International Data Transfers
Overview
StarWave Entertainment operates globally to deliver entertainment content, services, and experiences to audiences and partners worldwide. As part of our operations, personal data may be transferred across international borders. This page outlines how we handle these transfers, the legal mechanisms we rely upon, and the safeguards we implement to protect your data.
StarWave is committed to ensuring that all cross-border data transfers comply with applicable data protection laws, including the GDPR, CCPA, and other regional regulations. We do not transfer data to jurisdictions lacking adequate protection without appropriate safeguards.
Legal Basis for Transfers
Any international transfer of personal data is grounded in a valid legal basis under applicable law. Primary bases include:
- Performance of Contract: Transfers necessary to provide requested services or fulfill agreements.
- Legitimate Interests: Transfers required for global operations, security, and improvement of services, balanced against user rights.
- Consent: In specific cases where required, we obtain explicit consent for cross-border transfers.
- Legal Obligation: Transfers mandated by law or regulatory requirement.
Transfer Mechanisms
Depending on the destination and nature of the transfer, StarWave utilizes the following mechanisms to ensure compliance:
For transfers to countries without an adequacy decision (e.g., the United States), we rely on the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, Module One: Controller to Controller). These SCCs incorporate the 2021 revised text.
- Adequacy Decisions: Where the European Commission has determined a country provides adequate protection (e.g., UK, Japan, Canada), we rely on these decisions.
- Binding Corporate Rules (BCRs): Intra-group transfers within StarWave entities are governed by our BCRs, approved by relevant Supervisory Authorities.
- Derogations: In exceptional circumstances, we may rely on specific derogations under Article 49 GDPR, such as explicit consent or necessity for contract performance.
| Mechanism | Applicability | Status |
|---|---|---|
| SCCs (2021) | EEA to US/Third Countries | Active |
| BCRs | Intra-Group (Global) | Approved |
| Adequacy | EEA to Adequate Countries | Active |
Data Destinations & Recipients
Personal data may be transferred to or accessed by the following regions and third-party service providers. These transfers are essential for hosting, analytics, payment processing, and content delivery.
| Region/Country | Purpose | Mechanism |
|---|---|---|
| United States | Cloud Hosting, Analytics, Support | SCCs, BCRs |
| India | Customer Support, Back-office | SCCs |
| Singapore | APAC Operations Hub | Adequacy / BCRs |
| United Kingdom | Legal, Finance, HQ | Adequacy |
| Germany | EU Data Processing | GDPR (Intra-EEA) |
Third-party vendors are required to sign Data Processing Agreements (DPAs) and undergo security assessments prior to engagement. A full list of subprocessors is available in our Privacy Policy.
Security Measures
All international transfers are protected by technical and organizational measures (TOMs) to ensure confidentiality, integrity, and availability.
- Encryption: Data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
- Pseudonymization: Where possible, data is pseudonymized before transfer to reduce identifiability.
- Access Controls: Strict role-based access control (RBAC) and multi-factor authentication (MFA) for systems handling personal data.
- Audits: Regular third-party audits and penetration testing of cross-border data flows.
- Transfer Impact Assessments (TIAs): We conduct TIAs for transfers to high-risk jurisdictions to evaluate local laws and implement supplementary measures where necessary.
Your Rights Regarding Transfers
You have the right to be informed about international transfers of your personal data. Specifically, you can:
- Request details on which countries your data is transferred to.
- Object to transfers based on legitimate interests (where applicable).
- Withdraw consent for transfers if the transfer is based on consent.
- Request access, rectification, erasure, or portability of your data, including data stored in cross-border systems.
To exercise these rights, please contact our Data Protection Officer (DPO) using the details below.
Contact Data Protection Officer
StarWave DPO Office
For inquiries regarding international data transfers, SCCs, or to exercise your data rights: