Data processing within and outside the EU raises a number of questions: Does your personal data – your income, your online search behaviour, the websites you visit, your personnel file, medical records, location data and so on – belong to you or to the public? How high is the level of data protection within the EU, and what does it look like in non-EU countries? In the following sections, we have summarised the key facts about data processing within and outside the European Union. Get an overview!
Table of Contents
In the EU, your data is protected by law
Under Article 8 of the Charter of Fundamental Rights of the European Union, everyone has the right to the protection of their personal data. Rights such as the right of access and the right to erasure are also laid down, and oversight of data protection by independent authorities is guaranteed. All this is put into practice by the General Data Protection Regulation. The GDPR obliges companies to protect your data and uphold your rights.1
How is (was) your data protected abroad?
But the internet knows no borders. How is your data protected when it is processed outside Europe, for example in the USA? So that you don’t have to rely on empty promises from companies (who make money from your data), the EU tries to strengthen your rights:
Safe Harbor 2000–2015
In 2000, the Safe Harbor decision2 is adopted with the USA. It is meant to allow companies to transfer personal data from an EU country to the USA, in line with the European Data Protection Directive.
It soon becomes clear that the agreement does not effectively protect your personal data. As early as April 2010, the Düsseldorfer Kreis (the business working group of Germany’s independent federal and state data protection authorities) states that data exporters in Germany may not rely on US companies’ claims of Safe Harbor certification3.
In 2015, the Safe Harbor decision is finally struck down, partly on the following grounds:
“The United States safe harbour scheme (…) enables interference, by United States public authorities, with the fundamental rights of persons, and (…) does not refer either to the existence, in the United States, of rules intended to limit any such interference or to the existence of effective legal protection against the interference.”4
Conclusion: Without your knowledge, your data could be processed, analysed, passed on to third parties and used for mass or individual surveillance, and it was. You have no control or data sovereignty over your personal data as long as it is processed in the USA.
Privacy Shield 2016–2020
So that companies can keep sending your data to the USA, a new legal basis is needed, and fast. In 2016 the Privacy Shield agreement is concluded. The main difference from Safe Harbor: stricter requirements for US data recipients and a (theoretical) right of action for data subjects in the USA. But US law still takes precedence, so all your data continues to be used for blanket, suspicionless surveillance.5 Accordingly, this “deal6” is highly controversial from the start (even within the European Parliament)7. So it is a small miracle that Privacy Shield is not declared invalid until 2020.
The new standard contractual clauses since 2021
Still, the same rule applies – a quick fix is needed, because money is made from your data, so your data has to be exportable and shareable. This time, more responsibility is placed on the data exporter – that is, the company that wants to pass on your data.
The new standard contractual clauses mean more work for the data exporter – they must inform the data subjects, keep the data accurate and, where necessary, up to date, guarantee purpose limitation and, above all, satisfy themselves that the data importer is able to meet its obligations by implementing appropriate technical and organisational measures. But as before: other countries, above all the USA, have a keen interest in your data and gain control over it entirely legally under their national law.
Interim conclusion
The CJEU rulings confirm it: the protection of your data in non-EU countries has been, and still is, inadequately regulated by law. The legal systems of individual countries conflict with the use of standard contractual clauses8. This is the case in the USA, for example.9 Always bear in mind that companies’ technical and organisational measures to protect your data are only half the story. Government agencies intercept data relating to you and use it on a blanket, suspicionless basis.
It makes no difference whether the servers are in Europe, as long as the company is headquartered in the USA or controlled by US shareholders. That is why Microsoft OneDrive, for example, is legally highly contested even with EU servers, because US law applies. The same goes for tools such as SurveyMonkey or Qualtrics.
Data Privacy Framework since 2023
In July 2023 comes the third attempt, this time by decree of the US President. US law stays the same. In 2025 the General Court of the EU does uphold the agreement, but only for the legal situation in 2023, and the appeal before the Court of Justice is ongoing. Meanwhile, two key pillars of the agreement in the USA, the FTC as supervisory authority and the PCLOB as oversight board, have been hollowed out. Read the details here: Data Privacy Framework: Data Transfers to the USA Remain Problematic
Data processing at LamaPoll
You decide which data is processed, from which data subjects, for what purpose and in what way. You can exercise data subjects’ rights easily yourself or, if you prefer, with our support. You decide almost everything – from the type of cookies used to the deletion period.10
We are here for one thing only: to protect your data. Our information security management system is externally certified by TÜV SÜD to ISO/IEC 27001:2022 as well as ISO/IEC 27017 and 27018.11 We also hold a TISAX label at Assessment Level 2.
With regard to data transfer and disclosure:
- We process your data exclusively within the Federal Republic of Germany. As set out in our data processing agreement (DPA), we prohibit ourselves from processing data outside the European Union.
- We use sub-processors based in Germany only.12 Our hosting providers supply us with so-called root servers. These are servers that we manage ourselves and that only we can access. The servers are located in Germany. Data transfer to these servers and all server hard drives (data at rest) are encrypted.
- Neither we nor our sub-processors are subject to 50 U.S.C. § 1881a (= FISA 702).
- Neither we nor our sub-processors are controlled by a US parent company or a US shareholder, and we have no other relevant connection to the USA that could make US law indirectly applicable to us.
- Even if this were to change, EU law would oblige us to ignore any orders, requests or directives from US bodies requiring us to disclose personal data we process to the US government under 50 U.S.C. § 1881a (= FISA 702) or EO 12333. Based on the current, generally available state of the art, we are also able to block such access in practice.
- We are not subject to any other law that could be regarded as undermining the protection of personal data under the GDPR (Article 44 GDPR).
For questions about our technical and organisational measures to protect your data, please refer to the annex of our DPA13, our ISO certificate11 and, on request, our security concept.
Sources and references:
- https://www.bfdi.bund.de/DE/Buerger/Inhalte/Allgemein/Datenschutz/GrundlagenDatenschutzrecht.html
- https://en.wikipedia.org/wiki/International_Safe_Harbor_Privacy_Principles
- https://www.ldi.nrw.de/mainmenu_Service/submenu_Entschliessungsarchiv/Inhalt/Beschluesse_Duesseldorfer_Kreis/Inhalt/2010/Pruefung_der_Selbst-Zertifizierung_des_Datenimporteuers/Beschluss_28_29_04_10neu.pdf
- https://curia.europa.eu/jcms/upload/docs/application/pdf/2015-10/cp150117en.pdf
- http://ec.europa.eu/justice/data-protection/article-29/documentation/opinion-recommendation/files/2016/wp238_en.pdf
- https://www.nytimes.com/2016/07/13/technology/europe-eu-us-privacy-shield.html
- https://www.derstandard.at/consent/tcf/2000037687339/eu-parlament-privacy-shield-muss-ueberarbeitet-werden
- https://curia.europa.eu/juris/document/document.jsf?text=&docid=169195&doclang=EN
- https://www.deutschlandfunk.de/datenschutzvereinbarung-da-steht-genauso-drin-us-recht-hat-100.html
- https://app.lamapoll.de/contracts/downloadLatestEDV/
- https://www.lamapoll.de/cdn/media/files/LamaPoll-ISO-Certificate_27001_27017_27018-62366ms27001_english.pdf
- https://app.lamapoll.de/contracts/downloadLatestSUB/
- https://app.lamapoll.de/contracts/downloadLatestAVV


