Eternity Law International News Compliance GDPR

Compliance GDPR

Published:
April 2, 2020

GDPR COMPLIANCE: REGULATIONS FOR THE EXPORT OF PERSONAL DATA FROM THE EUROPEAN UNION

Compliance with GDPR is an urgent issue, since in recent years, when accessing any Internet resource, active users of the World Wide Web noted a change in privacy policy, as well as an update to this system.

There has also been a change in the type of request to save cookies (cookies) – temporary files and the possibility of using personal data.

This is due to the entry into force of the updated GDPR Regulation (GeneralDataProtectionRegulation) of the European Union No. 2016/679, which applies to all Internet pages from 05.25.2018.

REGULATIONS FOR THE EXPORT OF PD FROM THE EUROPEAN UNION ACCORDING TO THE GDPR REGULATION

The GDPR document sets forth the basic requirements and rules regarding the use of personal data (PD), as well as to all participants in the Regulation.

A very topical issue of the GDPR regarding organizations outside the EU is the requirement for the export (movement) of PD outside the territory of the Union of European States.

The main need to comply with the requirements of the GDPR Regulation is the case when the company acts:

  • PD controller (datacontroller), namely manages his own data bank in the EU;
  • a data processor (dataprocessor), which implies contact with the bank of personal data of members of the European Union.

There are a number of sanctions for non-compliance, so all companies that somehow work with users from the EU are required to adhere to the GDPR.

THE CONCEPT OF “EXPORT OF PD FROM THE EUROPEAN UNION” AND SUBJECTS OF DISTRIBUTION OF GDPR

The movement of PD from the EU countries occurs between the following data import and export entities:

  • from a processor in the European Union – a subprocessor located outside the European Union;
  • from a controller located in the European Union to a processor outside the EU;
  • from the controller in the European Union – to the controller outside the European Union.

PERSONAL DATA EXPORT REGULATION ON GDPR

The fundamental principle of Ch. 5 of the GDPR Regulation on the permitted export of PD outside the EU states that regardless of where the PD is processed, the Regulation guarantees the established level of protection of the rights of individuals.

This regulation fully applies to the countries of the European Economic Area (CES), which in addition to the EU countries include Liechtenstein, Iceland, and Norway.

The export of personal information between the EU and the CES is positioned as the movement of PD across the EU.

WHAT ACTIONS DO THE NON-EUROPEAN WEB RESOURCES WORKING WITH THE RESIDENTS OF THE EUROPEAN UNION TAKE?

Countries that are not in the EU, but are data importers, must be prepared for such requests to be consistent with GDPR rules, without which doing business in the EU will become illegitimate.

Regardless of the location of the data importing country, all GDPR points apply to it regarding the organization of the necessary PD protection measures, as well as the appointment in some situations of a representative in the European Union, and a database protection inspector (DataProtectionOfficer, DPO).

Only after signing a bilateral agreement will it be possible to process PD on the guarantee of an EU controller.

Eternity Law International specialists will assist you in providing legal assistance in establishing compliance of your business structure with GDPR Regulation. Any difficulties can be overcome.

We will tell you which jurisdiction in the EU or outside it to choose to register and conduct your business. We will help you write Privacypolicy and other clauses in accordance with GDPR.

You could be interested

Dubai’s Virtual Asset Regulatory Authority (VARA): Opportunities for Crypto Startups

There exists a recently created law which sets up the legislative structure for the digital currency landscape in the UAE. It serves as the basis for regional rules in various emirates, encompassing the recently enacted VARA. That regulation has issued overarching instructions that related to the supervision of digital assets and similar operations in the...

White label PSP: the beginner’s guide

Payment service providers or PSPs are one of the most important elements of the virtual payment transaction mechanism in general. Thanks to the existence of such companies, users can pay for goods on the Internet, accept money transfers and send funds, pay for various services, and so on. This is already firmly entrenched in our...

Company registration in Georgia

The process of establishing a company in Georgia will take no more than a week, provided that all rules and requirements have been properly followed. Some industries in this jurisdiction have zero VAT rates, while the standard rate is 18%. These areas include shipping with the involvement of international partners, exports, electricity, tourism and others....

Gaming license in Nigeria

In Nigeria, the evolving landscape of wagering is closely intertwined with cryptocurrency, leading to a surge in the demand for a structured wagering license framework. As company seek to establish their presence in this burgeoning market, the necessity to navigate through complex regulations, including the cost and price of obtaining a certificate, becomes paramount. Businesses...

PAS 99 Integration

Integrated management system is already an inalienable part of modern commercial sphere; it makes it possible to organize clearly administration of your firm, all production stages and guarantees great benefits without unnecessary financial costs. IMS is based on three main regulatory documents: PAS 99, ND No. 006.00-134 and GOST R 53893-2010. It should still be...

UK Small Payment Institution with banking

Company description in brief: Existing for 2+ years; Registered with the FCA (Financial Conduct Authority) as small payment institution, permission for money remittance; Banking with virtual IBANs for clients (UK provider) in place; Never traded, no debts, liens or clients. Sold due to departure of owners to another country. Takeover procedure takes from 1 to...
Fill the blank:

Zurich

Dreikonigstrasse, 31A, Stockerhof

Kyiv

Baseina street, 7

London

Grosvenor Gardens, 52

Washington

1629 K St. Suite 300 N.W.

Vilnius

Gediminas Avenue, 44A

Tallinn

Kesklinna linnaosa, Tuukri 19

Edinburgh

Lochrin Square, 1

Nicosia

Jacovides Tower, 5 floor

Riga

Esplanade, 7 floor

Hong Kong

18 Harbour Road, 35/F, Central Plaza, Wanchai

Singapore

Level 42, Suntec Tower Three, 8 Temasek Boulevard

Sydney

20 Martin Place

Porto

2609 Avenida da Boavista
Calls are made only from Portugal

Tbilisi

Revaz Tabukashvili Str., N 45, area N 7