{"id":39786,"date":"2023-06-20T09:42:54","date_gmt":"2023-06-20T07:42:54","guid":{"rendered":"https:\/\/zuniclaw.com\/transferring-data-across-oceans-without-fear-of-the-gdpr-4-million-fines\/"},"modified":"2026-03-25T10:49:32","modified_gmt":"2026-03-25T09:49:32","slug":"international-data-transfer","status":"publish","type":"post","link":"https:\/\/zuniclaw.com\/en\/international-data-transfer\/","title":{"rendered":"International Data Transfer Without the Fear of \u20ac4M+ GDPR Fines"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"39786\" class=\"elementor elementor-39786 elementor-33667\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-79f55b96 e-flex e-con-boxed e-con e-parent\" data-id=\"79f55b96\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-58aec5b7 elementor-widget elementor-widget-text-editor\" data-id=\"58aec5b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-id=\"10c344a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">In the era of information technology and constant data exchange through various applications, platforms, servers, and external service providers, keeping data within one country or organization is almost impossible.<\/div><div data-id=\"10c344a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\u00a0<\/div><div class=\"elementor-element elementor-element-dc84953 elementor-widget elementor-widget-theme-post-content\" data-id=\"dc84953\" data-element_type=\"widget\" data-widget_type=\"theme-post-content.default\"><div class=\"elementor-widget-container\"><section class=\"av_textblock_section av-cokvm3d-958a153b212bede05a44dee3b2242c4c\"><div class=\"avia_textblock\"><p>Furthermore, global business practices are becoming increasingly prevalent, and national borders are no longer barriers to product or service deployment. This type of business inevitably leads to international data transfer.<\/p><p>Whether you are a B2B company collaborating with a foreign client and sharing data about your employees who will be involved in the client\u2019s project, or you are a global provider of CRM solutions designed for the companies that will share data about their employees with you, it is clear that to establish and maintain these relationships, data sharing, including personal data, is necessary.<\/p><p>Learn the steps you need to take to avoid high fines for non-compliance with personal data protection regulations.<\/p><\/div><\/section><div class=\"hr av-c3s4vq1-6983e99027dd8fca6a59171eb37d16ac hr-invisible avia-builder-el-15 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div class=\"av-special-heading av-bumw66x-5ebeace72f56fa05c42225ed13aa9d96 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-16 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">1. Identify Which Regulations Apply to You and Your Role in Data Transfer<\/h2><\/div><section class=\"av_textblock_section av-b2mzg6x-4736578d3f1b77f67c8de42399a2c840\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>First and foremost, you need to determine which law applies to you to know which rules you need to comply with.<\/p><p>If your company is based in Serbia, you are required to comply with the Law on Personal Data Protection.<\/p><p>In addition, there is a possibility that the General Data Protection Regulation (GDPR) will also apply to you if the conditions for the extraterritorial application of the GDPR are met. To determine whether the GDPR applies to you, read our blog <a href=\"https:\/\/zuniclaw.com\/en\/gdpr-in-serbia\/\">Territorial Scope of GDPR in Serbia<\/a>.<\/p><p>On the other hand, if your company has headquarters in the EU, the GDPR certainly applies to your business.<\/p><p>Of course, other personal data protection regulations that allow for extraterritorial application, such as the <a href=\"https:\/\/www.mme.ch\/en\/magazine\/articles\/the-data-act-of-the-eu-and-switzerland\" target=\"_blank\" rel=\"noopener\">Swiss FADP<\/a> or UK GDPR, are also in play.<\/p><p>Once you have determined which law applies to you, it is necessary to identify your role in the data transfer.<\/p><p>Your company may act as a data controller, data processor, or sub-processor, and depending on your role in the data transfer, the obligations you must fulfill to comply with the applicable regulations will vary.<\/p><\/div><\/section><div class=\"hr av-au0qgux-db736cae583cf35203dbd93ae9919133 hr-invisible avia-builder-el-18 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div class=\"av-special-heading av-a7b3vsp-f5609ddbf08fd13b1f55476b830f632e av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-19 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">2. Verify if You Have Entered Into Appropriate Agreements<\/h2><\/div><section class=\"av_textblock_section av-9u3n43d-bcb5775ac466f3bbe5097bc545dfe6ff\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>The next step is to verify whether you have entered into appropriate agreements that regulate the processing and international transfer of personal data.<\/p><p>Both the Serbian Law on Personal Data Protection and the GDPR require you to regulate contractual relationships with parties with whom you share personal data. Such an agreement is called a Data Processing Agreement (DPA).<\/p><p>The specific content of the agreement will depend on your role and the role of the other party.<\/p><p>Furthermore, if there is an international transfer of personal data, it is crucial to determine which countries the data will be transferred to, as this will affect the application of Standard Contractual Clauses (SCCs) or other mechanisms for adequate data transfers (more on this in the next section).<\/p><p>Why is it important to conclude Data Processing and International Data Transfer Agreements (DPA)?<\/p><p>Because hefty fines await you!<\/p><p>Personal data protection regulations define extremely high penalties for failing to conclude appropriate data processing agreements. For example, according to the Serbian Law on Personal Data Protection, the penalty for violating this obligation can be up to 2 million Serbian dinars, while under the GDPR, this penalty can reach up to 10 million EUR (or 20 million in the case of international transfer) or 2% of your global annual revenue (or 4% in the case of international transfer), whichever amount is higher.<\/p><\/div><\/section><\/div><\/div><div class=\"hr av-9dom3vd-8bc88fd8691de7272693516ce02f9e94 hr-invisible avia-builder-el-21 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div>\u00a0<\/div><div class=\"elementor-element elementor-element-dc84953 elementor-widget elementor-widget-theme-post-content\" data-id=\"dc84953\" data-element_type=\"widget\" data-widget_type=\"theme-post-content.default\"><div class=\"elementor-widget-container\"><div class=\"av-special-heading av-93cmh3t-498d0ded95e920da54285b2e1d01c243 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-22 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">3. Have You Implemented Standard Contractual Clauses?<\/h2><\/div><section class=\"av_textblock_section av-8mmn3cp-bffb1881e14a71dff02d7a65e931b074\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>As mentioned above, it is crucial to determine the countries to which you will transfer personal data and whether they are considered \u201crisky\u201d countries.<\/p><p>\u201cRisky\u201d or so-called \u201cthird countries\u201d are those countries that do not provide an adequate level of data protection. From the EU perspective, these countries include the United States, China, Russia, and even Serbia. Practically, this means that any transfer of data from the EU to these countries is considered risky, and it is necessary to apply the\u00a0<a href=\"https:\/\/zuniclaw.com\/en\/standard-contractual-clauses\/\">EU Standard Contractual Clauses<\/a>\u00a0(SCCs) or other mechanisms defined by the GDPR for such transfers<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftn1\" name=\"_ftnref1\">[1]<\/a>.<\/p><p>From the perspective of domestic regulations, the United States is also not considered a country that provides an adequate level of data protection, and other countries such as China fall into the same category. Therefore, if you transfer data from Serbia to any of these countries, you will need to apply the Standard Contractual Clauses of the Commissioner for Personal Data Protection of Serbia (SCC SRB)<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftn2\" name=\"_ftnref2\">[2]<\/a>.<\/p><\/div><\/section><\/div><\/div><div class=\"hr av-sqfg0p-1b68f8a451e97dfd5d86fda55b95e0e6 hr-invisible avia-builder-el-24 el_after_av_textblock el_before_av_heading \">\u00a0<\/div><div>\u00a0<\/div><div class=\"elementor-element elementor-element-dc84953 elementor-widget elementor-widget-theme-post-content\" data-id=\"dc84953\" data-element_type=\"widget\" data-widget_type=\"theme-post-content.default\"><div class=\"elementor-widget-container\"><div class=\"av-special-heading av-7id9gah-14c5df0cb3394211c58a94bb6f16b9cd av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-25 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">4. Data Transfer Impact Assessment (DTIA)<\/h2><\/div><section class=\"av_textblock_section av-701nb6h-fad99d6727c0172a7dd56d6e4a0b2842\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>You have addressed all the previous steps, concluded appropriate agreements, and implemented the necessary SCCs, and now you can finally relax.<\/p><p>Or can you?<\/p><p>Unfortunately, you have not yet reached the end of your compliance process.<\/p><p>According to the GDPR and the new EU SCCs, which have been applicable since\u00a0<strong>December 27, 2022<\/strong>, you are obliged to conduct a Data Transfer Impact Assessment (DTIA).<\/p><p>DTIA is a relatively new obligation in the field of personal data protection and can be considered a consequence of the well-known Schrems II judgment of the European Court of Justice<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftn3\" name=\"_ftnref1\">[3]<\/a>, which deals with the transfer of data from the EU to third countries.<\/p><p>In this ruling, the court took the position that the application of only the EU SCCs is not sufficient for data transfers from the EU to third countries. It is also necessary to assess the risks and consequences of such transfers, whether the regulations in the recipient country are in line with EU regulations, and whether there is still a risk despite the implementation of additional measures and safeguards. This assessment is achieved through the implementation of DTIA.<\/p><\/div><\/section><div class=\"av-special-heading av-68cve6x-d6c8e946b37d94ba346fda25305f82aa av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-28 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h3>\u00a0<\/h3><h2 class=\"av-special-heading-tag\">What is DTIA?<\/h2><\/div><section class=\"av_textblock_section av-5ph2no9-03d32a797ffdb06a48373c24588bc692\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>Conducting DTIA in advance serves to map the risks that play or may play a role in the planned transfer of personal data to a third country.<\/p><p>This process must be documented, and you need to conduct it before any transfer takes place because the result of DTIA actually answers the question of whether you can transfer data outside the EU or not.<\/p><\/div><\/section><div class=\"av-special-heading av-4y9mge1-91b95ce92152c282b74c4f53b5eed2b9 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-31 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h3>\u00a0<\/h3><h2 class=\"av-special-heading-tag\">Who must conduct DTIA?<\/h2><\/div><section class=\"av_textblock_section av-4jpea8p-c91aec62f9fd05cef64755fbf5f06293\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>Both data controllers and data processors who export data from the EU\/EEA must conduct DTIA.<\/p><p>This obligation arises from both the aforementioned Schrems II judgment, and the\u00a0<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/edpb.europa.eu\/edpb_en\" target=\"_blank\" rel=\"noopener\">European Data Protection Board<\/a>\u00a0(EDPB) Guidelines on international data transfers<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftn4\" name=\"_ftnref1\">[4]<\/a>, as well as the EU SCCs themselves.<\/p><p><strong>Therefore, if you have concluded EU SCCs, you are obliged to conduct DTIA.<\/strong><\/p><p>If you think that this obligation bypasses your company if it is registered in Serbia, you are mistaken.<\/p><\/div><\/section><div class=\"avia-testimonial-wrapper av-3q76tvd-f42f5c793b65c5702cad7c6759d6ae1b avia-grid-testimonials avia-grid-2-testimonials avia_animate_when_almost_visible avia_start_animation\"><section class=\"avia-testimonial-row\"><div class=\"avia-testimonial av-3eh8xg9-dcea4fa6f307a3d9389644f22798a168 avia-testimonial-row-1 avia-first-testimonial flex_column no_margin av_one_half avia_start_animation\"><div class=\"avia-testimonial_inner\"><div class=\"avia-testimonial-content \"><div class=\"avia-testimonial-markup-entry-content\"><blockquote><p><em>The most common cases where you will have an obligation to conduct or at least participate in DTIA are situations when you engage in business cooperation with companies from the EU.<\/em><\/p><p><em>Since your business partner from the EU must comply with the GDPR and your Serbian company operates in a country that does not provide an adequate level of protection, the EU company will have to conduct DTIA. However, to answer the questions in DTIA related to the regulations of the Republic of Serbia and the treatment of data in Serbia, you will need to provide answers and explain the practices of our state authorities. Thus, the obligation to conduct DTIA falls on your shoulders, and the continuation of cooperation with the EU company depends precisely on your answers to DTIA.<\/em><\/p><\/blockquote><\/div><\/div><div class=\"avia-testimonial-meta\"><div class=\"avia-testimonial-meta-mini\">\u00a0<\/div><\/div><\/div><\/div><\/section><\/div><div class=\"hr av-33p8qih-6b3baf2ea17ba6bcffcbc1825315900c hr-invisible avia-builder-el-34 el_after_av_testimonials el_before_av_heading \">\u00a0<\/div><div class=\"av-special-heading av-915r21-41e38aaf0c43623735a24669a4e58158 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-35 el_after_av_hr el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">What are the consequences of not conducting DTIA?<\/h2><\/div><section class=\"av_textblock_section av-21w5ogp-31ff844b2349226696a2b2591cffaf61\"><div class=\"avia_textblock\"><p>\u00a0<\/p><p>The consequences of not conducting DTIA can be significant.<\/p><p>First and foremost, you risk facing (multi-million) fines for GDPR violations, which can amount to 20 million EUR or 4% of your global annual revenue, whichever amount is higher.<\/p><p>In addition, individuals whose data you have processed can sue you in competent courts, seeking compensation for the breach of their personal data and privacy rights due to international transfers without adequate protective measures.<\/p><p>Finally, if you fail to conduct or participate in DTIA upon the request of your business partners, you risk the termination or failure to establish business cooperation.<\/p><\/div><p>One of the most effective ways to ensure compliance with data protection regulations is by using specialized software like <a href=\"https:\/\/whisperly.ai\/\" target=\"_blank\" rel=\"noopener\">Whisperly<\/a>, which automates key compliance processes and supports organizations in meeting regulatory requirements, including those related to international data transfer.<\/p><\/section><section class=\"av_textblock_section av-1jk6oe1-1b73776a43c4b23a15076651945fd209\"><div class=\"avia_textblock\"><h6><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftnref1\" name=\"_ftn1\">[1]<\/a>\u00a0In addition to SCCs, other mechanisms that can be applied are Binding Corporate Rules (BCRs), approved codes of conduct, issued certificates, etc.<br class=\"avia-permanent-lb\" \/><br class=\"avia-permanent-lb\" \/><\/h6><h6><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftnref2\" name=\"_ftn2\">[2]<\/a>\u00a0Or another mechanism in accordance with the Law on Personal Data Protection, such as BCRs, approved codes of conduct, issued certificates, etc.<br class=\"avia-permanent-lb\" \/><br class=\"avia-permanent-lb\" \/><\/h6><h6><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftnref3\" name=\"_ftn1\">[3]<\/a>\u00a0Document 62018CJ0311, Judgment of the Court (Grand Chamber) of 16 July 2020.<\/h6><h6>Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems.\u00a0<a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A62018CJ0311\" target=\"_blank\" rel=\"noopener\">https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A62018CJ0311<br class=\"avia-permanent-lb\" \/><br class=\"avia-permanent-lb\" \/><br class=\"avia-permanent-lb\" \/><\/a><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/zuniclaw.com\/en\/international-data-transfer\/#_ftnref4\" name=\"_ftn1\">[4]<\/a><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/edpb.europa.eu\/edpb_en\" target=\"_blank\" rel=\"noopener\">European Data Protection Board<\/a><a href=\"https:\/\/web.archive.org\/web\/20250319201151\/https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A62018CJ0311\" target=\"_blank\" rel=\"noopener\">\u00a0\u2013 nezavisno telo EU \u010dija je svrha da obezbedi doslednu primenu GDPR<\/a><\/h6><\/div><\/section><\/div><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In the era of information technology and constant data exchange through various applications, platforms, servers, and external service providers, keeping data within one country or organization is almost impossible.\u00a0 Furthermore, global business practices are becoming increasingly prevalent, and national borders are no longer barriers to product or service deployment. This type of business inevitably leads [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":66854,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[84],"class_list":["post-39786","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-privatnost-i-zastita-podataka"],"_links":{"self":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39786","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/comments?post=39786"}],"version-history":[{"count":8,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39786\/revisions"}],"predecessor-version":[{"id":74448,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/39786\/revisions\/74448"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media\/66854"}],"wp:attachment":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media?parent=39786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/categories?post=39786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}