Skip to the page
WAKE UP EUROPEResponsibility

Who answers for it, and how far that reaches.

The supplier is subject to another country’s law. The duty to have chosen them, and to be able to show why, stays in Europe with the organisation that made the choice.

Who the law asks

European law puts the question to the organisation that decided to use the tool, not to the company that sold it. That is true of a tool bought through procurement and equally true of one a department started using on its own.

  1. GDPR Article 28(1)in force · checked 2026-09-22The organisation that decided to use the tool

    Choosing who runs it is the decision European law puts on the buyer

    The duty is not to have signed a contract. It is to have used only a supplier offering sufficient guarantees. Guarantees about what can be compelled from that supplier are part of what the word covers, and the assessment belongs to the buyer rather than to the seller who wrote the brochure.

    “the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject”
    Regulation (EU) 2016/679, Article 28(1)

    In practice

    A supervisory authority asking why this supplier was chosen is asking for the assessment, not for the contract.

  2. GDPR Article 5(2)in force · checked 2026-09-22The organisation that decided to use the tool

    Being able to show it is the duty, not merely being right

    The rule has two halves and the second one is the one that is failed in practice. Being lawful is not enough; the organisation has to be able to demonstrate that it is. A belief that a supplier is fine, however reasonable, is not a demonstration.

    “The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’).”
    Regulation (EU) 2016/679, Article 5(2)

    In practice

    The record that answers this is made before the question is asked, or it is not made at all.

  3. GDPR Article 24(1)in force · checked 2026-09-22The organisation, for what its staff do with its material

    A tool nobody signed for is still the organisation’s processing

    The duty attaches to the organisation, not to the purchase order. Where staff paste customer material into a free account, the organisation is still the one processing it, and still the one that has to be able to show what measures were in place. An unmanaged tool does not move the duty; it removes the evidence.

    “Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation.”
    Regulation (EU) 2016/679, Article 24(1)

    In practice

    The tools nobody approved are the ones with no assessment, no contract and no record of what went into them.

What has to be true before it is switched on

Each of these is a step taken in advance. Every one of them is cheap to take before the tool is in use and cannot be taken afterwards, because the date on the document is part of what it proves.

  1. GDPR Article 35(1)in force · checked 2026-09-22The organisation, before the tool is switched on

    Where the risk is high the assessment comes first, in writing

    Where a type of processing is likely to result in a high risk, an assessment is required before the processing starts. The Article names new technologies in its first line. Several national governments have published their own assessments of the large office suites and their assistants, and those documents are public.

    “Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.”
    Regulation (EU) 2016/679, Article 35(1)

    In practice

    An assessment written after a question arrives is dated after the question arrived.

  2. GDPR Article 44in force · checked 2026-09-22The organisation, and its supplier alongside it

    Sending material out of Europe is a step that has to be justified on its own

    A transfer to a country outside the Union is lawful only on one of the grounds set out in Chapter V, and the chapter carries its own instruction about how to read it: the level of protection guaranteed by the Regulation must not be undermined. That sentence is what turns a transfer question from a paperwork question into a question about what the receiving country's law allows.

    “All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.”
    Regulation (EU) 2016/679, Article 44

    In practice

    Whether the machines stand in Europe is a different question from whether the material is reachable from outside it.

  3. GDPR Article 48in force · checked 2026-09-22The supplier, on the organisation's material

    An order from a court outside Europe is not by itself permission to hand anything over

    European law names the situation directly. A judgment or an administrative decision from a country outside the Union is recognised or enforceable only where an international agreement provides for it — and the Article leaves the other grounds in the transfer chapter standing, which is what the closing clause is for. The European Data Protection Board and the European Data Protection Supervisor read the two together and put the consequence for these requests bluntly: absent such an agreement or another basis under the Regulation, a provider subject to EU law cannot lawfully disclose on one. American law meanwhile instructs the provider to comply wherever the material sits, and a supplier caught between the two is breaking one of them whichever way it goes.

    “Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.”
    Regulation (EU) 2016/679, Article 48

    In practice

    The conflict is the supplier's to resolve, and the consequences of how they resolve it are the customer's.

  4. GDPR Article 32(1)in force · checked 2026-09-22The organisation and its supplier, jointly

    The measures have to match the risk that actually exists

    Scrambling material is named in the Article as one of the measures, and it is the one most often relied on. It is a measure against the risk of somebody taking the material. Where a tool has to read the material in order to work, it is not a measure against that.

    “shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk”
    Regulation (EU) 2016/679, Article 32(1)

    In practice

    Which risk a measure answers is the question, and it has a different answer for a stolen disk than for a model summarising a contract.

What follows when it is not

Two separate routes, running at the same time and answering to different people. A supervisory authority acts on its own initiative; a claim for compensation belongs to the person whose material it was.

  1. GDPR Article 83(5)in force · checked 2026-09-22The organisation

    Transfers sit in the higher of the two fine bands

    The Regulation sets two bands. Failures of the basic principles and of the rules on sending material outside the Union sit in the upper one, which reaches twenty million euro or four per cent of worldwide annual turnover, whichever is greater. The figure is a ceiling rather than a tariff, and a supervisory authority has other powers that matter more in practice, including ordering the flow to stop.

    “Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher”
    Regulation (EU) 2016/679, Article 83(5)

    In practice

    An order suspending a flow of data arrives faster than a fine and stops the tool the same week.

  2. GDPR Article 82(1)in force · checked 2026-09-22The organisation, towards the people whose material it put in

    The people in the file can claim for themselves, and distress counts

    Alongside anything a supervisory authority does, a claim runs directly from the person whose material it was. The Regulation names damage that is not financial as well as damage that is, so the claim does not depend on showing a loss in money. Where a decision to use a tool was taken without an assessment, the record of that decision is what the claim is argued against.

    “Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.”
    Regulation (EU) 2016/679, Article 82(1)

    In practice

    A fine is one event with one counterparty; a claim of this kind has as many counterparties as there are people in the file.

Professions with a duty of secrecy carry a second set of rules

Lawyers, accountants, doctors and public bodies are bound by rules of confidentiality that exist independently of data protection law and are enforced by different bodies. Those rules vary by country and by profession, and this test has not read any of them. Where they apply, they apply in addition to everything above rather than instead of it.

What is not settled

Whether a disclosure compelled by an authority outside the Union is a personal data breach, and therefore notifiable within seventy-two hours, has no controlling answer. Searched for guidance from the European Data Protection Board and for a published supervisory decision on the point; none was found.

Checked 2026-09-22

Next

Which of your own tools does this land on?

The test asks which tools your company actually uses, names the companies running the machinery under each one, and shows what your own domain says. A few minutes, and your answers stay in this tab.

Run it on your own company

Not legal advice. Every Article on this page is quoted from the Official Journal and carries the date it was last checked, and every source is published with proof of what it said when it was read.