International Data Transfer
Last updated: October 24, 2024 | Version 2.1.0
1990 Web Archive operates a globally distributed infrastructure to preserve, index, and provide access to historical web content. Because our crawlers, storage nodes, and research partners span multiple jurisdictions, personal data and metadata may be transferred across international boundaries. This page outlines the legal basis, technical safeguards, and compliance mechanisms we employ to ensure all cross-border data transfers meet or exceed applicable regulatory standards.
Legal Frameworks & Transfer Mechanisms
All international data transfers conducted by 1990 Web Archive are grounded in recognized legal instruments. We evaluate each transfer route against current adequacy decisions and supplementary measures required by data protection authorities.
Standard Contractual Clauses (SCCs)
EU Commission Model Clauses (2021) adopted for all non-adequate jurisdiction transfers. Legally binding addendums execute before data flows.
EU-U.S. Data Privacy Framework
U.S. storage and processing partners are certified under the EU-U.S. DPF. Annual compliance audits are conducted by independent bodies.
Binding Corporate Rules (BCRs)
Internal global transfers between 1990 Web Archive entities follow approved BCRs covering EU, UK, and EEA personnel and system data.
Adequacy Decisions
Transfers to jurisdictions with formal adequacy status (UK, Japan, South Korea, Argentina, Canada-Commercial, etc.) proceed without additional safeguards.
Technical & Organizational Safeguards
Legal mechanisms are reinforced by cryptographic and architectural controls designed to minimize exposure and maintain data integrity across borders.
Encryption & Key Management
- All data in transit uses TLS 1.3 with forward secrecy and HSTS enforcement.
- Data at rest is encrypted using AES-256-GCM. Customer-managed keys (CMK) are available for enterprise archival contracts.
- PII fields are pseudonymized at the ingestion layer using salted SHA-3 hashing before cross-border routing.
Access & Monitoring
- Role-based access control (RBAC) with multi-factor authentication required for all administrative and research interfaces.
- Immutable audit logs record every cross-border data access, export, and transfer event. Logs are retained for 7 years.
- Automated data residency controls prevent unauthorized routing to non-compliant regions via policy-as-code enforcement.
Data Flow & Jurisdiction Mapping
The following table outlines primary data categories, their originating regions, and authorized transfer destinations.
| Data Category | Origin Region | Transfer Destination(s) | Transfer Mechanism |
|---|---|---|---|
| Researcher Account Data | EU / EEA | US (Oregon, Virginia), UK (London) | EU-U.S. DPF / UK IDTA / SCCs |
| Archival Metadata & Logs | Global Crawlers | Finland (Helsinki), Germany (Frankfurt) | Adequacy Decisions / Internal BCRs |
| Partner API Submissions | Asia-Pacific, Americas | Ireland (Dublin), Switzerland (Zurich) | SCCs 2021 / DPA Annexes |
| Payment & Billing Data | Global | Payment Processors (EU/US certified) | Third-Party DPA + SCCs |
Data Subject Rights & Cross-Border Requests
Individuals whose personal data is processed or transferred internationally retain full rights under applicable law, including:
- Right of access and portable copy of archived personal data
- Right to rectification of inaccurate metadata or account information
- Right to erasure, subject to archival preservation exemptions
- Right to restrict processing and object to cross-border transfers
Requests are processed through our unified data subject portal. Cross-border responses are coordinated by our Data Protection Officer within 30 days of verified submission. Exemptions for historical preservation are documented and communicated transparently at the time of request.
Contact & Compliance Inquiries
For questions regarding international data transfers, SCC execution, or data subject requests:
- Data Protection Officer: dpo@1990webarchive.org
- Legal & Compliance: compliance@1990webarchive.org
- Physical Address: 1990 Web Archive GmbH, Archivstraße 14, 10115 Berlin, Germany
Supervisory Authority: Berlin Commissioner for Data Protection and Freedom of Information (BfDI). We recognize the BfDI as our lead supervisory authority under GDPR Article 56.