Overview
That Is A Q operates globally and, in the course of providing our services, personal data may be transferred to and processed in countries outside the European Economic Area (EEA), the United Kingdom, and Switzerland. We take our data protection obligations seriously and ensure that all international transfers are conducted in full compliance with applicable law.
This page outlines the legal mechanisms, safeguards, and practices we put in place to protect personal data when it crosses borders.
No personal data is transferred outside the EEA, UK, or Switzerland unless appropriate legal safeguards are in place. Where required, we conduct Transfer Impact Assessments and implement supplementary measures.
Legal Basis for Transfers
All international data transfers by That Is A Q rely on one or more of the legal mechanisms recognized under Article 44โ49 of the GDPR and the UK GDPR. The specific mechanism depends on the destination country, the nature of the data, and the role of the recipient.
Adequacy Decisions
Where the European Commission or UK government has issued an adequacy decision for a particular country, we may transfer data to that country without requiring additional safeguards. We regularly monitor adequacy decisions and update our transfer practices accordingly.
Standard Contractual Clauses
For transfers to countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (EU SCCs) (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum (UK IDTA), as applicable.
We use the 2021 EU SCCs, which provide a modular approach covering controller-to-controller, processor-to-processor, controller-to-processor, and processor-to-controller transfers.
Binding Corporate Rules
For intra-group transfers, That Is A Q is in the process of obtaining approval for Binding Corporate Rules (BCRs) as a framework for ensuring consistent data protection standards across all entities worldwide.
Standard Contractual Clauses
The EU SCCs form the backbone of our international data transfer compliance. We incorporate these clauses into all relevant data processing agreements and service contracts.
Modules Applied
Depending on the roles of the parties involved, we apply the relevant modules of the 2021 SCCs:
- Module One: Controller to Controller โ applied when transferring data between our entities acting as independent controllers.
- Module Two: Controller to Processor โ applied when we engage a processor in a third country to process data on our behalf.
- Module Three: Processor to Processor โ applied when our subprocessors in third countries process data.
- Module Four: Processor to Controller โ applied in specific data return scenarios.
Transfer Impact Assessments
In line with the Schrems II ruling (C-311/18), we conduct Transfer Impact Assessments (TIAs) for all transfers relying on SCCs. Each TIA evaluates:
- The legal framework of the destination country, including surveillance laws and access by public authorities.
- The technical and organizational safeguards in place.
- Whether supplementary measures are needed and whether they are effective.
Transfer Mechanisms
The following mechanisms are available under EU and UK data protection law. We select the most appropriate mechanism based on the circumstances of each transfer.
| Mechanism | Legal Basis | When Used |
|---|---|---|
| Adequacy Decision | Art. 45 GDPR | Transfers to countries with an EU or UK adequacy decision (e.g., Japan, Canada, Argentina) |
| Standard Contractual Clauses | Art. 46(2)(c) GDPR | Transfers to countries without adequacy, where additional safeguards are required |
| Binding Corporate Rules | Art. 47 GDPR | Intra-group transfers between That Is A Q entities worldwide |
| UK IDTA / Addendum | Art. 46 UK GDPR | Transfers originating from the UK outside the EEA |
| Derogations | Art. 49 GDPR | Exceptional cases: explicit consent, contract performance, important reasons of public interest |
Transfer Destinations
That Is A Q transfers personal data to the following jurisdictions. The mechanism and safeguards vary by destination.
| Country | Region | Mechanism | Status |
|---|---|---|---|
| United States | North America | EUโUS DPF / SCCs + Supplementary | Active |
| India | South Asia | SCCs + Supplementary | Active |
| Singapore | Southeast Asia | SCCs + Supplementary | Active |
| Brazil | South America | SCCs + Supplementary | Active |
| Canada | North America | Adequacy (commercial orgs) | Active |
| Japan | East Asia | Adequacy Decision | Active |
| South Korea | East Asia | SCCs + Supplementary | Review |
For transfers to the United States, we leverage the EUโUS Data Privacy Framework (DPF) where applicable, alongside SCCs and supplementary measures. We continuously monitor the legal landscape, including challenges to the DPF and any changes to US surveillance law.
Supplementary Safeguards
Beyond contractual measures, That Is A Q implements technical and organizational safeguards to ensure an essentially equivalent level of protection for data transferred internationally.
Technical Measures
- Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed separately from encrypted data.
- Pseudonymization: Where possible, personal data is pseudonymized before transfer. Re-identification requires additional authentication and authorization.
- Access Controls: Role-based access controls (RBAC) and multi-factor authentication (MFA) restrict data access to authorized personnel only.
- Data Minimization: Only data strictly necessary for the intended purpose is transferred. We regularly review data flows to eliminate unnecessary transfers.
- Deletion Policies: Retention periods are enforced automatically. Data is securely deleted when no longer needed.
Organizational Measures
- Data Protection Training: All employees receive mandatory annual training on data protection and international transfer obligations.
- Vendor Management: Subprocessors are vetted for compliance with SCCs and data protection standards before engagement.
- Audits & Monitoring: We conduct regular audits of our data processing activities and subcontractor arrangements.
- Incident Response: Our data breach response plan includes specific procedures for cross-border transfer incidents.
Data Subject Rights
Individuals whose personal data is transferred internationally retain all rights granted under applicable data protection law, regardless of where their data is processed.
Your Rights Include:
- Right of Access โ to obtain a copy of your personal data and information about how it is processed.
- Right to Rectification โ to correct inaccurate or incomplete data.
- Right to Erasure โ to request deletion of your data under certain conditions.
- Right to Restrict Processing โ to limit how we process your data.
- Right to Data Portability โ to receive your data in a machine-readable format.
- Right to Object โ to object to processing based on legitimate interests or direct marketing.
- Right to Lodge a Complaint โ with a supervisory authority in your jurisdiction.
International data transfers do not affect or limit any of these rights. If you wish to exercise any of these rights, please contact our Data Protection Officer using the details below.
Liaison Officer
In accordance with the EU SCCs (Clause 17), That Is A Q has designated a liaison officer to receive and address requests from data subjects and data protection authorities in relation to international data transfers.
Name: Data Protection Officer
Email: dpo@thatisaq.com
Address: That Is A Q, [Registered Office Address], [Country]
Response Time: We aim to respond within 30 days of receiving a request.
Data protection authorities may also contact us at the same address to exercise their supervisory functions or request information about our transfer practices.
Questions or Concerns?
If you have questions about our international data transfer practices, need a copy of the SCCs we rely on, or wish to exercise your data protection rights, please don't hesitate to reach out.
Get in Touch with Our Data Protection Team
We're here to help you understand how your data is protected when it crosses borders.
โ๏ธ dpo@thatisaq.com