• Latest
  • Trending
Designing your SaaS solution in compliance with data protection regulations as a US company!

Designing your SaaS solution in compliance with data protection regulations as a US company!

5. January 2021
BGH considers Uber Black to be anti-competitive

Distance learning, coaching and synchronous online formats

2. March 2026
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026
Insolvency administrator and access to tax office data?

NRW audits influencers – and suddenly normal rules apply?

12. February 2026
iStock 1405433207 scaled

Legal pitfalls in revenue-based financing for start-ups

12. February 2026
Streaming setup, influencers and contract law

Streaming setup, influencers and contract law

9. February 2026
Platform cooperatives as a financing and business model

Platform cooperatives as a financing and business model

8. February 2026
Frankfurt district court a.M. softens influencer jurisdiction

VAT on donations, gifts and “support” from influencers?

5. February 2026
Chamber Court on obligations to injuntture in the case of acts of third parties

Jurisdiction in the contract: one word too many, one word too few

4. February 2026
New info on the status of the State Media Treaty

Customer hotline and support in SaaS

2. February 2026
BGH considers Uber Black to be anti-competitive

BGH: FRAND objection fails due to lack of willingness to license

28. January 2026
marianregel

InformationCheck.de is live: side project for source-based classification of social media claims

22. January 2026
DPMA

Paid mods, fan guidelines and EULA: when monetization is possible

21. January 2026
Is an 8 year old allowed to be an Esport player?

LOI, term sheet, MoU, often binding for startups?

20. January 2026
What actually is an IP? In the games, music and film industry!

Freelancer paid, but still not getting rights?

19. January 2026
Affiliate links for streamers and influencers

Comparison sites as an SEO trick

16. January 2026
Reverse vesting

Vesting, good leavers, bad leavers – why a lack of regulations costs startups dearly

15. January 2026
ai generated g63ed67bf8 1280

AI guideline for agencies and external service providers

14. January 2026
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Designing your SaaS solution in compliance with data protection regulations as a US company!

5. January 2021
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
communication 1927706 1280 384x192 1

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission’s Decision 2016/1250 on the transfer of personal data to the United States (Privacy Shield) invalid. At the same time, the ECJ found that Commission Decision 2010/87/EC on standard contractual clauses remains valid in principle.

Content Hide
1. What are the consequences of the decision according to the current state of discussion?
2. Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.
3. So what do providers who transfer data to the USA need to do?
4. The opportunity for a competitive advantage
4.1. Author: Marian Härtel
Key Facts
  • European Court of Justice declared Privacy Shield invalid on July 16, 2020
  • The standard contractual clauses from 2010 remain valid, but with additional conditions for data protection.
  • Over 5,300 companies lose the legal basis for transferring data to the USA.
  • The use of unencrypted data is insecure and inadmissible due to the powers of the US authorities.
  • Companies have to disclose customer information, which puts them at a competitive disadvantage.
  • Obtain the consent of the data subjects for data transfers to the USA.
  • The decision offers opportunities for SaaS providers to adapt their business models and gain competitive advantages.

As a result of this decision, it is now questionable whether and under what circumstances a US company can offer a SAAS solution in Europe or, more precisely, whether someone in Europe can use the SaaS solution of a US provider without committing a breach of data protection by using it.

What are the consequences of the decision according to the current state of discussion?

The decision deprived more than 5,300 registered companies as processors of the legal basis for transferring and receiving data. The main justification for this is that data transferred to the USA can be processed by the authorities there for the purposes of public security, national defense and national security. As an alternative, there are now only the standard contractual clauses as regulated in Decision 2010/87/EU of 05.02.2010. Theoretically, these can still be used, but only if the level of protection of the GDPR can be guaranteed during and after the transfer by the processor based in the USA. This is unlikely to be the case, at least for unencrypted data and for companies that are not 100% independent of a US company under group law.

Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.

Following the ruling, the supervisory authorities will, indeed must, press for the standard contractual clauses to be adapted in line with the ruling. However, it is to be expected that processors will not be able to guarantee the GDPR level of protection due to the far-reaching powers of the US authorities under Section 702 of the Foreign Intelligence Surveillance Act. The transfer of data to the USA is therefore not permitted. According to the ECJ ruling, national authorities are even obliged under Art. 58 (2) f) and j) GDPR to suspend or prohibit data traffic with the USA and to impose heavy fines in the event of a violation. Non-European companies that want to process data from Europeans, be it in the area of streaming, cloud, data processing, etc., will have a hard time. Those who process customer data directly may have three options, but all of them will be difficult to implement.

  1. Customers can be fully informed about the circumstances where and which data is processed and which persons and authorities in the USA have access to this data, possibly even if this data is stored on European servers. As this customer consent may not be hidden in general terms and conditions and must be comprehensive, this is likely to be at least a major competitive disadvantage.
  2. Data can be fully encrypted. And “end to end”. The future will show to what extent this is technically possible, e.g. for streaming solutions etc., where not only the person who uploads the data has access again. It is clear that US providers will require extensive technical updates, adjustments to server structures, legal adjustments and possibly also adjustments to business models.
  3. The data of Europeans may only be processed by companies that are involved in the transfer of data to a US company under group law or by contract. If at all, providers must establish independent European subsidiaries that are only linked to the US company via profit transfer or license agreements, for example. The extent to which this is practicable for the majority of US providers is difficult to assess.

So what do providers who transfer data to the USA need to do?

  • First of all, it must be checked whether there are data processes with the USA that are still based solely on the EU Privacy Shield. This is the obligation of every controller as part of the processing directory pursuant to Art. 30 GDPR. If this is the case, the transfer must be stopped immediately and alternatives must be examined as to how the conversion of the data processes can be managed while remaining in the EU.
  • If standard contractual clauses are used in addition to the EU Privacy Shield or if these must be agreed as an alternative, it must be checked in accordance with the ECJ ruling whether the level of protection can be complied with. Otherwise, data traffic must also be avoided. Under certain circumstances, the standard contractual clauses could be supplemented to the effect that requests from US authorities must be disclosed to the controller so that it can react in such cases and, under certain circumstances, inform its customers or other data subjects of this. Consideration should also be given to having the so-called Binding Corporate Rules approved by the national supervisory authorities in accordance with Art. 47 GDPR. However, this involves a long and cumbersome process.
  • The most important measure to be taken immediately is to obtain the consent of each data subject in accordance with Art. 49 para. 1 a) GDPR. Alternatively, the transfer of data must be based on Art. 49 para. 1 c) GDPR, according to which this is necessary for the performance of a contract between the data subject and the controller. However, this requires a corresponding data protection declaration. However, this legal basis is only a temporary remedy for individual cases and cannot be used for the regular transfer of data to the USA.

The opportunity for a competitive advantage

Even if the ECJ, as an independent judicial body, cannot be assumed to have political intentions, this ruling and the situation can be a great opportunity for a SaaS provider to change its corporate structure and/or business concept in such a way that the above-mentioned points are fulfilled. This would represent a major competitive advantage over all other providers and would also be a great opportunity for marketing, growth and a highly interesting investment case.

The Federal Data Protection Commissioner has also brought into play options for simple data storage such as pseudonymization or the use of trustees who process data on behalf of US companies and who do not have to grant access to US security authorities. As this will take a long time to implement for larger providers, there are enormous opportunities here for smaller, agile providers.

I have and can provide comprehensive advice on these issues and help US providers to create the corporate and other contractual foundations to take advantage of this opportunity.

Simply contact me without obligation and let’s find out how I can help you to offer your own SaaS solution in Germany in a legally compliant manner!

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AGBCompetitive advantageCorporateCustomizationInvestmentLizenzmarketingModelPrivacySaasServerSicherheitStandard contractual clausesVerträge

Weitere spannende Blogposts

OLG Frankfurt on discount campaigns and fixed book prices on eBay

False gold bars may also be sold on Ebay
16. March 2023

eBay itself is not subject to the requirements of the Book Price Fixing Act. Its one-off advent discount campaign, in...

Read moreDetails

Image posting in closed FB group may infringe copyright

copyright
7. November 2022

Posting an image in the closed group on Facebook may be public copying and thus infringe copyrights. The Munich Regional...

Read moreDetails

BFH and the taxation of gains from the sale of cryptocurrencies?

Bitcoin trading not subject to licensing
27. January 2023

What has been decided so far? Gains realized from the sale of cryptocurrencies are subject to income tax as part...

Read moreDetails

GAME founds exploitation company!

GAME founds exploitation company!
31. May 2023

In an exciting but certainly trend-setting development, the GAME Bundesverband, the leading association of the German computer games industry, has...

Read moreDetails

Kammergericht: No ancillary copyright for computer graphics

7. November 2022

An interesting ruling from my field of IT law comes from the Kammergericht in Berlin. It deals with the question...

Read moreDetails

Customer reviews through sweepstakes? Warning!

Customer reviews through sweepstakes? Warning!
19. June 2019

Sweepstakes are a tried and tested means of marketing for many online retailers, both on their own website and in...

Read moreDetails

#FreedomOfTagging: Influencer and the VSW

Brief reminder: Influencer as target of warning letters
21. December 2018

Influencer marketing is currently a hot topic again. This time it concerns Instagram influencer Vanessa Blumenthal, who continues to be...

Read moreDetails

What legal form as an esport team?

What legal form as an esport team?
7. November 2022

What legal form should you aim for if you want to start or professionalize an esports team? The answer to...

Read moreDetails

Sweepstakes and illegal image use

Facebook: New rulings on deletion claims
21. October 2019

The "Bild am Sonntag" was not allowed to use a picture of the former "dream ship captain" as part of...

Read moreDetails
BGH considers Uber Black to be anti-competitive
Law and Esport

Distance learning, coaching and synchronous online formats

2. March 2026

The Distance Learning Protection Act (FernUSG) has been experiencing a renaissance for some time now. What for decades was considered...

Read moreDetails
Media outlets consider influencers law pointless

Manipulated QR codes and quishing

27. February 2026
AI agents as autonomous contractual partners?

AI agents as autonomous contractual partners?

26. February 2026
Platform cooperatives as a financing and business model

AI training data as an asset: accounting, IP strategy and exit factor

25. February 2026
Streaming setup, influencers and contract law

Influencers: when marketing suddenly becomes commercial agency law

18. February 2026

Podcastfolge

238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024

This informative podcast offers a comprehensive insight into the legal challenges faced by start-ups when expanding internationally. The experienced lawyer...

Read moreDetails
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024
Legal challenges in the gaming universe: A guide for developers, esports professionals and gamers

What will 2025 bring for start-ups in legal terms? Opportunities? Risks?

24. January 2025
c9c5d7fd380061a8018074c2ca5a81bf

Startups and innovation in Germany – challenges and opportunities

26. September 2024
d5ab3414c7c4a7a5040c3c3c60451c44

The metaverse – legal challenges in virtual worlds

26. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung