Reseller Terms
EQUIFAX RESALE CUSTOMER TERMS
Standard Resale Customer Terms:
- DEFINITIONS
- For the purposes of these Terms the following words and phrases shall mean as follows, unless expressly stated to the contrary:
| “Applicable Laws” | means all applicable laws, enactments, rules, regulations, orders, regulatory policies, regulatory permits and licences, and any mandatory instructions or requests of a regulator, in each case which are in force from time to time, including: The Consumer Credit Acts 1974 and 2006; The Data Protection Laws; The Representation of the People (England and Wales) Regulations 2001; The Financial Services and Markets Act 2000 (Money Laundering Regulations 2001); Rules made by the Steering Committee on Reciprocity; and The Guide to Credit Scoring 2000 |
| “CRAIN” | means the Credit Reference Agency (CRA) Information Notice, the industry standard privacy information policy adopted by the leading UK CRAs (a copy of which can be found here: https://www.equifax.co.uk/crain), and as may be updated from time to time; |
| “Data Protection Laws” | means all applicable data protection and privacy legislation in force from time, including the UK GDPR and the Data Protection Act 2018, as all such laws are updated from time to time, and all other regulatory requirements in force from time to time which apply to a party relating to the use of personal data and the privacy of electronic communications; |
| “Equifax” | means Equifax Limited, a company incorporated and registered in England and Wales with company number 2425920 registered office is at 1 Angel Court, London, EC2R 7HJ; |
| “Equifax Security Requirements” | means the security requirements applicable to all users of Equifax’s services, as set out in Annex 1 to these Terms; |
| “Information Services” | means any services (including the provision of Output Data) provided by Equifax that the Resale Customer is authorised to receive via the Reseller, which is provided to the Reseller under the Resale Agreement |
| “Output Data” | means any information or data provided by Equifax that the Resale Customer is authorised to receive via the Reseller that are provided to the Reseller under the Resale Agreement; |
| “Permitted Purposes” | ID verification – Verifying the ID of individuals or businesses seeking to contract for goods and services, obtain credit and associated Financial Services, and (in the case of individuals) apply for or take up an offer of employment. The Reseller acknowledges and agrees that none of the Permitted Purposes allow the use of Services for direct marketing purposes. Employment ID, Credit and Fraud Risk Assessment – In relation to an employee or individual applying for a position of employment: (i) verifying their identity; (ii) assessing their creditworthiness (where permitted by Applicable Law); and/or (iii) detecting or preventing potential instances of fraud by undertaking (as applicable) address and bank account verification, employment status (and employer) checks, and Politically Exposed Person checks. |
| “Product Rules” | Means those additional terms and conditionsset out in Annex 2 (as applicable); |
| “Resale Agreement” | the agreement between Equifax and the Reseller, under which the Reseller is permitted to resell the Information Services and Output Data; |
| “Resale Customer” | the party receiving the Information Services or Output Data from the Reseller; |
| “Reseller” | the party permitted to resell the Information Services and Output Data pursuant to the Resale Agreement; |
| “Search” | means a search made of Equifax’s database (including via the Reseller) for the purpose of obtaining information in relation to an individual or corporate entity; |
| “Terms” | means the terms and conditions set out below, including these definitions; and |
| “UK GDPR” | means Regulation (EU) 2016/679 of the European Parliament (General Data Protection Regulation or ‘GDPR’) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018. |
- PERMITTED USE
- The Resale Customer shall only use the Output Data;
- in compliance with all Applicable Laws;
- for the Permitted Purposes; and
- otherwise in compliance with these Terms and any applicable Product Rules.
- The Resale Customer must not:
- resell or offer to resell any of the Output Data; or
- disclose to any other person any of the Output Data, except:
- when required to do so by law or any regulatory authority, including following a subject access request submitted by a consumer to whom the data relates; or
- to the Resale Customer’s personnel whose duties reasonably require such disclosure, on condition that the Resale Customer ensure that each such person to whom such disclosure is made, is informed of the Resale Customer’s obligation of confidentiality and non-disclosure, and are subject to equivalent obligations.
- ACCURACY
- The Resale Customer acknowledges and agrees that:
- the information forming part of the Output Data is provided to Equifax by third parties over which Equifax does not have control, in particular in relation to the accuracy or completeness of such information;
- the volume and nature of the information on Equifax databases makes it impractical for Equifax to verify the information;
- if Equifax were to attempt to verify the Output Data, Equifax would only be able to offer the Information Services to the Reseller at significantly increased cost, which would in turn increase the costs paid by the Resale Customer; and
- Equifax is not in any circumstances liable to any party for any loss or damage at all arising from any inaccuracies, faults or omissions in, or in the provision of, the Output Data unless caused by Equifax’s negligence or wilful default.
- DATA PROTECTION AND TRANSPARENCY
- For the purposes of the Data Protection Laws, the Resale Customer and Equifax shall be independent controllers of any personal data contained within the information provided by the Resale Customer to Equifax (including via the Reseller) (“Input Data”) and Output Data, and the Resale Customer shall comply with its obligations under the Data Protection Laws.
- Without prejudice to the generality of clause 4.1, before providing any Input Data to Equifax or otherwise conducting a Search in relation to an individual consumer, the Resale Customer shall:
- Ensure that it has a lawful basis to disclose the Personal Data contained within the Input Data and receive any Personal Data contained within he Output Data;
- notify the individual about whom a Search is made that their information will be disclosed to a credit reference agency, which may keep a record of that information and disclose it (and the fact that a search was made) to its other customers, including for the purposes of assessing the risk of giving credit and occasionally to prevent fraud, money laundering and to trace debtors;
- make a copy of the CRAIN available to the individual so that they might understand how the credit reference agencies process their personal data; and
- on request (which may be received directly or via the Reseller), provide a copy of the notification used to satisfy the obligations at clause 5.1.1 and 5.1.2 to Equifax.
- SECURITY AND AUDIT
- The Resale Customer shall maintain adequate security measures to protect the integrity, security and confidentiality of all Output Data, including as a minimum by complying with Equifax’s security requirements and policies, as made available by Equifax to the Reseller and Resale Customer from time to time.
- The Resale Customer shall provide to the Reseller and Equifax any information reasonably requested in order to assess whether the Resale Customer’s use of the Information Services and Output Data is in compliance with these Terms.
- TERMINATION OF SERVICES
- Equifax may cease to make the Output Data available to the Reseller for resale to the Resale Customer in the event of the following:
- the Resale Customer commits a material breach of these Terms;
- the Reseller commits a material breach of the Resale Agreement or Equifax is otherwise permitted to suspend or terminate services under the Resale Agreement; or
- the provision or intended use of Information Services by the Resale Customer is or is likely to be or become unlawful due to a change in Applicable Law, regulatory guidance or court ruling, or otherwise constitute a breach of contractual arrangements Equifax has in place with relevant data suppliers.
Annex 1 – Equifax Security Requirements (for Resale Customers)
This Annex applies to any means through which the Customer accesses, receives or uses the Information Services or Output Data including, without limitation, any access via system-to-system processes, personal computers or over the internet. For the purposes of this Annex:
“Customer” means the Resale Customer; “Authorised User” means the Customer’s personnel, or the personnel of its sub-contractors or agents that the Customer has authorised to access, receive or use the Information Services or the data obtained through the use of such services (“Equifax Information”); and the term “Services” or “Information Services” means the services provided by Equifax to the Customer via the Reseller.
The Customer will, with respect to handling the Equifax Information:
- ensure that only Authorised Users can request or have access to the Services and take all necessary measures to prevent any unauthorised requests for or access to the Services by any person other than an Authorised User acting in accordance with the Agreement, including, without limitation, by limiting disclosure of any relevant Customer security codes, member numbers, user IDs, and any passwords the Customer may use access or user the Services, to those individuals on a need to know basis, and ensuring that Any user IDs are unique to each person, and the sharing of user IDs or passwords is prohibited;
- ensure that Authorised Users are trained on the contents of this Annex and instructed not to request any Equifax Information for any purpose other than as permitted by the Agreement, and not for any personal reasons or to provide Equifax Information to third parties except as permitted by the Agreement and this Annex;
- ensure that secure authentication practices are utilized when accessing the Services, including but not limited to restricting access based on Authorised User location and only permitting access to the Services through Customer approved devices;
- ensure that Equifax Information is encrypted in transit with Advanced Encryption Standard (AES)-256 or an equivalent or better National Institute of Standards and Technology (NIST) approved cypher;
- use commercially reasonable efforts to secure Equifax Information at rest, including: (i) encrypting all Equifax Information at rest in accordance with industry accepted encryption standards; (ii) separating Equifax Information from the Internet or other public networks by firewalls configured to meet industry accepted best practices; (iii) protecting Equifax Information through multiple layers of network security, including but not limited to, industry-recognized firewalls, routers, and intrusion detection/prevention devices (IDS/IPS), (iv) securing access (both physical and network) to systems storing Equifax Information; and (v) patching servers on a timely basis with appropriate security-specific system patches, as they are available;
- ensure that: (i) all hard copy Equifax Information is stored in a secure manner; (ii) Equifax Information, including electronic and hard copy information, is securely destroyed when no longer needed for the the Customer’s permitted use of the Services under the Agreement; and (iii) maintain documented policies to ensure compliance with the foregoing;
- not allow Equifax Information to be displayed via the Internet unless utilizing, at a minimum, a three-tier architecture configured in accordance with industry best practices;
- use commercially reasonable efforts to establish procedures and logging mechanisms for systems and networks that will allow tracking and analysis in the event there is a compromise, and maintain an audit trail history;
- provide prompt notification to Equifax of any change in address or office location where Equifax Services are or will be accessible, and permit Equifax or its designated representative to conduct an onsite visit of the new location in accordance with the rights of audit set out in the Agreement; and
- in the event that the Customer has a Security Incident involving Equifax Information, the Customer will notify Equifax as soon as possible, but in no event more than twenty-four (24) hours following the Security Incident, and: (i) fully cooperate with Equifax in a security assessment process; (ii) promptly remediate any findings; and (iii) take all necessary actions to prevent a recurrence. For purposes of this Section “Security Incident” means any suspected or actual breach, theft or unauthorized access, use, misuse, theft, vandalism, modification or transfer of or to Services or Equifax Information.
If Equifax reasonably believes the Customer is in breach of this Annex, Equifax may, in addition to any other right or remedy it has under the Agreement, with reasonable advance written notice to the Customer and at Equifax’s sole expense, conduct, or have a third party conduct on its behalf, an audit of the Customer’s facilities, security practices and procedures to the extent Equifax reasonably deems necessary, including an on-site inspection, to evaluate the Customer’s compliance with the data security requirements of this Annex.
Annex 2 – Product Rules
BT OSIS END USER TERMS/PRODUCT RULES
These BT OSIS Terms shall only apply where the Customer receives BT OSIS Data as part of a QCB (as such term is defined above).
- For the purposes of these BT OSIS Terms, the following definitions shall apply:
| “BT” | shall mean British Telecommunications plc; |
| “BT OSIS Data” | the name, address and telephone number of a consumer or business; |
| “BT Marks” | shall mean registered or unregistered trademarks and service marks, house marks and marks of ownership, trading names, brand names, distinctive colour schemes, devices, styles, emblems and other manifestations associated with BT; |
| “You” or “Your” | shall mean the Licensee’s customer; |
| “Licensee” | shall mean Equifax Limited. |
- These BTOSIS Terms shall apply only to the extent that You receive BT OSIS Data from the Licensee.
- In relation to Your receipt and use of BT OSIS Data, You shall:
- comply with all applicable laws and codes of practice including those in relation to data protection and privacy of information;
- use all reasonable endeavours to prevent any unauthorised disclosure of any BT OSIS Data and keep it appropriately secure and confidential; and
- only use or process any of BT OSIS Data for Your own internal purposes or, in the alternative, for a single use for a single specific person who is Your customer.
- To the extent that any complaint is made which relates to Your use of the Information, You shall assist BT and the Licensee in investigating the complaint and shall take such steps as are reasonably necessary to remedy the complaint as soon as practicable.
- You shall not:
- distribute, publish or display any material amount of the BT OSIS Data by any means, except as otherwise permitted by these BT OSIS Terms;
- export or permit the export of the BT OSIS Data to a country which is not within the UK or European Economic Area, without the prior written express consent of the Licensee and/or BT;
- have any rights to use the BT Marks and shall not make reference to BT or any BT product or service in any promotional or marketing advertising, communications, literature or packaging; and
- alter any copyright or other intellectual property right acknowledgement or confidentiality marking incorporated into or applied to the BT OSIS Data and/or documentation owned by BT.
