Skip to main content

Data Processing Addendum

Last Updated: September 11, 2025

This Data Processing Addendum, including its exhibits (collectively, the “DPA”), is incorporated into each agreement between Tanium and its customers and partners for the provision of Tanium Services (the “Agreement”). Unless specifically defined in this DPA, capitalized terms used in this DPA will have the meaning set forth in the Agreement.

1. Definitions.

a) “CCPA” means the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act, and its implementing regulations.

b) “Customer Personal Data” means any Personal Data that Tanium Processes as Data Processor in the course of providing, and through Customer’s use of, the Tanium Services.

c) “Customer” means the customer or partner that is a party to the Agreement.

d) “Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including, where applicable, European Data Protection Laws and the CCPA.

e) “Data Controller ” means an entity that determines the purposes and means of the Processing of Personal Data.

f) “Data Processor ” means an entity that Processes Personal Data on behalf of a Data Controller, including, as applicable, any “service provider” as that term is defined by the CCPA.

g) “European Data Protection Laws” means: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation) (the “EU GDPR”); (ii) the EU e-Privacy Directive (Directive 2002/58/EC); (iii) the EU GDPR as saved into United Kingdom’s law by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (the “UK GDPR”); (iv) the Swiss Federal Data Protection Act of 19 June 1992 (the “Swiss Data Protection Act”); and (v) any and all applicable national data protection laws made under, pursuant to or that apply in conjunction with any of (i) to (iv); in each case as may be amended or superseded from time to time.

h) “Personal Data” means any information relating to an identified or identifiable natural person.

i) “Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, and “Process”, “Processes”, and “Processed” will be interpreted accordingly.

j) “Restricted Transfer” means: (i) where the EU GDPR applies, a transfer of Personal Data from the European Economic Area to a country outside of the European Economic Area which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to any other country which is not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; and (iii) where the Swiss Data Protection Act applies, a transfer of Personal Data from Switzerland to any other country that has not been determined to provide adequate data protection by the Federal Data Protection and Information Commissioner or other competent Swiss authority.

k) “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

l) “Standard Contractual Clauses” means the Module Two (controller to processor) contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council in the form set out in Section 6.1 of this DPA.

m) “Sub-processor” means any Data Processor engaged by Tanium to assist in fulfilling its obligations with respect to providing the Tanium Services pursuant to the Agreement. Sub-processors may include third parties or Tanium’s Affiliates.

n) “Tanium” means the Tanium entities that are a party to the Agreement.

o) “Tanium Services” means software provided as a Tanium hosted service as well any Support Services for Tanium software products.

p) “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner’s Office on March 21, 2022.

2. Scope of this DPA. This DPA applies where and only to the extent that Tanium Processes Customer Personal Data.

3. Relationship of the Parties. As between Tanium and Customer, Customer is the Data Controller of Customer Personal Data. Tanium will Process Customer Personal Data only for the purposes described in this DPA and the Agreement and only in accordance with Customer’s documented lawful instructions. The parties agree that this DPA and the Agreement set out the Customer’s complete and final instructions to Tanium in relation to the Processing of Customer Personal Data and any Processing outside the scope of these instructions will require prior written consent of Customer.

4. Customer Processing of Personal Data. Customer agrees that (i) it will comply with its obligations under Data Protection Laws in respect of its Processing of Personal Data and any Processing instructions it issues to Tanium; and (ii) it has provided notice and obtained (or will obtain) all consents and rights necessary under Data Protection Laws for Tanium to Process Customer Personal Data and provide the Tanium Services pursuant to the Agreement and this DPA.

5. Details of Processing. The details of the Processing of Customer Personal Data are set out in Exhibit 1 to this DPA.

6. Data Transfers.

6.1. Where the transfer of Customer Personal Data is a Restricted Transfer made from the European Economic Area, the Standard Contractual Clauses are incorporated into this DPA and apply to the transfer as follows:

b) Clause 9 (Use of subprocessors) – Option 2 (General written authorization) will apply, and the time period is as specified in Section 9 of this DPA.

d) Clause 17 (Governing Law) – Option 1 will apply and the governing law will be: (a) the laws of the country specified in the Agreement if the Agreement is governed by the laws of an EU member state; or (b) the laws of the Netherlands if the Agreement is governed by the laws of a non-EU member state.

f) The details of Annexes I and II of the Standard Contractual Clauses are set out in Exhibit 1 to this DPA.

6.2. Where the transfer of Customer Personal Data is a Restricted Transfer made from the United Kingdom, the UK Addendum is incorporated into this DPA and applies to the transfer. Tables 1, 2, and 3 of the UK Addendum are completed with the information in Section 6.1 above and Exhibit 1 to this DPA, and Table 4 in Part 1 of the UK Addendum is completed by selecting “Importer”.

