Description
This article examines how the EU’s GDPR data controls and GCC data localization policies interact with each other and the impact this has on both outbound and inbound data flows between the two jurisdictions. The ability of a European firm to send protected personal data out of Europe is regulated by Article 45 of the GDPR which mandates recipient jurisdictions deemed ‘adequate’ by the European Commission in terms data protection laws. In countries where data localization laws exist, it is not merely a question of getting data out of Europe but also comply with local laws to store that data domestically. In jurisdictions like the GCC, that have yet to achieve the ‘adequate’ designation, this has created a number of challenges for European firms seeking to expand into that region. The article concludes by offering guidance on how firms are dealing with this dilemma in both technical and legal terms.



Reviews
There are no reviews yet.