EU Regulation
GDPR and international data access
Access to European personal data from another country must be distinguished from the supplier's location alone and from the nature of the goods or service provided.
Effect of this requirement
This rule cannot be read in isolation.
- Transfers
- Bilateral relationship
- Country sources reviewed on
Assumptions, limitations and sources of this reading
Reading point
Remote access is a flow that must be governed
Country, role, purpose, people and systems are examined together.
- Controller and processor roles
- Access paths and processing locations
- Contractual and technical measures
- Sub-processors and deletion
Data journey
Observe the actual flow rather than reducing the relationship to a country.
Data and purpose
What data is needed, for what processing and under whose responsibility?
People and systems
Who accesses, from where, with what means and what traces?
Transfer mechanism
Adequacy, clauses, internal rules and supplementary measures are distinguished.
End of access
Departure, role change, return of assets, retention and deletion are demonstrable.
Decision path
Trace the actual path of data and access
The supplier's country is not sufficient on its own: qualification depends on the roles, purposes, individuals and systems actually accessible.
Identify the data controller, the processors, the permitted purposes and the instructions governing each access.
Map the data accessed, where it is stored, the countries from which it can be accessed, and the operations carried out remotely.
Tie the transfer mechanism, clauses, supplementary measures and downstream subcontractors to the precise flow they must govern.
Demonstrate the withdrawal of access, the return, deletion and handling of temporary copies when the purpose or the relationship ends.
Control of non-EU access
The questions that make the data flow understandable and defensible.
Questions to address
- Who accesses European data, from where, for what purpose
- Your transfer mechanisms and contractual safeguards
- Your chain of sub-subcontractors
- Your deletion and return capabilities
Elements that support the response
- Mapping of access and processing locations
- Clauses and technical measures associated with transfers
- Register of approved subcontractors
- Evidence of deletion and export carried out
Confusions to avoid
- Thinking in terms of "server location" while ignoring remote access
- Allowing support to access production without logging
- Discovering a downstream subcontractor during the client's audit
- Treating end-of-contract deletion as a last-month topic
Demonstration
Qualify the transfer based on the access that actually takes place.
The case follows the data, the people, the countries and the systems in order to tie the safeguards to the exact flow rather than to the provider's registered office alone.
Understanding how evidence is qualified →Apply this reading
Map the flow and access before qualifying the transfer.
The categories of data, their storage locations and the countries of access make it possible to reconstruct the path before selecting the relevant safeguards.

