Data Processing Agreement

Data Processing Agreement

Date of publication: Sep 7, 2026

Effective Date: Sep 2, 2026

This Data Processing Agreement, including its Annexes (collectively referred to as the “DPA”), governs the Processing of personal Data  between Toloka (the “Processor”) and Customer (the “Controller”), in connection with the Services provided by Toloka under the Toloka Terms of Use.

This DPA is supplemental to and forms an integral part of the Toloka Terms of Use (the “Agreement”) entered into by the parties.

The parties may update the terms of this DPA as required by law, due to changing circumstances, jurisprudence, or other developments. The parties will inform of such changes via email and/or other appropriate means. 

The parties agree as follows:

1. ROLES

When Processing Personal Data in accordance with the Customer’s instructions, the parties acknowledge and agree that the Customer acts as the Controller and Toloka as the Processor under the Agreement.

2. DEFINITIONS

2.1. “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. For the purposes of this definition, “control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

2.2. “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 et. seq., as may be amended from time to time, including the California Privacy Rights Act.‎

2.3. The terms, "Controller", "Member State", "Processor", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR. The terms “Business”, “Business Purpose”, “Consumer” and “Service Provider” shall have the same meaning as defined in the CCPA. For clarity, within this DPA “Controller” shall also mean “Business”, and “Processor” shall also mean “Service Provider”, to the extent the CCPA applies.

2.4. “Data Protection Laws” means all applicable and binding privacy and data protection laws and regulations,  including but not limited to the General Data Protection Regulation (GDPR), the UK GDPR, the Serbian Law on Protection of Personal Data 2018, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Act Concerning Personal Data Privacy and Online Monitoring (CTDPA), the Utah Consumer Privacy Act (UCPA), and any other laws applicable to the Processing of Personal Data under this DPA, as in effect at the time of Processor’s performance.

2.5. “Data Subject” means an identified or identifiable person to whom the Personal Data relates.

2.6. “GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

2.7. “GDPR” includes the retained EU law version of the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”), and “Data Protection Laws”, for the avoidance of doubt, includes the Law on Personal Data Protection of the Republic of Serbia (“Official Gazette of the Republic of Serbia,” No. 87/18), in each case to the extent applicable to the Processing of Personal Data hereunder.

2.8. “Personal Data” or “Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable natural person or Consumer, which is processed by Toloka on behalf of the Customer under this DPA and the Agreement.

2.9. “Services” means the services provided to the Customer(s) by Toloka in accordance with the Agreement.

2.10. “Standard Contractual Clauses'' means:

  • the standard contractual clauses set out in the Annex of European Commission Implementing Decision (EU) 2021/914 of 4 June 2021;

  • the Standard Contractual Clauses adopted by the Commissioner for Information of Public Importance Personal Data Protection of the Republic of Serbia under the Law on Personal Data Protection (“Official Gazette of the Republic of Serbia,” No. 87/18) (the “Serbian SCCs”); and

  • the UK’s international data transfer addendum to the European Commission’s standard contractual clauses for international data transfers of 21 March 2022.

2.11. “Sub-processor” means any third party that Processes Personal Data under the instruction or supervision of Toloka.

2.12. "UK GDPR" means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).

2.13. “Personal Data Breach” means the unauthorized destruction, loss, alteration, disclosure of or access to, Personal Data as it is transmitted, stored or otherwise Processed by the Processor and/or its Sub-Processors in connection with the provision of the Subscription Services. A Personal Data Breach does not include unsuccessful attempts or activities that do not compromise the security of Personal Data. Such activities include, but are not limited to, unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

3. CONTROLLER’S OBLIGATIONS

3.1.  Compliance with Laws. The Controller is responsible for ensuring compliance with all applicable Data Protection Laws concerning its Processing of Personal Data and the Instructions issued to the Processor. In particular, but not exclusively, the Controller acknowledges and agrees that it is solely responsible for: 

(i) the accuracy, quality, and legality of the data provided to Processor; 

(ii) complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including obtaining any necessary consents and authorizations; 

(iii) ensuring that it may legally transfer or provide access to the Personal Data that the Processor will process in accordance with the terms of the Agreement (including this DPA); 

(iv) ensuring that the instructions provided to the Processor comply with applicable laws, including Data Protection Laws. 

Furthermore, the Controller shall inform the Processor without undue delay if it is unable to comply with its responsibilities under this section or applicable Data Protection Laws.
3.2.  Security Measures. The Controller is responsible for ensuring the secure use of the Services offered by the Processor and must independently determine whether the data security measures provided adequately meet the obligations under applicable Data Protection Laws.

4. PROCESSOR’S OBLIGATIONS

4.1.  Compliance with Applicable Law and Instructions. The Processor shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data.

4.2.  Instructions. If the Processor believes that Controller’s Instructions infringe applicable Data Protection Laws (where applicable), it shall inform the Controller without delay. However, such notification shall not constitute a general obligation on the part of the Processor to monitor or interpret the laws applicable to the Controller, nor shall it constitute legal advice to the Controller.

4.3. Security. The Processor implements and maintains appropriate technical and organizational measures to protect Personal Data, as described in Annex II to this DPA ("Security Measures"). The Processor may modify or update the Security Measures at its own discretion, provided that such modification or update does not result in a material degradation of the protection offered by the Security Measures. 

4.4. Confidentiality. The Processor ensures that all employees authorized to process Personal Data on its behalf are subject to appropriate confidentiality obligations with respect to such Personal Data.

4.5. Personal Data Breaches. The Processor will notify the Controller without undue delay after becoming aware of any Personal Data Breach and will provide the necessary information relating to the breach as requested by the Controller. At Controller’s request, the Processor will promptly provide reasonable assistance as necessary to enable the Controller to notify the relevant Personal Data Breach to the competent authorities and/or affected Data Subjects, if required under Data Protection Laws.

4.6. Deletion or Return of Personal Data. At the direction of the Controller, the Processor will delete or return all Personal Data processed on behalf of the Controller upon termination or expiration of the Services provided under the Agreement, within timeframes specified by Controller. As an exception, the Processor may retain part of the Personal Data if required by applicable law. 

4.7.  Data Protection Impact Assessments and Supervisory Authorities. To the extent that the required information is reasonably available to the Processor, and Controller does not otherwise have access to the required information, the Processor will provide reasonable assistance with any data protection impact assessments and prior consultations with supervisory authorities as required by applicable Data Protection Laws.

5. DATA SUBJECT REQUESTS

5.1. Handling of Data Subject Requests. When a Data Subject Request or other communication regarding the Processing of Personal Data under the Agreement is received directly by the Processor, the Processor will promptly inform the Controller and ask the Data Subject to submit their request to the Controller. The Controller will be solely responsible for addressing and responding to any such Data Subject Requests.

6. SUB-PROCESSORS

6.1. Engagement. The Controller authorizes Processor to engage Sub-Processors. When engaging Sub-Processors, the Processor will impose data protection terms on these Sub-Processors that provide an equivalent level of protection for Personal Data as those outlined in this DPA, to the extent applicable to the nature of the services provided by such Sub-Processors. The Processor remains responsible for the compliance of any Sub-Processor with the obligations under this DPA.

6.2. List. The Controller hereby agrees that Processor may engage Sub-Processors to Process Personal Data on its behalf. A list of the current Sub-Processor is included as Annex IV of this DPA.

6.3. Changes. If the Processor adds or changes one or more Sub-Processor(s), it will notify the Controller at least 10 days prior to any such change and provide the Controller the opportunity to object to the engagement of the new Sub-Processors on reasonable grounds relating to the protection of Personal Data within 10 days. If the Controller notifies the Processor of such an objection, both parties will discuss the concerns in good faith, aiming to reach a reasonable solution. If no such solution can be reached, the Processor will either not engage the intended new Sub-Processor or allow the Controller to terminate the Service in accordance with the termination provisions of the Service Agreement, without prejudice to any fees incurred by the Controller prior to suspension or termination, but without liability to either party. 

6.4. Engagement of Users. The Controller may restrict the region of Users for the performance of its tasks using the tools available on the Toloka Platform.