6.3. Where the transfer of Customer Personal Data is a Restricted Transfer made from Switzerland, the Standard Contractual Clauses are incorporated into this DPA and apply to the transfer as modified in Section 6.1 above, except that:

b) References to specific articles of “Regulation (EU) 2016/679” are replaced with the equivalent article or section of the Swiss Data Protection Act.

d) References to the “competent supervisory authority” and “competent courts” are replaced with the “Swiss Federal Data Protection Information Commissioner” and “applicable courts of Switzerland”.

f) In Clause 17, the Standard Contractual Clauses are governed by the laws of Switzerland.

a) Customer will exercise its audit rights under the Standard Contractual Clauses as set out in Section 14 of this DPA.

b) Before commencing a Restricted Transfer to a Sub-processor, Tanium will enter into an agreement with a Sub-processor containing Standard Contractual Clauses Module Three (processor to processor), or alternatively, Tanium will determine that the Sub-processor will have appropriate safeguards pursuant to Articles 46 or 47 of the EU GDPR and/or UK GDPR (as applicable) with respect to the Sub-processor’s processing.

c) In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses will prevail.

7. Confidentiality of Processing. Tanium will ensure that any person it authorizes to Process Customer Personal Data will protect Customer Personal Data in accordance with Tanium’s confidentiality obligations under the Agreement.

8. Security.

8.1. Tanium Responsibilities. Tanium will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in the security measures found at https://help.tanium.com/bundle/ug_cloud_cloud/page/cloud/trust_compliance.html, to protect Customer Personal Data from a Security Incident. Tanium may review and update the security measures from time to time, provided that any such updates will not materially diminish the overall privacy or security of Customer Personal Data.

8.2. Customer Responsibilities. Notwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Tanium Services, including securing its account authentication credentials, protecting the security of Customer Personal Data when in transit to and from the Tanium Services and taking any appropriate steps to securely encrypt or backup any Customer Personal Data provided in connection with the Tanium Services.

9. Sub-processors. Customer provides a general authorization for Tanium to engage third-party Sub-processors to Process Customer Personal Data provided that: (i) Tanium maintains an up-to-date list of its Sub-processors at https://www.tanium.com/subprocessors (“Sub-processor List”); (ii) Tanium imposes data protection terms on any Sub-processor it appoints that require it to protect the Customer Personal Data to the standard required by applicable Data Protection Laws; and (iii) Tanium remains liable for any breach of this Agreement that is caused by an act, error or omission of its Sub-processors. The Sub-processor List contains a mechanism to subscribe to notifications of new Sub-processors, and if Customer subscribes, Tanium will provide prior notice to Customer of any proposed new Sub-processor by updating such list before the new Sub-Processor is to commence Processing any Customer Personal Data. Customer may object to Tanium’s appointment or replacement of a Sub-processor within ten (10) days of such notice being provided as shown by the “Last updated” date on the Sub-processor List, provided such objection is based on reasonable grounds relating to the protection of Customer Personal Data and is communicated to Tanium in writing in the manner provided by the Agreement. In such circumstances, either Tanium will not appoint that Sub-processor or permit it to Process Customer Personal Data. If such measures are not possible, Customer may suspend or terminate the Agreement upon thirty (30) days’ prior written notice. Any such termination will be deemed as a non-default termination and without prejudice to Customer’s obligation to pay any fees due under the Agreement up to the date such termination takes effect. Neither party will have any further liability to the other following any such termination.

10. Cooperation and Data Subjects’ Rights. The Tanium Services provide Customer with controls that Customer may use to retrieve, correct, delete or restrict Customer Personal Data. Customer may use these controls to assist it with its obligations under applicable Data Protection Laws, including its obligations relating to responding to requests from data subjects or applicable data protection authorities. To the extent that Customer is unable to independently access the relevant Customer Personal Data within the Tanium Services, Tanium will provide commercially reasonable and timely assistance to Customer to enable Customer to respond to: (i) any request from a data subject to exercise any of its rights under applicable Data Protection Laws (including its rights of access, correction, objection, erasure and data portability, as applicable); and (ii) any other correspondence, inquiry or complaint received from a data subject, regulator or other third-party in connection with the Processing of Customer Personal Data. If any such request, correspondence, inquiry or complaint is made directly to Tanium, Tanium will promptly inform Customer providing full details of the same.

11. Data Protection Impact Assessment. To the extent Tanium is required under European Data Protection Laws, Tanium will provide commercially reasonable requested information regarding the Tanium Services (such information being Tanium’s Confidential Information) to enable the Customer to carry out data protection impact assessments or prior consultations with data protection authorities as required by European Data Protection Laws.

12. Security Incidents. If Tanium becomes aware of a Security Incident, Tanium will notify Customer via email without undue delay and will provide reasonable information and cooperation to Customer so that Customer can fulfil any data breach reporting obligations it may have under, and in accordance with the timescales required by, applicable Data Protection Laws. Tanium will further take such reasonably necessary measures and actions to remedy or mitigate the effects of the Security Incident and will keep Customer apprised when possible of all material developments in connection with the Security Incident.

