• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
SAVED POSTS
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Designing your SaaS solution in compliance with data protection regulations as a US company!

5. January 2021
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
communication 1927706 1280 384x192 1
Key Facts
  • European Court of Justice declared Privacy Shield invalid on July 16, 2020
  • The standard contractual clauses from 2010 remain valid, but with additional conditions for data protection.
  • Over 5,300 companies lose the legal basis for transferring data to the USA.
  • The use of unencrypted data is insecure and inadmissible due to the powers of the US authorities.
  • Companies have to disclose customer information, which puts them at a competitive disadvantage.
  • Obtain the consent of the data subjects for data transfers to the USA.
  • The decision offers opportunities for SaaS providers to adapt their business models and gain competitive advantages.

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission’s Decision 2016/1250 on the transfer of personal data to the United States (Privacy Shield) invalid. At the same time, the ECJ found that Commission Decision 2010/87/EC on standard contractual clauses remains valid in principle.

Content Hide
1. What are the consequences of the decision according to the current state of discussion?
2. Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.
3. So what do providers who transfer data to the USA need to do?
4. The opportunity for a competitive advantage
4.1. Author: Marian Härtel

As a result of this decision, it is now questionable whether and under what circumstances a US company can offer a SAAS solution in Europe or, more precisely, whether someone in Europe can use the SaaS solution of a US provider without committing a breach of data protection by using it.

What are the consequences of the decision according to the current state of discussion?

The decision deprived more than 5,300 registered companies as processors of the legal basis for transferring and receiving data. The main justification for this is that data transferred to the USA can be processed by the authorities there for the purposes of public security, national defense and national security. As an alternative, there are now only the standard contractual clauses as regulated in Decision 2010/87/EU of 05.02.2010. Theoretically, these can still be used, but only if the level of protection of the GDPR can be guaranteed during and after the transfer by the processor based in the USA. This is unlikely to be the case, at least for unencrypted data and for companies that are not 100% independent of a US company under group law.

Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.

Following the ruling, the supervisory authorities will, indeed must, press for the standard contractual clauses to be adapted in line with the ruling. However, it is to be expected that processors will not be able to guarantee the GDPR level of protection due to the far-reaching powers of the US authorities under Section 702 of the Foreign Intelligence Surveillance Act. The transfer of data to the USA is therefore not permitted. According to the ECJ ruling, national authorities are even obliged under Art. 58 (2) f) and j) GDPR to suspend or prohibit data traffic with the USA and to impose heavy fines in the event of a violation. Non-European companies that want to process data from Europeans, be it in the area of streaming, cloud, data processing, etc., will have a hard time. Those who process customer data directly may have three options, but all of them will be difficult to implement.

  1. Customers can be fully informed about the circumstances where and which data is processed and which persons and authorities in the USA have access to this data, possibly even if this data is stored on European servers. As this customer consent may not be hidden in general terms and conditions and must be comprehensive, this is likely to be at least a major competitive disadvantage.
  2. Data can be fully encrypted. And “end to end”. The future will show to what extent this is technically possible, e.g. for streaming solutions etc., where not only the person who uploads the data has access again. It is clear that US providers will require extensive technical updates, adjustments to server structures, legal adjustments and possibly also adjustments to business models.
  3. The data of Europeans may only be processed by companies that are involved in the transfer of data to a US company under group law or by contract. If at all, providers must establish independent European subsidiaries that are only linked to the US company via profit transfer or license agreements, for example. The extent to which this is practicable for the majority of US providers is difficult to assess.

So what do providers who transfer data to the USA need to do?

  • First of all, it must be checked whether there are data processes with the USA that are still based solely on the EU Privacy Shield. This is the obligation of every controller as part of the processing directory pursuant to Art. 30 GDPR. If this is the case, the transfer must be stopped immediately and alternatives must be examined as to how the conversion of the data processes can be managed while remaining in the EU.
  • If standard contractual clauses are used in addition to the EU Privacy Shield or if these must be agreed as an alternative, it must be checked in accordance with the ECJ ruling whether the level of protection can be complied with. Otherwise, data traffic must also be avoided. Under certain circumstances, the standard contractual clauses could be supplemented to the effect that requests from US authorities must be disclosed to the controller so that it can react in such cases and, under certain circumstances, inform its customers or other data subjects of this. Consideration should also be given to having the so-called Binding Corporate Rules approved by the national supervisory authorities in accordance with Art. 47 GDPR. However, this involves a long and cumbersome process.
  • The most important measure to be taken immediately is to obtain the consent of each data subject in accordance with Art. 49 para. 1 a) GDPR. Alternatively, the transfer of data must be based on Art. 49 para. 1 c) GDPR, according to which this is necessary for the performance of a contract between the data subject and the controller. However, this requires a corresponding data protection declaration. However, this legal basis is only a temporary remedy for individual cases and cannot be used for the regular transfer of data to the USA.

The opportunity for a competitive advantage

Even if the ECJ, as an independent judicial body, cannot be assumed to have political intentions, this ruling and the situation can be a great opportunity for a SaaS provider to change its corporate structure and/or business concept in such a way that the above-mentioned points are fulfilled. This would represent a major competitive advantage over all other providers and would also be a great opportunity for marketing, growth and a highly interesting investment case.

