Paradraw
Stripe/
Part of the agreement

Legal > Supplier Data Transfers Addendum

3,620 words, 140 clausesupdated November 11, 2025read 08/10/2026source

·Last updated: November 11, 2025 On this page

  • 1Introduction
  • 2Roles of the Parties
  • 3Cross-Border Data Transfer Mechanisms
  • 4Conflict
  • 5Definitions

Exhibit AExhibit A (Description of Processing and Transfers)

11. Introduction.

·This Supplier Data Transfers Addendum ("SDTA"), which governs Supplier's Processing of Personal Data, is incorporated by reference into the Data Processing Agreement ("DPA") between Stripe and Supplier. Any capitalized terms not defined in this Supplier Data Transfers Addendum have the meanings given to them in the DPA or Agreement.

22. Roles of the Parties.

2.12.1 Supplier as a Data Processor of Stripe Data.

·Supplier may Process Stripe Processor Data only as necessary to provide the Services. For the Processing of Stripe Processor Data, Stripe is a Data Controller, and Supplier is a Data Processor or Sub-processor acting on Stripe's behalf. Where Supplier Processes Stripe Processor Data, it will do so only according to Stripe's instructions set out in Section 2 of the DPA (Instructions), an SOW (if any), the Agreement, and this SDTA.

2.22.2 Supplier as a Data Controller of Stripe Data.

·Supplier may Process Stripe Controller Data only as necessary to provide the Services. For the Processing of Stripe Controller Data, Stripe is a Data Controller, and Supplier is an independent Data Controller, not a joint Data Controller with Stripe. Where Supplier Processes Stripe Controller Data, it will do so only as: (a) set out in an SOW (if any) and the Agreement and necessary to provide the Services; and (b) necessary to comply with Law or DP Law.

2.32.3 Stripe and Supplier as Independent Data Controllers of Supplier Data.

·For the Processing of Supplier Data, Supplier is a Data Controller, and Stripe is an independent Data Controller, not a joint Data Controller with Supplier. Stripe will Process Supplier Data as DP Law permits and according to Stripe's Privacy Policy, the Agreement, the DPA, and this SDTA.

33. Cross-Border Data Transfer Mechanisms.

3.13.1 Order of Precedence.

·If Supplier has certified its participation under the Data Privacy Framework (as recorded on the Data Privacy Framework website accessed here), then subsections (a) - (c) of this Section 3.1 apply:

·(a) If, in connection with the Agreement, more than one Data Transfer Mechanism could apply to a transfer of Personal Data, the Parties agree that the transfer will be subject to one Data Transfer Mechanism only, according to the following order of precedence:

·(i) the Data Privacy Framework;

·(ii) the EU Standard Contractual Clauses;

·(iii) the UK Data Transfer Addendum; and

·(iv) Any other data transfer mechanism available under DP Law that is incorporated into the DPA, including this Supplier Data Transfers Addendum.

·(b) Supplier is self-certified under the Data Privacy Framework. If EEA/UK/Swiss Data is transferred to Supplier, Supplier will receive the Personal Data under the Data Privacy Framework and, when Processing that Personal Data, will comply with the data privacy principles and relevant supplemental principles stated in the Data Privacy Framework.

·(c) Supplier will promptly notify Stripe in writing at privacy@stripe.com if Supplier's self-certification under the Data Privacy Framework is withdrawn, terminated, revoked, or otherwise invalidated (in which case, an alternative Data Transfer Mechanism will apply).

3.23.2 The EU Standard Contract Clauses.

·For transfers of Personal Data from the EEA to any jurisdiction that is not recognized as having an adequate level of protection for Personal Data under DP Law, the EEA Standard Contractual Clauses apply, are incorporated into this SDTA, and are completed as follows:

·(a) Module One of the EEA Standard Contractual Clauses shall apply to the extent Stripe and Supplier, as independent controllers, process Supplier Data originating in the European Economic Area.

·(b) Module Two of the EEA Standard Contractual Clauses shall apply to the extent Stripe transfers Stripe Processor Data to Supplier under the Agreement.

·(c) For each Module, where applicable:

·(i) The optional docking clause of Clause 7 shall not apply;

·(ii) Option 2 of Clause 9 shall apply, and the time period for prior notice shall be as set forth in the DPA.

·(iii) The optional language in Clause 11 shall not apply;

·(iv) Option 1 will apply in Clause 17 and the EEA Standard Contractual Clauses shall be governed by Irish law;

·(v) Under Clause 18, all disputes shall be resolved before the courts of Ireland;

·(vi) Annex I of the EEA Standard Contractual Clauses shall be deemed completed as set out in Exhibit A of this SDTA.

·(vii) Annex II of the EEA Standard Contractual Clauses shall be deemed completed as set out in Exhibit A of the DPA.

3.33.3 The UK International Data Transfer Addendum.

·For all transfers of Personal Data from the UK to any jurisdiction that is not recognized as having an adequate level of protection for Personal Data under DP Law, the UK Data Transfer Addendum applies, is incorporated into this DPA, and is completed as follows:

·(a) The data exporter and importer shall be as set out in Sections 2 and 3.2 of this SDTA;

·(b) Table 1 of the UK Data Transfer Addendum is deemed to be populated with the information set out in Section 2 of this SDTA, the underlying Agreement, and Exhibit A of the DPA, as applicable;

·(c) For purposes of Table 2 of the UK Data Transfer Addendum, the version of the "Approved EU SCCs" (including the appendix information, modules, and selected clauses) appended to the UK Data Transfer Addendum is the EEA Standard Contractual Clauses, as supplemented by Sections 2 and 3.2(a-c) of this SDTA.

·(d) Table 3 of the UK Data Transfer Addendum is deemed to be populated with the information set out in Exhibit A of the SDPA and Exhibit A of this SDTA, as applicable;

·(e) For purposes of Table 4 of the UK Data Transfer Addendum, the "importer" and "exporter" options shall apply;

·(f) Under Part 2, the mandatory clauses of the UK Data Transfer Addendum will apply; and

·(g) By entering into this Agreement, the data importer and data exporter are deemed to have signed the UK Data Transfer Addendum, as of the DPA Effective Date.

3.43.4 Personal Data Transfers from Switzerland.

·For all data transfers from Switzerland to any jurisdiction that is not recognized as having an adequate level of protection for Personal Data under DP Law, the EEA Standard Contractual Clauses, as outlined in Section 3.2 and as supplemented as follows, apply:

·(a) Any reference to "Member State" will not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland);

·(b) References to the "European Union", "Union", "EU", "EU Member State", "Member State" and "EU or Member State" are replaced with "Switzerland"; and

·(c) To the extent the transfer of Personal Data is governing by the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner will act as the competent supervisory authority; to the extent the transfer of data is governing by the GDPR, the supervisory authority set forth in Exhibit A of this SDTA will act as the competent supervisory authority; and any references to the "competent supervisory authority" will be interpreted accordingly.

3.53.5 Personal Data Transfers from Thailand.

·The EEA SCCs, supplemented by this Data Transfers Addendum and adapted as follows, applies to a transfer of Personal Data by the Parties that is subject to the Personal Data Protection Act B.E. 2562 ("PDPA") to any jurisdiction that does not, for the purposes of the PDPA, have adequate Personal Data protection standards, and is Processed under the Agreement:

·(a) Any reference to "applicable laws" will be interpreted to include the PDPA; and

·(b) References to the "European Union", "Union", "EU", "EU Member State", "Member State" and "EU or Member State" are replaced with "Thailand".

3.63.6 Personal Data Transfers from Brazil.

·The Brazilian Standard Contractual Clauses ("Brazilian SCCs"), supplemented by this SDTA and adapted as set out in Sections 2 and 3.2 of this SDTA, as well as Exhibit A of this SDTA, apply to the transfer of Personal Data subject to the Brazilian General Data Protection Law ("LGPD"), from Brazil to a third country or territory without an adequacy decision from the Brazilian National Data Protection Authority.

3.73.7 Personal Data Transfers from CBPR Participating Economies.

·Stripe Processes Personal Data in accordance with the Cross-Border Privacy Rules ("CBPR") framework. Where CBPR is recognized as a valid transfer mechanism under DP Law, Stripe will transfer Personal Data in accordance with the CBPR and PRP certifications SINC has obtained.

3.83.8 Supplemental Clauses to the EEA Standard Contractual Clauses.

·As applicable to the Processing under the Agreement, Supplier will comply with the supplemental terms of the EEA Standard Contractual Clauses as set forth in Annex IV of this SDTA.

3.93.9. Personal Data transfers from the United Arab Emirates (UAE)

3.9.13.9.1 UAE onshore. The EEA SCCs, supplemented by this Supplier Data Transfers Addendum and adapted as set out below, applies to a transfer of Personal Data that is subject to the United Arab Emirates ("UAE") Federal Decree‐Law No. 45 of 2021 on the Protection of Personal Data ("PDPL"). The EEA SCCs shall apply as applicable and be amended to comply with all PDPL requirements for such transfers, including:

  • 1The "competent supervisory authority" and "supervisory authority" shall be replaced with the "applicable UAE supervisory authority".
  • 2References to "Regulation (EU) 2016/679", "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)" and "that Regulation" are all replaced by "the UAE's Personal Data Protection Law". References to specific Article(s) of "Regulation (EU) 2016/679" are replaced with the equivalent Article or Section of the UAE's Personal Data Protection Law.
  • 3References to Regulation (EU) 2018/1725 shall be omitted.
  • 4References to the "European Union", "Union", "EU", "EU Member State", "Member State" and "EU or Member State" are all replaced with the "United Arab Emirates".
  • 5The reference to "Clause 12(c)(i)" at Clause 10(b)(i) of Module 1 is replaced with "Clause 11(c)(i)".
  • 13Clause 13(a) and Part C of Annex I are not used and shall be omitted.
  • 16Clause 16(c) is supplemented by: "(iv) a UAE supervisory authority makes regulations that cover the transfer of personal data to which these Clauses apply;".
  • 17Clause 17 is replaced with: "These Clauses are governed by the federal laws of the UAE."
  • 18Clause 18 is replaced with: "Any dispute arising from these Clauses shall be resolved by the courts of the UAE. The Parties agree to submit themselves to the jurisdiction of such courts."

3.9.23.9.2 Financial Free Zones. The provisions in this Section 3.8.2 apply solely if and to the extent that the Personal Data is subject to the data protection laws of the Abu Dhabi Global Market ("ADGM") or Dubai International Financial Centre ("DIFC") and is processed in a country not deemed to provide adequate protection for Personal Data by the relevant competent authority of the DIFC and ADGM respectively:

·(a) ADGM. The Parties shall comply with the obligations set out in the ADGM Standard Data Protection Contractual Clauses namely Module 1 (Controller-to-Controller), Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) issued by the ADGM Office of Data Protection ("ADGM SCCs"), each to the extent applicable, incorporated into and form part of this Agreement. For the purposes of: (a) Clause 5 of the ADGM SCCs, the optional docking clause is deemed to be omitted; (b) Clause 9 of the Modules 2 and 3 of the ADGM SCCs, Option 2 is selected and the time period is 30 days; (c) Clause 11 of the ADGM SCCs, the optional redress wording is deemed to be omitted; (d) for purposes of Section A of Annex I of the ADGM SSCs, the name, address, contact details and signature is as set out in this Data Transfer Agreement or DPA; (e) for the purposes of Section B of Annex A, the processing details set out in the Appendices to the EU Standard Contractual Clauses shall apply (where relevant); and (f) for the purposes of Annex II, the technical and organizational measures set out in the Agreement and the DPA (as applicable) shall apply.

·(b) DIFC. The Parties shall comply with the obligations set out in the DIFC Standard Data Protection Contractual Clauses issued by the DIFC Data Protection Commissioner's Office ("DIFC SCCs"), which are incorporated into and form part of this Data Transfer Agreement, for that particular transfer of Personal Data. For the purposes of: (a) Clause 7 of the DIFC SCCs, the optional docking clause is deemed to be omitted; (b) Clauses 9(1)(a) and 9(2)(a) of the DIFC SCCs, Option 2 is selected and the time period is 30 days; (c) Clause 16(6) of the DIFC SCCs, the optional termination clause is omitted; (d) for the purposes of Appendix 1 of the DIFC SCCs, the Parties' details as set out in the DPA or Agreement will apply and the processing details set out in the Appendices to the EU Standard Contractual Clauses shall apply (where relevant); and (e) for the purposes of Appendix 2 of the DIFC SCCs, the technical and organizational measures set out in the Agreement and the DPA (as applicable) shall apply.

44. Conflict.

·If there is any conflict or ambiguity between the provisions of the SDTA, the DPA, or any provision contained in the EEA Standard Contractual Clauses or the UK Data Transfer Addendum, as applicable, the provisions of the EEA Standard Contractual Clauses or the UK Data Transfer Addendum, as applicable, will prevail.

55. Definitions.

·All capitalized terms not otherwise defined in this SDTA have the meanings set out in the Statement of Work or Agreement, including the DPA.

·"Data Privacy Framework" means, as applicable, the EU-US, Swiss-US, or UK-US Data Privacy Framework self-certification program operated by the US Department of Commerce.

·"EEA/UK/Swiss Data" means Personal Data about a Data Subject that is transferred from the European Economic Area, Switzerland or the United Kingdom.

·"EEA Standard Contractual Clauses" mean Module 2 (Transfer: Controller to Processor) of the standard contractual clauses set out in the European Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as amended or replaced from time to time by a competent authority under the relevant DP Law.

·"GDPR" means the General Data Protection Regulation (EU) 2016/679, as amended or replaced from time to time.

·"UK Data Transfer Addendum" means the international data transfer addendum to the EEA Standard Contractual Clauses issued by the UK Information Commissioner in accordance with section 119A of the UK Data Protection Act 2018, as amended or replaced from time to time by a competent authority under DP Law.

·"UK GDPR" means the GDPR, as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019, as amended or replaced from time to time.

Exhibit AExhibit A (Description of Processing and Transfers).

Annex IANNEX I A. LIST OF PARTIES

1I. Data exporter(s) and Data importer(s):

·a. Name: Stripe or Supplier, as applicable. b. Address: As set out in the Agreement

·c. Contact details: Stripe: privacy@stripe.com; Supplier: Supplier's publicly-available email address for receiving privacy-related notices.

·d. Activities relevant to the data transferred under these Clauses: Processing of Personal Data in connection with Stripe's use of the Services under the Agreement.

·e. Data Exporter Role: The Data Exporter's role is set forth in Section 2 (Relationship of the Parties) of this Addendum

·f. Data Importer Role: The Data Importer's role is set forth in Section 2 (Relationship of the Parties) of this Addendum.

·g. Signature and date: By entering into the Agreement, the data exporter and data importer are deemed to have signed these 2021 Standard Contractual Clauses incorporated herein, including their Annexes, as of the Effective Date of the Agreement. B. DESCRIPTION OF TRANSFER

1I. Categories of data subjects whose personal data is transferred

·a. The personal data transferred concern the following categories of data subjects or consumers:

·● Prospective users and/or users of Stripe's online and mobile payment services.

·● The customers and donors of the Stripe's users

·● Stripe's employees and/or potential employees

2II. Categories of personal data transferred

·a. The personal data transferred concern the following: Personal Data necessary to provide the services under the Agreement and the DPA.

·b. The categories of personal data may include, but are not limited to, the following: ● Contact details, name, address

·● IP addresses, usage data, cookies data, location data

·● Financial data: cardholder name, bank account details, payment card details, card expiration date, CVC code, date/time/amount of transaction

·● Identifiers: unique customer identifier, order ID, merchant name/ID and location

·● Employment data: employee ID, performance data, compensation

·● Device identifiers and characteristics ● Browsing and activity indicators

·● Sensitive information: Driver's license number, Social security number (SSN), Tax ID / TIN, Other government-issued ID number

·● Other: As specified in the Statement of Work and the Agreement

3III. Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

·a. Special categories of data may include, but are not limited to, the following: ● ID documents

·● Facial recognition data and / or behavioral biometrics ● Health data

·● Other: As specified in the Statement of Work and the Agreement

4IV. The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

·As specified in the Statement of Work and the Agreement. V. Nature of the processing

·a. The nature of the processing comprises various operations to achieve the purposes of the processing and may also include: ● collection, ● recording, ● organization, ● structuring, ● storage, ● adaptation or ● alteration, ● retrieval, ● consultation, ● use, ● disclosure by transmission, ● dissemination

·● or otherwise making available, alignment or combination, restriction, erasure or destruction of data

6VI. Purpose(s) of the data transfer and further processing

·a. The subject matter and purpose(s) as set out in the Statement of Work and the Agreement.

7VII. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

·a. The period for which the personal data will be retained is set out in the DPA.

8VIII. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing

·a. The subject matter and nature of the processing related to transfers to sub-processors is set out at Annex III to these clauses. Subject to the DPA, the duration of the processing is the duration of the Agreement, unless otherwise agreed in writing. C. COMPETENT SUPERVISORY AUTHORITY

1I. The competent supervisory authority in accordance with Clause 13 is the Irish Data Protection Commission. ANNEX II

·TECHNICAL AND ORGANIZATIONAL MEASURES INCLUDING TECHNICAL AND ORGANIZATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

1I. Supplier as Data Importer: In the event Supplier acts as the Data importer, Annex II is deemed completed by Exhibit A of the DPA.

2II. Stripe as Data Importer: In the event Stripe acts as the Data importer, Annex II is deemed completed. In addition to the technical and organizational measures contained in the Security Requirements Addendum attached as Exhibit A to the DPA, Data importer maintains the following technical and organizational measures: www.stripe.com/security ANNEX III LIST OF SUB-PROCESSORS

·For transfers to Supplier's Sub-processors, the subject matter, nature, and duration of the Processing for each approved Sub-processor is as necessary for the provision of the Services. Stripe has authorized the use of Sub-processors in accordance with Section 10 of the DPA. ANNEX IV SUPPLEMENTAL CLAUSES

·In addition to the obligations under the EEA Standard Contractual Clauses and the UK Data Transfer Addendum (as applicable), the parties agree to the following supplementary measures with respect to Stripe Controller Data:

  • 1Personal Data shall be encrypted both in transit and at rest using encryption technology.
  • 2Supplier will resist, to the extent permitted by Law, any request under Section 702 of Foreign Intelligence Surveillance Act ("FISA").

·Supplier will resist, to the extent permitted by Law, any request under Section 702 of Foreign Intelligence Surveillance Act ("FISA").

  • 3Supplier will use all reasonably available legal mechanisms to challenge any demands for data access through the national security process that it may receive in relation to data exporter's data.
  • 4No later than the Effective Date of the DPA that incorporates or references this Annex, Supplier will notify the data exporter of any binding legal demand for the Personal Data it has received, including national security orders and directives, which shall encompass any process issued under FISA Section 702, subject to Law.

·No later than the Effective Date of the DPA that incorporates or references this Annex, Supplier will notify the data exporter of any binding legal demand for the Personal Data it has received, including national security orders and directives, which shall encompass any process issued under FISA Section 702, subject to Law.

  • 5Supplier shall ensure that its data protection officer, if applicable, has oversight of Supplier's approach to international data transfers.