The objective of the Policy is to define the principles, requirements and responsibilities governing the novation of Virgin Atlantic (VS) New Distribution Capability (NDC) bookings. The Policy supports the effective distribution of VS products and services by ensuring that any transfer of booking ownership or servicing responsibility is undertaken in a consistent, controlled and transparent manner, while safeguarding customer experience, commercial integrity and compliance with VS distribution standards.

This Policy explains how Virgin Atlantic manages access to its NDC distribution environment where an aggregator, technology provider or other access party provides connectivity, processing or routing services on behalf of travel agents or other authorised partners.

The Policy sets out:

  • ownership and control of bookings, Orders, PNRs, Virgin systems and Virgin Data;
  • data protection and security requirements;
  • rules relating to novation, assignment, subcontracting and change of control;
  • continuity expectations in the event of service disruption, distress or insolvency;
  • exit and offboarding requirements; and
  • operational safeguards during the transition to Offers & Orders.

This Policy applies to all Access Parties operating under the Terms for the Provision of Travel Platform Services (Technical User Agreement — TUA), together with any applicable Data Processing Agreement (DPA), and to all Agents operating under the Agency Sales Agreement (ASA) and related distribution, booking and ticketing policies.

Virgin Atlantic may update this Policy from time to time to reflect operational, regulatory, security or industry requirements.

For the purposes of this Policy:

Access Party means an aggregator, technology provider, API intermediary or other entity authorised to access Virgin Atlantic NDC content or systems.

Agent means a travel agency or other authorised seller operating under the ASA and applicable IATA/BSP arrangements.

Controller has the meaning given under applicable data protection law.

Processor has the meaning given under applicable data protection law.

Virgin Data means any booking, passenger, operational, servicing, transaction or related data provided by, generated through or connected to Virgin Atlantic systems.

Virgin Materials means Virgin Atlantic systems, APIs, content, documentation, technical specifications, branding and related intellectual property.

Novation or assignment means any transfer of rights or obligations relating to Virgin Atlantic access, connectivity or services from one legal entity to another.

Change of control includes any merger, acquisition, sale of business, restructuring or material ownership change affecting an Access Party.

Virgin Atlantic’s distribution model is based on the following principles:

  • Virgin Atlantic remains the system of record for Orders and PNRs;
  • Access Parties provide technical routing and processing services only;
  • Agents remain responsible for selling and servicing obligations unless Virgin Atlantic expressly agrees otherwise;
  • customer, booking and data integrity must be maintained at all times;
  • Virgin Data must be protected in accordance with applicable data protection laws; and
  • operational resilience and continuity must be maintained across all distribution channels.

Virgin Atlantic acts as Controller of passenger personal data and determines the purposes and means of processing personal data for retailing, booking fulfilment, servicing, customer communications, fraud prevention, operational management and regulatory compliance.

Virgin Atlantic remains the authoritative source and system of record for Orders, bookings and servicing information.

Access Parties act as Processors and may process Virgin Data only:

  • on Virgin Atlantic’s documented instructions;
  • for the purposes authorised under the TUA and applicable DPA;
  • to provide approved technical services; and
  • in accordance with this Policy.

Access Parties may route, transmit and technically process shopping, booking and servicing messages. Access Parties must not:

  • act as seller of record unless separately authorised in writing;
  • act as merchant of record or settlement intermediary;
  • hold themselves out as Virgin Atlantic;
  • create or maintain authoritative booking or servicing records outside Virgin Atlantic systems; or
  • exercise discretionary servicing authority unless expressly approved by Virgin Atlantic.

Agents remain responsible for seller obligations, servicing responsibilities and settlement obligations under the ASA and applicable IATA/BSP arrangements unless Virgin Atlantic expressly agrees to assume limited responsibilities for customer protection or regulatory compliance purposes.

Virgin Atlantic owns all rights, title and interest in:

  • Virgin Materials;
  • Virgin Data;
  • Orders and PNR records maintained within Virgin Atlantic systems; and
  • all related operational and servicing information.

Access Parties receive a limited, revocable, non-exclusive and non-transferable licence to use Virgin Materials solely for the purposes authorised under the TUA and related agreements.

