International Data Transfers Policy
Applies to: 42 Support, 42 Ekonomi
We aim to keep Customer Data within the European Economic Area (EEA) whenever reasonably possible.
- Where Personal Data is transferred outside the EEA, we implement appropriate safeguards as required by the GDPR.
- We do not transfer Personal Data internationally unless there is a lawful basis for doing so.
- We rely on lawful transfer mechanisms such as adequacy decisions and Standard Contractual Clauses.
- Supplementary technical and organisational measures are applied where appropriate.
This summary is provided for convenience only. The legally binding terms are set out below.
Purpose
This Policy explains how 42 Scandinavia AB manages international transfers of Personal Data.
It supplements our:
Scope
This Policy applies whenever Personal Data processed by 42 Scandinavia AB may be transferred to, accessed from, or processed in a country outside the European Economic Area (EEA).
Our Approach
Where reasonably possible, we select service providers that process Personal Data within the EEA.
However, some providers operate internationally or may provide support, maintenance or infrastructure services from countries outside the EEA.
Where this occurs, 42 Scandinavia will ensure that appropriate safeguards are in place before such transfers occur.
Lawful Transfer Mechanisms
Where Personal Data is transferred outside the EEA, we rely on one or more lawful transfer mechanisms recognised under Chapter V of the GDPR.
These may include:
- Adequacy Decisions. Transfers to countries recognised by the European Commission as providing an adequate level of protection.
- Standard Contractual Clauses (SCCs). Where appropriate, we rely on the latest European Commission Standard Contractual Clauses together with supplementary measures where required.
- Other Lawful Mechanisms. Where applicable, other lawful transfer mechanisms recognised under the GDPR.
Subprocessors
Our subprocessors may process Personal Data in multiple jurisdictions.
Current subprocessors are listed in our published Subprocessor Register.
Before engaging a subprocessor that may process Personal Data outside the EEA, 42 Scandinavia will assess whether appropriate safeguards are in place.
Supplementary Measures
Where appropriate, 42 Scandinavia may implement supplementary measures to protect Personal Data.
These measures may include:
- encryption during transmission;
- access controls;
- contractual confidentiality obligations;
- organisational security measures;
- data minimisation;
- technical safeguards appropriate to the risks involved.
Customer Information
Customers may request reasonable information regarding the safeguards used for international transfers.
Where legally permitted, 42 Scandinavia will provide information sufficient to demonstrate compliance with applicable data protection legislation.
Future Changes
As international data protection law evolves, 42 Scandinavia may update its transfer mechanisms and safeguards.
Material changes will be reflected in this Policy or related documentation.
Contact
Questions regarding international transfers may be directed to:
42 Scandinavia AB
Organisation No. 556827-3204
P O Hallmans gata 3
SE-112 06 Stockholm
Sweden
Document History
| Version | Date | Description |
|---|---|---|
| 1.0 | Publication | Initial release |
