Last Updated: 11 August 2026
1.Scope
1.1.
This DORA Addendum (the “DORA Addendum”) is an addendum to and forms part of the Agreement. In the event of conflict between this DORA Addendum and the Agreement, this DORA Addendum shall prevail.
2.Definitions and interpretation
2.1.
Terms used in this DORA Addendum shall have the meanings set out below unless the context requires otherwise.
| Agreement | means the Outsourcing Agreement between Service Provider and Nium (each a “Party” and together the “Parties”) to which this DORA Addendum is incorporated, whereby Nium procures the Services from the Service Provider; |
| Applicable Law(s) | means any laws, regulations, regulatory constraints, obligations or rules which are applicable to the Agreement and this DORA Addendum (including binding codes of conduct and binding statements of principle incorporated and contained in such rules from time to time), interpreted (where relevant) in accordance with any guidance, code of conduct or similar document published by any regulatory authority; |
| Confidential Information | means all information (including Data, as applicable) (however recorded or preserved) disclosed by a Party to the other Party in connection with the Agreement; and/or includes, but is not limited to, any Service deliverables, trade secrets, know-how, inventions, techniques, processes, software programs and other IT related information, documentation, schematics, procedures, contracts, customer information, information regarding employees, policyholders or beneficiaries, financial information, budgets, sales, marketing, public relations, advertising and commerce plans, ideas, strategies, designs, projections, business plans, real estate plans, strategic expansion plans, products and product designs, sourcing information, potential product labelling and marking ideas, unpublished information relating to the intellectual property rights of either Party, personal data, all communications between the Parties and other non-public information relating to either Party’s business; |
| Nium | means the Nium entity that is identified as the service recipient under, and is a party to, the Agreement; |
| Data | means the data (including text, drawings, diagrams, images or sounds (together with any database made up of any of these)) which are embodied in any electronic, magnetic, optical or tangible media, which may include personal data and which are:
(a)
supplied to the Service Provider by or on behalf of Nium or a Service recipient; or
(b)
which the Service Provider is required to generate, process, store or transmit pursuant to this Agreement;
|
| Data Protection Laws | means:
(a)
any legislation in force from time to time relating to privacy and/or the processing of personal data including the General Data Protection Legislation (EU 2016/679) (“GDPR”) the Data Protection Act 2018 in the UK (as applicable), the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) and any laws or regulations implementing the Privacy and Electronic Communications Directive 2002/58/EC;
(b)
any laws which replace, extend, re-enact, consolidate or amend any of the foregoing whether or not before or after the date of the Agreement from the date they come into force (except, where permissible under applicable domestic law, to the extent that the GDPR is modified by applicable domestic law from time to time but where the modification has the effect of depriving data subjects of rights to which they would otherwise be entitled were any relevant processing be carried out in the EEA or the UK (as applicable) such modification will have no effect on this Agreement); and
(c)
the guidance and codes of practice issued by any relevant EEA or UK (as applicable)] Regulator and applicable to a party;
|
| DORA | means the Digital Operational Resilience Act Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011; |
| Good Industry Practice | means the capacity, resources, organisational structure, methods, techniques, designs, standards, skills, diligence, efficiency, reliability and prudence which are generally and reasonably expected from a reasonably skilled and experienced service provider engaged in the same type of undertaking as envisaged under the Agreement and which would be expected to result in the performance of its obligations in accordance with Applicable Law in a reliable, safe, economical and efficient manner; |
| Insolvency Event | means any of the following:
(a)
an order is made by a court of competent jurisdiction or a resolution is passed for the administration of the Service Provider; or
(b)
the presentation of a petition for winding up of the Service Provider, which petition is not dismissed within any relevant period as required under Applicable Laws; or
(c)
an order is made or a resolution is passed for winding up of the Service Provider or the Service Provider goes into liquidation (voluntary or otherwise), save for the purpose of a solvent reconstruction or amalgamation with the resulting entity assuming all the obligations of the entity that has been wound up; or
(d)
the application for an order or application for the appointment of a receiver (including an administrative receiver or manager), administrator, examiner, liquidator, provisional liquidator, trustee or similar officer is made in respect of the Service Provider; or
(e)
if a receiver, administrative receiver, administrator, examiner, liquidator, provisional liquidator or similar officer is appointed over all or any part of the assets or undertaking of the Service Provider and is not discharged with thirty (30) days of such appointment; or
(f)
the Service Provider proposes any voluntary arrangement with its creditors or convenes a meeting of its creditors or makes a composition with its creditors generally or an assignment for the benefit of its creditors or other similar arrangement; or
(g)
the Service Provider ceases, or threatens to cease, to carry on business or trade; or
(h)
any third party enforces a security interest over all, or substantially all, of the assets of the Service Provider; or
(i)
if any event analogous to events described under (a) to (h) above shall occur in any other jurisdiction to which the Service Provider is subject;
|
| IT System(s) | means an information technology system (comprising hardware, software and/or network(s)); |
| Regulator(s) | means any regulatory or quasi-regulatory, administrative, or taxation body or court or listing authority or law enforcement agency which regulates or governs Nium or the Service Provider in relation to the provision or receipt of the Services under the Agreement, and any replacement or successor body in any relevant jurisdiction from time to time; |
| Services | means any services and/or products provided by the Service Provider to Nium pursuant to the Agreement; |
| Service Location(s) | means the countries and regions where the Services are provided from, including the hosting, processing and storage of Data, as set out in Annex B of this Addendum; |
| Service Standards | means the service levels and relevant key performance indicators to which Service Provider is required to perform the Services or as otherwise agreed between the Parties in writing; |
| Service Provider | means the Service Provider entity that is identified as such under, and is a party to, the Agreement; |
| Service Provider Personnel | means each person employed, contracted or engaged from time to time by or on behalf of the Service Provider for the provision of all or part of the Services; |
| Service Provider Premises | means any premises owned, leased or otherwise occupied or controlled by the Service Provider; and |
| Virus(es) | means any computer program code, computer virus, computer worm, Trojan horse, authorisation key, licence control utility or software lock, which is intended by any person to, is likely to, or may:
(a)
impair the operation of any computer systems or programs in the possession of Nium; or
(b)
cause loss of, or corruption or damage to, any program or data held on the computer systems or programs in the possession of Nium.
|
2.2.
References in this DORA Addendum to paragraphs are to paragraphs of this DORA Addendum.
3.Services
3.1.
Service Provider shall provide Nium with the Services from the Service Location(s) in accordance with the Service Standards.
3.2.
Any amendments to the Service Standards shall be governed by the standard variation process set out in the Agreement.
3.3.
The Service Provider shall not change the location from which the Services are provided without notifying Nium in advance and subject to Nium’s prior written consent (not to be unreasonably withheld).
4.General obligations and regulatory compliance
4.1.
The Service Provider undertakes throughout the duration of the Agreement that all of the Service Provider’s liabilities, responsibilities and obligations pursuant to the Agreement and this DORA Addendum (including, without limitation, any that relate to Service Provider Personnel) shall be fulfilled in compliance with all Applicable Law, including any Applicable Laws as they apply to Nium in respect of the Services that the Service Provider provides to Nium.
4.2.
The Service Provider acknowledges that:
4.2.1.
Nium is subject to the rules, regulations and requirements of its Regulators in the conduct of its business. Accordingly, the Service Provider shall:
4.2.1.1.
cooperate fully with Nium’s Regulators and their agents and promptly inform Nium of all communications or dealings which it has with such parties; and
4.2.1.2.
in any dealings with Nium’s Regulators and their agents, take reasonable care to preserve Nium’s relationship and standing with the such Regulators;
4.2.2.
all or part of the Services are considered ‘ICT services’ (as defined under DORA) and the Service Provider is considered an ‘ICT third-party service provider’ (as defined in DORA) of Nium that is not supporting a ‘critical or important function’ (as defined in DORA) of Nium and that, accordingly, this DORA Addendum includes provisions designed to ensure Nium's compliance with the requirements under DORA and other Applicable Laws and to facilitate any Regulator’s exercise of authority in relation to material obligations under this DORA Addendum or the Agreement; and
4.2.3.