The Federal Data Protection Commissioner has also brought into play options for simple data storage such as pseudonymization or the use of trustees who process data on behalf of US companies and who do not have to grant access to US security authorities. As this will take a long time to implement for larger providers, there are enormous opportunities here for smaller, agile providers.

I have and can provide comprehensive advice on these issues and help US providers to create the corporate and other contractual foundations to take advantage of this opportunity.

Simply contact me without obligation and let’s find out how I can help you to offer your own SaaS solution in Germany in a legally compliant manner!

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AGBCompetitive advantageCorporateCustomizationInvestmentLizenzmarketingModelPrivacySaasServerSicherheitStandard contractual clausesVerträge

Weitere spannende Blogposts

Geoblocking: A Turning Point for the Digital Single Market?

Lego brick still protected as a design patent
4. October 2023

Introduction Geoblocking is a complex but highly relevant issue that affects not only online stores, but also a wide range...

Read moreDetails

Esport Teams & Streamer: What is part of a sponsorship agreement?

Terms and Conditions and Prohibited Clauses
10. December 2019

I regularly receive sponsorship agreements from clients with which companies or advertisers want to engage with esports teams or enter...

Read moreDetails

Cookies for advertising purposes only with the active consent of the user

ECJ: Cookies require explicit consent of users
5. June 2020

The BGH has ruled on the question of the requirements for consent to telephone advertising and the storage of cookies...

Read moreDetails

Streamers, marketing agencies and the artists’ social security fund

Streamers, marketing agencies and the artists’ social security fund
7. November 2022

Recently, it has happened more and more that larger streamers but especially marketing agencies, influencer agencies or managers have to...

Read moreDetails

Why ‘Payable within 14 days’ on your invoice could be legal nonsense ;-)

Why ‘Payable within 14 days’ on your invoice could be legal nonsense ;-)
13. June 2023

Introduction: In my career, I have often seen the phrase "Payable within 14 days" on invoices. It's almost as if...

Read moreDetails

ECJ tightens requirements for GDPR disclosures

Data protection: “Targeted advertising” through “legitimate interest” at the end? EDPB vs. meta
19. January 2023

The European Court of Justice (ECJ) has ruled that data controllers must, in principle, disclose the identity of the recipients...

Read moreDetails

Consumer’s right of withdrawal for teak trees in Costa Rica with a Swiss company

BGH considers Uber Black to be anti-competitive
17. May 2024

On the right of withdrawal of a consumer residing in Germany when concluding "purchase and service contracts" for teak trees...

Read moreDetails

Attention with Facebook-Like and similar plugins

LG Munich: Data protection consent on dating platform
7. November 2021

The possibility to include Facebook Like as a plugin, for example, has been controversial for a long time. This is...

Read moreDetails

Contracts in IT law – everything always in writing

Contracts in IT law – everything always in writing
7. November 2022

I feel that 10% of my work as a lawyer consists of people or companies in IT law trusting each...

Read moreDetails
Q&A: Rechtsfragen für Spieleentwickler
Law and computer games

5‑Tage‑Guide: Gründung eines Spieleentwickler‑Studios

5. August 2025

Als Unterstützung für junge Studios fasst diese Serie die wesentlichen Schritte zur Gründung einer Spieleentwicklung zusammen. Der Leitfaden gliedert sich...

Read moreDetails
EU Inc: Warum Europa jetzt eine einheitliche Startup-Gesellschaft braucht

EU Inc: Warum Europa jetzt eine einheitliche Startup-Gesellschaft braucht

22. July 2025
BGH hält Uber Black für wettbewerbswidrig

BGH erschüttert Coachingbranche – Was gilt nun?

21. July 2025
Growth Hacking und virales Marketing – Juristische Anforderungen

Games-Förderung 2025 – endlich zurück!

20. July 2025
Eigentum an Software – Wem gehört eigentlich der Code?

Eigentum an Software – Wem gehört eigentlich der Code?

14. July 2025

Podcastfolge

Der IT Media Law Podcast. Folge Nr. 1: Worum geht es hier eigentlich?

Der IT Media Law Podcast. Folge Nr. 1: Worum geht es hier eigentlich?

26. August 2024

Yeah, die erste richtige Folge mit mir selbst! In diesem Podcast tauchen wir ein in die spannende Welt des IT-Rechts...

Read moreDetails
Web3, Blockchain und Recht – Eine kritische Bestandsaufnahme

Web3, Blockchain und Recht – Eine kritische Bestandsaufnahme

25. September 2024
KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

28. August 2024
Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

1. November 2024
Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

Rechtliche Risiken bei langen Entwicklungszeiten und der Stornierung von Crowdfundingspielen

20. April 2025

Video

Mein transparente Abrechnung

Mein transparente Abrechnung

10. February 2025

In diesem Video rede ich ein wenig über transparente Abrechnung und wie ich kommuniziere, was es kostet, wenn man mit...

Read moreDetails
Faszination zwischen und Recht und Technologie

Faszination zwischen und Recht und Technologie

10. February 2025
Meine zwei größten Herausforderungen sind?

Meine zwei größten Herausforderungen sind?

10. February 2025
Was mich wirklich freut

Was mich wirklich freut

10. February 2025
Was ich an meinem Job liebe!

Was ich an meinem Job liebe!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung