Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 2518
Next
In Process
Anonymous
  • 0
Asked: February 4, 20212021-02-04T11:33:11+01:00 2021-02-04T11:33:11+01:00In: GDPR, Privacy Management

How and who to engage to get traction for Schremes II

  • 0

I am the sole privacy employee for our multinational company. We don’t use Privacy Shield for data transfers, we have SCC’s in place and I am completing a data mapping exercise. I suspect our cloud based providers like AWS may store data in the US. Virtually all our client & employee data would be visible and processed to some extent in the US.
I am worried about the lack of concern from other areas of the business like IT, IS. Who do i need to get engaged and how best can i do this?

  • 2 2 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    2 Answers

    • Voted
    • Oldest
    • Recent
    1. Elisavet D.

      Elisavet D.

      • 1 Question
      • 21 Answers
      • 0 Best Answers
      • 21 Points
      View Profile
      Elisavet D. Bronze contributor
      2021-02-05T13:58:16+01:00Added an answer on February 5, 2021 at 1:58 pm

      Hi! Compliance with Shcrems II can be challenging 🙂 The first thing to do is map your processors and the subprocessors. Carry out a data transfer mapping. Have in mind that you need to capture US (sub)processors that fall under the scope of US surveillance laws, even if a transfer of personal data doesn’t occur (e.g. you use AWS but selected region is in the EEA-there is no data transfer per se, but US authorities can still access the data due to the extraterritorial scope of US surveillance laws). After you do that, since we know that US is not an adequate country, you need to consider if the application of additional technical, organisational or contractual measures will ensure an effective protection.

      • 2
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. Elisavet D.

      Elisavet D.

      • 1 Question
      • 21 Answers
      • 0 Best Answers
      • 21 Points
      View Profile
      Elisavet D. Bronze contributor
      2021-02-05T13:58:33+01:00Added an answer on February 5, 2021 at 1:58 pm

      You can read the EDPB’s Guidelines on the topic for more info: https://edpb.europa.eu/our-work-tools/public-consultations-art-704/2020/recommendations-012020-measures-supplement-transfer_en

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor
    Andrea

    Andrea

    • 15 Answers
    Bronze contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.