Loading

Data Processing Addendum

This Data Processing Addendum, including its schedules and annexes (collectively, the “DPA”) forms part of the agreement (written or electronic) for the supply and provision of products, software, hardware, solutions and/or services (collectively “Products” or “Services”) between Rockwell Automation and Customer (“Agreement”) and governs Rockwell Automation’s Processing of Customer Personal Data.

This DPA applies only to the extent Rockwell Automation Processes Personal Data on behalf of Customer under or in connection with the Agreement. In the event of a conflict between Applicable Privacy Laws, the General Data Processing Terms, the Jurisdiction-Specific Terms, and the Agreement, the order of precedence as to the subject matter of this DPA will be: (1) Applicable Privacy Laws; (2) the Jurisdiction-Specific Terms; (3) the General Data Processing Terms; and (4) the Agreement, unless otherwise stated herein. Any terms not defined in the Agreement or this DPA shall have the meaning given to them in the Applicable Privacy Laws.

The English version of this DPA is the authoritative version. Any translation is provided for convenience only. In the event of any inconsistency, ambiguity, or difference in interpretation, the English version shall govern and prevail.

DPA STRUCTURE

This DPA consists of:

A. General Data Processing Terms. These terms apply to all Processing of Customer Personal Data by Rockwell Automation under the Agreement.

B. Jurisdiction-Specific Terms (Schedules A – E). Each schedule applies only to the extent Customer Personal Data originates from the jurisdiction specified in that schedule:

  • Schedule A: European Economic Area and Switzerland
  • Schedule B: United Kingdom
  • Schedule C: USA
  • Schedule D: China
  • Schedule E: Brazil

 

GENERAL DATA PROCESSING TERMS

1. DEFINITIONS

“Adequacy Decision” means positive finding of data protection adequacy issued by the relevant authority under the Applicable Privacy Laws concerning any country, territory, sector or international organization confirming that the country, territory, sector or international organization to which Customer Personal Data is transferred ensures an adequate level of data protection.  

“Affiliates” means, unless otherwise defined in the Agreement, an entity that is directly or indirectly controlled by or is under common control with a party.

“Control” means an ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the relevant entity.

“Applicable Privacy Laws” means all laws and enforceable regulations relating to the Processing of Personal Data that apply either to Customer or Rockwell Automation in connection with the Processing of Personal Data under the Agreement.

“Customer” means: (i) the entity that executed the Agreement; or (ii) in the event this DPA forms part of and is incorporated into a frame agreement capable of being utilized by several related entities, the entity executing a binding contract with Rockwell Automation under such frame agreement (for example, under an order form and/or statement of work referencing the frame agreement that incorporates this DPA, or that references this DPA directly).

“Customer Personal Data” means any Personal Data that is Processed by Rockwell Automation on behalf of the Customer for the purpose of providing the Products and/or Services.

“Covered Region” means the jurisdiction from which Customer Personal Data originates.

“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as may be amended from time to time.

“Rockwell Automation” means Rockwell Automation, Inc., a Delaware corporation, having a principal place of business at 1201 South 2nd Street, Milwaukee, Wisconsin 53204, or a Rockwell Automation Affiliate identified in or executing the Agreement, an order form, or statement of work (as applicable).

“Restricted Transfer” shall mean the export of Customer Personal Data by Rockwell Automation or its SubProcessors outside a Covered Region or a third country without an Adequacy Decision, to the extent Applicable Privacy Laws restrict such transfers.

“Security Incident” means a confirmed breach of security that results in the unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Rockwell Automation on behalf of Customer. Based on the Applicable Privacy Laws, the determination of a Security Incident may take into account the potential risk of harm to the rights and freedoms of Data Subjects based on the nature of Customer Personal Data and the context in which it is Processed. Security Incident excludes unsuccessful attempts or activities that are blocked by Rockwell Automation’s security controls and that do not compromise the confidentiality, integrity, or availability of Customer Personal Data. 

“Trust Center” means Rockwell Automation’s Trust Center available at https://www.rockwellautomation.com/en-us/company/about-us/sustainability/trust-security.html

The terms “Controller”, “Data Subject”, “Personal Data”, “Processing”, “Process” and “Processor” shall have the meaning given in the Applicable Privacy Laws and any associated or similar terms shall be interpreted in line with the foregoing.  

2. PURPOSE AND SUBJECT-MATTER OF PROCESSING  

2.1. To provide Customer with the Products and/or Services, Rockwell Automation may Process Customer Personal Data. The parties agree that the Customer is the Controller and Rockwell Automation is the Processor in relation to the Customer Personal Data Processed in the course of providing Products and/or Services. The subject matter of the said Processing is the performance of the Agreement. The obligations and rights of Customer and Rockwell Automation are as set out in this DPA. Details regarding the nature, duration and purpose of the Processing, the types of Personal Data Rockwell Automation Processes and the categories of Data Subjects whose Personal Data is Processed are described in the schedules to this DPA.

2.2. The extent of the obligations owed to and the rights exercisable by Customer may vary based on the nature of the Personal Data provided by Customer, the scope of Rockwell Automation’s Processing activities, and Applicable Privacy Laws. Customer is solely responsible for identifying and disclosing the applicable Covered Regions from which Customer Personal Data originates. Refer to section 3.2.3 of this DPA for further details.

3. OBLIGATIONS

3.1. Rockwell Automation Obligations.  

Subject to Applicable Privacy Laws, Rockwell Automation will:

3.1.1. Process the Customer Personal Data only on and in accordance with Customer’s documented written instructions, or as set out in this DPA and the Agreement (“Processing Instructions”); 

3.1.2. Inform Customer if Rockwell Automation becomes aware of a Processing Instruction that, in Rockwell Automation’s reasonable opinion, infringes Applicable Privacy Laws, provided that, to the maximum extent permitted by applicable law, Rockwell Automation shall have no liability whatsoever arising (whether in contract, tort (including negligence) or otherwise) for any losses, costs, expenses or liabilities  arising from or in connection with any Processing in accordance with Customer's Processing Instructions. The parties acknowledge that Rockwell Automation shall not be obliged to conduct any legal review or exercise legal expertise to assess whether Customer's Processing Instructions are compliant with the Applicable Privacy Laws.

3.2. Customer Obligations:

3.2.1. Customer shall comply with the Agreement, order form and/or statement of work (as applicable), Applicable Privacy Laws, and its obligations under this DPA. Prior to any Processing of Customer Personal Data by Rockwell Automation and its Products and/or Services, and in accordance with Applicable Privacy Laws, Customer is responsible for providing appropriate information and obtaining any required consent from all Data Subjects whose Personal Data is Processed by Rockwell Automation under the Agreement.

