Overview

That Is A Q operates globally and, in the course of providing our services, personal data may be transferred to and processed in countries outside the European Economic Area (EEA), the United Kingdom, and Switzerland. We take our data protection obligations seriously and ensure that all international transfers are conducted in full compliance with applicable law.

This page outlines the legal mechanisms, safeguards, and practices we put in place to protect personal data when it crosses borders.

โ„น๏ธ Key Principle

No personal data is transferred outside the EEA, UK, or Switzerland unless appropriate legal safeguards are in place. Where required, we conduct Transfer Impact Assessments and implement supplementary measures.

Standard Contractual Clauses

The EU SCCs form the backbone of our international data transfer compliance. We incorporate these clauses into all relevant data processing agreements and service contracts.

Modules Applied

Depending on the roles of the parties involved, we apply the relevant modules of the 2021 SCCs:

  • Module One: Controller to Controller โ€” applied when transferring data between our entities acting as independent controllers.
  • Module Two: Controller to Processor โ€” applied when we engage a processor in a third country to process data on our behalf.
  • Module Three: Processor to Processor โ€” applied when our subprocessors in third countries process data.
  • Module Four: Processor to Controller โ€” applied in specific data return scenarios.

Transfer Impact Assessments

In line with the Schrems II ruling (C-311/18), we conduct Transfer Impact Assessments (TIAs) for all transfers relying on SCCs. Each TIA evaluates:

  • The legal framework of the destination country, including surveillance laws and access by public authorities.
  • The technical and organizational safeguards in place.
  • Whether supplementary measures are needed and whether they are effective.
๐Ÿ”
Identify Transfer
Data, roles, destination
โ†’
๐Ÿ“‹
Conduct TIA
Assess legal landscape
โ†’
๐Ÿ›ก๏ธ
Apply Safeguards
SCCs + supplementary
โ†’
โœ…
Authorize Transfer
Document & monitor

Transfer Mechanisms

The following mechanisms are available under EU and UK data protection law. We select the most appropriate mechanism based on the circumstances of each transfer.

Mechanism Legal Basis When Used
Adequacy Decision Art. 45 GDPR Transfers to countries with an EU or UK adequacy decision (e.g., Japan, Canada, Argentina)
Standard Contractual Clauses Art. 46(2)(c) GDPR Transfers to countries without adequacy, where additional safeguards are required
Binding Corporate Rules Art. 47 GDPR Intra-group transfers between That Is A Q entities worldwide
UK IDTA / Addendum Art. 46 UK GDPR Transfers originating from the UK outside the EEA
Derogations Art. 49 GDPR Exceptional cases: explicit consent, contract performance, important reasons of public interest

Transfer Destinations

That Is A Q transfers personal data to the following jurisdictions. The mechanism and safeguards vary by destination.

Country Region Mechanism Status
United States North America EUโ€“US DPF / SCCs + Supplementary Active
India South Asia SCCs + Supplementary Active
Singapore Southeast Asia SCCs + Supplementary Active
Brazil South America SCCs + Supplementary Active
Canada North America Adequacy (commercial orgs) Active
Japan East Asia Adequacy Decision Active
South Korea East Asia SCCs + Supplementary Review
โš ๏ธ Note on the EUโ€“US Data Privacy Framework

For transfers to the United States, we leverage the EUโ€“US Data Privacy Framework (DPF) where applicable, alongside SCCs and supplementary measures. We continuously monitor the legal landscape, including challenges to the DPF and any changes to US surveillance law.

Supplementary Safeguards

Beyond contractual measures, That Is A Q implements technical and organizational safeguards to ensure an essentially equivalent level of protection for data transferred internationally.

Technical Measures

  • Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Encryption keys are managed separately from encrypted data.
  • Pseudonymization: Where possible, personal data is pseudonymized before transfer. Re-identification requires additional authentication and authorization.
  • Access Controls: Role-based access controls (RBAC) and multi-factor authentication (MFA) restrict data access to authorized personnel only.
  • Data Minimization: Only data strictly necessary for the intended purpose is transferred. We regularly review data flows to eliminate unnecessary transfers.
  • Deletion Policies: Retention periods are enforced automatically. Data is securely deleted when no longer needed.

Organizational Measures

  • Data Protection Training: All employees receive mandatory annual training on data protection and international transfer obligations.
  • Vendor Management: Subprocessors are vetted for compliance with SCCs and data protection standards before engagement.
  • Audits & Monitoring: We conduct regular audits of our data processing activities and subcontractor arrangements.
  • Incident Response: Our data breach response plan includes specific procedures for cross-border transfer incidents.

Data Subject Rights

Individuals whose personal data is transferred internationally retain all rights granted under applicable data protection law, regardless of where their data is processed.

Your Rights Include:

  • Right of Access โ€” to obtain a copy of your personal data and information about how it is processed.
  • Right to Rectification โ€” to correct inaccurate or incomplete data.
  • Right to Erasure โ€” to request deletion of your data under certain conditions.
  • Right to Restrict Processing โ€” to limit how we process your data.
  • Right to Data Portability โ€” to receive your data in a machine-readable format.
  • Right to Object โ€” to object to processing based on legitimate interests or direct marketing.
  • Right to Lodge a Complaint โ€” with a supervisory authority in your jurisdiction.

International data transfers do not affect or limit any of these rights. If you wish to exercise any of these rights, please contact our Data Protection Officer using the details below.

Liaison Officer

In accordance with the EU SCCs (Clause 17), That Is A Q has designated a liaison officer to receive and address requests from data subjects and data protection authorities in relation to international data transfers.

๐Ÿ“ง Liaison Contact

Name: Data Protection Officer
Email: dpo@thatisaq.com
Address: That Is A Q, [Registered Office Address], [Country]
Response Time: We aim to respond within 30 days of receiving a request.

Data protection authorities may also contact us at the same address to exercise their supervisory functions or request information about our transfer practices.

Questions or Concerns?

If you have questions about our international data transfer practices, need a copy of the SCCs we rely on, or wish to exercise your data protection rights, please don't hesitate to reach out.

Get in Touch with Our Data Protection Team

We're here to help you understand how your data is protected when it crosses borders.

โœ‰๏ธ dpo@thatisaq.com