6.5. Standard Contractual Clauses. The Standard Contractual Clauses are incorporated in accordance with Commission Implementing Decision (EU) 2021/914 of 4 June 2021. The Controller and Processor agree that the following options shall be used in the SCCs concluded with any Sub-Processors:

        i. in Clause 11(a) Option shall apply;

        ii. in Clause 17 Option 2 shall apply. 

6.6. For Personal Data Subject to the GDPR:

        i. Processor is the "data exporter" and Sub-Processor is the "data importer";

        ii. the Module Three terms apply.

6.7. For Personal Data Subject to the UK GDPR:

The Standard Contractual Clauses will apply in accordance with the following modifications: 

        i. the Standard Contractual Clauses will be modified and interpreted in accordance with the UK Addendum, which will be incorporated by reference and form an integral part of the Agreement.

6.8. For Personal Data Subject transferred from Serbia:

The Standard Contractual Clauses issued by the Serbian data protection authority will apply.

6.9. Dispute Resolution for SCC. Any dispute arising from SCC shall be resolved by the courts:

  • For the EU: of the Netherlands;

  • For Serbia: of Serbia;

  • For the UK: Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts.

6.10. Standard Contractual Clauses: Transfers to Processor. Where Customer’s transfer of Personal Data to Processor under the Agreement and this DPA is a restricted transfer for purposes of Article 46 GDPR, Article 46 UK GDPR, the Parties incorporate by reference, and are deemed to have executed without any further signature being required, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the “Controller-to-Processor SCCs”), completed as follows: (i) Module Two (Controller to Processor) applies, with Customer as “data exporter” and Processor as “data importer”; (ii) the optional docking clause (Clause 7) does not apply; (iii) in Clause 9, Option 2 (general written authorization) applies, with the notice period set out above; (iv) in Clause 11(a), the optional language does not apply; (v) in Clause 17, the Controller-to-Processor SCCs are governed by the law of the Netherlands; (vi) in Clause 18(b), disputes are resolved before the courts of the Netherlands; and (vii) Annex I.A, Annex I.B, and Annex II to the Controller-to-Processor SCCs are populated by Annex I, Annex II, and Annex III to this DPA, respectively. For transfers subject to the UK GDPR, the Controller-to-Processor SCCs apply as modified by the UK Addendum.    For transfers subject to the Serbian Law on Personal Data Protection, the Controller-to-Processor SCCs apply as modified by the Serbian SCCs referenced in Section 6.8.

6.11. Serbian Standard Contractual Clauses. Where Personal Data is transferred from the Republic of Serbia (including by or through Toloka d.o.o. Beograd, listed as a Sub-Processor in Annex IV) to a country not recognized by the Government of the Republic of Serbia as ensuring an adequate level of data protection, the Parties incorporate by reference, and are deemed to have executed without any further signature being required, the Standard Contractual Clauses adopted by the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia under the Law on Personal Data Protection (“Official Gazette of the Republic of Serbia,” No. 87/18) (the “Serbian SCCs”). The subject matter, nature, and categories of data and data subjects for purposes of the Serbian SCCs are as set out in Annex II; the technical and organizational measures are as set out in Annex III; and the list of approved sub-processors is as set out in Annex IV. The Serbian SCCs’ sub-processor authorization terms align with, and are provided for in, Section 6.3 of this DPA (general written authorization, 10 days’ notice), and the data-breach notification deadline referenced in the Serbian SCCs aligns with Section 4.6 of this DPA.

7. CONTROLS FOR THE PROTECTION OF PERSONAL DATA

7.1.  Records of Processing. The Processor will duly maintain records of its Processing activities performed on behalf of the Controller.

7.2. Audits and Inspections. Upon prior written request and subject to confidentiality undertakings by the Controller, the Processor shall make available to the Controller (or the Controller’s independent third-party auditor, subject to their confidentiality undertakings) information reasonably necessary to demonstrate compliance with this DPA. The Processor shall also allow and contribute to audits, including inspections, conducted by them. In the event of an audit or inspection, the Controller shall take reasonable steps to avoid causing, or if unavoidable, to minimize, any disruption to the Processor’s operations while conducting such audit or inspection.

7.3. Reports. Upon written request by the Controller and limitedly to once a year, unless substantial elements arise indicating the non-compliance by the Processor with the requirements of applicable law and this DPA, at the Controller’s request, Processor will provide the Controller with a report demonstrating the Processor's compliance with its obligations under this DPA and applicable law.

8. GENERAL PROVISIONS

8.1. Severability. If any provision of this DPA is found to be invalid or unenforceable, the validity and enforceability of the remaining provisions of this DPA shall not be affected.

8.2. Limitation of Liability. The liability of each Party and their respective Affiliates, in the aggregate, arising out of or in connection with this DPA (including any other DPAs between the parties) and the Standard Contractual Clauses, where applicable, shall be subject to the limitations and exclusions of liability set forth in the Agreement.

8.3.  Additional Provisions for California Personal Information. This Section applies only with respect to California Personal Information. When processing California Personal Information in accordance with Customer Instructions, the Parties acknowledge and agree that Controller is a Business, and Processor is a Service Provider, for purposes of the CCPA. Processor certifies that it will Process California Personal Information as a Service Provider strictly for the purpose of performing the Services under the Agreement (the “Business Purpose”) or as otherwise permitted by the CCPA, and further certifies that it (a) will not Sell or Share California Personal Information; (b) will not Process California Personal Information outside the direct business relationship between the Parties, unless required by applicable law; and (c) will not combine California Personal Information with personal information Processor collects or receives from another source, other than as permitted by the CCPA. Processor will comply with its obligations as a Service Provider under the CCPA and will notify Controller if it determines it can no longer meet those obligations. Controller may take reasonable and appropriate steps to ensure Processor uses California Personal Information consistently with Controller’s obligations under the CCPA, and to stop and remediate any unauthorized use. The Parties acknowledge that Customer’s disclosure of California Personal Information to Processor does not form part of any monetary or other valuable consideration exchanged between the Parties.

ANNEX I – LIST OF THE PARTIES

List of parties

List of parties

Controller (Customer):

Legal entity, or sole trader, or individual who accepted Toloka Terms of Use or signed the Master Service Agreement for the provision of Toloka Services (each referred as "Agreement").

Processor (Toloka):

Toloka AI B.V. 
Claude Debussylaan 7, 1082MC Amsterdam, the Netherlands. 

Contact person’s name, position and contact details: privacy@toloka.ai.

Controller (Customer):

Legal entity, or sole trader, or individual who accepted Toloka Terms of Use or signed the Master Service Agreement for the provision of Toloka Services (each referred as "Agreement").

Processor (Toloka):

Toloka AI B.V. 
Claude Debussylaan 7, 1082MC Amsterdam, the Netherlands. 

Contact person’s name, position and contact details: privacy@toloka.ai.

ANNEX II – DESCRIPTION OF THE PROCESSING

Categories of data subjects whose personal data is processed

Natural persons whose personal data are included in the Customer’s dataset and/or are necessary for performing Tasks.

Categories of personal data processed

Any personal data included in the Customer’s dataset and/or required for performing Tasks.

Sensitive data processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures

Nature of the processing
As instructed by the Controller in the performance of Services under the Terms of Use or Master Service Agreement.

Purpose(s) for which the personal data is processed on behalf of the controller

1. Providing the Services to Controller;

2. Performing the Agreement and this DPA;

3. Acting upon the Controller’s written instructions in accordance with the Agreement;

4. Complying with applicable laws and regulations.

Duration of the processing
For the duration of the performance of Services.

Categories of data subjects whose personal data is processed

Natural persons whose personal data are included in the Customer’s dataset and/or are necessary for performing Tasks.

Categories of personal data processed

Any personal data included in the Customer’s dataset and/or required for performing Tasks.

Sensitive data processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures

Nature of the processing
As instructed by the Controller in the performance of Services under the Terms of Use or Master Service Agreement.

Purpose(s) for which the personal data is processed on behalf of the controller

1. Providing the Services to Controller;

2. Performing the Agreement and this DPA;

3. Acting upon the Controller’s written instructions in accordance with the Agreement;

4. Complying with applicable laws and regulations.

Duration of the processing
For the duration of the performance of Services.

ANNEX III – SECURITY MEASURES

Processor maintains an information security management system and personal information management system implemented in accordance with and audited against ISO 27001 and 27701 respectively.

Processor maintains an information security management system and personal information management system implemented in accordance with and audited against ISO 27001 and 27701 respectively.

ANNEX IV – SUB-PROCESSORS

List of sub-processors
The Controller has authorised the use of the following sub-processors:

Name: Microsoft Azure (Microsoft Corporation)

Address: Redmond, One Microsoft Way, United States

Hosting location: East Europe 

Contact person's name, position and contact details: Online web-form

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Cloud storage and processing


Name: Databricks, Inc.

Address: 160 Spear Street, 13th Floor San Francisco, CA 94105

Hosting location: East Europe 

Contact person's name, position and contact details: Scott Starbird, General Counsel, Public Affairs and Strategic Partnerships, dpa@databricks.com

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Data transformation, analytics, batch processing


Name: Google (Google Workspace and Gemini)

Address: Google LLC

Hosting location: EU

Contact person's name, position and contact details: Online web-form

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Exchanging personal data in inputs and outputs and other documentation necessary for providing Toloka Services (e.g., instructions)


Name:  Zendesk, Inc.

Address: 181 Fremont Street, 17th Floor, San Francisco, CA 94105, U.S.A.

Contact person's name, position and contact details:  privacy@zendesk.com

Description of the processing:  customer support


OpenAI Ireland Limited

Address: 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland

Hosting location: EEA or Switzerland 

Contact person's name, position and contact details:
privacy@openai.com


Description of the processing:  General purpose AI tool


Name: Toloka affiliates 

Addresses: 

Claude Debussylaan 7, 1082MC Amsterdam

Starine Novaka 23, Sprat 4, Belgrade (Palilula). 11000, Belgrade, Serbia

1604 Philadelphia Pike PMB 117 Wilmington, DE 19809

Processing location: East Europe, Serbia, United States

Contact person's name, position and contact details: privacy@toloka.ai

Description of the processing: Support and Maintenance of Toloka Services

List of sub-processors
The Controller has authorised the use of the following sub-processors:

Name: Microsoft Azure (Microsoft Corporation)

Address: Redmond, One Microsoft Way, United States

Hosting location: East Europe 

Contact person's name, position and contact details: Online web-form

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Cloud storage and processing


Name: Databricks, Inc.

Address: 160 Spear Street, 13th Floor San Francisco, CA 94105

Hosting location: East Europe 

Contact person's name, position and contact details: Scott Starbird, General Counsel, Public Affairs and Strategic Partnerships, dpa@databricks.com

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Data transformation, analytics, batch processing


Name: Google (Google Workspace and Gemini)

Address: Google LLC

Hosting location: EU

Contact person's name, position and contact details: Online web-form

Description of the processing (including a clear delimitation of responsibilities in case several sub-processors are authorised): Exchanging personal data in inputs and outputs and other documentation necessary for providing Toloka Services (e.g., instructions)


Name:  Zendesk, Inc.

Address: 181 Fremont Street, 17th Floor, San Francisco, CA 94105, U.S.A.

Contact person's name, position and contact details:  privacy@zendesk.com

Description of the processing:  customer support


OpenAI Ireland Limited

Address: 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland

Hosting location: EEA or Switzerland 

Contact person's name, position and contact details:
privacy@openai.com


Description of the processing:  General purpose AI tool


Name: Toloka affiliates 

Addresses: 

Claude Debussylaan 7, 1082MC Amsterdam

Starine Novaka 23, Sprat 4, Belgrade (Palilula). 11000, Belgrade, Serbia

1604 Philadelphia Pike PMB 117 Wilmington, DE 19809

Processing location: East Europe, Serbia, United States

Contact person's name, position and contact details: privacy@toloka.ai

Description of the processing: Support and Maintenance of Toloka Services

Download previous versions of the document: