Expert knowledge for digital decisions
What Requirements Apply to Data Location and Subcontractors in AI?
Short answer
Requirements for Data Location
The General Data Protection Regulation (GDPR) sets clear requirements for the location where personal data is processed. In principle, data may only be processed in countries that provide an adequate level of data protection. This means that companies must ensure that data processing occurs within the European Union or in a country that has been deemed safe by the European Commission. When processing data outside these regions, additional measures are required to ensure data protection. These include, among others, standard contractual clauses or binding internal data protection regulations.
Requirements for Subcontractors
When companies engage subcontractors to process data, they must ensure that these subcontractors also comply with the requirements of the GDPR. This includes the necessity of entering into a written contract that clearly outlines the data protection obligations of the subcontractor. The contract should include, among other things:
- The type of data processed
- The purposes of processing
- The security measures that the subcontractor must implement
- Provisions to assist the primary processor in fulfilling its obligations
Furthermore, it is important to regularly verify whether subcontractors are adhering to the agreed standards. This can be done through audits or regular reporting.
Conclusion
Compliance with the requirements for data location and regulations for subcontractors is crucial for the legally secure use of AI technologies. Companies should therefore thoroughly inform themselves about the applicable regulations and ensure that all contractual and technical measures are taken to protect personal data.
Key facts
- Data Location
- Compliance with GDPR
- Subcontractors
- Contractual regulations required
Sources
All external claims are backed by traceable sources.- 01
-
02
Datenschutz-Grundverordnung (Verordnung (EU) 2016/679) EUR-Lex / Europäische Union
-
03
Artificial Intelligence Risk Management Framework (AI RMF 1.0) National Institute of Standards and Technology (NIST)