13. Deletion or Return of Data. Upon termination or expiry of the Agreement, Tanium will, at Customer’s election, delete or return to Customer all Customer Personal Data in its possession or control that Tanium Processes as a Data Processor. If Customer does not notify Tanium of its election within thirty (30) days following termination or expiration of the Agreement, then Tanium will automatically delete all such Customer Personal Data. If Tanium has Customer Personal Data archived on back-up systems, then Tanium will securely isolate and protect the Customer Personal Data from any further Processing until such time the back-up systems delete such data. Tanium will not delete Customer Personal Data to the extent required by law to retain Customer Personal Data.

14. Audit. Customer acknowledges that Tanium is regularly audited against applicable standards by independent third-party auditors. Upon request, no more than once in any 12-month period, except where required by a competent supervisory authority, and at no additional cost to Customer, Tanium will supply a summary copy of its audit report(s) to Customer, which will be subject to the confidentiality provisions of the Agreement. Upon request and subject to the confidentiality provisions of the Agreement, Customer may request responses to an information security and audit questionnaire to confirm Tanium’s compliance with the provisions of this DPA, provided that Customer will not exercise this right more than once per year, except where required by a competent supervisory authority. Tanium and Customer will mutually agree in advance on the scope of the Customer request and the start and end dates.

15. Miscellaneous.

15.1. As between the parties, each party’s liability arising out of or related to this DPA is subject to the limitation of liability provisions of the Agreement. In no event will either party limit its liability with respect to any data subject or data protection authority under the Standard Contractual Clauses.

15.2. In the event of any conflict or inconsistency between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA will prevail.

15.3. This DPA will be governed by, and construed in accordance with, the choice of law provision governing the Agreement, except where otherwise required by applicable Data Protection Laws.

15.4. Where the Standard Contractual Clauses are applicable, Tanium Inc. is the “data importer” under the Standard Contractual Clauses. Where the Tanium entity that is a party to this DPA is not Tanium Inc., that Tanium entity is carrying out the obligations of the “data importer” on behalf of Tanium Inc.

15.5. Notwithstanding any limitations on modification or amendment in the Agreement, the parties agree that Tanium may periodically update this DPA in order to maintain compliance with changes in Data Protection Laws. In the event of such a change, Tanium will post an updated version to www.tanium.com/dpa. No such update will materially diminish the privacy or security of Customer Personal Data.

Exhibit 1

ANNEX I

A. LIST OF PARTIES

Data exporter(s):

1.

Name:

Customer (as identified in the Agreement)

Address:

Please see the Agreement.

Contact person’s name, position and contact details:

Please see the Agreement.

Activities relevant to the data transferred under these Clauses:

Customer’s license of the Tanium Services pursuant to the Agreement

Signature and date:

These Standard Contractual Clauses will be deemed executed by the Customer upon execution or acceptance of the Agreement.

Role (controller/processor):

Controller

Data importer(s):

1.

Name:

Tanium Inc.

Address:

2100 Powell Street, Suite 1600, Emeryville, CA 94608

Contact person’s name, position and contact details:

Attn: Legal Department – [email protected]

Activities relevant to the data transferred under these Clauses:

Provision of the Tanium Services

Signature and date:

These Standard Contractual Clauses will be deemed executed by Tanium upon execution or acceptance of the Agreement.

Role (controller/processor):

Processor

В. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred

The categories of Personal Data that may be Processed in connection with the Tanium Services are determined and controlled by Customer in its sole discretion and may include but are not limited to Personal Data relating to the following categories of data subjects: Customer’s employees, agents, advisors, and freelancers, and Customer’s prospects, vendors, customers, and business partners who are natural persons.

Categories of personal data transferred The categories of Personal Data that may be Processed in connection with the Tanium Services are determined and controlled by Customer in its sole discretion and may include but are not limited to: identification and contact data (name, address, title, contact details, username, machine names, IP addresses) and employment details (employer, job title, geographic location, area of responsibility). Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures Not applicable The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis) Continuous throughout the duration of the Customer’s use of the Tanium Services. Subject Matter and Duration of processing The subject matter of the processing is Customer Personal Data. The duration of the Processing under this DPA and the Agreement is until the termination of the Agreement in accordance with its terms. Nature of the processing Tanium provides the Tanium Services to Customer, as described in the Agreement. Purpose(s) of the data transfer and further processing For Tanium to provide the Tanium Services to Customer and to perform Tanium’s obligations under the Agreement or as otherwise agreed by the parties in writing. The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period Throughout the duration of the Agreement. Upon termination or expiry of the Agreement, Section 13 of this DPA will apply. For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing For transfers to sub-processors, the subject matter is Customer Personal Data, the nature is for the provision of the Tanium Services, and the duration is during the term of the Agreement.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13The competent supervisory authority will be determined in accordance with Clause 13 of the Standard Contractual Clauses.

ANNEX II - TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organizational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural personsPlease see Section 8.1 of this DPA. In addition, Customer can use self-serve functionality within the Tanium Services to access, correct and/or delete data subjects’ personal data. Tanium will, upon request, provide reasonable assistance to Customer to fulfil any request from a data subject to exercise their rights, in accordance with Section 10 of this DPA.
For transfers to (sub-) processors, also describe the specific technical and organizational measures to be taken by the (sub-) processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporterPlease see Section 9 of this DPA.
Data Processing Addendum