Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. For purposes of this DPA:
1.1 "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
1.2 "Applicable Data Protection Laws"means all data protection and privacy laws and regulations applicable to a party's Processing of Personal Data under the Agreement, including, to the extent applicable, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (collectively, the "CCPA") and its implementing regulations; other U.S. state privacy laws (including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and comparable enacted statutes); and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and the UK GDPR.
1.3 "Business," "Business Purpose," "Consumer," "Sell," "Share," and "Service Provider" have the meanings given in the CCPA.
1.4 "Controller," "Processor," "Data Subject," "Personal Data Breach," "Processing" (and "Process"), and "Supervisory Authority" have the meanings given in the GDPR, and, where the CCPA applies, are read to include their CCPA analogues ("Business," "Service Provider," "Consumer," and a breach of the security of Personal Data, respectively).
1.5 "Customer Personal Data" means Personal Data contained within Customer Data (as defined in the Agreement) that FleetPath Processes on behalf of Customer in the course of providing the Services, as further described in Schedule 1.
1.6 "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household, where protected as personal data or personal information under Applicable Data Protection Laws.
1.7 "Sub-processor" means any third party engaged by FleetPath or its Affiliates to Process Customer Personal Data in connection with the Services.
1.8 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission (Commission Implementing Decision (EU) 2021/914) and/or the UK International Data Transfer Agreement or Addendum, as applicable and as incorporated by reference under §9.
1.9 "Technical and Organizational Measures" or "TOMs" means the technical and organizational security measures set out in Schedule 3.