| (ccc) | Data Protection. Except as disclosed in the Registration Statement and the Prospectus, the Company and the Subsidiaries have at all times complied in all respects with (i) all applicable laws, statutes, rules, regulations, enacting instruments, codes of practice, guidance notes, recommendations, decisions and orders of any Governmental Authority (including, up to May 24, 2018, the EC Data Protection Directive 95/46/EC and, on and from May 25, 2018, the General Data Protection Regulation 2016/679, together with all applicable legislation implementing that Directive and Regulation, including, but not limited to the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG) and the German Telemedia Act (Telemediengesetz - TMG)) (collectively, the “Data Protection Laws”), (ii) all policies and procedures of the Company and the Subsidiaries, respectively, and (iii) all applicable contractual obligations, in each case, relating to privacy, data protection or the Company’s and the Subsidiaries’ collection, storage, use, transfer and any other processing of any information that alone, or in combination with other information collected, stored, used, transferred, otherwise processed or obtainable from a third party by the Company or the Subsidiaries, can be used to directly or indirectly identify a natural person (i.e. personal data as defined under Article 4 para. 1 GDPR). There is no investigation, disciplinary proceeding or enquiry by, or order, decree, decision or judgment of, any Governmental Authority outstanding against the Company or and any of the Subsidiaries in connection with the collection, processing, use and storage of personal data and the Company or any of the Subsidiaries have not received any notice from any Governmental Authority with respect to a violation and/or failure to comply with applicable Data Protection Laws or requiring the Company or any of the Subsidiaries to take or omit any action. Except as disclosed in the Registration Statement and the Prospectus, the Company and the Subsidiaries have at all times taken all measures necessary to ensure availability and resilience of processing systems and services and to protect the ongoing confidentiality, integrity and security all such information against accidental or unlawful destruction, loss, alteration, and unauthorized access, use, modification or disclosure. Except as disclosed in the Registration Statement and the Prospectus, the Company was not subject to any personal data breach, security breach or other compromise of or relating to any of the Company’s or its Subsidiaries’ information technology and computer systems, networks, hardware, software, data (including the data of their respective customers, employees, suppliers, vendors and any third party data maintained by or on behalf of them), equipment or technology (collectively, the “IT Systems and Data”) and the Company and its Subsidiaries have not been notified of any, and there is no event or condition that would reasonably be expected to result in, any security breach or other compromise to their IT Systems and Data. The Company and its Subsidiaries have at all times been and are on the Closing Date in compliance with all applicable laws or statutes and all judgments, orders, rules and regulations, enacting instruments, codes of practice, guidance notes, recommendations, decisions and orders of any court or arbitrator or Governmental Authorities or regulatory authority, internal policies and contractual obligations relating to the privacy and security of IT Systems and Data and to the protection of the ongoing confidentiality, integrity, availability and resilience of such IT Systems and Data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized use, access, misappropriation or |