Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 1273
Next
In Process
Anonymous
  • 2
Asked: January 28, 20212021-01-28T11:21:36+01:00 2021-01-28T11:21:36+01:00In: GDPR

Third country transfers – Schrems II

  • 2

Companies which have relationship with Microsoft, Amazon, Facebook etc. are not compliant with Schrems II as it is obvious that these companies do not have additional safeguards needed. Small companies cannot negotiate with them to put additional safeguards in place to protect data as mandated by Schrems II. So before EDPB and EC publish new set of SCC and third country transfer guidelines, should the companies just accept the risk and wait?

  • 3 3 Answers
  • 1 Follower
  • 1
Answer
Share
  • Facebook

    3 Answers

    • Voted
    • Oldest
    • Recent
    1. DT

      DT

      • 0 Questions
      • 1 Answer
      • 0 Best Answers
      • 1 Point
      View Profile
      DT
      2021-01-28T16:44:38+01:00Added an answer on January 28, 2021 at 4:44 pm

      I would ensure that you understand and have mapped all the data flows to these organisations (easier said than done I know). Any additional measures that you can put in place such as encryption, anonymisation, data minimisation etc. should be put in place if not already. We’re facing the same dilemma and it is frustrating that there is only so much we can do.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. Tash

      Tash

      • 0 Questions
      • 23 Answers
      • 0 Best Answers
      • 23 Points
      View Profile
      Tash Bronze contributor
      2021-01-28T12:37:21+01:00Added an answer on January 28, 2021 at 12:37 pm

      I would look to your own DPA for guidance on this. In the UK they have said that they are being pragmatic about it.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    3. Chris Roberts

      Chris Roberts

      • 0 Questions
      • 42 Answers
      • 0 Best Answers
      • 42 Points
      View Profile
      Chris Roberts Silver contributor
      2021-01-29T17:44:12+01:00Added an answer on January 29, 2021 at 5:44 pm

      As Tash says the ICO currently says they’ll be pragmatic. Let’s hope in practice its true. As an SME you are right to say you have no power to negotiate with the big boys that most organisations have no option to use (the ones you mention included).

      My opinion is that organisations must have a well developed RoPA that helps expose the risks of each processing activity and should then be using that understanding to drive continuous improvement in their posture. By doing this you are reducing the overall risk to the organisation. Every little bit helps 🙂

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.