3.2.2. Under Applicable Privacy Laws, Data Subjects may have certain rights in relation to their Personal Data. These rights may include the right to access, correct, update, disclose, delete, and/or port Personal Data, and/or to withdraw consent to Processing, opt-out of communications, restrict Processing of Personal Data, and/or make claims/complaints in relation to the exercise of such rights. As Controller and responsible entity under Applicable Privacy Laws, Customer (or Rockwell Automation if and to the extent applicable), is responsible for responding to any request by Data Subjects to exercise such rights (“Data Subject Request”).

3.2.3. In the event Customer is subject to additional industry or data-specific legal or regulatory restrictions based on its area of business, jurisdiction, and/or categories of data it collects and maintains, including Customer Personal Data beyond those covered in this DPA, such as data localization or record-specific retention requirements, Customer shall, prior to providing Rockwell Automation with access to Customer Personal Data,  notify Rockwell Automation in writing of all such restrictions that may impact Rockwell Automation’s Processing activities and will be responsible for any additional costs incurred by Rockwell Automation to meet these additional restrictions. Rockwell Automation shall bear no liability for any failure to comply with jurisdiction-specific requirements where Customer has failed to provide such prior written notice and reasonable details in accordance with this provision.

4. SUB-PROCESSING

4.1. Pursuant to Applicable Privacy Laws, Customer acknowledges and expressly agrees that Rockwell Automation may engage its Affiliates and/or any third party as sub-processors who may Process Customer Personal Data in connection with Rockwell Automation’s provision of Products and/or Services under the Agreement (each, a “Sub-Processor”) and consents to such engagements. To the extent it Processes Customer Personal Data, and it is required by Applicable Privacy Law, Rockwell Automation will make available a list of Sub-Processors used in Rockwell Automation’s provision of the Products and/or Services to Customer (depending on the Products and/or Services in question, a current list of Sub-Processors may be made available on Rockwell Automation’s Trust Center, in the applicable Agreement, order form, statement of work (as defined in the  Agreement), or otherwise as agreed between the parties, collectively referred to as the “Sub-Processor List”). Rockwell Automation may remove or add new Sub-Processors from time to time. Where required by Applicable Privacy Laws, Rockwell Automation will notify Customer of intended changes to the Sub-Processor List, by posting updates on its website or Trust Center, via email, in the applicable Agreement, order form, statement of work (as  applicable), or by other appropriate means, at least ten (10) days prior to engaging such Sub-Processor and will allow Customer to object within this time if there are reasonable grounds to believe the new Sub-Processor cannot meet the privacy and security standards set forth in this DPA. If Customer does not object within the notice period, or fails to describe in reasonable detail the basis for the objection, including the specific privacy or security obligation implicated and the facts supporting the concern, Customer will be deemed to have approved the change. If Customer objects and states such reasonable grounds, the parties will negotiate in good faith to reach a commercially reasonable solution. If no commercially reasonable solution is agreed, either party may terminate the affected portion of the Agreement related to that Processing, without penalty.

4.2. Rockwell Automation shall ensure appropriate written agreements apply to each relevant Sub-Processor prior to providing such Sub-Processor access to Customer Personal Data. These agreements shall impose data protection obligations on the Sub-Processor that are relevant and appropriate to the data protection obligations Rockwell Automation is subject to as a Processor of Customer Personal Data under this DPA. Rockwell Automation shall remain liable to Customer for the performance of the Sub-Processor’s obligations.

5. COOPERATION

5.1. Rockwell Automation shall reasonably assist Customer in complying with Customer’s obligations under Applicable Privacy Laws, taking into account the nature and relative risks of the Processing, the nature of the Products and/or Services and Rockwell Automation’s subsequent Processing under the Agreement, and the information reasonably available to Customer directly. Reasonable costs and expenses incurred by or on behalf of Rockwell Automation in connection with this section 5 shall be borne and reimbursed by Customer.

5.2. To the extent Rockwell Automation receives an access request from a government or law enforcement agency directly relating to Customer Personal Data Processing conducted by Rockwell Automation, Rockwell Automation will, to the extent permitted by applicable law and practicable, notify Customer (not the Data Subject) of such request.

6. AUDITS

6.1. Where Applicable Privacy Laws afford Customer an audit right, Rockwell Automation will allow, and collaborate with, Customer and/or or a third-party auditor appointed by Customer, to audit Rockwell Automation’s compliance with this DPA, provided that the audit, unless Rockwell Automation expressly agrees to a written amendment to this DPA, will:

6.1.1. Be subject to thirty (30) days’ prior written notice from Customer;

6.1.2. Be conducted at reasonable intervals, but not more than once per calendar year;

6.1.3. Be conducted during business hours and not unreasonably disrupt Rockwell Automation’s business;

6.1.4. Not interfere with the interests of Rockwell Automation’s other customers;

6.1.5. Not cause Rockwell Automation to breach its confidentiality obligations vis-à-vis its other customers, suppliers or any other organization;

6.1.6. Not exceed a period of two (2) business days;

6.1.7. Start with reviewing and assessing the information Rockwell Automation may provide through external, shared platforms it may support; 

6.1.8. Be conducted as a remote review only. For the avoidance of doubt, Customer audits shall not involve, require, or permit: (i) physical access to Rockwell Automation's facilities or premises, or (ii) access to any of Rockwell Automation's internal systems, networks, or infrastructure; and

6.1.9. Relate only to the Processing of Customer Personal Data by Rockwell Automation as a Processor on behalf of Customer, as applicable to the Processing and for the duration of the related Agreement, this DPA, or applicable statement of work or order.

6.2. Customer shall, and shall cause its third-party auditor to, comply with Rockwell Automation’s relevant safety and security standards and appropriate confidentiality expectations. Demonstration of Customer’s instructions to its personnel and/or third-party auditor personnel in compliance with this section 6.2, shall be provided to Rockwell Automation in writing prior to scheduling Customer’s audit.

6.3. When Rockwell Automation accepts that an audit goes beyond the parameters in clause 6, Customer will reimburse Rockwell Automation for its reasonable costs and expenses associated with the audit.

