Data Processing Addendum

(United States Vendor)

Last Updated: September 3, 2026

QVC Group is a group of companies that includes QVC Group, Inc. ("QVC") and QVC's Affiliates. In this Data Processing Addendum, "QVC Group Company" means QVC or the QVC Affiliate that is a party to the Agreement with Vendor. This Addendum forms part of any Agreement between QVC Group Company and Vendor covering use of the Services.

  1. Definitions.
    • "Addendum" means this Data Processing Addendum.
    • "Affiliate" means with respect to QVC any other present or future entity that directly or indirectly controls, is controlled by, or is under common control with QVC. For purposes of the preceding sentence, "control", "controlled", and "controls" with respect to an entity means (a) direct or indirect ownership of at least 35% of such entity's capital stock or other voting interests or (b) the ability to direct the senior management of such entity.
    • "Agreement" means any purchase order or other contract that incorporates this Addendum.
    • "Data Protection Law" means any present or future federal, state, territorial, or local law or regulation that relates to data privacy, data security, or the use or other processing of Personal Data.
    • "Data Regulator" means any regulatory, supervisory, or governmental authority that is responsible for administering or enforcing Data Protection Laws.
    • "Personal Data" means information provided to, or Processed by, Vendor or Vendor's Subcontractors by or on behalf of QVC Group Company and its Affiliates if such information identifies, relates to, describes, is capable of being associated with, or could be directly or indirectly linked to a natural person.
    • "Privacy Rights" means rights provided to people under Data Protection Law including, without limitation (a) deleting Personal Data; (b) obtaining a copy of Personal Data; (c) correcting Personal Data; (d) obtaining Personal Data in a portable format; and (e) terminating any sales of Personal Data.
    • "Processing" means any creation, access, modification, disclosure, transfer, storage, deletion, destruction, or other use of Personal Data. "Process" and "Processed" shall be construed in accordance with the preceding part of this definition.
    • "Security Breach" means (a) a breach of security or Personal Data under any Data Protection Law; or (b) any other unauthorized access, unauthorized acquisition, unauthorized destruction, unauthorized deletion, unauthorized disclosure, unauthorized use, unauthorized modification, loss, or misappropriation of Personal Data or other compromise of the security, confidentiality, integrity, or availability of Personal Data.
    • "Security Controls" means the Security Controls at this link.
    • "Services" means goods, services, technology or other products provided by Vendor under the Agreement.
    • "Subcontractor" means any person or entity other than Vendor and Vendor's employees.
    • "Vendor" means the company that is a party to the Agreement with QVC Group Company.
  2. The type of Personal Data Vendor shall Process is QVC Group Company customer, prospective customer, employee, applicant, or vendor data. Additional details of Vendor's Processing may be set forth in data processing exhibits that reference this Addendum.
  3. Vendor shall comply with Data Protection Law applicable to Vendor, and Vendor shall notify QVC Group Company if Vendor determines that Vendor is not able to comply with Data Protection Law applicable to Vendor. QVC Group Company has the right to take reasonable and appropriate steps to ensure that Vendor is using Personal Data in a manner consistent with Vendor's obligations under Data Protection Law.
  4. Vendor shall ensure that each person or entity that Processes Personal Data by or on behalf of Vendor is subject to contractual duties to Vendor with respect to Personal Data that are at least as restrictive and protective as Vendor's obligations to QVC Group Company with respect to Personal Data. If Vendor uses a Subcontractor to Process Personal Data, Vendor will provide QVC Group Company with notice of the Subcontractor's identity at least 15 days before Vendor permits the Subcontractor to Process Personal Data, and QVC Group Company shall have 15 days from receipt of such notice to object to the Subcontractor by providing a notice of objection to Vendor. If a QVC Group Company provides a notice of objection with respect to a Subcontractor, Vendor and QVC Group Company agree to work together to resolve such notice of objection. If such notice of objection cannot be resolved, QVC Group Company may terminate the portion of the Services for which Vendor is retaining the Subcontractor.
  5. Taking into account the context of Processing of Personal Data, Vendor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of Processing Personal Data. Without limiting the previous sentence, Vendor shall implement and maintain the Security Controls with respect to Personal Data.
  6. Vendor (a) shall Process Personal Data solely for the benefit of QVC Group Company and QVC Group Company's Affiliates and solely for the business purpose of providing Services to QVC Group Company and QVC Group Company's Affiliates; (b) shall not combine Personal Data with other data about natural persons that Vendor collects from Vendor's own interactions with natural persons or that Vendor receives from another person; (c) shall not Process Personal Data for any purpose other than as set forth in Section 6(a). Without limiting the previous part of this Section 6, Vendor shall not use Personal Data for marketing, advertising, modeling, training (including training of AI models), analytics or any other secondary use.
  7. Vendor shall Process Personal Data only while the Agreement is in effect. Vendor shall delete and destroy and cause the deletion and destruction of all Personal Data, except to the extent such Personal Data is required by law to be maintained by Vendor, upon the earlier of (a) the Agreement's expiration or termination; or (b) 30 days after QVC Group Company requests that Vendor delete Personal Data. Vendor shall certify in writing to QVC Group Company that Vendor has complied with its obligations under this Section 7 within 45 days after QVC Group Company's request for such certification, and in such certification, Vendor shall disclose any applicable laws under which Vendor is retaining Personal Data if Vendor is retaining Personal Data. If Vendor receives or creates de-identified data derived from Personal Data, Vendor shall not attempt to re-identify it and shall take reasonable measures to prevent re-identification.
  8. At QVC Group Company's option, Vendor shall either (a) allow for, and contribute to, reasonable audits and inspections by QVC Group Company or QVC Group Company's designated auditor of locations where Personal Data is Processed by or for Vendor; or (b) arrange for a qualified and independent auditor to conduct annually an audit of Vendor's policies and technical and organizational measures in support of Vendor's obligations under this Addendum using an appropriate and accepted control standard or framework and audit procedure for the audits as applicable. Subject to the next sentence, QVC Group Company may exercise its option under this Section 8 only once per calendar year. If a Security Breach occurs, QVC Group Company may also exercise its option under this Section 8 even if QVC Group Company has already exercised its option in the same calendar year. Vendor shall provide a report of any audits or inspections at QVC Group Company's request. Vendor shall provide to QVC Group Company all information reasonably necessary to demonstrate Vendor's compliance with Vendor's obligations under this Addendum or Data Protection Law. Vendor shall also provide QVC Group Company with information reasonably necessary to enable QVC Group Company to conduct and document any data protection assessment required under Data Protection Law in relation to the Services.
  9. Vendor shall promptly investigate, and take all reasonable steps to limit and stop, each Security Breach. In addition to any notice required under the Agreement, Vendor shall notify QVC Group Company at privacynotice@qvc.com of a Security Breach promptly, but in any event within 48 hours, after Vendor first becomes aware of a Security Breach. Such notification shall include, at a minimum: (a) a description of the nature of the Security Breach, the number of people affected, and the types and numbers of Personal Data records affected; (b) identification of the name and contact details of the data protection officer or other person at Vendor from whom additional information can be obtained; (c) a description of the likely consequences of the Security Breach; and (d) a description of the measures taken or proposed to be taken to address the Security Breach. Following the initial notification described in this Section 9, Vendor shall promptly provide QVC Group Company with any further information regarding the Security Breach as requested by QVC Group Company or Data Regulators. Vendor shall cooperate with and assist QVC Group Company, its agents, and Data Regulators in connection with any investigation, response and other activities conducted with respect to a Security Breach. Vendor grants QVC Group Company the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data by or through Vendor or Vendor's agents.
  10. As part of the Services, Vendor shall assist QVC Group Company promptly (and, in any event, within any period of time required by Data Protection Law) in responding to, and fulfilling, exercises of Privacy Rights.
  11. QVC may update this DPA from time to time. Updates to comply with or reflect applicable Data Protection Law or the guidance of a competent Data Regulator, and administrative amendments that do not materially increase Vendor's obligations beyond what such law or guidance requires, take effect on publication at the applicable URL without prior notice. Any other change that materially increases Vendor's obligations (a "material change") requires no less than 15 days' prior notice (which may be written, email or other electronic notice). If Vendor objects in writing before the effective date, the parties shall negotiate the affected provision(s) in good faith; if no agreement is reached, QVC may proceed and Vendor's sole remedy shall be to terminate the affected Agreement(s) on written notice, without penalty. Absent timely written objection, Vendor is bound by the change.
  12. Pursuant to 28 CFR Part 202, as may be amended (the "Bulk Data Transfer Rule"), implementing Executive Order 14117 (issued February 28, 2024) governing access to United States persons' bulk sensitive personal data and government-related data, Vendor represents, warrants and covenants that: (a) Vendor shall not engage in any prohibited Covered Data Transaction, and shall engage in a restricted Covered Data Transaction only in compliance with the requirements of the Bulk Data Transfer Rule applicable to such transaction; (b) Vendor shall not grant, and shall ensure that no Covered Person or country of concern is granted, Access to Bulk U.S. Sensitive Personal Data or Government-related Data Processed under the Agreement, except to the extent expressly permitted under, and in strict compliance with, the Bulk Data Transfer Rule; (c) if Vendor meets the definition of a Covered Person, or engages, contracts with or is affiliated with a Covered Person in a manner relevant to the Services, Vendor shall notify QVC Group Company within 2 days of becoming aware and shall, at QVC Group Company's direction, cease the relevant Access to, use of, and other activities related to data obtained or accessed under the Agreement; (d) if Vendor determines that any Covered Person or country of concern has obtained Access to Bulk U.S. Sensitive Personal Data or Government-related Data in a manner not permitted by the Bulk Data Transfer Rule, Vendor shall immediately terminate such Access and notify QVC Group Company within 2 days of discovery; and (e) Vendor complies with all requirements of the Bulk Data Transfer Rule applicable to it. Each capitalized term in this Section that is not defined in this Addendum has the meaning set forth in the Bulk Data Transfer Rule.
  13. This Addendum is in addition to any obligations of Vendor under Vendor's other contracts with QVC Group Company or its Affiliates. If this Addendum conflicts with any provision of the Agreement with respect to Personal Data, then this Addendum shall control with respect to Personal Data. This Addendum shall continue to be in effect with respect to Personal Data for so long as Vendor or any agent on behalf of Vendor Processes Personal Data, notwithstanding the termination of the Agreement.

Previous Versions

You are now going to be redirected to