GDPR (Regulation (EU) 2016/679)
Rendered when the buyer ticks "GDPR (EU or UK personal data)". The register cites 4 of its 40 clauses, behind 1 finding: personal data at a site outside the home area, and on the duty rows of every site it reaches.
Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: GDPR (Regulation (EU) 2016/679). What it attaches to a site: the GDPR regime page.
Clauses cited
4 of 40GDPR Art. 32 Security of processingImplement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.
Common gap: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
Source framework: GDPR (Regulation (EU) 2016/679)
GDPR Art. 44 General principle for transfersTransfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
Common gap: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
Source framework: GDPR (Regulation (EU) 2016/679)
GDPR Art. 45 Transfers on the basis of an adequacy decisionPersonal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.
Common gap: Adequacy assumed for a whole country where the decision covers only a sector or only listed recipients, with the recipient's listing never verified
Source framework: GDPR (Regulation (EU) 2016/679)
GDPR Art. 46 Transfers subject to appropriate safeguardsIn the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.
Common gap: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
Source framework: GDPR (Regulation (EU) 2016/679)
See which clauses your list engages
Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.
Build my edge register