Effective: 17th May, 2021
This Data Sharing Agreement (”Agreement”) forms a legally binding agreement between Institution and ApplyBoard, applies to the extent Institution and ApplyBoard share Personal Information regarding students/applicants as described below, and is incorporated into the ApplyBoard Institution Partner Agreement. This data sharing agreement, which is sometimes referred to as a controller-to-controller data processing agreement, serves to meet accountability obligations under the GDPR, or other Applicable Data Protection Laws. Some terms used in this Agreement are defined in the ApplyBoard Institution Partner Agreement. ApplyBoard Inc acts as the data controller under this Agreement regardless of which ApplyBoard entity you contract with for the underlying ApplyBoard Institution Partner Agreement.
This Agreement will terminate automatically upon termination of the ApplyBoard Institution Partner Agreement.
If this Agreement conflicts with the ApplyBoard Institution Partner Agreement, or ApplyBoard’s Terms and Conditions, then to the extent of the conflict the governing documents will be, in descending order: Schedule 2 of this Agreement (but only to the extent it applies under section 4.a above), this Agreement, the ApplyBoard Institution Partner Agreement, and ApplyBoard’s Terms and Conditions.
The subject matter and duration of the Processing | The subject matter of the Processing is the Processing of Personal Information in relation to prospective applicants to the Institution. ApplyBoard will Process the Personal Information in relation to the Institution’s prospective applicants in providing the Services to the Institution. ApplyBoard will Process the Personal Information for the duration of the Agreement or as otherwise specified in the data protection provisions. |
The nature and purpose of the Processing | The nature and purpose of the Processing is the provision of the Services by ApplyBoard to the Institution. |
The type of Personal Information being Processed. |
The type of personal information being processed includes all data required for an application to be submitted to the Institution for admission purposes. This includes data related to:
|
Sensitive Data being processed |
|
The categories of Data Subjects | Prospective applicants to the Institution |
Where applicable, this Schedule 3 will serve as Annex II to the EU Standard Contractual Clauses. The following table provides more information regarding the technical and organizational security measures set forth below.
Technical and Organizational Security Measure | Evidence of Technical and Organizational Security Measure |
---|---|
Measures of pseudonymisation and encryption of personal data | For the ApplyBoard Services, (a) the databases that store Personal Information are encrypted using the Advanced Encryption Standard and (b) Student Data is encrypted when in transit between a student/applicant’s browser application and the ApplyBoard platform using TLS v1.2. |
Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services | The ApplyBoard platform uses tools and mechanisms within AWS to achieve high availability and resiliency. For ApplyBoard services, the ApplyBoard infrastructure spans multiple fault-independent AWS availability zones in the USA and Canada. |
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident | ApplyBoard performs regular backups of Personal Information, which is hosted on AWS’s data center infrastructure. Personal Information that is backed up is retained redundantly across multiple availability zones and encrypted in transit and at rest using Advanced Encryption Standard (AES-256) |
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing | ApplyBoard performs penetration tests and engages independent third-party entities to conduct application-level penetration tests. Security threats and vulnerabilities that are detected are prioritized, triaged, and remediated promptly. |
Measures for user identification and authorisation | Each user account inside of ApplyBoard is mapped back to a unique email address which the user enters and validates during the account creation. The system enforces a strong password selection upon account setup. Password reuse is blocked for the previous four passwords. ApplyBoards use of the third party authentication provider Okta allows students the option of, after registration to the ApplyBoard system, using their Facebook, Apple, or Google authentication to provide a seamless login to the ApplyBoard system. If the user has activated MFA to 2FA with one of these three authentication systems the ApplyBoard application will automatically support it. |
Measures for the protection of data during transmission and during storage. | For the ApplyBoard Services, (a) the databases that store Personal Information are encrypted using the Advanced Encryption Standard and (b) Personal Information is encrypted when in transit between Student’s browser application and the Services using TLS v1.2. (Only Strong Ciphers are permitted) ApplyBoard performs regular backups of Personal Information, which is hosted on AWS’s data center infrastructure. Personal information that is backed up is retained redundantly across multiple availability zones and encrypted in transit and at rest using Advanced Encryption Standard (AES-256). The cloud platform for the ApplyBoard Services is hosted by Amazon Web Services (“AWS”). The AWS data center infrastructure used in providing the ApplyBoard Services is located in the United States. Additional information about security provided by AWS is available at https://aws.amazon.com/security and https://aws.amazon.com/whitepapers/overview-of-security-processes. ApplyBoard’s production environment within AWS, where Student Data and the ApplyBoard Services are hosted, is a logically isolated Virtual Private Cloud (VPC). |
Measures for ensuring physical security of locations at which personal data are processed | AWS data centers that host the ApplyBoard Services are strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication (2FA) a minimum of two (2) times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. These facilities are designed to withstand adverse weather and other reasonably predictable natural conditions. Each data center has redundant electrical power systems that are available twenty-four (24) hours a day, seven (7) days a week. Uninterruptible power supplies and on-site generators are available to provide back-up power in the event of an electrical failure. In addition, ApplyBoard headquarters and office spaces have a physical security program that manages visitors, building entrances, CCTVs (closed circuit televisions), and overall office security. All employees, and contractors are required to possess an access badge, and visitors are required to wear identification badges. |
Measures for internal IT and IT security governance and management | ApplyBoard maintains a risk-based assessment security program. The framework for ApplyBoard’s security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Personal Information. ApplyBoard’s security program is intended to be appropriate to the nature of the Services and the size and complexity of ApplyBoard’s business operations. |