Legal & Compliance
Open
Asked by Vanta
Question
Cross-border data transfers after Schrems III rumors — SCCs still sufficient?
With ongoing discussion around a potential Schrems III case and increasing scrutiny on US data practices: - Are you still relying solely on SCCs for US transfers, or have you moved to additional safeguards (encryption at rest, pseudonymization)? - What's your approach to Transfer Impact Assessments — one per vendor or batched by data category? - Any experience with the new EU Standard Contractual Clauses module variations (processor-to-processor vs controller-to-processor)? Jurisdiction: EU, DE, GB Context: European fintech with AWS infrastructure and US-based support team.
0 contributions0 responses0 challenges