6.4. Customer acknowledges that Rockwell Automation is regularly audited for compliance with various recognized standards. Rockwell Automation is allowed to reject, or reduce the scope of, a requested audit, where it can demonstrate  compliance with its obligations under or pursuant to this DPA, by adhering to a code of conduct approved by the competent authority or regulator, by providing a generally recognized certification, or by providing an audit or information report issued by a generally accepted organization or independent third-party auditor.

7. SECURITY

7.1. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

7.1.1. Taking into account the scope and purposes of the processing, the types of Personal Data involved, the categories of affected Data Subjects, the possible privacy risks, the generally available technology and the costs of implementation, Customer and Rockwell Automation will implement and maintain reasonable technical and organizational security measures (as further specified in Annex II to Schedule A) to ensure a level of security, in respect of Customer Personal Data Processed by Rockwell Automation under the Agreement, that is appropriate to the identified privacy risks, in order to protect against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Customer Personal Data.

7.1.2. Rockwell Automation shall ensure that persons who are authorized to Process, or have access to, Customer Personal Data hereunder have committed themselves to confidentiality or are otherwise subject to appropriate confidentiality obligations.

7.1.3. Without prejudice to other applicable confidentiality obligations between the parties, Rockwell Automation will keep the Customer Personal Data confidential, and shall use the Customer Personal Data for the purposes provided in the Agreement and this DPA. Rockwell Automation will not share Customer Personal Data with third parties (other than Sub-Processors), unless required to deliver the Products and/or perform the Services under the Agreement.

7.1.4. Customer acknowledges and agrees that, taking into account the nature, scope, risks and context of the processing of Customer Personal Data by Rockwell Automation within the context of the Agreement, Rockwell Automation’s implementation of the technical and organizational security measures referenced in section 7.1.1. above provide an appropriate level of security.

7.2. SECURITY INCIDENTS

7.2.1. In the event of a confirmed Security Incident affecting Customer Personal Data Processed by Rockwell Automation under the Agreement, Rockwell Automation shall, without undue delay after it becomes aware of the confirmed incident:

a. Notify Customer of the Security Incident within the timeframe required under Applicable Privacy Laws;

b. Investigate the Security Incident, take necessary actions to mitigate, and rectify the incident, and keep Customer informed of these actions; and

c. Use reasonable efforts to assist Customer, at Customer’s request, in collecting and providing the information relating to the Security Incident which is required under Applicable Privacy Laws for Customer to assess the requirement of, and to comply with, Customer’s timely breach notification obligations to competent authorities and/or affected Data Subjects pursuant to the Applicable Privacy Laws. Any notification of or response to a Security Incident shall not give rise to any presumption of, or inference of, fault or liability on the part of Rockwell Automation.

7.2.2. Where Customer becomes aware of a Security Incident affecting the systems and/or activities that are under the control of Customer or Rockwell Automation and/or its approved Sub-Processors, Customer shall, without undue delay, after it becomes aware of the incident:

a. Notify Rockwell Automation of the Security Incident; and

b. Use reasonable efforts to assist Rockwell Automation, at Rockwell Automation’s request, in collecting and providing the information relating to the Security Incident which Rockwell Automation needs in order to investigate the Security Incident, to take protective actions, and to comply with Rockwell Automation’s obligations pursuant to the Applicable Privacy Laws, if any.

7.2.3. Any damages, losses, costs and expenses incurred by or on behalf of Rockwell Automation in connection with this section 7.2 shall be borne and reimbursed by Customer, except and to the extent that the Security Incident occurred as a direct result of a breach of Rockwell Automation’s obligations under this DPA.

8. DURATION OF PROCESSING

Unless otherwise instructed by Customer in writing, Rockwell Automation is authorized to Process Customer Personal Data under the Agreement until the expiration or termination of the Agreement or until Customer Personal Data is returned or destroyed upon written instruction from Customer. To the extent Rockwell Automation is not authorized under Applicable Privacy Laws, Customer’s instructions, or the Agreement to Process relevant Customer Personal Data, Rockwell Automation may refrain from such Processing, and any resulting delay, limitation, or non-performance will not constitute a breach of the Agreement or this DPA.

9. TERMINATION AND RETURN/DESTRUCTION OF PERSONAL DATA

Upon Customer’s termination of the Agreement, Rockwell Automation shall, at the discretion of Customer and upon Customer’s written request, either delete, destroy, or return all Customer Personal Data to Customer and destroy or return existing copies. To the extent that applicable laws require Rockwell Automation to retain Customer Personal Data following termination of the Agreement, Rockwell Automation will continue to meet the obligations set forth in this DPA and the Agreement with respect to Customer Personal Data and will only use it for the purpose for which it must be retained as required by the applicable laws. Certification of deletion of Customer Personal Data shall be provided by Rockwell Automation upon Customer’s written request. Rockwell Automation reserves the right to retain Customer Personal Data to meet Rockwell Automation obligations under applicable law, regulations, security and other best practices, provided that such retention shall continue to be governed by the Agreement and this DPA.

10. ROCKWELL AUTOMATION AS CONTROLLER

Where Rockwell Automation Processes Personal Data on Rockwell Automation’s own behalf as required to establish and maintain its business relationship with Customer (e.g. for purposes of contract administration; billing; business inquiries; establishment, maintenance, support of the business relationship; maintenance, analysis, and/or improvement of the Products and/or Services) (collectively “Business Relationship Processing”), Rockwell Automation will be an independent Controller of all such Business Relationship Processing, and its Processing will be solely in accordance with Rockwell Automation’s Privacy Policy available at https://www.rockwellautomation.com/en-us/company/about-us/legal-notices/privacy-and-cookies-policy.html. Where such Processing results in the cross-border transfer of Personal Data, Customer and Rockwell Automation agree to complete the required documentation specified in Applicable Privacy Laws or as set forth in the appropriate Jurisdiction-Specific Terms herein.

11. JURISDICTION-SPECIFIC TERMS

11.1. Where Customer Personal Data originating from the European Economic Area, Switzerland, the United Kingdom, USA, China, or Brazil (as applicable) is Processed by Rockwell Automation under the Agreement, such Processing will be performed in accordance with the Jurisdiction-Specific Terms in the applicable schedule to this DPA. In the event of a conflict or inconsistency between the Jurisdiction-Specific Terms in the applicable schedule and this DPA, the Jurisdiction-Specific Terms schedule governing the Processing of Customer Personal Data from the originating jurisdiction shall prevail, but solely with regard to the portion of the provision in conflict or inconsistent with this DPA.

11.2. The Jurisdiction-Specific Terms in the schedules shall not replace any additional rights relating to Processing of Personal Data in the Agreement; provided that, in the event of inconsistencies between the provisions of a schedule and the Agreement, the provisions of the Jurisdiction-Specific Terms in the applicable schedule shall prevail.

12. INTERNATIONAL DATA TRANSFERS

Customer agrees to authorize Restricted Transfers as set out in Schedules A-E of this DPA. In the case of a Restricted Transfer, Rockwell Automation will transfer Customer Personal Data using appropriate safeguards in accordance with Applicable Privacy Laws and as further set forth in the Jurisdiction-Specific Terms. In case of cross-border transfer other than those set out in Schedules A-E of this DPA, Customer is responsible for securing any required mechanism to enable under applicable law for the transfer before any Personal Data is transferred. 

13. INDEMNIFICATION; LIMITATION OF LIABILITY

13.1. The limitation of liability and indemnification provisions contained in the Agreement shall govern this DPA but are amended to include the following.

13.2. Indemnification. Each party (indemnifying party) shall indemnify the other party (indemnified party) against any claims of Data Subjects, governmental authorities or other third parties, if and to the extent such claims are a result of breach by the indemnifying party of its obligations under this DPA and/or under Applicable Privacy Laws. Where a party receives a third-party claim in relation to the Processing of Customer Personal Data in connection with this DPA or the Agreement, it will inform the other party thereof and will make no admission of liability nor agree to any settlement or compromise of the relevant claim without the prior written consent of the other party (which shall not be unreasonably withheld or delayed).

13.3. Limitation of Liability. To the maximum extent permitted by applicable law, Rockwell Automation shall have no liability for any losses, costs, expenses, or liabilities arising from or in connection with any Processing in accordance with the Processing Instructions.

14. UPDATES TO DPA

 Rockwell Automation reserves the right to amend this DPA by posting an updated DPA on its website.

 

SCHEDULE A – EUROPEAN ECONOMIC AREA AND SWITZERLAND

In addition to each party’s obligation to comply with Applicable Privacy Laws, this Schedule A applies where: (i) Rockwell Automation Processes Customer Personal Data on behalf of Customer; (ii) Rockwell Automation or Customer Process Personal Data under this Agreement in the Controller-to-Controller scenario, and such Personal Data originates from the European Economic Area (“EEA”) and/or Switzerland pursuant to the Agreement. Such Processing shall be governed by the applicable modules of the EU Standard Contractual Clauses (defined below) as set forth in section A.2.1. of this Schedule A.

A.1. DEFINITIONS

“EU Standard Contractual Clauses” or “EU SCCs” means the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as may be amended from time to time and as currently set out at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, and which are incorporated herein by reference.

A.2. PERSONAL DATA TRANSFERS

A.2.1. Applicable Modules. Any Restricted Transfer between Rockwell Automation and Customer under this Schedule A will be performed in accordance with the applicable module of the EU SCCs as set forth in the following table:

  Rockwell Automation Customer
Controller Processor Controller Processor
Module 1 x   x  
Module 2   x x  
Module 3   x   x

A.2.2. Switzerland. Where a Restricted Transfer relates to Customer Personal Data originating from Switzerland, any reference to the EU SCCs or the GDPR shall be interpreted as the Applicable Privacy Laws in Switzerland and reference to the ‘competent supervisory authority’ will mean the competent data protection authority in Switzerland.

A.3. EU SCCS GOVERNING LAW, FORUM AND JURISDICTION, AND OPTIONAL PROVISIONS

Rockwell Automation and Customer will comply with the applicable EU SCCs. The following optional provisions are selected together with the stated governing law, forum and jurisdiction:

             A.3.1. Clause 7: Docking clause;

A.3.2.  Clause 9(a) Use of sub-processors: Option 2 - General Written Authorisation, with a notice period of ten (10) days has been selected;

A.3.3. Clause 11 Redress: The optional clause is not included;

A.3.4. Clause 17 Governing law: Option 1 has been selected, with the governing law as follows: For customers in the EEA: Belgium; For customers in Switzerland: Switzerland;

A.3.5.  Clause 18(b) Choice of forum and jurisdiction: The choice of forum and jurisdiction shall be as follows: EEA: Belgium; Switzerland: Switzerland.

A.4. COOPERATION. 

Rockwell Automation shall reasonably assist Customer in ensuring compliance with its obligations under GDPR (or applicable and substantially similar Swiss data protection law) (security of Processing, Security Incident notification, data protection impact assessments, and prior consultation with a relevant supervisory authority in relation to a data protection impact assessment) in relation to Customer Personal Data Processed by Rockwell Automation on Customer behalf, taking into account the nature of the Processing and scope of information available to Rockwell Automation.

A.5. UPDATES AND AMENDMENTS. In the event the EU SCCs are amended, replaced, or repealed by the European Commission or other competent authority under European Privacy Laws, the parties shall work together, in good faith, to enter into an updated version of the EU SCCs or negotiate an alternative solution to enable the cross-border transfer of Personal Data in compliance with applicable European or Swiss privacy laws.

A.6. EU SCCs Annexes. The following Annexes are added to the EU SCCs.

ACCEPTANCE AND SIGNATURE. The Parties agree that the acceptance of or the date of Customer’s execution of the Agreement is deemed Customer’s signature and acceptance of the DPA and the EU SCCs.

 

ANNEX I TO THE EU STANDARD CONTRACTUAL CLAUSES

A. LIST OF PARTIES

Data exporter(s): [Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union]

Name: The Customer identified in the Agreement, order form or statement of work (as applicable).
Address: As set forth in the Agreement, order form or statement of work (as applicable) or as may be otherwise provided to Rockwell Automation at the time of purchase of the Products and/or Services.
Contact person’s name, position and contact details: As confirmed in writing by data exporter.
Activities relevant to the data transferred under these Clauses: Obligations related to the Products and/or Services as set forth in the Agreement.
Signature and date: Exporter agrees that the acceptance of or the date of Customer’s execution of the Agreement, order form or statement of work (as applicable) is deemed Customer’s signature and acceptance of the DPA and the EU SCCs.
Role 
(Controller/Processor)
Controller for the purposes of Module 1 or 2 EU SCCs as applicable, Processor for the purposes of Module 3 EU SCCs.

Data importer(s): [Identity and contact details of the data importer(s), including any contact person with responsibility for data protection]

Name: Rockwell Automation
Address: As set forth in the Agreement, order form or statement of work (as applicable) or as may be otherwise provided
Contact person’s name, position and contact details: Chief Privacy Officer, 1201 South 2nd Street, Milwaukee, WI 53204, USA
Activities relevant to the data transferred under these Clauses: Provision of Products and/or Services pursuant to the Agreement. 
Signature and date: Rockwell Automation agrees the acceptance of or the date of Exporter’s execution of the Agreement, order form or statement of work (as applicable) is deemed the date of and signature   by Rockwell Automation of the EU SCCs.
Role 
(Controller/Processor)
For the purpose of Business Relationship Processing, Rockwell Automation is a Controller subject to Module 1 EU SCCs. For all other Processing, Rockwell Automation shall Process Customer Personal Data as a Processor in   accordance with Module 2 or 3 of the EU SCCs (as applicable). 


B. DESCRIPTION OF TRANSFER

Categories of Data Subjects whose Personal Data is transferred:

Subject to the Product and/or Service and as determined by Customer, but may include, and are not limited to, Customer’s:

  • Prospects, customers, business partners, contractors, and vendors.
  • Employees or contact persons of prospects, customers, business partners, contractors, and vendors.
  • Employees, contractors, agents, and advisors.
  • Users authorized by Customer to use Rockwell Automation Products and/or Services. As otherwise indicated in the Agreement and the DPA.

Categories of Personal Data transferred:

Subject to the Product and/or Service and as determined by Customer, which may include:

First and last name, Title, Position, Employer, Contact Information (company email, phone number, physical business address), IP address, and as otherwise indicated in the Agreement and the DPA.

Sensitive data transferred (if applicable):

The Products and/or Services are not intended for the Processing of sensitive Personal Data and Customer and/or its Affiliates shall not transfer, directly or indirectly, any sensitive Personal Data to Rockwell Automation.

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis):

Continuous (subject to the term and post termination provisions of the Agreement and the DPA).

Nature of the Processing:

The context for and purpose of the Processing of Customer Personal Data is Rockwell Automation’s provision of Products and/or Services to data exporter in accordance with the Agreement and the DPA.

Purpose(s) of the data transfer and further Processing:

The context for and purpose of the Processing of Customer Personal Data is Rockwell Automation’s provision of Products and/or Services to data exporter in accordance with the Agreement and the DPA.

The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period:

Subject to the Product and/or Service, Applicable Privacy Laws, the Agreement and the DPA.

For transfers to Sub-Processors, also specify subject matter, nature and duration of the Processing:

Subject to the Product and/or Service and as determined by Customer as set forth above, and as otherwise indicated in the Agreement and the DPA.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13:

EEA: Belgian Data Protection Authority

Switzerland: Swiss Federal Data Protection and Information Commissioner (FDPIC)

 

ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES

Technical and Organisational Measures

This Annex II refers to and includes the Technical and Organizational Measures (TOMS) which are available on the Rockwell Automation Trust Center and that are implemented by Rockwell Automation to protect Rockwell Automation’s information technology systems and its Products and/or Services. Some Products and/or Services may have different and/or additional TOMS as may be set forth in the Agreement or in specific Product and/or Service documentation available on Rockwell Automation’s Trust Center.

 

ANNEX III TO THE STANDARD CONTRACTUAL CLAUSES

As of the date of this DPA, Customer authorizes Rockwell Automation to engage the Sub-Processors identified on the Sub-Processor List available on Rockwell Automation’s Trust Center, in the applicable order form, statement of work or otherwise as appropriate, specific to the Products and/or Services purchased by Customer.

 

SCHEDULE B – UNITED KINGDOM DATA TRANSFER ADDENDUM

This Schedule B sets out the additional requirements where Customer Personal Data originating from the United Kingdom (“UK”) is Processed by Rockwell Automation. Such Processing will be subject to the template International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by UK’s Information Commissioners Office (“ICO”) and laid before UK Parliament in accordance with section 119A of the UK’s Data Protection Act 2018 and as set forth on the  ICO’s website (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/) and incorporated herein by reference (“UK Addendum”).

B.1. UK ADDENDUM 

The UK Addendum consists of two parts: Part One and Part Two. The information required to complete the UK Addendum is as follows: 

Part 1 (Tables 1 to 3) responses are either included in the DPA or in the Annexes to the EU SCCs set forth in Schedule A.

Part 1 (Table 4): neither party may terminate the UK Addendum when the Approved Addendum changes.

Part 2, “Mandatory Clauses” are included here by reference, and are the Mandatory Clauses of the Approved Addendum being the template addendum B.1.0 issued by the UK ICO and laid before UK Parliament in accordance with section 119A of the UK’s Data Protection Act 2018, as it is revised under section 18 of the Mandatory Clauses.

B.2. EU SCCs 

The selected EU SCCs, its annexes, applicable module(s), and optional provisions are those set out in Schedule A.

 

SCHEDULE C – US PRIVACY LAWS

This Schedule C applies only to the extent that Rockwell Automation Processes Personal Information on behalf of Customer subject to the US Privacy Laws. Appendix 1 to this Schedule C sets forth the Personal Information Processed by Rockwell Automation under the Agreement. This Schedule C, together with its Annexes, shall only apply where US Privacy Laws are applicable to the Processing of Customer Personal Data originating from the USA.

C.1. DEFINITIONS

“Contracted Business Purposes” means the Products and/or Services described in the Agreement for which the Rockwell Automation receives or accesses Personal Information.

“US Privacy Laws” means any applicable federal and state laws in the United States governing the Processing of Personal Information, including but not limited to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), and any other applicable state or federal privacy legislation, as amended or replaced from time to time. 

“Personal Information” shall have the meaning given in the applicable US Privacy Laws and any associated or similar terms shall be interpreted in line with the foregoing.   

C.2. ROCKWELL AUTOMATION OBLIGATIONS UNDER US PRIVACY LAWS

C.2.1. Rockwell Automation will only collect, use, retain, or disclose Personal Information for the Contracted Business Purposes for which Customer provides or permits Personal Information access in accordance with Customer's written instructions.

C.2.2. Rockwell Automation will not collect, use, retain, disclose, sell, or otherwise make Personal

Information available in a way that does not comply with the US Privacy Laws. If a law requires Rockwell

Automation to disclose Personal Information for a purpose unrelated to the Contracted Business Purposes, where required by law, Rockwell Automation will inform Customer of the legal requirement and give Customer an opportunity to object or challenge the requirement, unless the law prohibits such notice.

C.2.3. Rockwell Automation will limit Personal Information collection, use, retention, and disclosure to activities reasonably necessary and proportionate to achieve the Contracted Business Purposes or another compatible operational purpose.

C.2.4. Rockwell Automation will comply with any Customer reasonable written request or instruction requiring Rockwell Automation to provide, amend, transfer, or delete the Personal Information, or to stop, mitigate, or remedy any unauthorized Processing.

C.2.5. If the Contracted Business Purposes require the collection of Personal Information from individuals on Customer's behalf, Customer is responsible for providing a US Privacy Laws-compliant notice as required under applicable US Privacy Laws and for ensuring that Rockwell Automation receives all instructions and information necessary to comply with such notice. 

C.2.6. To the extent permitted under the US Privacy Laws, Rockwell Automation may aggregate, de-identify, or anonymize Personal Information so it no longer meets the Personal Information definition, and may use such aggregated, deidentified, or anonymized data to perform analytics and reporting for system metrics, benchmarking and marketing for industry, financial and other business purposes. Rockwell Automation will not attempt to or actually re-identify any previously aggregated, de-identified, or anonymized data and will contractually prohibit downstream data recipients from attempting to or actually re-identifying such data.

C.3. US PRIVACY LAWS WARRANTIES

C.3.1. Customer and Rockwell Automation will comply with all applicable requirements of the US Privacy Laws when collecting, using, retaining, or disclosing Personal Information.

C.3.2. Rockwell Automation will comply with the restrictions and obligations contained in the applicable US Privacy Laws with regards to selling Personal Information and retaining, using, or disclosing Personal Information outside of the parties' direct business relationship.

C.3.3. Rockwell Automation confirms it has no reason to believe any US Privacy Laws requirements or restrictions prevent it from providing any of the Contracted Business Purposes or otherwise performing the Agreement. Rockwell Automation will promptly notify Customer of any changes to the US Privacy Laws' requirements that may adversely affect its performance under the Agreement.

C.4. SUBCONTRACTING 

Customer agrees to Rockwell Automation’s use of the Sub-Processors set forth in the Trust Center, the Agreement, applicable order form, statement of work (as defined in the Agreement), or otherwise as appropriate.

 

ANNEX 1 TO SCHEDULE C

PERSONAL INFORMATION PROCESSING PURPOSES AND DETAILS

Contracted Business Purposes: As set forth in the Agreement or this DPA.

Personal Information Categories: The scope of Personal Information categories Processed is set forth in section B of Annex I to the EU Standard Contractual Clauses, Schedule A.

Types of Consumers: As set forth in section B of Annex I to the EU Standard Contractual Clauses in Schedule A.

Approved Subcontractors: As set forth in the list of Sub-Processors available on Rockwell Automation’s Trust Center, or in the applicable Agreement, order form, statement of work (as applicable), or otherwise as appropriate.

 

SCHEDULE D – CHINA

This Schedule D applies solely to the extent Rockwell Automation Processes Customer Personal Data on behalf of Customer that originates from the People’s Republic of China (PRC) pursuant to the Agreement. Any Processing of Personal Data under this Schedule D will be in accordance with the DPA and applicable PRC privacy laws.

To ensure that the Processing of Personal Data by overseas recipients meets the protection standards stipulated in applicable PRC privacy laws, Customer and Rockwell Automation agree that the Standard Contract of Outbound Cross-Border Transfer of Personal Information (“China SCC”) shall apply and is automatically incorporated herein by reference. The parties agree that for the China SCC the following elections apply: 

D.1. Article 6 Clause 1, the Parties agree that the name of the contact person and contact details are as indicated in the Agreement, order form or statement of work (as applicable); 

D.2. Article 9 Clause (3), the parties agree that all notices, sent according to such provision, will be sent to the address as indicated in the Agreement, order form or statement of work (as applicable) and deemed received within five (5) business days;  

D.3. Article 9; Clause (5)(1), the parties agree that the China International Economic and Trade Arbitration Commission shall act as the arbitration institution;

D.4. Article 9; Clause (6), the parties agree that the original of this Agreement is in two (2) copies and each party shall maintain one (1) copy.  

D.5. Appendix 1 of the China SCC shall be deemed to be prepopulated with the relevant sections of Annex I of this Schedule D.  

Where filing of the China SCC requires that the document be provided and filed in Chinese, Customer agrees to execute a Chinese version of the China SCCs consistent with this Schedule D and to provide to Rockwell Automation in a timely manner.  

 

ANNEX I TO SCHEDULE D

Information of Outbound Cross-Border Transfer of Personal Information in Cross-Border Transfers from the PRC To be completed for China Data Transfers

Personal Information transmitted belongs to the following types of Individuals:

Customer employees, contractors, and third parties as authorized and necessary under the Agreement.

Transfers are made for the following purposes:

The context for and purpose of the Processing of Customer’s Personal Data is Supplier’s provision of Products and/or Services to Customer in accordance with the Agreement.

Method of Processing:

Processing will be in accordance with this DPA.

Amount of Personal Information transferred:

Less than 1,000,000 individuals and fewer than 100,000 in aggregate since January 1 of the preceding year.

Types of cross-border transferred Personal Information:

Customer employees, contractors, and third parties as authorized under the Agreement.

Types of cross-border transferred sensitive Personal information:

Customer is not permitted to transfer sensitive Personal information to Rockwell Automation.

Overseas recipients will only provide Personal Information to the following recipients outside the PRC:

As set forth on the Sub-Processor List available on Rockwell Automation’s Trust Center, or in the Agreement, order form, statement of work (as applicable), or otherwise as appropriate.

Transfer method:

For On-Premises Software: as determined by Customer and Rockwell Automation in the Agreement or as may otherwise be agreed in writing. For Software-as-a-Service (SaaS): via the applicable cloud service.

For Professional Services:

As set forth in the applicable order form or statement of work (as applicable).

Storage time after cross-border transferred:

Subject to applicable law, Personal Data will only be stored for the duration of the Agreement or as otherwise agreed between the parties.

Storage location after cross-border transferred:

As set forth in the Sub-Processor List available on the Trust Center, or in the applicable Agreement, order form, statement of work (as applicable), or otherwise as appropriate.

 

SCHEDULE E – BRAZIL

This Schedule E applies only to the extent that either: (i) Rockwell Automation Processes Customer Personal Data on behalf of Customer; or (ii) Rockwell Automation or Customer Process Personal Data under the Agreement on a Controller-to-Controller basis, and for both (i) and (ii) provided that such data is subject to the LGPD (defined below). Any Processing of Personal Data under this Schedule E will be performed in accordance with the General Data Processing Terms of the DPA, the LGPD and the regulations issued by the ANPD (defined below). In the event of a conflict between the Agreement, the General Data Processing Terms, this Schedule E and the LGPD, enforceable ANPD regulations, the order of precedence set out in the DPA applies, with this Schedule E governing matters specific to the Processing of Customer Personal Data that LGPD applies to.

E.1. DEFINITIONS

“LGPD” means Lei nº 13.709, of 14 August 2018, the Brazilian General Data Protection Law, as amended by Lei nº 13.853, of 8 July 2019, and as further amended from time to time.

“ANPD” means the Agência Nacional de Proteção de Dados, the Brazilian data protection authority, as defined in art. 5, XIX, of the LGPD, with the wording given by Lei nº 15.352/2026.

“ANPD Standard Contractual Clauses” or “ANPD SCCs” means the standard contractual clauses for the international transfer of personal data approved by the ANPD under Resolução CD/ANPD nº 19, of 23 August 2024 (Annex II), as may be amended, replaced or supplemented from time to time and as currently set out at: https://www.gov.br/anpd/pt-br/assuntos/assuntos-internacionais/transferencia-internacional-de-dados/international-affairs and which are incorporated herein by reference.

“Encarregado” means the person appointed by the Controller or the Processor to act as a communication channel between the Controller, the data subjects and the ANPD, pursuant to art. 5, VIII, and art. 41 of the LGPD.

For the purposes of this Schedule E, the terms “Controller”, “Processor”, “Personal Data”, “Sensitive Personal Data”, “Processing”, “Data Subject” and “Security Incident” have the meanings given in the LGPD. References in the DPA to “Processor” shall be read as references to the “operador” under the LGPD.

E.2. ROLES AND LAWFUL BASIS

E.2.1. Unless otherwise agreed in the Agreement, Customer is the Controller, and Rockwell Automation is the Processor (operador) in respect of Customer Personal Data Processed in the course of providing the Products and/or Services. Rockwell Automation acts as an independent Controller solely in respect of Business Relationship Processing as described in the General Data Processing Terms.

E.2.2. As Controller, Customer is responsible for identifying and ensuring an appropriate legal basis for the Processing under art. 7 (or, where Sensitive Personal Data is involved, art. 11) of the LGPD, and for providing data subjects with the information required by art. 9 of the LGPD.

E.2.3. The Products and Services are not intended for the Processing of Sensitive Personal Data, and Customer shall not transfer Sensitive Personal Data to Rockwell Automation. Where the Processing involves personal data of children or adolescents, Customer shall comply with art. 14 of the LGPD.

E.3. DATA SUBJECT RIGHTS

E.3.1. In addition to the data subject rights set out in the General Data Processing Terms, data subjects in Brazil hold the rights set out in art. 18 of the LGPD: (i) confirmation of the existence of Processing; (ii) access to the data; (iii) correction of incomplete, inaccurate or outdated data; (iv) anonymization, blocking or deletion of unnecessary, excessive or non-compliant data; (v) portability; (vi) deletion of data Processed on the basis of consent; (vii) information on the public and private entities with which the data has been shared; (viii) information on the possibility of withholding consent and the consequences thereof; and (ix) withdrawal of consent. Under art. 20 of the LGPD, data subjects may also request the review of decisions taken solely on the basis of automated Processing that affect their interests.

E.3.2. As Controller, Customer is responsible for responding to data subject requests within the time limits set out in the LGPD and in enforceable ANPD regulation. For requests for confirmation of the existence of Processing and for access to the data, the time limit is immediate in simplified form or up to fifteen (15) days for the complete response, pursuant to art. 19 of the LGPD. Rockwell Automation will reasonably assist Customer upon Customer’s written request, taking into account the nature of the Processing, the information available to Customer and to Rockwell Automation and its respective role in Processing.

E.3.3. Data subjects may also petition the ANPD against the Controller in connection with the Processing of their Personal Data.

E.4. SECURITY MEASURES

E.4.1. Rockwell Automation will implement and maintain technical and administrative security measures suitable to the identified privacy risks in order to protect Customer Personal Data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication or unlawful Processing, as required in arts. 46 to 49 of the LGPD and the applicable and enforceable ANPD regulation.

E.4.2. The technical and organizational measures set out in the General Data Processing Terms and in the Rockwell Automation Trust Center are deemed sufficient to satisfy the obligation in clause E.4.1 with respect to Customer Personal Data originating from Brazil, without prejudice to any additional measures reasonably required by enforceable ANPD regulation.

E.5. SECURITY INCIDENTS

E.5.1. The Security Incident provisions of the General Data Processing Terms apply, supplemented as follows. Where the LGPD requires notification of a Security Incident to the ANPD and/or to affected data subjects, Customer shall make such notification within the period established under the LGPD and enforceable ANPD regulation (as of the date of this Schedule, three (3) business days from the Controller’s confirmation of the Security Incident, pursuant to Resolução CD/ANPD nº 15, of 26 April 2024).

E.5.2. The notification will include, to the extent then available and subject to the Rockwell Automation’s role in Processing and information reasonably available to the Customer, the elements required by art. 48, § 1, of the LGPD.

E.6. INTERNATIONAL DATA TRANSFERS

E.6.1. Where a transfer of Customer Personal Data that LGPD applies to is carried out to a country or international organization that has not been recognized by the ANPD as providing an adequate level of data protection, such transfer will be governed by the ANPD SCCs, which are incorporated herein by reference and adopted without modification, pursuant to art. 33 of the LGPD and Resolução CD/ANPD nº 19/2024. The following optional provisions of the ANPD SCCs are selected:

E.6.1.1. Clause 3.1, Option B shall apply, and the conditions of onward transfer are set out in the DPA and this Schedule E.

E.6.1.2. Clause 4.1, Option A shall apply and Customer as the exporter indicated in Annex I to this Schedule E is responsible for the activities indicated in Clause 4.1. In case the cross-border transfer is carried out between processors, option B shall apply and shall be completed with the details as set out in Annex I to this Schedule E, this DPA, the Agreement, or as otherwise appropriate. Customer shall be responsible for completing required and relevant details of any third-party Controller in 4.1 Option B.

E.6.2. For the purposes of the ANPD SCCs, Customer is the data exporter and Rockwell Automation is the data importer. The information required to complete the ANPD SCCs is set out in Annex I to this Schedule E.

E.6.3. Should the ANPD amend, replace or repeal the ANPD SCCs, or should an alternative transfer mechanism become available under the LGPD (including specific contractual clauses, binding corporate rules or an adequacy decision), the Customer will initiate Parties’ negotiations and then the Parties will work together in good faith to adopt the updated or alternative instrument.

E.7. SUB-PROCESSORS

E.7.1. The Sub-Processor provisions of the General Data Processing Terms apply, with each Sub-Processor being a suboperador under the LGPD. Rockwell Automation shall impose by contract on each suboperador data protection obligations equivalent to those undertaken by Rockwell Automation under this Schedule E and the DPA, and shall remain liable to Customer for the performance of those obligations, subject to the rules described in section 4 of the DPA.

E.7.2. Where the engagement of a suboperador involves an international transfer of Customer Personal Data originating from Brazil, Customer authorizes such transfers, provided such transfer is governed by appropriate safeguards.

E.8. CONTACT INFORMATION

E.8.1. As Controller, Customer shall comply with Art. 41 of the LGPD, including by appointing an Encarregado where required.

E.8.2. Rockwell Automation’s Privacy Office can be contacted via e-mail as indicated on Rockwell Automation’s Trust Center.  

E.9. RETENTION AND DELETION

The retention, return and deletion provisions of the General Data Processing Terms apply. Rockwell Automation may retain Customer Personal Data after the end of the Processing only in the circumstances permitted by art. 16 of the LGPD, including compliance with a legal or regulatory obligation, the regular exercise of rights in judicial, administrative or arbitral proceedings, transfer to a third party in compliance with the LGPD, or as necessary for the provision of Services, or to meet Rockwell Automation obligations under applicable law, regulations, security and other best practices, or the Processor’s exclusive use, with access by third parties otherwise prohibited and provided the data is anonymized whenever practicable.

E.10. COOPERATION WITH THE ANPD

E.10.1. Upon Customer’s written request, Rockwell Automation will reasonably cooperate with Customer in responding to inquiries, requests, investigations or enforcement actions by the ANPD directly relating to Customer Personal Data Processed by Rockwell Automation under the Agreement, taking into account the nature of the Processing and the information available to Customer and to Rockwell Automation. Reasonable costs and expenses incurred by or on behalf of Rockwell Automation in connection with this section E.10.1. shall be borne and reimbursed by Customer.

E.10.2. Each Party will promptly notify the other of any formal request to disclose the other party’s Personal Data received from the ANPD directly relating to the Processing of the other party’s Personal Data under the Agreement, to the extent permitted by applicable law and practicable.

E.11. LIABILITY

Liability for the Processing of Customer Personal Data under this Schedule E is governed by the Indemnification and Limitation of Liability provisions of the DPA and, to the extent required by LGPD, by arts. 42 and 43 of the LGPD. For the purposes of art. 42, § 1, of the LGPD, Rockwell Automation, as Processor, shall be jointly liable only in the cases set out in item I of that paragraph – where it fails to comply with the data protection law obligations attributable to it under LGPD or has not followed the lawful instructions of the Controller – with the exclusions of art. 43 of the LGPD applying in all cases.

E.12. TRANSPARENCY AND LANGUAGE

Information made available to data subjects in Brazil under the LGPD will be provided in Portuguese. With respect to the international transfer of Customer Personal Data, Customer, as Controller, is responsible for publishing in its own privacy policy the simplified information required by Resolução CD/ANPD nº 19/2024. Rockwell Automation’s Privacy and Cookies Policy are made available as a complementary transparency channel.

 

ANNEX I TO SCHEDULE E

Information required to complete the ANPD Standard Contractual Clauses (Resolução CD/ANPD nº 19/2024).

Data exporter (Controller) The Customer identified in the Agreement, order form or statement of work (as applicable), established in Brazil.
Data importer Rockwell Automation, as set forth in the Agreement, order form or statement of work (as applicable).
Categories of data subjects

As set out in Annex I to Schedule A; Subject to the Product and/or Service and as determined by Customer, but may include, and are not limited to, Customer’s:  

  • Prospects, customers, business partners, contractors, and vendors. 
  • Employees or contact persons of prospects, customers, business partners, contractors, and vendors. 
  • Employees, contractors, agents, and advisors. 
  • Users authorized by Customer to use Rockwell Automation Products and/or Services. 
  • As otherwise indicated in the Agreement and the DPA.
Categories of Personal Data As set out in Annex I to Schedule A; Subject to the Product and/or Service and as determined by Customer, which may include:  First and last name, title, position, employer, contact information (company email, phone, physical business address), IP address, and as otherwise indicated in the Agreement and the DPA.
Sensitive Personal Data Not applicable. The Products and/or Services are not intended for Sensitive Personal Data; Customer shall not transfer such data to Rockwell Automation.
Purpose of the transfer Provision of the Products and/or Services to Customer under the Agreement.
Retention period As set out in the DPA and the Agreement, subject to clause E.9 and to retention obligations under applicable Brazilian law.
Transfer mechanism ANPD Standard Contractual Clauses (Resolução CD/ANPD nº 19/2024), incorporated by reference (clause E.6).
Competent authority Agência Nacional de Proteção de Dados (ANPD).
Contact person’s name, position and contact details   Chief Privacy Officer, Rockwell Automation Privacy Office, 1201 South 2nd Street, Milwaukee, WI 53204, USA

Download the Data Processing Addendum

  • English [PDF]

Revised Septermber 14, 2026

View All Legal Notices

  1. Chevron LeftChevron Left Home Rockwell Automation
  2. Chevron LeftChevron Left Azienda
  3. Chevron LeftChevron Left Chi siamo
  4. Chevron LeftChevron Left Data Processing Addendum
I testi di questo sito sono stati tradotti utilizzando l'intelligenza artificiale (AI) senza revisione o modifica da parte di esseri umani. I testi possono contenere errori o imprecisioni e sono forniti “così come sono” senza alcun tipo di garanzia. Il testo ufficiale è la versione inglese del contenuto.
Aggiorna le tue preferenze sui cookie per continuare.
Questa funzionalità richiede i cookie per migliorare la tua esperienza. Ti preghiamo di aggiornare le tue preferenze per consentire questi cookie:
  • Cookie dei social media
  • Cookie funzionali
  • Cookie di prestazione
  • Cookie di marketing
  • Tutti i cookie
Puoi aggiornare le tue preferenze in qualsiasi momento. Per ulteriori informazioni consultare il nostro {0} politica sulla riservatezza
CloseClose