Unlock AI Compliance: Master the new EU AI Act with our comprehensive guide.

Teilen Sie

2 min read

Writen by Adam

Posted on: January 15, 2021

Are you sharing data outside of the EU ? Read this

The rules relating to sharing data with any company outside the EU  have recently changed and the previously accepted standard contract clauses are no longer considered adequate. If you share data with any company outside the EU,  you need to ensure that you have completed a risk assessment as well as checking that your contract meets the standard clauses.

The EU Data Protection Board (EDPB) has issued ‘an FAQ’ on the invalidation of the Privacy Shield and the implications for Standard Contractual Clauses (SCCs). This guidance still applies to UK controllers and processors.

It is important to recognise that there is no grace period for companies to act and third-country transfers are currently illegal.

There is no guidance on how companies should ensure that data transferred is now safe and no information to help companies complete a risk assessment. So, until more guidance is provided, we are suggesting the following approach:

  1. List all third country transfers you currently have in place.
  • Document the data, nature of processing, and third-party details so you understand exactly what data is involved.
  • Ensure you have SCC’s in place with all third parties – in many cases these will be covered in the company’s terms and conditions.
  • Contact all third parties to ask for copies of any risk assessments they have completed. Don’t be too disappointed if you do not receive any as many companies are unaware.
  • Complete a Supplier Data Security Checklist for each company you share data with outside of the EU , focussing on the smaller companies. You can ignore Facebook, Google, Microsoft at this point
  • Review Facebook, Google, and Apple responses to this and keep a record of any updates.
  • Use this analysis to decide whether to stop transferring data to any company that fails your risk assessment.

This is a complex area, but we can help. We have produced a standard risk assessment template you can use and will keep you updated.

Kontakt

Ich hoffe, Sie finden dies nützlich. Wenn Sie einen EU-Vertreter benötigen, Fragen zur DSGVO haben oder eine SAR- oder Regulierungsanfrage erhalten haben und Hilfe benötigen, können Sie sich jederzeit an uns wenden. Wir helfen Ihnen immer gerne...
GDPR Lokales Team.

Kontakt

Recent blogs

The Future of Finance: Adapting to AI and Data Privacy Laws

The rapidly evolving landscape of financial technology is witnessing a significant transformation w

Navigating the Contradictions: Automated Decision-Making and Regulatory Legislation in AI Systems

The Dilemma of Automated Decision-Making At the heart of AI systems lies the promise of aut

How to Implement the New AI Law in Your Company

The implementation of the AI Act marks a significant stride towards responsible and fair use of art

Holen Sie sich jetzt Ihr Konto

Einrichtung in nur wenigen Minuten. Geben Sie Ihre Unternehmensdaten ein und wählen Sie die gewünschten Dienste aus.

Konto erstellen

Kontakt aufnehmen

Sie sind sich nicht sicher, welche Option Sie wählen sollen? Rufen Sie uns an, schicken Sie uns eine E-Mail oder chatten Sie mit uns
.

Kontakt
06 GDPR-INFO

Auf dem Laufenden bleiben

Hinterlassen Sie hier Ihre Daten und wir senden Ihnen Updates und Informationen zu allen Aspekten der DSGVO und des EU-Vertreters. Wir werden Sie nicht mit E-Mails bombardieren und Sie können uns jederzeit auffordern, damit aufzuhören.

Vollständiger Name ist erforderlich!

Eine geschäftliche E-Mail ist erforderlich!

Gesellschaft ist gefragt!

Bitte akzeptieren Sie die Allgemeinen Geschäftsbedingungen und die Datenschutzrichtlinie