Virgin Atlantic must be able to reconstruct, service and manage bookings directly from Virgin Atlantic-controlled systems without dependency on any proprietary Access Party state.

Access Parties must not maintain any authoritative servicing or lifecycle state outside Virgin Atlantic systems.

Access Parties must not alter, override or interfere with Virgin Atlantic pricing, offer logic, servicing logic, order management or booking integrity controls.

Where caching or temporary storage is permitted for operational reasons, such activity must not create conflicting or authoritative records.

The relationship between Virgin Atlantic and each Access Party operates on a Controller-to-Processor basis.

All processing of Virgin Data must comply with:

  • applicable data protection laws, including UK GDPR and other applicable privacy legislation;
  • the applicable DPA; and
  • Virgin Atlantic’s documented instructions.

Access Parties may process only the minimum data necessary to perform the approved services.

Virgin Data must not be used for:

  • resale;
  • benchmarking;
  • analytics unrelated to the approved services;
  • AI or model training;
  • cross-carrier intelligence; or
  • any other unauthorised commercial purpose,

unless expressly authorised by Virgin Atlantic in writing.

Access Parties must implement appropriate technical and organisational security measures, including:

  • encryption;
  • access controls;
  • monitoring and logging;
  • vulnerability management;
  • incident detection and response;
  • segregation of Virgin Data from unrelated datasets; and
  • security governance measures aligned to ISO/IEC 27001 or equivalent recognised standards.

Cross-border transfers of Virgin Data may occur only where lawful transfer mechanisms and appropriate safeguards are in place.

Virgin Atlantic remains the primary contact for passenger data subject requests.

Access Parties must reasonably assist Virgin Atlantic with requests relating to access, rectification, erasure, portability, objection or other applicable privacy rights within agreed service levels.

Access Parties must not appoint subprocessors or subcontractors that process Virgin Data without Virgin Atlantic’s prior written approval or inclusion within a pre-approved subprocessor list.

All approved subprocessors must be subject to written agreements imposing equivalent:

  • data protection obligations;
  • confidentiality obligations;
  • security requirements; and
  • operational controls.

The Access Party remains responsible for the acts and omissions of its subprocessors.

Access to Virgin Atlantic NDC content and systems is personal to the approved Access Party and does not automatically transfer as part of:

  • a merger;
  • acquisition;
  • outsourcing arrangement;
  • insolvency process;
  • sale of assets;
  • restructuring; or
  • platform migration.

Access Parties may not novate, assign, transfer or otherwise dispose of any rights or obligations under the TUA, DPA or related agreements without Virgin Atlantic’s prior written consent.

Virgin Atlantic may require:

  • due diligence reviews;
  • operational and technical assessments;
  • data protection and security reviews;
  • new contractual documentation;
  • migration testing; or
  • re-onboarding activities,

before approving any proposed transfer.

Any material change of control affecting an Access Party must be notified to Virgin Atlantic promptly.

Virgin Atlantic may review whether the proposed change creates:

  • operational resilience risks;
  • customer or booking continuity risks;
  • confidentiality concerns;
  • competition or conflict-of-interest concerns;
  • sanctions or compliance exposure; or
  • data protection or security risks.

Following review, Virgin Atlantic may:

  • approve continued access;
  • approve access subject to conditions;
  • require operational or technical separation measures;
  • restrict certain access rights; or
  • suspend or terminate access where risks cannot reasonably be mitigated.

Virgin Atlantic will exercise these rights reasonably and proportionately, taking into account customer impact, operational continuity, legal obligations and security considerations.

Access Parties must maintain appropriate operational resilience, business continuity and disaster recovery arrangements to support continued servicing and customer protection.

Virgin Atlantic maintains contingency measures, including alternate routing and direct-connect pathways, to support continuity in the event of disruption.

Where an Access Party experiences:

  • sustained outages;
  • significant degradation of service;
  • operational distress;
  • insolvency indicators;
  • cyber security incidents; or
  • inability to support required operational changes,

Virgin Atlantic may take reasonable operational measures to protect customers, bookings, servicing continuity and data integrity.

Such measures may include:

  • temporary servicing-only access;
  • credential rotation or revocation;
  • migration to alternate routing options;
  • temporary access restrictions; or
  • direct servicing support arrangements.

Virgin Atlantic may communicate operational guidance or continuity instructions directly to Agents and authorised partners where reasonably necessary to:

  • protect customers;
  • maintain operational continuity;
  • preserve booking integrity; or
  • support regulatory or settlement obligations.

Access Parties must notify Virgin Atlantic without undue delay, and in any event within 24 hours of becoming aware of:

  • a personal data breach affecting Virgin Data;
  • a material security incident;
  • a significant integrity issue affecting Orders or bookings; or
  • any incident materially affecting the availability, confidentiality or integrity of Virgin systems or data.

Notifications should include, where available:

  • the nature of the incident;
  • affected data categories;
  • estimated impact;
  • containment actions taken; and
  • proposed remediation steps.

Access Parties must:

  • preserve relevant logs and evidence;
  • cooperate with investigations and remediation activities;
  • support credential rotation and containment actions;
  • assist with regulatory reporting where required; and
  • implement agreed corrective measures.

Virgin Atlantic and the Access Party may coordinate response activities through the following phases:

  • Detection and assessment;
  • Containment and mitigation;
  • Stabilisation and recovery; and
  • Post-incident review and remediation.

Upon termination, expiry or suspension of access:

  • credentials may be revoked or rotated;
  • system access may be disabled;
  • APIs and connectivity permissions may be withdrawn; and
  • additional technical controls may be implemented to protect systems and data.

Access Parties must securely return or delete Virgin Data in accordance with the DPA and provide certification of completion where requested.

Any legally required retention must:

  • be limited to the minimum necessary scope;
  • remain subject to appropriate security protections; and
  • be documented and justified.

Access Parties must reasonably cooperate with Virgin Atlantic to support the continued servicing of existing bookings and minimise disruption to Agents and customers during any transition or exit process.

Virgin Atlantic monitors operational dependency and concentration risk across distribution channels and technology providers.

Virgin Atlantic may implement:

  • alternate routing arrangements;
  • multi-provider strategies;
  • resilience testing;
  • operational contingency planning; and
  • direct-connect readiness measures,

to reduce single points of failure and maintain continuity.

Access Parties may be subject to:

  • onboarding reviews;
  • periodic security assessments;
  • operational resilience reviews;
  • audit activities;
  • compliance certifications; and
  • contingency testing.

Any deviation from this Policy requires Virgin Atlantic’s documented approval.

Failure to comply with this Policy or related agreements may result in:

  • remediation requirements;
  • restricted access;
  • suspension;
  • termination; or
  • other contractual remedies.

Virgin Atlantic will apply such measures reasonably and proportionately, taking into account customer impact, operational continuity, legal obligations and security requirements.

During the transition to Offers & Orders retailing models:

  • Virgin Atlantic reference integrity must be maintained;
  • Orders and/or PNR references must remain traceable within Virgin Atlantic systems;
  • Access Parties must not maintain authoritative lifecycle state outside Virgin Atlantic systems; and
  • temporary caching or storage mechanisms must not override Virgin Atlantic retail, fulfilment or servicing logic.

This Policy should be read together with:

  • the Technical User Agreement (TUA);
  • the applicable Data Processing Agreement (DPA);
  • the Agency Sales Agreement (ASA);
  • applicable Virgin Atlantic distribution policies; and
  • applicable regulatory obligations.

Where there is any inconsistency between this Policy and a signed agreement, the signed agreement will prevail unless otherwise stated.

The DPA between Virgin Atlantic and each Access Party includes provisions relating to:

  • processing only on documented instructions;
  • categories of data and data subjects;
  • security and technical measures;
  • confidentiality obligations;
  • approved subprocessors;
  • data subject rights support;
  • audit and compliance rights;
  • breach notification requirements;
  • international transfers;
  • return and deletion obligations; and
  • processor liability for failure to comply with applicable data protection requirements.

The DPA survives termination to the extent necessary to ensure continued protection, return or deletion of Virgin Data and cooperation with any ongoing regulatory or legal obligations.