Transfer
Transport of personal data across geopolitical or contractual boundaries can be quite troublesome because there are many things you need to consider. As already stated in Chapter 8, many of the laws and regulations around privacy today are based on the eight principles of privacy proposed by the Organization for Economic Co-operation and Development (OECD). However, they also suggested that there should be a free flow of data between nations for as long as the following conditions apply:
- The other country follows the same guidelines
- The data controller has put in place sufficient safeguards to ensure a sufficient level of protection to meet the guidelines
Figure 9.1: Data being transferred around the world
The General Data Protection Regulation (GDPR) and many other regulations took this a step further, however, and applied it to their citizens’ data irrespective of where that data is. The GDPR states the following: