Data Transfer and Privacy

Last updated:
14.10.2024
The entry into force of the General Data Protection Regulation (GDPR) has created an urgent need for action for many agencies and companies. If you have not yet taken a closer look at data protection law and the legal requirements for data transfers via the internet, email, or fax: the stricter rules on data security and data transfers have been in effect since May 2018. But what exactly constitutes a data transfer?
Data Transfer and Privacy
Key Takeaways
  • GDPR since May 2018: Stricter rules for data security and data transfers.
  • Data transfers require a legal basis and an adequate level of data protection.
  • High fines for GDPR violations; up to 4% of annual turnover.
  • Opt-in for cookies and strict rules for email, IP addresses, and fingerprints.
  • Obligation to delete personal data once the purpose has been fulfilled or the retention period has expired.

Data transfer

Under the GDPR, data transfer refers to the sharing of personal data within a company, a corporate group, or with third parties. Before any data transfer can take place, it must first be verified that there is a legal basis for doing so. Furthermore, a distinction must be made between data transfers within the European Union and those to third countries. Data transfers to third countries may only occur if there is an adequate level of data protection that complies with GDPR regulations. Additionally, measures must be implemented during data transfer to ensure control over the transmission. It must be guaranteed that personal data cannot be processed (read, copied, altered, removed, etc.) by unauthorized parties during transit. Possible measures include email encryption or the use of VPN technology.

Highly professional solutions and technical expertise for data transfers

As your data protection officer, we are your point of contact for information on the details of the General Data Protection Regulation, reviewing your data transfer practices, and assessing your existing data protection measures. The new legal landscape presents many companies with new challenges that are not always easy to implement. Should changes be necessary, we can act on your behalf to support you in ensuring future compliance. Violations can be costly, potentially resulting in fines of up to 4% of your company's total annual global turnover. Meeting strict data security requirements often necessitates upgrading or supplementing your technical infrastructure to ensure compliance, protect the rights of data subjects, and avoid legal breaches during data transfers.

Challenges posed by the EU GDPR regarding data transfer

The GDPR has concrete implications for data transfer: with its entry into force, an opt-in solution for cookie collection, for example, is required. It is no longer sufficient to simply inform website visitors about the use of cookies. As a data controller, you are on the safe side when the user provides consent by checking a box. However, cookies are just one example of the changes that have occurred since May 2018, which you must strictly observe.

The use of

  • email addresses
  • IP addresses
  • or digital fingerprints

is also no longer possible without adhering to data protection regulations.

Data protection – customer data must be reliably deleted

Agencies and companies are required to delete all personal data and associated cross-references, such as links, after a certain period. If you fail to fulfill this obligation to remove data once the purpose has been served or the retention period has expired—or if you delete it too late, incompletely, or not at all—you are committing a data protection violation and risking heavy fines. The regulation strengthens the general right of personality of individual customers and places the responsibility for data processing on you. If a user requests the complete removal of their data from your database, you should comply with this request immediately while adhering to the strict guidelines of the new regulation.

The rules of the General Data Protection Regulation (GDPR) also apply to credit agencies such as SCHUFA, Bürgel, or Creditreform. Read our blog to learn what is important regarding the transfer of personal data and credit agencies.

Numerous requirements – a data protection officer can help!

Compliance with the data protection regulation is a top priority and protects against the costs that can arise from high fines for data protection violations. A data protection officer is also advantageous for small and medium-sized enterprises, as they are often busy with their core business and may outsource processing operations involving personal data. Especially for data transfers via email, fax, or other channels, consulting the law is highly recommended. Furthermore, due to the GDPR's accountability principle, compliance with data protection principles should be fully and seamlessly documentable.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in