Your CRM may well be with a ‘local’ provider but where is it hosted?

Your responsibility for international transfers

Buying and selling goods, engaging suppliers, and using hosting providers internationally is as natural to a business as river water flowing downstream. Data flows back and forth with those goods, services, and hosting arrangements, and this is where things get a little more complicated.

If you host, store, or transfer people's information to countries outside the EEA, you must do so knowingly and in compliance with GDPR Chapter 5, which protects the privacy and rights of an individual's personal information. That obligation doesn't disappear just because your supplier has an Irish or UK-sounding name, or a ".ie" website. Plenty of "local" CRMs, helpdesk tools, and email platforms are actually hosted on servers in the US or elsewhere outside the EEA, and it's your responsibility as the data controller to know that.

Businesses exporting and importing customer data must put appropriate safeguards in place to ensure a regulated approach to international transfer. One element of this is an agreement that sits alongside your standard supplier contract or SLA. The standardised, ready-made Standard Contractual Clauses (SCCs)remain the go-to mechanism: an easy-to-implement tool for transferring data internationally.

What it means for your business

This comes down to due diligence. An SCC is a contract that protects your customer's data, but it also protects you as a business. Performing due diligence on the data importer means satisfying yourself that they're reputable, and that they won't use data given to them in confidence for questionable purposes or pass it on to people who shouldn't have access to it. The SCC helps you stand behind your business's good name as a credible upholder of your customers' data protection rights.

The current versions of the SCCs, adopted by the European Commission on 4 June 2021, have been the only valid form since the transition deadline of 27 December 2022 passed. If your contracts still reference the pre-2021 clauses, they're no longer valid and need to be replaced now, not "before a deadline."

Where things stand with the US

For years, this was the most unsettled area of GDPR. The 2020 Schrems II judgment struck down the EU–US Privacy Shield, and businesses fell back on SCCs while everyone waited to see what would replace it.

That replacement arrived on 10 July 2023, when the European Commission adopted an adequacy decision for the EU–US Data Privacy Framework (DPF). If your US supplier is DPF-certified, you can transfer personal data to them without needing SCCs or a Transfer Impact Assessment. You can check a supplier's certification status at dataprivacyframework.gov.

The DPF isn't beyond challenge, though. It survived its first legal test in the EU General Court in September 2025, but questions remain over the independence of the US oversight body that underpins it, and privacy campaigners have signalled they're not finished challenging it. Our fuller breakdown of where that stands is in Is the USA Open for EU Personal Data Transfers? The Story So Far — worth a read if a meaningful share of your suppliers are US-based.

Practical takeaway: don't rely on DPF certification alone. Keep SCCs in place as a fallback, and keep your Transfer Impact Assessments current, so you're not caught out if the framework changes again.

What about the UK?

The UK has held an EU adequacy decision since June 2021, which was reviewed and renewed in December 2024. For most businesses, that means EU–UK transfers can continue without SCCs, provided your documentation reflects the UK's status as an adequate third country. Adequacy isn't permanent, though. It can be revisited if UK data protection standards diverge materially from the EU framework, so it's worth keeping an eye on.

Action points

  1. Check your SCCs are the 2021 version. If any supplier contract still references the old clauses, replace it now.

  2. Know where your data actually goes. Don't assume a "local" provider means local hosting; ask your suppliers directly where personal data is processed and stored.

  3. Layer your safeguards. Where a US supplier relies on DPF certification, keep SCCs as a backup rather than your only mechanism.

  4. Do your due diligence. An SCC or adequacy decision is a starting point, not a substitute for satisfying yourself that your data importer is reputable and will handle customer data appropriately.

If you are working with suppliers, applications, hosting providers and not clear if you need to take action before December 27th 2022, get in touch for a free confidential chat.

Previous
Previous

How to juggle the many hats of a DPO

Next
Next

Data breaches and email correspondence