The Processor is not, but the Controller is still required to guarantee appropriate security for personal data.
Appropriate means running a risk assessment and deciding accordingly.
The problem is when in the EU we take as security responsible for healthcare people who handled IAM for Jira tops.
Appropriate means running a risk assessment and deciding accordingly
The risk assessment doesn’t require the company to assess the reliability of international diplomatic relationships. Having your data on EU soil (even under the care of a US company) is enough for compliance.
The Processor is not, but the Controller is still required to guarantee appropriate security for personal data. Appropriate means running a risk assessment and deciding accordingly.
The problem is when in the EU we take as security responsible for healthcare people who handled IAM for Jira tops.
The risk assessment doesn’t require the company to assess the reliability of international diplomatic relationships. Having your data on EU soil (even under the care of a US company) is enough for compliance.