{"id":8812,"date":"2024-10-21T12:24:41","date_gmt":"2024-10-21T10:24:41","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8812"},"modified":"2024-10-21T12:24:42","modified_gmt":"2024-10-21T10:24:42","slug":"gdpr-as-a-non-eu-company","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/","title":{"rendered":"Embracing the GDPR as a non-EU company"},"content":{"rendered":"\n<p>6 years after becoming enforceable, the GDPR has not died out in popularity as a conversation topic among board members. While is remains the elephant in the room for many a stakeholder, non-EU companies who have embraced its application and requirements <a href=\"https:\/\/insights.pecb.com\/pecb-insights-issue-43-april-june-2023\/#page100\">are finding it much easier to remain contenders on the European market<\/a>. This article How can non-EU companies get started complying with a regulation they believe does not apply to them?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">When does the GDPR apply?<\/h2>\n\n\n\n<p>The GDPR applies when public or private organization process personal data. These assume one of two distinct roles, either as a <strong>data controllers <\/strong>and <strong>data processors<\/strong>. When discussing role distribution in supplier or customer relationships, we label one or the other as data controller or processor, respectively. However, one logically determines this at the level of a<em> single processing activity<\/em>.<\/p>\n\n\n\n<p>The law is extremely clear about the territoriality, targeting and offering of goods and services. Thus, the <strong>GDPR applies to your non-EU company <\/strong>if:\u00a0<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>you<strong> establish a company<\/strong> or a subsidiary in the EU.<br>No matter your product or service, your employees are people too and their data is protected by law. This places you under <em>data controller<\/em><strong> <\/strong>obligations.<\/li>\n\n\n\n<li>you <strong>provide goods and services<\/strong> (for a fee or not) to people in the EU.<br>Since processing their personal data is a requirement to provide said goods and services, you are under <em>data controller<\/em> obligations.<\/li>\n\n\n\n<li>you <strong>provide processing services<\/strong> (SaaS, PaaS) to a company to which the GDPR applies by virtue of the above points.<br>The GDPR becomes applicable when handling personal data for a company established in the EU. In this case you likely assume <em>data processor<\/em> obligations. <\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">Supplying services to end users<\/h3>\n\n\n\n<p>Beyond the letter of the law, your sales teams faces demanding questions from client procurement teams and end users alike. This is the case whether you offer B2B, B2B2C or B2C goods and services. Sales teams need to understand what procurement teams asked of them. At the very least, it communicates a sense of preparedness. In practice, they should only occasionally forward less obvious questions to the tech, product or legal teams. <\/p>\n\n\n\n<p>Your internal or <a href=\"https:\/\/techgdpr.com\/consultancy\/data-protection-officer-dpo\/\">external data protection officer<\/a> (DPO) or <a href=\"https:\/\/dataofficer.eu\">chief privacy officer<\/a> (CPO) should sit comfortably astride legal and tech. If they do, have them train sales to reduce back and forth communication. These individuals see data processing from the technical perspective of data flows. Importantly, they understand risk from the perspective of risk to the data subject.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"585\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek-1024x585.webp\" alt=\"\" class=\"wp-image-8852\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek-1024x585.webp 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek-300x171.webp 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek-768x439.webp 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek-1536x878.webp 1536w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-08-10.39.40-A-surreal-and-imaginative-image-of-Sisyphus-leveraging-compliance-to-finish-in-1st-place-at-the-Olympics.-Sisyphus-depicted-as-a-strong-ancient-Greek.webp 1792w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Sisyphus leveraging compliance to finish 1st place.<\/figcaption><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">Leveraging privacy<\/h3>\n\n\n\n<p>Being able to address <strong>data subject requests<\/strong> (DSRs) in a timely manner, ensures you remain a contender in your client\u2019s procurement shortlist. Some clients operate in a highly regulated field so compliance is crucial to them. Others show high ethical drive and understand non compliance as a risk to their operations. For clients who don\u2019t care, your common relationship will deteriorate at the first privacy pinch from data subject requests. Pressure will come from their own vertical relationships in the supply chain, or enquiries by supervisory authorities.<\/p>\n\n\n\n<p>If your business enjoys a direct relationship with people in the EU, you likely assume a data controller role. This is the case with the provision of B2C goods and services. The full requirements of transparency, security and accountability apply, so do the performance of data subject rights. Subjects are savvier now about exercising their rights. You can expect their privacy experience with you to make it onto social media if they don&#8217;t trust your practices.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">Supplying services to other organizations<\/h3>\n\n\n\n<p>When supplying SaaS or PaaS solutions, the B2B \/ B2B2C scenario likely makes you a data processor. The requirements for security and accountability apply to both controllers and processors. Yet, transparency obligations are fulfilled by the data controller. This is done through their own channels or via a notice your platform allows them to provide to their end-users. However, your ability to be forthcoming with demonstrations immediately satisfy your customers\u2019 expectation that you are set up to help them demonstrate <em>how they comply<\/em>.<\/p>\n\n\n\n<p>Transparency is not the only obligation you will help your customer fulfil. Say you provide a platform that corporate customers can use to create user retail experiences. They remain responsible for collecting proof of consent to the data processing resulting from triggering your platform features (e.g. shopping cart memory or reward schemes). Your platform being the front-end of user interaction for your customers, ask yourself whether your platform<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>provides your customers with consent collection mechanisms, collecting <strong>proof of consent<\/strong> and allowing for user <strong>revocation <\/strong>of consent;<\/li>\n\n\n\n<li>provides APIs to push data from your platform to your customer\u2019s ERP, therefore triggering data transfers and access right management;<\/li>\n\n\n\n<li>helps generate <strong>records of processing activities <\/strong>that satisfy GDPR Article 30 requirements;<\/li>\n\n\n\n<li>helps generate a <strong>privacy notice <\/strong>based on the factual data processing caused by the user\u2019s choice of features.<\/li>\n<\/ul>\n\n\n\n<p>Engaging a non-compliant SaaS solution remains the data controller\u2019s statutory responsibility. Yet remember that their DPO and legal counsels can be powerful show-stoppers when signing procurement contracts. No one appreciates manual work, much less when it involves getting it from the less responsive solutions providers out there.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">Are employees people too?<\/h3>\n\n\n\n<p>You bet they are. Tunnel vision is frequent when focusing on exporting your product. Yet, when setting up a subsidiary to manage staff locally or remotely contracting staff in the EU, the data you process about them for employment and project management purposes <a href=\"https:\/\/techgdpr.com\/blog\/understanding-gdpr-compliance-in-recruitment\/\">is subject to regulation<\/a>. Job boards and recruiting agencies allow you to tap into talent but the nature of the services you use may vary. Yet your obligations on the underlying data remain those of transparency, lawfulness and retention.<\/p>\n\n\n\n<p>When onboarding and during the employment lifecycle, employees yield and generate tons of personal data. Some of that data may be highly sensitive, such as that associated with sick leave and disabilities. Remember that your HR systems may not be contracted in the EU and likely plug into other tools. That is often the case with payroll management, training and employee development. As you would expect, this tool landscape comes with additional challenges for complex organizations sharing services across multiple jurisdictions. Due diligence should take place <em>before <\/em>onboarding a tool and continuously <em>while <\/em>feature testing.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"585\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks-1024x585.webp\" alt=\"HR personnel carelessly distributing job applicants' personal data throughout the company.\" class=\"wp-image-8847\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks-1024x585.webp 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks-300x171.webp 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks-768x439.webp 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks-1536x878.webp 1536w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.21.18-A-landscape-oriented-image-showing-a-scene-of-job-applicants-sharing-personal-information-with-a-careless-recruiter.-The-recruiter-is-seen-with-stacks.webp 1792w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">HR personnel carelessly distributing job applicants&#8217; personal data throughout the company.<\/figcaption><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">What about applicants?<\/h3>\n\n\n\n<p>No evidence suggests that merely looking at profiles on LinkedIn triggers GDPR obligations. The GDPR refers to that data as <em>publicly available<\/em>. However, the moment you make use of a third party tool or structure information, requirements are triggered. This customarily takes the form using spreadsheet trackers for driving applicants through a conversion funnel or sharing them for assessment. Not all applicant tracking software is created equal. Identifying a supplier based in the EU does not guarantee that its compliance is up to par. At the very least, you should expect them to know what compliance you need their solution to offer.&nbsp;<\/p>\n\n\n\n<p>Don&#8217;t take their word for it, challenge their assertions and document their response.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does it take for non-EU companies to become compliant?<\/h2>\n\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">How is compliance defined and measured?<\/h3>\n\n\n\n<p>At its heart, compliance is about developing and maintaining the ability to demonstrate awareness of risk and risk control. Note that in data protection we do not measure risk in financial terms, nor in terms of corporate reputation. We see privacy risk through the lens of impact to the data subject. However, whether you rely on staff that is good at understanding ISO norms or legal officers good at interpreting legal provisions, your compliance essentially relies on whether your product owners understand:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>what data they need (<strong>data<\/strong>);<\/li>\n\n\n\n<li>what they are doing with it <strong>(<strong>purpose<\/strong>)<\/strong>;<\/li>\n\n\n\n<li>to whom they have provided access to -e.g. through APIs- (<strong>recipients<\/strong>);<\/li>\n\n\n\n<li>where it comes from (<strong>source <\/strong>&amp; <strong>confidentiality<\/strong>),<\/li>\n\n\n\n<li>how they legitimize its handling (<strong>legal basis<\/strong>), and<\/li>\n\n\n\n<li>what rights can be exercised against that data (<strong>DSRs<\/strong>).<\/li>\n<\/ul>\n\n\n\n<p>This inventory is not established in a week. Not unless employees actually speak to one another and have nothing else on their plate. Needless to say, the inventory is never perfect. Worse, it is often erected on erroneous assumptions. For instance, ruling too quick on <a href=\"https:\/\/www.ftc.gov\/policy\/advocacy-research\/tech-at-ftc\/2024\/07\/no-hashing-still-doesnt-make-your-data-anonymous\">what is <em>not <\/em>personal data<\/a> or failing to register the implementation of an API as triggering a processing activity. Have you ever had an awkward discussions with partner procurement teams?<\/p>\n\n\n\n<p>For organizations making use of the <a href=\"https:\/\/techgdpr.com\/consultancy\/iso-27001-implementation-support\/\">ISO27001 security management cookbook<\/a>. The 27701 extension is the <em>cherry on top <\/em>to help demonstrate, to customers and authorities, the organization is serious about compliance. Serious enough that it allows a third party to independently audit its compliance management system (ISMS and PIMS respectively).\u00a0<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"585\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the-1024x585.webp\" alt=\"A stressed compliance officer attempting to provide proof of compliance to an auditor.\" class=\"wp-image-8845\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the-1024x585.webp 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the-300x171.webp 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the-768x439.webp 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the-1536x878.webp 1536w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/08\/DALL\u00b7E-2024-08-05-12.25.21-A-landscape-oriented-image-of-a-stressed-compliance-officer-providing-evidence-of-compliance-to-an-auditor.-The-scene-shows-an-office-setting-with-the.webp 1792w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">A stressed compliance officer attempting to provide proof of compliance to an auditor.<\/figcaption><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading has-medium-font-size\">What do you need in order to demonstrate compliance?<\/h3>\n\n\n\n<p>You\u2019ll need <strong>Records of Processing Activities<\/strong> (RoPA) to start with. That will put everyone on the same page; from your tech teams, to your legal teams, your product owners, your sales and procurement teams. It will allow you to update your <strong>privacy notices<\/strong>, enter (and exit!) sales discussions comfortably. You\u2019ll need to review all your 3rd party contracts to identify where <strong>Data Processing Agreements<\/strong> (DPAs) and <strong>international transfer mechanisms<\/strong> are missing. You may also need to perform <a href=\"https:\/\/techgdpr.com\/blog\/difference-fundamental-rights-impact-assessment-dpia\/\">impact assessments<\/a> based on whether your activity is blacklisted.<\/p>\n\n\n\n<p>You might need to drop vendors with appalling documentation or those refusing to provide it. For instance, consent management platforms will lur your into thinking you don&#8217;t process personal data. If you are not willing to change suppliers, then maintain a list of vendors to deprecate for compliance issues and communicate it to upper management. You\u2019ll need robust <strong>security documentation<\/strong>, and a fair share of <strong>training <\/strong>and <strong>awareness raising <\/strong>at all levels of the organization. Perhaps least discussed but most wanted on your compliance journey, is an organizational appetite for <strong>change management<\/strong>.<\/p>\n\n\n\n<p>Much like that of ISO27001, whether your company is EU or non-EU-based, what helps you demonstrate GDPR compliance is the amount of available, relevant, readable, useful [and used !] documentation that demonstrate <strong>accountability<\/strong>. Compliance and product teams are already getting <em>creative<\/em> with MS copilot, allowing it to read through emails, repositories and spreadsheets. Are your ready to let an algorithm adjudicate on your company\u2019s compliance and leave you none the wiser?&nbsp;AI is likely to become an audit support tool in first and second party <strong>audits<\/strong>. It is however unlikely to replace the auditor\u2019s judgement and decisional independence any time soon for third party audits that rely on market-leading certification bodies.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>6 years after becoming enforceable, the GDPR has not died out in popularity as a conversation topic among board members. While is remains the elephant in the room for many a stakeholder, non-EU companies who have embraced its application and requirements are finding it much easier to remain contenders on the European market. This article [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":8420,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[10,88,62],"tags":[323,35,58,235,79],"class_list":["post-8812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-eu","category-gdpr","category-strategy","tag-consent-management-2","tag-gdpr","tag-gdpr-compliance","tag-hr","tag-international-transfers"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg",1600,1067,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg",1600,1067,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>6 years after becoming enforceable, the GDPR has not died out in popularity as a conversation topic among board members. While is remains the elephant in the room for many a stakeholder, non-EU companies who have embraced its application and requirements are finding it much easier to remain contenders on the European market. This article How can non-EU companies get started complying with a regulation they believe does not apply to them? When does the GDPR apply? The GDPR applies when public or private organization process personal data. These assume one of two distinct roles, either as a data controllers&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/strategy\/\" rel=\"category tag\">Strategy<\/a>","author_info":{"name":"Alex Carroll","url":"https:\/\/techgdpr.com\/blog\/author\/alex\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg",1600,1067,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-1024x683.jpg",640,427,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-1536x1024.jpg",1536,1024,true],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg",1600,1067,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>6 years after becoming enforceable, the GDPR has not died out in popularity as a conversation topic among board members. While is remains the elephant in the room for many a stakeholder, non-EU companies who have embraced its application and requirements are finding it much easier to remain contenders on the European market. This article How can non-EU companies get started complying with a regulation they believe does not apply to them? When does the GDPR apply? The GDPR applies when public or private organization process personal data. These assume one of two distinct roles, either as a data controllers&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/beyond-eu\/\" rel=\"category tag\">Beyond EU<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/strategy\/\" rel=\"category tag\">Strategy<\/a>","author_info_v2":{"name":"Alex Carroll","url":"https:\/\/techgdpr.com\/blog\/author\/alex\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Embracing the GDPR as a non-EU company - TechGDPR<\/title>\n<meta name=\"description\" content=\"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Embracing the GDPR as a non-EU company - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-21T10:24:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-10-21T10:24:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1067\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alex Carroll\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Qual2Privacy\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Carroll\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/\"},\"author\":{\"name\":\"Alex Carroll\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/c2bece665e6d3fdd4a8d10c5f7c2a26a\"},\"headline\":\"Embracing the GDPR as a non-EU company\",\"datePublished\":\"2024-10-21T10:24:41+00:00\",\"dateModified\":\"2024-10-21T10:24:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/\"},\"wordCount\":1771,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Team_WO_5399.jpg\",\"keywords\":[\"consent management\",\"GDPR\",\"GDPR Compliance\",\"HR\",\"International transfers\"],\"articleSection\":[\"Beyond EU\",\"GDPR\",\"Strategy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/\",\"name\":\"Embracing the GDPR as a non-EU company - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Team_WO_5399.jpg\",\"datePublished\":\"2024-10-21T10:24:41+00:00\",\"dateModified\":\"2024-10-21T10:24:42+00:00\",\"description\":\"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Team_WO_5399.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/Team_WO_5399.jpg\",\"width\":1600,\"height\":1067},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/gdpr-as-a-non-eu-company\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Embracing the GDPR as a non-EU company\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/c2bece665e6d3fdd4a8d10c5f7c2a26a\",\"name\":\"Alex Carroll\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Alex_OF_5121_700-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Alex_OF_5121_700-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Alex_OF_5121_700-150x150.jpg\",\"caption\":\"Alex Carroll\"},\"description\":\"Alex\u2019s consulting experience in data protection and information security is supported by a decade in adult training and course design. Specialised in normative frameworks and quality management he has developed decision-making tools and guidance for process management for numerous organisations. In 2018, he joined TechGDPR with the intention of helping organisations through risk-based security management, accountability and the GDPR compliance lifecycle. He has since then acquired 5 data protection and security certifications, supporting a variety of clients in privacy program development, auditing, ISO 27001 implementation support, delivering data protection training and privacy engineering.\",\"sameAs\":[\"https:\\\/\\\/techgdpr.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/wgp01\\\/\",\"https:\\\/\\\/x.com\\\/Qual2Privacy\"],\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/alex\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Embracing the GDPR as a non-EU company - TechGDPR","description":"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/","og_locale":"en_US","og_type":"article","og_title":"Embracing the GDPR as a non-EU company - TechGDPR","og_description":"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.","og_url":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/","og_site_name":"TechGDPR","article_published_time":"2024-10-21T10:24:41+00:00","article_modified_time":"2024-10-21T10:24:42+00:00","og_image":[{"width":1600,"height":1067,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg","type":"image\/jpeg"}],"author":"Alex Carroll","twitter_card":"summary_large_image","twitter_creator":"@Qual2Privacy","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Alex Carroll","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/"},"author":{"name":"Alex Carroll","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/c2bece665e6d3fdd4a8d10c5f7c2a26a"},"headline":"Embracing the GDPR as a non-EU company","datePublished":"2024-10-21T10:24:41+00:00","dateModified":"2024-10-21T10:24:42+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/"},"wordCount":1771,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg","keywords":["consent management","GDPR","GDPR Compliance","HR","International transfers"],"articleSection":["Beyond EU","GDPR","Strategy"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/","url":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/","name":"Embracing the GDPR as a non-EU company - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg","datePublished":"2024-10-21T10:24:41+00:00","dateModified":"2024-10-21T10:24:42+00:00","description":"We explore what is needed under the GDPR for non-EU companies to build trust and sign service contracts with their EU partners and clients.","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/04\/Team_WO_5399.jpg","width":1600,"height":1067},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/gdpr-as-a-non-eu-company\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Embracing the GDPR as a non-EU company"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/c2bece665e6d3fdd4a8d10c5f7c2a26a","name":"Alex Carroll","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Alex_OF_5121_700-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Alex_OF_5121_700-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Alex_OF_5121_700-150x150.jpg","caption":"Alex Carroll"},"description":"Alex\u2019s consulting experience in data protection and information security is supported by a decade in adult training and course design. Specialised in normative frameworks and quality management he has developed decision-making tools and guidance for process management for numerous organisations. In 2018, he joined TechGDPR with the intention of helping organisations through risk-based security management, accountability and the GDPR compliance lifecycle. He has since then acquired 5 data protection and security certifications, supporting a variety of clients in privacy program development, auditing, ISO 27001 implementation support, delivering data protection training and privacy engineering.","sameAs":["https:\/\/techgdpr.com\/","https:\/\/www.linkedin.com\/in\/wgp01\/","https:\/\/x.com\/Qual2Privacy"],"url":"https:\/\/techgdpr.com\/blog\/author\/alex\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8812"}],"version-history":[{"count":22,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8812\/revisions"}],"predecessor-version":[{"id":9530,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8812\/revisions\/9530"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8420"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}