Your company uses cloud services, software or service providers based or hosting outside the EU, or it exchanges data with group companies or partners in the US or other third countries.
What matters now
- Every transfer needs a legal basis: an adequacy decision, standard contractual clauses or another recognised safeguard.
- For the US, the EU-US Data Privacy Framework is currently usually decisive if the recipient is certified. It is being challenged in court; a plan B makes sense.
- Standard contractual clauses require an assessment of the legal situation in the recipient country.
- Remote access, support and subcontractors also count as transfers.
- Privacy notices and the record of processing activities must reflect the transfer.
Documents I need
- a list of services and recipients outside the EU
- data processing agreements and standard contractual clauses
- existing assessments and privacy notices
- the types of data transferred
Next steps
Send me the documents by email to kanzlei@bauer.legal or use the appointment request, and mention any deadline that is running. I usually reply within one working day and let you know how things can proceed. You can write to me in English or German. How we work together and how fees are charged is explained under How we work together.
More: IT law.
This page gives a general overview of German law and does not replace advice on the individual case.