Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - GDPR: The Best Strategy For International Businesses
Articles

GDPR: The Best Strategy For International Businesses

ISBuzz TeamBy ISBuzz TeamMay 21, 20195 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The EU’s General Data Protection Regulation (GDPR) was created with the aim of homogenising data privacy laws across the EU. GDPR also applies to organisations outside the EU, if they monitor EU data subjects, or offer goods and services to them. The GDPR applies to personal data, which is defined as any information relating to an identifiable natural person.

In certain cases, frameworks such as the EU-US Privacy Shield have been implemented to ensure the protection of data being transferred outside the EEA. However, such frameworks have not been established with all countries outside of the EEA. In such cases, businesses need to be keenly aware of the data protection laws in each territory, in order to ensure compliance.

Businesses based within the EEA that wish to send personal data outside the EEA also need to pay particularly close attention to GDPR. GDPR restricts the transfer of any personal data to countries outside the EEA.

The European Commission has made “adequacy decisions” as regards the data protection regimes in certain territories.  Territories where the data protection regime has been deemed adequate include Andorra, Argentina, Guernsey, Isle of Man, Israel, Jersey, New Zealand, Switzerland and Uruguay. The EU Commission has also made partial findings as regard the adequacy of the regimes in the US, Japan and Canada.

If a business wishes to send data to a country which is not in the EEA, and which is not covered by an “adequacy decision”, it will need to ensure that the appropriate safeguards set out in the GDPR are implemented.

In order to facilitate data transfers within multinational corporate groups, “binding corporate rules” may be submitted to an EEA data supervisory authority for approval. If these are approved, then all members of the group must sign up to these rules and they then may transfer data outside the EEA, subject to the binding corporate rules.

Another way to make a restricted transfer outside the EEA is for both parties to enter into a data sharing agreement, which incorporates the standard data protection clauses adopted by the European Commission.

The Commission has published four sets of such model clauses, which set out the obligations of both the data exporter and data importer. The clauses may not be amended and must appear in the agreement in full. The penalties for noncompliance with GDPR are significant, since organisation can be fined €20 Million or 4% of their annual global turnover for breaches.

Article 49 of GDPR also sets out derogations from the GDPR’s general prohibition on transferring personal data outside the EEA without adequate protections. The derogations can apply, for example, where there is an important public interest, or the data must be transferred for legal proceedings. A derogation can also apply where the data subject has been fully informed of the risks, but has given their explicit consent to the transfer.

The advent of GDPR has a significance for companies doing business internationally. However,  companies doing business internationally also need to think beyond GDPR. Companies may find themselves subject to the data protection regimes of third countries, even if they do not have any physical presence there. For example, international companies without a presence in Turkey may be subject to Turkish data protection law if their activities have an effect in Turkey.   

A registration system for data processors is currently being rolled out in Turkey. Data processors based outside Turkey whose activities have an effect in Turkey may need to register by 30 September 2019.

Turkey’s 2016 Law on the Protection of Personal Data is based largely on EU data protection law. As a candidate state for EU membership, Turkey aligns much of its legal system with EU law. Many of its requirements are broadly similar to EU law. However, there are also some very important differences which companies whose businesses have an effect in Turkey should be mindful of.

Turkish data protection law allows for administrative fines of up to three per cent of a company’s net annual sales to be levied if personal data is stolen, or disclosed without consent.  Turkish data protection law applies to both sensitive and non-sensitive personal information.

Personal data may not be transferred outside Turkey without the consent of the data subject, except in strictly limited circumstances. Regulatory approval is required for such transfers where the transfer may harm Turkey or the data subject.

Unlike GDPR, however, “explicit consent” is required by Turkish Law to process both sensitive and non-sensitive data. The exceptions to this general rule include where there is a legal obligation on a data processor to process the data, and where such processing is necessary to protect the life of the subject. Further processing is not allowed without specific consent, and there is no “compatible purpose” exception in Turkish law. The definitions of consent also differ in Turkish law and under GDPR.

GDPR has caused many EEA companies to consider in detail the laws restricting the transfer of data out of the EEA. However, companies may also be subject to laws restricting the transfer of data into the EEA.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}