Factory-direct from Turkey since 1982·Global B2B supply
Request a SampleDownload CatalogueRegion / Market
Logo
HOME/DATA PROCESSING AGREEMENT

CAGS Data Processing Agreement (DPA)

Effective Date: 24 June 2026 | Last Updated: 24 June 2026 | Next Review: June 2027

1. Purpose & Legal Basis

This Data Processing Agreement ('DPA') is entered into between CAGS TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY ('Data Controller' or 'CAGS') and any business partner, supplier, or service provider ('Data Processor') who processes personal data on behalf of CAGS in connection with a commercial relationship.

This DPA is incorporated by reference into all contracts between CAGS and its Data Processors and governs the processing of personal data in accordance with:

  • GDPR Article 28 — processor obligations and written contracts.
  • GDPR Articles 32, 33, 34 — security and breach notification.
  • Turkey's KVKK Law No. 6698 — data transfer and processor obligations.
  • UK GDPR — applied for processors handling data of UK data subjects.
  • EU Standard Contractual Clauses (SCCs) — for international data transfers.

2. Definitions

  • 'Controller': CAGS — the entity that determines the purposes and means of processing personal data.
  • 'Processor': any third-party business, supplier, or service provider that processes personal data on behalf of CAGS.
  • 'Personal Data': any information relating to an identified or identifiable natural person, as defined under GDPR Article 4.
  • 'Processing': any operation performed on personal data, including collection, storage, use, transfer, and deletion.
  • 'Sub-Processor': any third party engaged by the Processor to carry out processing activities on behalf of CAGS.

3. Scope of Processing

3.1 Categories of Personal Data

  • Identity data: names, job titles, identity document numbers
  • Contact data: business email addresses, phone numbers, business addresses
  • Financial data: bank account details, invoice and payment records
  • Employment data: HR records, payroll information
  • Technical data: IP addresses, system log data, access records

3.2 Categories of Data Subjects

  • CAGS employees and job applicants
  • CAGS customers and business contacts
  • CAGS suppliers and business partners
  • Website visitors and platform users

3.3 Purpose of Processing

Personal data is processed solely for the purposes set out in the main commercial agreement between CAGS and the Processor, including but not limited to: HR services, payroll processing, IT infrastructure, logistics, accounting, and marketing services.

4. Processor Obligations

The Data Processor agrees to:

  • Process personal data only on documented instructions from CAGS, unless required to do so by applicable law.
  • Ensure that all personnel authorised to process personal data are subject to appropriate confidentiality obligations.
  • Implement technical and organisational measures sufficient to meet GDPR Article 32 security requirements.
  • Not engage any Sub-Processor without prior written authorisation from CAGS.
  • Where Sub-Processors are engaged, impose equivalent data protection obligations on them by contract.
  • Assist CAGS in fulfilling its obligations to respond to data subject rights requests (access, rectification, erasure, portability, objection).
  • Notify CAGS without undue delay — and in any event within 24 hours — upon becoming aware of a personal data breach.
  • At CAGS's choice, delete or return all personal data to CAGS upon termination of the services, and delete existing copies unless retention is required by applicable law.
  • Make available to CAGS all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits and inspections conducted by CAGS or its authorised representative.

5. Security Measures (GDPR Article 32)

The Processor shall implement appropriate technical and organisational security measures including, as a minimum:

  • Encryption of personal data at rest and in transit using industry-standard protocols (AES-256, TLS 1.2+).
  • Pseudonymisation of personal data where technically feasible.
  • Ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems.
  • Ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
  • A process for regularly testing, assessing, and evaluating the effectiveness of security measures.
  • Access controls ensuring only authorised personnel can access personal data, with role-based access permissions.
  • Multi-factor authentication (MFA) for systems containing personal data.
  • Regular security patching and vulnerability management.
  • Documented incident response procedures.

6. Sub-Processing

The Processor shall not engage Sub-Processors to process CAGS personal data without CAGS's prior written consent. Where Sub-Processors are engaged:

  • The Processor must impose equivalent data protection obligations on the Sub-Processor by written contract.
  • The Processor remains fully liable to CAGS for the Sub-Processor's performance of data protection obligations.
  • CAGS may object to any proposed new Sub-Processor within 14 days of notification.

7. International Data Transfers

The Processor may not transfer CAGS personal data outside the EEA or Turkey without CAGS's prior written consent and one of the following transfer mechanisms in place:

  • EU Commission Adequacy Decision for the destination country.
  • EU Standard Contractual Clauses (SCCs) — 2021 version — between the parties.
  • UK International Data Transfer Agreement (IDTA) for transfers of UK personal data.
  • Binding Corporate Rules (BCRs) approved by the relevant supervisory authority.
  • KVKK Board approval for transfers of Turkish personal data.

8. Data Breach Notification

In the event of a personal data breach involving CAGS data, the Processor shall:

  • Notify CAGS in writing within 24 hours of becoming aware of the breach.
  • Provide sufficient information to allow CAGS to assess the nature, scope, and impact of the breach.
  • Include in the notification: the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
  • Cooperate fully with CAGS in investigating the breach, notifying supervisory authorities, and communicating with affected data subjects where required.
  • Take immediate steps to contain, remediate, and prevent recurrence of the breach.

9. Data Subject Rights Assistance

The Processor shall assist CAGS in responding to data subject rights requests within the timeframes required by applicable law (generally 30 calendar days under GDPR). This includes providing relevant data, supporting rectification or erasure, and enabling data portability where applicable.

10. Audit Rights

CAGS reserves the right to audit the Processor's data processing activities and security measures, with reasonable notice (minimum 14 days), no more than once per year unless a breach or compliance concern arises. The Processor shall cooperate fully with such audits and provide access to relevant records, systems, and personnel.

11. Term & Termination

This DPA remains in force for the duration of the commercial agreement between CAGS and the Processor. Upon termination:

  • The Processor shall, at CAGS's election, securely delete or return all personal data processed under this DPA within 30 days of termination.
  • The Processor shall provide written confirmation of deletion upon request.
  • Obligations regarding confidentiality and security of personal data survive termination.

12. Governing Law

This DPA is governed by the laws of the Republic of Turkey. For processing of UK personal data, UK GDPR requirements apply additionally. For processing of EU personal data, GDPR (EU 2016/679) requirements apply additionally. Any disputes shall be resolved in accordance with the dispute resolution provisions of the main commercial agreement.

13. Contact for DPA Enquiries

For any questions, audit requests, or data protection matters under this DPA:

CAGS TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY
Fulya Mahallesi, Buyukdere Caddesi, Torun Center A Blok No: 74A, Ic Kapi No: 19, Sisli / Istanbul, Turkey
Email: info@cagstobacco.com
Telephone: +90 212 916 27 27
Website: www.cagsgrp.com

Related Policies

  • Privacy Policy: www.cagsgrp.com/privacypolicy
  • Terms & Conditions: www.cagsgrp.com/terms-and-conditions
  • Contact CAGS: www.cagsgrp.com/contact