Auditing GDPR compliance of vendors, and undertaking cross-border transfer assessments, post-Schrems II

A woman with her hands outstretched in front of a white background.

Most business sectors have a figurehead – someone who is pushing the boundaries and making people think about how the products and services of that sector impact them, and how they can be improved. Think Elon Musk for car manufacture (and space travel), Jeff Bezos for e-commerce, the list goes on.

In the world of privacy, our figurehead in Max Schrems. He doesn’t have the stage presence of an Arianna Huffington or the financial power of a Mark Zuckerberg, but he makes up for that with his unrelenting pursuit of privacy rights for the people of the European Union.

The Schrems II case needs little introduction at this point – the quickest summary would be to simply say that Max identified the use of Privacy Shield (a system whereby US companies were permitted to receive personal data from the EU, in the absence of a finding by the EU that the US’s data protection laws automatically provided equivalent protections to EU laws) wasn’t necessarily a guarantee that the personal data would receive the same level of protection once received in the US as it does in the EU. The European Court of Justice agreed, and accordingly Privacy Shield fell, in much the same way as its predecessor, the Safe Harbour.

In addition to voiding Privacy Shield, the ECJ considered the use of standard contractual clauses (SCCs), another mechanism to transfer personal data across borders permitted by GDPR. They noted that the SCCs weren’t automatically ineffective and could continue to be used as a method of enabling these transfers, but that their use needed to be considered in the context of the details of the transfer – in particular, would there be a possibility of the protections in the SCCs being overridden by local law in the jurisdiction to which the data was to be transferred.

So the question then arises for the companies which use those SCCs (and those who, having previously used Privacy Shield, were now relegated to using the SCCs) – how do we assess those protections? In the (most-common and relevant) case of transfers from the EU to the US, how much can be done to prevent the US government and its surveillance apparatus from accessing that data?

Advice from the EU data protection authorities on this point has varied considerably – from statements that personal data of EU individuals simply shouldn’t be sent to the US in the current situation, to others which focussed on the fact that the SCCs hadn’t been struck down entirely, including the UK government (although not the UK’s data protection authority – the ICO – which remained more circumspect in its comments ), concluding that “this important mechanism for transferring data internationally remains in place”.

How to assess the compliance of vendors

If checks need to be made – to ascertain the compliance of a data transfer with GDPR – what should those checks consist of?

The guidance from the European Data Protection Board (EDPB) provides some information on this and, as the body comprised of the various EU data protection authorities, their guidance is probably the best source. However, it would be fair to say that it lacks specifics:

  • “Whether or not you can transfer personal data on the basis of SCCs will depend on the result of your assessment, taking into account the circumstances of the transfers, and supplementary measures you could put in place. The supplementary measures along with SCCs, following a case by-case analysis of the circumstances surrounding the transfer, would have to ensure that U.S. law does not impinge on the adequate level of protection they guarantee.
  • “If you come to the conclusion that, taking into account the circumstances of the transfer and possible supplementary measures, appropriate safeguards would not be ensured, you are required to suspend or end the transfer of personal data. However, if you are intending to keep transferring data despite this conclusion, you must notify your competent [supervisory authority].”

And, in respect of supplementary measures which could be used to improve privacy protections:

  • “The EDPB is looking further into what these supplementary measures could consist of and will provide more guidance.”

Clearly, each situation will be different, but we would propose the following simple steps which can be taken to evidence whether a vendor isn’t complaint with GDPR – if they pass these tests then an EU data exporter may ask for the completion of a vendor questionnaire at the next stage with questions around the specifics (e.g. appointment of a DPO, use of data protection impact assessments etc). The advantage of these tests is that they can be done independently – there’s no need to ask the vendor for information, as only publicly-available information is considered:

  1. Cookies – does the company’s website notify visitors that cookies are used? If so, does it require that the visitor agrees first to their use? If so, does this agreement take the form of a pre-ticked box? In order for consent to be adequately obtained for the use of cookies, a company should obtain permission before their use starts, and there must be a positive action from the user consenting to that use – a pre-ticked box is not enough.
  2. Privacy policy – does the company’s website provide easy access to the privacy policy of the company? Does that privacy policy contain sufficient information about the information which is being collected and how it is being processed (this second part is harder to identify from the outside, but you may be able to draw some conclusions from the nature of the company – e.g. a medical service provider is likely to be processing special category data as part of their usual operations, so is likely to need to appoint a DPO).
  3. EU establishment or EU Representative – does the company have an office (or other location) in the EU? If not, have they appointed an EU Representative, as required by GDPR Article 27? On the privacy policy, is there a physical address in the EU to which data subjects access requests can be raised? Although not specifically mentioned as a requirement in GDPR, we infer that the obligation to have an EU establishment or an EU-based Representative implies the need to have a physical – EU-located – address to which data subjects can raise their requests.

If your prospective vendor meets all these requirements, then you may want to get into a more-detailed discussion about their GDPR compliance and safeguards which exist to protect the data of EU-based individuals. If some – or all – of these publicly-visible GDPR expectations are not met, you may be thinking about looking for an alternative.

DataRep delivers its EU Representative service through 27 EU contact locations – one in each EU member state – and will offer the UK Representative service from our UK contact location, retained post-Brexit. If you have any questions on the EU or UK Representative obligation, or would like a quote, please contact us at contact@datarep.com.

The dpr logo on a white background.
Datarep logo with an orange and blue background.

Thank you for visiting DPR Group’s website!

We are still the same company, offering the most-compliant EU Representative service in the privacy marketplace, but we now have an exciting new brand!

Although we now operate as DataRep, all our DPR Group clients continue to be represented by us, to enable their GDPR compliance.

If you have any questions about the change, please don’t hesitate to contact us here!

We see you’re leaving our site

Can we help you further?

 If you have a question or you’d like more information, please leave your email address and someone will contact you: