Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / EU Regulation

EU Regulation

GDPR and international data access

Access to European personal data from another country must be distinguished from the supplier's location alone and from the nature of the goods or service provided.

Effect of this requirement

This rule cannot be read in isolation.

Applicability to be qualified
Transfers
Bilateral relationship
Country sources reviewed on
Assumptions, limitations and sources of this reading

Reading point

Remote access is a flow that must be governed

Country, role, purpose, people and systems are examined together.

  • Controller and processor roles
  • Access paths and processing locations
  • Contractual and technical measures
  • Sub-processors and deletion

Data journey

Observe the actual flow rather than reducing the relationship to a country.

01

Data and purpose

What data is needed, for what processing and under whose responsibility?

02

People and systems

Who accesses, from where, with what means and what traces?

03

Transfer mechanism

Adequacy, clauses, internal rules and supplementary measures are distinguished.

04

End of access

Departure, role change, return of assets, retention and deletion are demonstrable.

Decision path

Trace the actual path of data and access

The supplier's country is not sufficient on its own: qualification depends on the roles, purposes, individuals and systems actually accessible.

01Roles and instructions

Identify the data controller, the processors, the permitted purposes and the instructions governing each access.

02Access and transfer

Map the data accessed, where it is stored, the countries from which it can be accessed, and the operations carried out remotely.

03Applicable safeguards

Tie the transfer mechanism, clauses, supplementary measures and downstream subcontractors to the precise flow they must govern.

04End of processing

Demonstrate the withdrawal of access, the return, deletion and handling of temporary copies when the purpose or the relationship ends.

Control of non-EU access

The questions that make the data flow understandable and defensible.

Questions to address

  • Who accesses European data, from where, for what purpose
  • Your transfer mechanisms and contractual safeguards
  • Your chain of sub-subcontractors
  • Your deletion and return capabilities

Elements that support the response

  • Mapping of access and processing locations
  • Clauses and technical measures associated with transfers
  • Register of approved subcontractors
  • Evidence of deletion and export carried out

Confusions to avoid

  • Thinking in terms of "server location" while ignoring remote access
  • Allowing support to access production without logging
  • Discovering a downstream subcontractor during the client's audit
  • Treating end-of-contract deletion as a last-month topic
Assurance file, TD-034Demonstration example
GDPR commitmentAccess to EU data limited and loggedFinding
Proposed response"Access from the EU only"Finding
Actual pathLevel 2 support accesses from a third countryFinding
Divergence observedAn access path contradicts the declarationGap
ImpactFalse response on a highly sensitive topicGap
ActionDeclare the pathway, frame it and log it — or close itDecision
Reading the coloursFactual observationGap or riskDecision or action

Demonstration

Qualify the transfer based on the access that actually takes place.

The case follows the data, the people, the countries and the systems in order to tie the safeguards to the exact flow rather than to the provider's registered office alone.

Understanding how evidence is qualified →

Apply this reading

Map the flow and access before qualifying the transfer.

The categories of data, their storage locations and the countries of access make it possible to reconstruct the path before selecting the relevant safeguards.