Data Transfer and Privacy

- GDPR since May 2018: Stricter rules for data security and data transfers.
- Data transfers require a legal basis and an adequate level of data protection.
- High fines for GDPR violations; up to 4% of annual turnover.
- Opt-in for cookies and strict rules for email, IP addresses, and fingerprints.
- Obligation to delete personal data once the purpose has been fulfilled or the retention period has expired.
Data transfer
Under the GDPR, data transfer refers to the sharing of personal data within a company, a corporate group, or with third parties. Before any data transfer can take place, it must first be verified that there is a legal basis for doing so. Furthermore, a distinction must be made between data transfers within the European Union and those to third countries. Data transfers to third countries may only occur if there is an adequate level of data protection that complies with GDPR regulations. Additionally, measures must be implemented during data transfer to ensure control over the transmission. It must be guaranteed that personal data cannot be processed (read, copied, altered, removed, etc.) by unauthorized parties during transit. Possible measures include email encryption or the use of VPN technology.
Highly professional solutions and technical expertise for data transfers
As your data protection officer, we are your point of contact for information on the details of the General Data Protection Regulation, reviewing your data transfer practices, and assessing your existing data protection measures. The new legal landscape presents many companies with new challenges that are not always easy to implement. Should changes be necessary, we can act on your behalf to support you in ensuring future compliance. Violations can be costly, potentially resulting in fines of up to 4% of your company's total annual global turnover. Meeting strict data security requirements often necessitates upgrading or supplementing your technical infrastructure to ensure compliance, protect the rights of data subjects, and avoid legal breaches during data transfers.
Challenges posed by the EU GDPR regarding data transfer
The GDPR has concrete implications for data transfer: with its entry into force, an opt-in solution for cookie collection, for example, is required. It is no longer sufficient to simply inform website visitors about the use of cookies. As a data controller, you are on the safe side when the user provides consent by checking a box. However, cookies are just one example of the changes that have occurred since May 2018, which you must strictly observe.
The use of
- email addresses
- IP addresses
- or digital fingerprints
is also no longer possible without adhering to data protection regulations.
Data protection – customer data must be reliably deleted
Agencies and companies are required to delete all personal data and associated cross-references, such as links, after a certain period. If you fail to fulfill this obligation to remove data once the purpose has been served or the retention period has expired—or if you delete it too late, incompletely, or not at all—you are committing a data protection violation and risking heavy fines. The regulation strengthens the general right of personality of individual customers and places the responsibility for data processing on you. If a user requests the complete removal of their data from your database, you should comply with this request immediately while adhering to the strict guidelines of the new regulation.
The rules of the General Data Protection Regulation (GDPR) also apply to credit agencies such as SCHUFA, Bürgel, or Creditreform. Read our blog to learn what is important regarding the transfer of personal data and credit agencies.
Numerous requirements – a data protection officer can help!
Compliance with the data protection regulation is a top priority and protects against the costs that can arise from high fines for data protection violations. A data protection officer is also advantageous for small and medium-sized enterprises, as they are often busy with their core business and may outsource processing operations involving personal data. Especially for data transfers via email, fax, or other channels, consulting the law is highly recommended. Furthermore, due to the GDPR's accountability principle, compliance with data protection principles should be fully and seamlessly documentable.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













