DORA – Digital Operational Resilience Act
Acceptance without separate signature: Where the customer is a financial entity or insurance undertaking under DORA, this addendum is accepted by confirming the terms (AGB), the privacy policy and the data processing agreement (DPA). No separate signature is required. It does not apply to other customers.
ICT third-party provider: CHAOS GmbH · Customer: the contracting party, where it is a financial/insurance undertaking under DORA.
1. Preamble
The parties are in a contractual relationship for ICT services. Due to DORA, this addendum forms an integral part of that relationship. Undefined terms have the meaning given in DORA.
2. ICT services
CHAOS (Microsoft 365 licence/usage analysis, recommendations, dashboard and, where agreed, related control/commerce functions) constitutes the ICT services. CHAOS maintains appropriate information-security standards (oriented on ISO/IEC 27001 and comparable standards) and grants the customer reasonable instruction rights compatible with the SaaS architecture.
3. Subcontractors
Flow-down of obligations; prior written consent for material subcontracting where required; proper selection and monitoring; confidentiality and audit access for supervisors, as set out in more detail in the German version and the DPA.
4. Locations
Processing/storage within the EEA by default; prior notice of changes; prior written consent for third-country relocation where legally required.
5. Cooperation and audit
Reasonable cooperation with competent authorities; customer monitoring and audit rights; prompt notice of material developments; reasonable TLPT cooperation.
6. Continuity
Incident response / continuity plans, regular testing, backup facilities.
7. ICT-related incidents
Immediate notice to the customer’s designated contact/CISO; reasonable support without extra charge for related incidents; GDPR Arts. 33/34 remain unaffected.
8. Training
CHAOS staff may attend customer ICT-security training by arrangement; generally free of charge for participation; confidentiality applies.
9. Data protection
The Art. 28 GDPR DPA including TOMs forms an integral part of this addendum.
10. Contacts
Customer: contact/CISO named in onboarding, portal or in writing.
CHAOS (ICT incidents): Roland Kremnitzer · +43 3339 20 10 20 · +43 660 18 39 008 · chaos@chaos.ms
11. Termination
Follows the main agreement; additional extraordinary termination grounds for material non-performance, legal breaches, ICT risk weaknesses, obstruction of supervisory rights, etc.; data return without retention right (subject to mandatory law); exit support for at least three (3) months.
12. Final provisions
Austrian law; venue Graz where permitted; written form; severability; order of precedence: mandatory law (incl. DORA) > this addendum > DPA > AGB. Full German text prevails in case of doubt.
See also the DPA and the privacy policy.