Nium may be obliged to regularly assess the status and criticality of the Services, and accordingly its status may change during the duration of the Agreement, and the Service Provider may become a ‘critical ICT third-party service provider’ (as defined in DORA). In such circumstances, Nium shall be entitled to:
4.2.3.1.
require amendments to the terms of this Agreement (in particular, this DORA Addendum) in order to ensure it continues to comply with DORA, and other guidance of Nium’s Regulators in relation to ’ICT services’ (as defined in DORA); and
4.2.3.2.
inform Nium’s Regulators of the change in status of the criticality of the Services (whether actual, expected or planned).
4.2.4.
Nium is required to inform its Regulators if for any reason the Service Provider is unable or unwilling to contractually facilitate Nium’s compliance with its regulatory obligations and expectations (including those under DORA).
4.3.
The Service Provider acknowledges that Nium may be required to disclose Confidential Information to a Regulator (including, where required, provide a copy of the Agreement and this DORA Addendum), to the extent that such disclosure is required to enable effective supervision of Nium by any relevant competent authorities and enable Nium to fulfil its obligations under DORA or other Applicable Laws.
5.Confidentiality
5.1.
Subject to Applicable Law, each Party will treat the other Party's Confidential Information as strictly confidential and will not copy, disclose, reproduce or use it, except if the disclosure, copying, reproduction or use is:
5.1.1.
to a Party's personnel or any third-party service providers, to the extent necessary to perform or receive the Services (as applicable), or otherwise to perform that Party's obligations under the Agreement, and provided that such personnel, advisors, potential financiers or third-party service providers are subject to confidentiality obligations equivalent to those in this paragraph 5;
5.1.2.
required for the purpose of any court, arbitration, tribunal, alternative dispute resolution procedures or other civil proceedings connected with the Agreement;
5.1.3.
approved in writing by the Party whose Confidential Information it is; or
5.1.4.
subsequent to the Confidential Information becoming publicly available (other than because of a breach of this paragraph 5).
5.2.
Each Party will promptly notify the other if there is a breach of the confidentiality obligations included in this paragraph 5.
5.3.
The confidentiality obligations in this paragraph 5 will continue in force for 3 years after the Agreement is terminated.
6.Data protection
6.1.
In this paragraph 6 and this DORA Addendum, “personal data”, “data controller” and “data processor” shall have the meaning defined in Article 4 of GDPR.
6.2.
For the purposes of this Agreement, it is agreed that Nium is the “data controller” and the Service Provider is the data processor.
6.3.
All personal data to be processed by the Service Provider on behalf of Nium, pursuant to the Agreement shall be processed in accordance with the terms of Data Protection Agreement.
7.Data security
7.1.
Service Provider shall take responsibility for (a) preserving the confidentiality, authenticity, availability and integrity of Data, (b) restricting the access to Data to only such Service Provider Personnel that are required to have access to Data on a needs-to-know basis for the proper performance of the Service Provider’s obligations under this Agreement, and (c) preventing the corruption or loss of Data, while such Data is within the possession or control of Service Provider, or its agents, contractors or sub-contractors and shall ensure that it has in place appropriate controls (including with its agents, contractors or sub-contractors) to guard against unauthorised and/or unlawful use of Data.
7.2.
For a period of 60 days following termination of the Agreement for any reason (the “Retrieval Period”), the Service Provider shall make available, via secure protocols and in a structured, machine-readable format, any Data residing in the production environment, or keep the service system accessible, for the purpose of Data retrieval by Nium. During the Retrieval Period the Service Provider will provide reasonable assistance to Nium to facilitate the retrieval of Data, including assistance with understanding the structure and format of any relevant export files.
8.Security
8.1.
The Service Provider shall put in place and maintain a level of security in relation to its activities under the Agreement (including the Services) and any IT Systems and locations which it uses to undertake such activities which (as a minimum and on an on-going basis):
8.1.1.
is compliant with Good Industry Practice and which the Service Provider reasonably considers is necessary to ensure compliance with Applicable Law;
8.1.2.
is appropriate to contain the risk of the following occurrences at risk levels that are acceptable in view of Good Industry Practice:
8.1.2.1.
loss of any Service deliverables, Nium intellectual property rights or Data;
8.1.2.2.
loss of integrity or confidentiality of any Service deliverables, Nium intellectual property rights or Data;
8.1.2.3.
unauthorised access to, use of or interference with any Service deliverables, Nium intellectual property rights or Data by any person or organisation; and
8.1.2.4.
the introduction of Viruses into any IT Systems, and internal or external attacks on Service Provider systems, including hacking, denial of service, phishing and similar phenomena; and
8.1.3.
in respect of the Service Provider Premises (and any other locations from which the Services are permitted to be performed), will comprise a site security policy which contains provisions in relation to:
8.1.3.1.
site security access requirements;
8.1.3.2.
key card access requirements;
8.1.3.3.
visitor requirements (including the pre-approval of any visitors by Nium, and accompaniment of visitors whilst on site);
8.1.3.4.
premises access control requirements;
8.1.3.5.
mobile phone and photo capable device requirements; and
8.1.3.6.
portable media requirements.
8.2.
The Service Provider shall implement and maintain appropriate security measures to meet its obligations under paragraph 8.1 of this DORA Addendum and shall regularly test and keep such measures under review.
8.3.
The Service Provider shall participate in any information and communication technology security awareness programmes or digital operational resilience training that Nium is required under Applicable Laws to deliver to its staff or management, by providing Service Provider subject matter expertise for inclusion in the related programme or training materials.
8.4.
In respect of the level of security and security measures referred to in paragraph 8.1 and 8.2 of this DORA Addendum, Nium shall be entitled to review and verify the detail and effectiveness of these (including by carrying out thread-led security penetration testing), and the Service Provider shall take into account any security directions and procedures which are reasonably required by Nium and notified to the Service Provider.
8.5.
Each Party shall promptly inform the other of any actual, attempted or suspected unauthorised access, use or other abuse of any IT Systems, Data, or other security incident, of which it becomes aware (an "Incident"). Thereafter, each Party shall provide the other with full co-operation and assistance in investigating the causes and impact of such Incident and putting together a detailed remediation plan setting out the steps each Party is taking to resolve the Incident.
9.Termination
9.1.
Without prejudice to any other rights or remedies it may have under the Agreement, Nium may terminate the Agreement (in whole or part):
9.1.1.
with immediate effect by serving a written notice to the Service Provider if the Service Provider:
9.1.1.1.
is in breach of Applicable Law; or
9.1.1.2.
commits a material breach or persistent (including a persistent failure to meet any prescribed service levels), or a series of minor breaches of the Agreement that may not individually be material, but in aggregate, such breaches together amount to a material breach, in respect of the Agreement which:
(a)
in the case of a breach capable of remedy following notice from Nium requiring the Service Provider to cure the breach, and the Service Provider does not cure the breach within thirty (30) days, provided that the Service Provider shall use all reasonable endeavours to remedy the breach as soon as possible notwithstanding such thirty (30) day cure period; or
(b)
given the nature of the breach or the remediation action proposed by the Service Provider, is incapable of remedy;
(c)
or an Insolvency Event affecting the Service Provider occurs; or
9.1.2.
by providing the Service Provider with thirty (30) days’ prior written notice where:
9.1.2.1.
Nium is required or instructed by a Regulator to do so;
9.1.2.2.
impediments affecting (a) the Service Provider’s ability to perform the Services; or (b) the management and security of Data by the Service Provider are identified; or
9.1.2.3.
there are [changes affecting the Services or the Service Provider, which in Nium’s opinion result in an adverse impact of the provision of the Services.