Commercial
GDPR
The EU regulation governing how personal data may be handled.
Definition
The General Data Protection Regulation, known in German-speaking markets as the DSGVO, sets the rules for processing personal data of people in the EU and EEA. It applies to the controller wherever the processing happens, including work performed by suppliers outside the EU, and requires an appropriate transfer mechanism for data leaving the bloc.
Why it matters
Outsourcing does not move the obligation: as controller you remain accountable for what your processor does. The practical items are a signed data processing agreement, a documented transfer mechanism such as standard contractual clauses, and a current list of sub-processors. Discovering during an audit that a supplier never signed one is the failure mode.
Related
Read next
Data processing agreement
The contract governing what a supplier may do with personal data.
Read the definition ›Sub-processor
A supplier's own supplier that also touches your data.
Read the definition ›Data residency
Where your data physically sits, and which laws follow from that.
Read the definition ›Background check
Verifying identity, right to work, education and employment history.
Read the definition ›Next step
Ready to build or scale your team?
Tell us what you need and we will match you with pre-vetted Lebanese professionals ready to integrate with your team.
