In many cases, the pronounced division of labour in the economy also applies to IT and results in the need to divide the processing of personal data between different parties. IT companies, for example, often act as processors who process certain data on behalf of a customer, and this is also frequently the case as part of software development. Although sometimes difficult to distinguish, the joint controllership of the parties involved for the processing of personal data is a significantly different situation from a legal perspective. Cooperation between different parties becomes particularly complex if the data are transferred to so-called third countries, i.e. outside the territorial scope of the GDPR, and processed or stored there, for example, in the context of cloud usage. This chapter therefore describes the regulations defined by the GDPR under which an exchange of data is permitted and what effects this has on the architecture of ICT systems and their development. As such systems are often used across borders, the chapter concludes with a brief overview of the various data protection regulations worldwide.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Data Transfer

  • Ralf Kneuper

摘要

In many cases, the pronounced division of labour in the economy also applies to IT and results in the need to divide the processing of personal data between different parties. IT companies, for example, often act as processors who process certain data on behalf of a customer, and this is also frequently the case as part of software development. Although sometimes difficult to distinguish, the joint controllership of the parties involved for the processing of personal data is a significantly different situation from a legal perspective. Cooperation between different parties becomes particularly complex if the data are transferred to so-called third countries, i.e. outside the territorial scope of the GDPR, and processed or stored there, for example, in the context of cloud usage. This chapter therefore describes the regulations defined by the GDPR under which an exchange of data is permitted and what effects this has on the architecture of ICT systems and their development. As such systems are often used across borders, the chapter concludes with a brief overview of the various data protection regulations worldwide.