings made with Participant via the Travelport System;
“Party” means Travelport or Participant, and “Parties” shall mean both of them;
“Personal Data” refers to “personal data” as defined by applicable Data Protection Laws and processed pursuant to the Agreement and such other personal data as further described in Annex I in Attachment 1 to this DPA;
“Processor” and “Processing” shall have the meanings given to them in EU GDPR;
“SCCs” shall have the meaning given to it under clause 6.2;
“Third Country” means a country outside the EEA not recognised by the European Commission as providing an adequate level of protection for Personal Data (as described in EU GDPR);
“TIGADA” means the Travelport International Global Airline Distribution Agreement (formerly known as GIGADA) as may be in force between Travelport and Participant, as amended from time to time;
“TPA” means the Travelport Participation Agreement as may be in force between Travelport and Participant, as amended from time to time;
“Travelport’s Privacy Policy” means Travelport’s privacy policy which can be found at https://archive.travelport.com/privacy;
“Travelport System” means any CRS operated by Travelport or Travelport’s affiliates;
“UK GDPR” has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.
9.2 Except as otherwise specified in this DPA, terms used in this DPA which are not otherwise defined in this DPA shall have the same meanings as used in the Agreement.
Attachment 1
Annex I
A. LIST OF PARTIES
Data exporter / importer(s) (as applicable):
Name: Participant as listed in the Agreement.
Address: as listed in the Agreement
Contact person’s name, position and contact details: as notified by Participant to Travelport in accordance with clause 1.2 of the DPA.
Activities relevant to the data transferred under these clauses: According to the Agreement
Role (controller/processor): controller
Data exporter / importer(s) (as applicable):
Name & Address: TRAVELPORT, LP, a limited partnership organized and existing under the laws of State of Delaware, USA and with a principal place of business at 300 Galleria Parkway, N.W. Atlanta GA 30339, United States of America (“Travelport, LP”); and
Name & Address: TRAVELPORT INTERNATIONAL OPERATIONS LIMITED, registered in England & Wales (Company Registration No. 09726717) whose registered office is at Axis One, Axis Park, 10 Hurricane Way, Langley, Berkshire, SL3 8AG (“TIOL”).
Contact person’s name, position and contact details:
Data Protection Officer
Axis One, Axis Park, 10 Hurricane Way, Langley, Berkshire, SL3 8AG
Privacy@Travelport.com
Activities relevant to the data transferred under these clauses: According to the Agreement.
Role (controller/processor): controller
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
The personal data transferred concern the following categories of data subjects:
- Travellers/Consumers, being individual customers of Participant.
Categories of personal data transferred
The personal data transferred concern the following categories of data:
- Personal and family information, including name, contact information (postal address, email address and telephone number), visa or passport information, date of birth, gender, credit or debit card information, marital status, travel and accommodation details, languages spoken/preference, special travel requests (such as a request for a wheelchair or a special meal) and corporate loyalty program number.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
- The Parties do not intend to transfer special categories of data about consumers, but in providing their services, there may be incidental and indirect transfers of special categories of data related to Travellers/Consumers’ health condition or religious affiliation.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)
- Continuous
Nature of the processing
- Automated
Purpose(s) of the data transfer and further processing
In respect of Travelport:
The purpose of the transfer is the fulfilment of the Traveller/Consumer’s reservation request through the Travelport System. Reservation requests may subsequently be amended by customers of Travelport leading to a transfer of personal data back to the Travelport System to reflect the amendment and update the booking details.
On behalf of Participant, Travelport provides access to and operates a substantial computer hardware and software complex (the “Travelport System”). The Travelport System acts as the technology intermediary between Participant and travel agencies (both considered customers of Travelport). For the travel itineraries requested from Participant by travel agents for their end Travellers/Consumers, the Travelport System facilitates the booking and ticketing of travel reservations.
The Travelport System provides information about the availability and price of travel alternatives to its customers which provide it to the end Traveller/Consumer. The Traveller/Consumer provides Personal Data and chooses travel arrangements (flight, airline, departure date, etc.) in communication with the travel agent. The travel agent retrieves Participant’s travel information from the Travelport System and makes a reservation for the Traveller/Consumer by inputting the Traveller/Consumer’s Personal Data as part of the reservation and booking process.
The Travelport System creates and maintains a record of the requested components of the Traveller/Consumer’s trip in the passenger name record or similar files.
Each travel service provider, such as Participant, then receives information as processed by the Travelport System about its portion of the trip and confirms the reservation back to the Travelport System. The travel agent provides this information to Travelport for the benefit of the Traveller/Consumer seeking to purchase travel services.
Travelport also uses Personal Data to perform internal business processes (such as testing, quality assurance, and product development and enhancement), conduct scientific, statistical and research activities regarding travel trends, conduct loss prevention and anti-fraud activities and provide help desk services.
In respect of Participant:
The transfer is for the purpose of bookings made through the Travelport System (including, without limitation, to facilitate the provision of air passenger transportation and ancillary services by Participant). Participant also uses Personal Data to provide support services to Traveller/Consumer, to reply to and answer Traveller/Consumer’s question or to respond to Traveller/Consumer’s complaints or requests perform, internal business processes and conduct scientific, statistical and research activities regarding business and travel trends.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Travelport retains traveller personal data no longer than is necessary to comply with legal obligations and to fulfil legitimate business and compliance purposes. It is Travelport’s policy to keep traveller personal data for no longer than 36 months after the completion of the last travel transaction in the reservation unless it is necessary to keep the data longer to comply with legal obligations.
Participant retains traveller personal data no longer than is necessary to comply with legal obligations and to fulfil legitimate business and compliance purposes.
For transfers to (sub-) processors, also specify subject matter, nature and duration
- N/A
C. COMPETENT SUPERVISORY AUTHORITY
Identify the competent supervisory authority/ies in accordance with clause 12
The following shall apply:
- If Participant is established in an EU Member State the competent supervisory authority shall be the supervisory authority which is responsible for Participant’s compliance with EU GDPR;
- If Participant is not established in an EU Member State but falls within the territorial scope of EU GDPR under Article 3(2) and has appointed a representative under Article 27(1) EU GDPR, the supervisory authority of the Member State in which the representative (as defined in Article 27(1) of GDPR) is established shall act as the competent supervisory authority.
- If Participant is established in Switzerland, the Swiss Federal Data Protection and Information Commissioner shall act as competent supervisory authority.
- If Participant is not registered in a EU Member State and has not appointed a representative the following supervisory authority shall be the competent supervisory authority:
Irish Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland
Annex 2
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Travelport ensures that its products and services are designed with privacy principles in mind. Travelport has incorporated safeguards such as Data Protection Impact Assessments and other privacy-by-design mechanisms into its processing activities.
Whilst there is no industry standard as to the categories of personal data required to be inputted by our customers, our systems require only the minimum amount of personal data, such as an agency identifier and traveller’s name however additional information is frequently included in agency bookings.
As a data controller, Travelport sets forth the division of responsibilities with its customers, who are also data controllers, in written agreements.
Travelport has established internal processes to support our customers should a data subject, i.e. traveller, exercise his/her rights under GDPR. The ability to access a PNR is already available to subscribers through current booking tools, as is the ability to rectify those records. Likewise, the right to data portability may be fulfilled through current PNR access functionality. Our customers may also leverage applicable Travelport itinerary services to assist in producing relevant records.
Travelport security practices establish appropriate levels of security based upon data classification and risk criteria. The level of security measures employed is based upon a combination of the sensitivity classification of the data, and requirements for data integrity, non-repudiation, authenticity, availability, and mission criticality.
Passenger records reside on the Travelport mainframe systems, where it is encrypted while stored. As part of our commitment to ensure that we employ state of the art solutions, we continue to explore alternatives such as cloud processing and storage. Access is controlled by user identification and authentication technologies appropriate to the mainframe environment. GDS users/subscribers must be authenticated at a minimum by user identification and password controls. The level of access authority into the mainframe environment is defined for each user/subscriber or user group. Access to all GDS data is subject to “deny by default”. Subscribers are limited to accessing only the data for which they have been provided access authority.
Access to passenger data in production and test environments is limited to only programmers and personnel whose duties require access to such data for problem solving, quality control and development purposes.
Access to distributed systems (i.e., non-mainframe systems) is controlled via a combination of third party and native security access technologies appropriate to each system/platform. Company policy permits access to a distributed system based upon a “need to know” or “need to conduct business” basis. At a minimum, access is controlled through user identification and password authentication.
Data transmissions are encrypted with TLS 1.2, and inbound access from the Internet is tightly controlled through numerous layers of security controls. This includes access restrictions on routers, switches, and access control rules on firewalls. Network security is based upon a “deny all” by default policy. Current network architecture requires inbound access from the Internet to be brought into a “Demilitarized Zone” (DMZ – an isolated network) to ensure that systems exposed to the Internet will not compromise other Travelport information assets. Travelport employs active host and network-based intrusion detection and prevention systems with 24x7x365 security monitoring and alerting.
Data is encrypted at rest utilizing the IBM DS8000 Storage Management System to encrypt data stored on mainframe DASD hardware. Gemalto SafeNet encryption is also utilized to protect databases that contain sensitive data.
Travelport undergoes regular testing and auditing to measure the effectiveness of existing security controls. This includes a combination of internal and external vulnerability scanning, third party external vulnerability scanning, and application penetration testing. Information Technology controls are regularly audited by Travelport Internal Audit, Risk Management, and external auditors. Travelport has professionally certified dedicated personnel in the roles of Information Security, Internal Audit and Risk Management.
Travelport has senior management support for the implementation and support of its ISMS, which oversees the actions of the Cyber Security organization. The Travelport Cyber Security & Risk program is risk-based, where risk is categorized according to likelihood and impact, is based on industry accepted best practices, and consists of a layered approach to security including physical, technical, and administrative controls. The Travelport Cyber Security program is reviewed and approved by the Senior Leadership.
Travelport currently follows ISO27001:2013 compliance for its Information Security Management System (ISMS) or an equivalent industry standard. This stringent certification demonstrates adherence to a comprehensive systems methodology for implementing, managing, and maintaining corporate information security. Travelport currently complies with the Payment Card Industry Data Security Standard (PCI DSS 3.2.1) and shall maintain an information security program designed to provide at least the same level of protection as ISO27001:2013 and PCI DSS 3.2.1.