DubbeDynamics

Legal

Annex D — Data Protection, Information Security and Cybersecurity

Version 2.0 · As of: June 2026 · Annex to the AEB

Working English translation — provided for convenience only and not yet legally reviewed. The legally binding version is the German original; a final reviewed English version will follow.

§ 1 Purpose and Scope

1. This Annex D defines requirements for data protection, information security and cybersecurity for contractors who, in the course of orders, projects or services, process or use data, information, systems, software, interfaces, remote access or documents of or for DubbeDynamics.

2. It applies in addition to confidentiality agreements, data-protection agreements, data processing agreements, technical specifications, IT security requirements and the General Purchasing Terms of DubbeDynamics.

3. The Contractor must take security measures that appropriately reflect the nature, scope, risk and protection needs of the processed information and systems.

§ 2 Data Protection and Personal Data

1. The Contractor must comply with all applicable data-protection regulations, in particular the General Data Protection Regulation and the German Federal Data Protection Act, insofar as personal data is processed.

2. If the Contractor processes personal data on behalf of DubbeDynamics, a required data processing agreement or other data-protection agreement must be concluded before the start of processing.

3. The Contractor may process personal data only for the contractually intended purpose, only to the extent necessary and only in accordance with documented instructions, insofar as processing on behalf is involved.

§ 3 Information Security and Protection of Confidential Information

1. The Contractor must implement technical and organisational measures to protect confidential information, technical data, drawings, specifications, access credentials, personal data, software and project documentation.

2. The measures must in particular ensure protection against unauthorised access, loss, alteration, disclosure, manipulation, malware, phishing, social engineering, insecure remote access and uncontrolled disclosure.

3. Access rights must be granted on a need-to-know basis, reviewed regularly and revoked without undue delay when no longer required.

§ 4 IT Systems, Remote Access and Software

1. Remote access to systems of DubbeDynamics or its customers is only permitted with prior consent and in accordance with the security requirements specified for this purpose.

2. The Contractor must ensure that software, scripts, macros, data carriers, files and digital deliverables used are free of known malware and do not contain deliberately built-in backdoors or impermissible telemetry, copying or access functions.

3. Default passwords, insecure accounts, undocumented administrator access or unprotected interfaces must be eliminated before delivery, commissioning or handover, or expressly disclosed insofar as elimination is technically not possible.

§ 5 Security Incidents and Reporting Obligations

1. The Contractor must report without undue delay any actual or suspected security incidents, data breaches, unauthorised access, data losses, malware infections, compromised credentials or other events that may affect data, systems or projects of DubbeDynamics.

2. The report must contain all available information on the nature, scope, affected data, affected systems, time, cause, measures already taken and further remedial steps.

3. The Contractor must reasonably cooperate in investigation, containment, recovery, documentation, notification of data subjects or authorities, and prevention of further damage.

§ 6 Storage, Transmission and Subcontractors

1. Confidential information and personal data of DubbeDynamics may only be processed and stored on adequately protected systems. Transmission to third countries may only take place if the data-protection and security requirements are met.

2. The use of cloud services, external platforms, AI systems, translation services or other third-party applications for confidential information of DubbeDynamics requires an appropriate legal and security basis.

3. Subcontractors who receive access to data or systems must be bound to confidentiality, data protection and information security to the same extent.

§ 7 Evidence, Audits and Legal Consequences

1. DubbeDynamics may request reasonable evidence regarding data protection, information security and cybersecurity, in particular security concepts, certifications, policies, technical descriptions or confirmations of the Contractor.

2. In the event of significant security deficiencies or security incidents, DubbeDynamics is entitled to suspend services, demand additional protective measures or terminate the contract for good cause, insofar as adherence to the contract is unreasonable.

3. The Contractor is liable for damages, costs, fines and claims arising from culpable breaches of data-protection, information-security or cybersecurity obligations.

Appendix D.1 — Minimum Information Security Measures

Access: need-to-know, strong passwords, MFA where appropriate. Protect project-critical access in particular.

Malware protection: up-to-date protective measures and patch management. Check digital deliverables.

Data transmission: secured transfer, no uncontrolled sharing. Review cloud/AI use.

Incident reporting: report without undue delay and cooperate. Provide details as they become available.

Subcontractors: equivalent obligation. Limit access.

← Back to home