Kostenlose Kurzberatung
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
ITMediaLaw - Rechtsanwalt Marian Härtel
Warenkorb
Plugin Install : Cart Icon need WooCommerce plugin to be installed.
  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Sonstiges
      • Terms
      • Privacy policy
      • Imprint
  • Leistungen
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Kurz-Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • E-Books
  • Beratung
  • Kostenlose Vertragsmuster
  • Freebies
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Sonstiges
      • Terms
      • Privacy policy
      • Imprint
  • Leistungen
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Kurz-Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • E-Books
  • Beratung
  • Kostenlose Vertragsmuster
  • Freebies
ITMediaLaw - Rechtsanwalt Marian Härtel

ITMediaLaw - Rechtsanwalt Marian Härtel > Data protection Law > Designing your SaaS solution in compliance with data protection regulations as a US company!

Designing your SaaS solution in compliance with data protection regulations as a US company!

5. January 2021
in Data protection Law
Reading Time: 4 mins read
0 0
A A
0
communication 1927706 1280 384x192 1
Key Facts
  • European Court of Justice declared Privacy Shield invalid on July 16, 2020
  • The standard contractual clauses from 2010 remain valid, but with additional conditions for data protection.
  • Over 5,300 companies lose the legal basis for transferring data to the USA.
  • The use of unencrypted data is insecure and inadmissible due to the powers of the US authorities.
  • Companies have to disclose customer information, which puts them at a competitive disadvantage.
  • Obtain the consent of the data subjects for data transfers to the USA.
  • The decision offers opportunities for SaaS providers to adapt their business models and gain competitive advantages.

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission’s Decision 2016/1250 on the transfer of personal data to the United States (Privacy Shield) invalid. At the same time, the ECJ found that Commission Decision 2010/87/EC on standard contractual clauses remains valid in principle.

Content Hide
1. What are the consequences of the decision according to the current state of discussion?
2. Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.
3. So what do providers who transfer data to the USA need to do?
4. The opportunity for a competitive advantage

As a result of this decision, it is now questionable whether and under what circumstances a US company can offer a SAAS solution in Europe or, more precisely, whether someone in Europe can use the SaaS solution of a US provider without committing a breach of data protection by using it.

What are the consequences of the decision according to the current state of discussion?

The decision deprived more than 5,300 registered companies as processors of the legal basis for transferring and receiving data. The main justification for this is that data transferred to the USA can be processed by the authorities there for the purposes of public security, national defense and national security. As an alternative, there are now only the standard contractual clauses as regulated in Decision 2010/87/EU of 05.02.2010. Theoretically, these can still be used, but only if the level of protection of the GDPR can be guaranteed during and after the transfer by the processor based in the USA. This is unlikely to be the case, at least for unencrypted data and for companies that are not 100% independent of a US company under group law.

Simply maintaining a server in the European Union, at least without encrypting the data, is probably not enough.

Following the ruling, the supervisory authorities will, indeed must, press for the standard contractual clauses to be adapted in line with the ruling. However, it is to be expected that processors will not be able to guarantee the GDPR level of protection due to the far-reaching powers of the US authorities under Section 702 of the Foreign Intelligence Surveillance Act. The transfer of data to the USA is therefore not permitted. According to the ECJ ruling, national authorities are even obliged under Art. 58 (2) f) and j) GDPR to suspend or prohibit data traffic with the USA and to impose heavy fines in the event of a violation. Non-European companies that want to process data from Europeans, be it in the area of streaming, cloud, data processing, etc., will have a hard time. Those who process customer data directly may have three options, but all of them will be difficult to implement.

  1. Customers can be fully informed about the circumstances where and which data is processed and which persons and authorities in the USA have access to this data, possibly even if this data is stored on European servers. As this customer consent may not be hidden in general terms and conditions and must be comprehensive, this is likely to be at least a major competitive disadvantage.
  2. Data can be fully encrypted. And “end to end”. The future will show to what extent this is technically possible, e.g. for streaming solutions etc., where not only the person who uploads the data has access again. It is clear that US providers will require extensive technical updates, adjustments to server structures, legal adjustments and possibly also adjustments to business models.
  3. The data of Europeans may only be processed by companies that are involved in the transfer of data to a US company under group law or by contract. If at all, providers must establish independent European subsidiaries that are only linked to the US company via profit transfer or license agreements, for example. The extent to which this is practicable for the majority of US providers is difficult to assess.

So what do providers who transfer data to the USA need to do?

  • First of all, it must be checked whether there are data processes with the USA that are still based solely on the EU Privacy Shield. This is the obligation of every controller as part of the processing directory pursuant to Art. 30 GDPR. If this is the case, the transfer must be stopped immediately and alternatives must be examined as to how the conversion of the data processes can be managed while remaining in the EU.
  • If standard contractual clauses are used in addition to the EU Privacy Shield or if these must be agreed as an alternative, it must be checked in accordance with the ECJ ruling whether the level of protection can be complied with. Otherwise, data traffic must also be avoided. Under certain circumstances, the standard contractual clauses could be supplemented to the effect that requests from US authorities must be disclosed to the controller so that it can react in such cases and, under certain circumstances, inform its customers or other data subjects of this. Consideration should also be given to having the so-called Binding Corporate Rules approved by the national supervisory authorities in accordance with Art. 47 GDPR. However, this involves a long and cumbersome process.
  • The most important measure to be taken immediately is to obtain the consent of each data subject in accordance with Art. 49 para. 1 a) GDPR. Alternatively, the transfer of data must be based on Art. 49 para. 1 c) GDPR, according to which this is necessary for the performance of a contract between the data subject and the controller. However, this requires a corresponding data protection declaration. However, this legal basis is only a temporary remedy for individual cases and cannot be used for the regular transfer of data to the USA.

The opportunity for a competitive advantage

Even if the ECJ, as an independent judicial body, cannot be assumed to have political intentions, this ruling and the situation can be a great opportunity for a SaaS provider to change its corporate structure and/or business concept in such a way that the above-mentioned points are fulfilled. This would represent a major competitive advantage over all other providers and would also be a great opportunity for marketing, growth and a highly interesting investment case.

The Federal Data Protection Commissioner has also brought into play options for simple data storage such as pseudonymization or the use of trustees who process data on behalf of US companies and who do not have to grant access to US security authorities. As this will take a long time to implement for larger providers, there are enormous opportunities here for smaller, agile providers.

I have and can provide comprehensive advice on these issues and help US providers to create the corporate and other contractual foundations to take advantage of this opportunity.

Simply contact me without obligation and let’s find out how I can help you to offer your own SaaS solution in Germany in a legally compliant manner!

Tags: AGBCompetitive advantageCorporateCustomizationInvestmentLizenzmarketingModelPrivacySaasServerSicherheitStandard contractual clausesVerträge

Weitere spannende Blogposts

Warning because of double optin e-mail

Warning because of double optin e-mail
7. November 2022

Today I became aware of a decision of the Berlin Regional Court that obligated a sender of a confirmation e-mail...

Read moreDetails

Drafting contracts for SaaS companies: Tips from an IT law expert

Drafting contracts for SaaS companies: Tips from an IT law expert
10. October 2024

Software as a Service (SaaS) has established itself as the dominant business model in the IT industry. For SaaS companies,...

Read moreDetails

Withholding tax and Google Ads

HOT/Important: Google Ads tax liability trap
7. November 2022

On Saturday I reported in detail on the issue of withholding tax on Google Ads / Adwords. Although I was...

Read moreDetails

Legal aspects of the use of AI in marketing

Legal aspects of the use of AI in marketing
11. August 2023

In recent years, artificial intelligence (AI) has emerged as a transformative technology across numerous industries, with the marketing sector standing...

Read moreDetails

Contract for work vs. contract for services: What you need to know in the IT, software and Esports sector

New info on the status of the State Media Treaty
22. September 2023

Introduction: Why the right type of contract is crucial There are many gray areas in the world of contracts that...

Read moreDetails

BGH refers question on data protection and competition law to the ECJ

Data protection: “Targeted advertising” through “legitimate interest” at the end? EDPB vs. meta
12. January 2023

The First Civil Senate of the Federal Court of Justice, which is responsible for competition law, has referred the questions...

Read moreDetails

Missing/incorrect data protection declaration liable to a warning?

Missing/incorrect data protection declaration liable to a warning?
7. November 2022

This question is currently not so easy to answer, because the case law is currently wildly mixed. Even in pre-DSGVO...

Read moreDetails

France: Steam must allow resale of games

frankreich steam muss weiterverkauf von spielen ermoeglichen 3
20. September 2019

Steam and other providers of computer game licenses are currently under pressure in Europe to violate the Geo-blocking Regulation(see this...

Read moreDetails

Tax law: What’s new in tax law besides home office?

Risk Social Security / Tax audit for streamers, esports enthusiasts, etc.
7. November 2022

Two days after the Bundestag, the Bundesrat also approved numerous new rules in tax law on 18.12.2020. The law can...

Read moreDetails
880085a7e6ef3e5c780e702f73241a53

silent partnership

25. June 2023

A silent partnership is a form of corporate finance in which an individual or entity invests capital in a company...

Read moreDetails
Greenwashing: what it is and why it might violate competition law

Greenwashing

29. March 2025

Hamburg custom

26. June 2023
Never, Never, Never Sign a Contract Without a Lawyer

Letter of Intent (LOI)

24. June 2023
Design / Design

Design / Design

26. June 2023

Podcast Folgen

Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

Rechtliche Basics für Startup-Gründer – So startest du auf der sicheren Seite!

1. November 2024

In dieser Episode des Itmedialaw Podcasts nimmt euch Rechtsanwalt und Unternehmer Marian Härtel mit auf eine Reise durch den rechtlichen...

Juristische Trends für Startups 2025: Chancen und Herausforderungen

Juristische Trends für Startups 2025: Chancen und Herausforderungen

19. April 2025

In dieser Episode beleuchten wir die rechtlichen Entwicklungen, die das Startup-Umfeld 2025 prägen werden. Von der KI-Regulierung über neue Kryptowährungsrichtlinien...

KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

KI im Recht: Chancen, Risiken und Regulierung – der IT Media Law Podcast Episode 3

28. August 2024

Willkommen zur dritten Episode unseres Podcasts "IT Media Law"! In dieser Folge tauchen wir ein in die faszinierende Welt der...

Rechtliche Herausforderungen im Gaming-Universum: Ein Leitfaden für Entwickler, Esportler und Gamer

Was wird 2025 für Startups juristisch bringen? Chancen? Risiken?

24. January 2025

In dieser spannenden Episode des itmedialaw-Podcasts tauchen wir tief in die rechtlichen Entwicklungen ein, die die Startup-Welt im Jahr 2025...

  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Sonstiges
      • Terms
      • Privacy policy
      • Imprint
  • Leistungen
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Kurz-Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung