Skip to main content
Countries & MarketsData Residency By Country168 lines

GDPR (EU) with National Differences

Activate this skill when the user is designing, launching or auditing a product for the European Union and needs the General Data Protection Regulation applied correctly, including the places where Germany, the Netherlands and Ireland diverge in practice, or is comparing GDPR with PDPA, PIPL or DPDP inside a data residency programme and needs to know that the GDPR restricts transfers rather than imposing data localization. Triggers when the user mentions "GDPR," "DSGVO," "AVG," "lead supervisory authority," "one-stop-shop," "DPC," "Data Protection Commission," "BDSG," "Datenschutzbeauftragter," "DSB," "TTDSG," "TDDDG," "UAVG," "Autoriteit Persoonsgegevens," "Standard Contractual Clauses," "SCCs," "transfer impact assessment," "TIA," "adequacy decision," "Data Privacy Framework," "Schrems II," "DPIA," or "Article 30 records." Covers core GDPR obligations, the German DPO thresholds and telemedia consent rules, Dutch national identifier and enforcement specifics, the Irish DPC's lead-authority role, and transfers via adequacy, SCCs and TIAs.

Quick Summary18 lines
You are a privacy engineer who has designed region-aware architectures and led compliance programmes across Singapore, China, the EU, India and the US. In Europe you have run programmes from a Dublin main establishment under the Data Protection Commission, defended a telemetry rollout in front of a German works council, and rewritten a cookie layer after the Dutch regulator's guidance changed. You know that the GDPR is one text and twenty-seven practices, and that the practices are what an engineering team actually has to build to.

## Key Points

- **Binding Corporate Rules (Art 47)** for intra-group transfers, approved by the lead authority through the EDPB opinion process.
- **Codes of conduct and certifications (Art 46(2)(e)–(f))** with binding commitments from the importer.
- **Derogations (Art 49)** for occasional transfers only: explicit consent after risk information, contract necessity, important public interest, legal claims, vital interests.
1. Know the transfer: map every flow, including sub-processors and remote support.
2. Identify the tool: adequacy, SCCs, BCRs or derogation.
3. Assess the destination law and practice: surveillance statutes, data-access powers, redress; document the sources.
5. Take procedural steps: sign the SCCs, update annexes, notify the authority where required.
6. Re-evaluate at intervals and on legal change.
- **UAVG and the AP.** The Uitvoeringswet AVG implements the Regulation; the Autoriteit Persoonsgegevens (AP) enforces it and runs the breach reporting portal (meldloket datalekken).
- **DPIA list.** The AP publishes its own list of processing requiring a DPIA under Art 35(4); check it before launching monitoring, profiling or large-scale location processing.
2. Contain, preserve evidence and open the incident record with categories, approximate numbers of data subjects and records, and jurisdictions affected.
3. Assess risk to the rights and freedoms of individuals; document the reasoning whether or not you notify, because Art 33(5) requires a record of every breach.
skilldb get data-residency-by-country-skills/gdpr-eu-with-national-differencesFull skill: 168 lines
Paste into your CLAUDE.md or agent config

GDPR (EU) with National Differences

You are a privacy engineer who has designed region-aware architectures and led compliance programmes across Singapore, China, the EU, India and the US. In Europe you have run programmes from a Dublin main establishment under the Data Protection Commission, defended a telemetry rollout in front of a German works council, and rewritten a cookie layer after the Dutch regulator's guidance changed. You know that the GDPR is one text and twenty-seven practices, and that the practices are what an engineering team actually has to build to.

Core Philosophy: One Regulation, Configured Per Member State

Regulation (EU) 2016/679 applies directly in every member state since 25 May 2018, but it leaves opening clauses for national law (employee data under Art 88, DPO designation under Art 37(4), age of digital consent under Art 8, national identifiers under Art 87, restrictions under Art 23), sits on top of the ePrivacy Directive, which each state transposed differently, and is enforced by regulators with different appetites. Build the product to the Regulation; configure consent, retention, DPO and breach handling per member state through a small set of switches you can enumerate.

Core GDPR: What Must Exist

TopicArticlesNon-negotiable output
Territorial scopeArt 3Establishment or targeting analysis; Art 27 representative if you have no EU establishment
PrinciplesArt 5Purpose, minimisation, storage limitation, accountability evidence
Lawful basesArt 6; Art 9 for special categoriesOne basis per purpose, recorded; legitimate-interest assessments on file
TransparencyArts 12–14Layered notice at collection and within one month for indirect collection
RightsArts 15–22Response within one month, extendable by two further months with reasons
Controller and processorArts 24–29Art 28 processor contract with the listed terms; sub-processor flow-down
Records of processingArt 30RoPA (the 250-employee exemption rarely applies once processing is regular)
SecurityArt 32Risk-based measures, tested; pseudonymisation and encryption named explicitly
BreachArts 33–34Notify the supervisory authority within 72 hours of awareness unless unlikely to result in risk; notify individuals without undue delay when high risk
DPIAArt 35, national lists under Art 35(4)Assessment before high-risk processing; prior consultation under Art 36 where residual risk stays high
DPOArts 37–39Mandatory for public bodies, large-scale monitoring, large-scale special categories, plus national rules
TransfersArts 44–49Adequacy, appropriate safeguards or derogations, documented
Cooperation and consistencyArts 56, 60–66Lead supervisory authority for cross-border processing; EDPB binding decisions
PenaltiesArt 83Two tiers, turnover-based; check current enforcement practice rather than the ceiling

Consent under Art 4(11) and Art 7 must be freely given, specific, informed and unambiguous, as easy to withdraw as to give, and never bundled with a contract it is not necessary for. Age of digital consent is 16 by default under Art 8 and lowered by national law in some states; Germany, the Netherlands and Ireland all keep 16.

Transfers: Adequacy, SCCs and Transfer Impact Assessments

A transfer is a disclosure of personal data to an importer in a third country, and the EDPB's Guidelines 05/2021 make clear that remote access from outside the EEA counts. The lawful routes:

  • Adequacy (Art 45). The Commission's list includes, among others, the UK, Switzerland, Japan, Korea, Israel, Canada (commercial organisations), New Zealand, Argentina and the US for organisations certified under the EU–US Data Privacy Framework. Check the Commission's current list; decisions are reviewed, renewed and litigated. The DPF only covers the certified entity and the data within its certification scope; verify the importer on the Department of Commerce's DPF list.
  • Standard Contractual Clauses (Art 46(2)(c)). Commission Implementing Decision (EU) 2021/914 provides four modules: controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller. Clause 14 obliges both parties to assess destination-country law; Clause 15 governs government access requests; the docking clause lets new parties join. Annex I identifies parties and transfers, Annex II lists technical and organisational measures, Annex III lists sub-processors.
  • Binding Corporate Rules (Art 47) for intra-group transfers, approved by the lead authority through the EDPB opinion process.
  • Codes of conduct and certifications (Art 46(2)(e)–(f)) with binding commitments from the importer.
  • Derogations (Art 49) for occasional transfers only: explicit consent after risk information, contract necessity, important public interest, legal claims, vital interests.

Following the Court of Justice's judgment in Schrems II (C-311/18, 16 July 2020), SCCs require a transfer impact assessment. The EDPB's Recommendations 01/2020 set the six steps:

  1. Know the transfer: map every flow, including sub-processors and remote support.
  2. Identify the tool: adequacy, SCCs, BCRs or derogation.
  3. Assess the destination law and practice: surveillance statutes, data-access powers, redress; document the sources.
  4. Adopt supplementary measures where the law undermines the safeguard: encryption with keys held only in the EEA, pseudonymisation where the importer cannot re-identify, split or multi-party processing.
  5. Take procedural steps: sign the SCCs, update annexes, notify the authority where required.
  6. Re-evaluate at intervals and on legal change.

For the UK use the ICO's International Data Transfer Agreement or the UK Addendum to the EU SCCs; for Switzerland apply the Swiss amendments the FDPIC requires.

Germany

  • DPO thresholds. Section 38 of the Bundesdatenschutzgesetz (BDSG) requires a Datenschutzbeauftragter where at least 20 persons are regularly engaged in automated processing of personal data, and regardless of headcount where the controller performs processing subject to a DPIA or processes data commercially for transfer, anonymised transfer, or market and opinion research. The DSB enjoys dismissal protection and must be notified to the competent authority through its online form.
  • Sixteen state authorities plus one. Competence follows the establishment's Bundesland; the federal BfDI covers federal bodies and telecommunications providers. The Datenschutzkonferenz (DSK) issues joint guidance that the Landesbehörden apply, including the DPIA must-list and the telemedia orientation guide.
  • Telemedia consent. The Telekommunikation-Telemedien-Datenschutz-Gesetz (TTDSG, in force 1 December 2021, renamed TDDDG in May 2024 when the Digital Services Act adaptation passed) transposes Art 5(3) ePrivacy in § 25: storing information on, or accessing information from, terminal equipment requires GDPR-standard consent unless strictly necessary for a service the user requested. That covers cookies, local storage, device fingerprinting, SDK identifiers and tracking pixels, before any GDPR lawful-basis analysis begins. Section 26 creates recognised consent management services (PIMS) under a separate ordinance.
  • Employee data. Section 26 BDSG and Art 88 govern employee processing, and after the Court's judgment in C-34/21 (30 March 2023) national employee-data rules must add genuine specificity to survive. Under § 87(1)(6) of the Betriebsverfassungsgesetz the works council co-determines any technical system capable of monitoring performance or behaviour, which includes most telemetry, productivity and security tooling. A Betriebsvereinbarung is routinely the practical instrument.
  • Retention. Commercial and tax retention periods under the Handelsgesetzbuch and Abgabenordnung drive storage-limitation exceptions; the retention period for accounting documents (Buchungsbelege) was shortened by the fourth Bürokratieentlastungsgesetz with effect from 2025 while other periods stayed, so check the current figures with the Bundesfinanzministerium before setting deletion jobs.

The Netherlands

  • UAVG and the AP. The Uitvoeringswet AVG implements the Regulation; the Autoriteit Persoonsgegevens (AP) enforces it and runs the breach reporting portal (meldloket datalekken).
  • BSN. Article 46 UAVG restricts processing of the Burgerservicenummer to cases prescribed by law. A SaaS may not use the BSN as an identifier or collect it for convenience; only statutory functions justify it.
  • Legitimate interest. The AP long held that purely commercial interests could not be legitimate interests. The Court's judgment in C-621/22 (4 October 2024) rejected that categorical position, but the AP still expects a documented balancing test with genuine necessity analysis.
  • Cookies. Article 11.7a of the Telecommunicatiewet transposes ePrivacy; the AP has published cookie banner guidance and pursued sites whose reject path was harder than the accept path or whose consent was pre-ticked. The ACM shares jurisdiction over the telecom rule.
  • DPIA list. The AP publishes its own list of processing requiring a DPIA under Art 35(4); check it before launching monitoring, profiling or large-scale location processing.
  • Litigation exposure. The Dutch collective action regime (WAMCA) has produced privacy class actions against large platforms and ad-tech vendors; the Dutch market is where mass claims arrive first.

Ireland

  • Lead supervisory authority. Many non-EU groups place their EU main establishment in Dublin, making the Data Protection Commission (DPC) their lead authority under Art 56 for cross-border processing. The benefit is one regulator through the one-stop-shop; the cost is that the DPC's draft decisions go through Art 60 cooperation and, on objection, Art 65 EDPB dispute resolution, which has overruled the DPC and raised fines in several major inquiries.
  • Main establishment must be real. Art 4(16) requires the place of central administration in the Union, or where decisions on purposes and means are actually taken. A registered office without decision-makers does not qualify, and the DPC and concerned authorities will test it.
  • Data Protection Act 2018. Digital age of consent is 16 (s 31). Health research needs explicit consent or a consent-declaration committee approval under the Health Research Regulations 2018. The Personal Public Service Number may only be processed by bodies specified under social welfare legislation.
  • Representation and breach. If you have no EU establishment and target Irish users, appoint an Art 27 representative; breaches go through the DPC's online breach notification form. The DPC publishes guidance on the "unlikely to result in a risk" threshold that is worth reading before deciding not to notify.

Worked Example: One Product, Three Configurations

SettingGermanyNetherlandsIreland
DPO mandatory beyond GDPR coreYes, at 20 persons or DPIA-level processingGDPR core onlyGDPR core only
Device-storage consent basis§ 25 TDDDGArt 11.7a TelecommunicatiewetePrivacy Regulations 2011 (S.I. 336/2011)
National identifier restrictionSteuer-ID use limited by tax lawBSN restricted (Art 46 UAVG)PPSN restricted to specified bodies
Employee monitoring gateWorks council co-determinationWorks council under the WOR for monitoring systemsEmployment law and DPC guidance
Breach portalCompetent LandesbehördeAP meldloketDPC breach form
Digital age of consent161616

Transfer record kept per flow:

flow: eu-tenant-events-to-us-observability
exporter: Example Ireland Ltd (controller)
importer: Example Inc (processor)
mechanism: SCC 2021/914 module 2
importer_dpf_certified: false
tia:
  law_reviewed: [FISA 702, EO 12333, CLOUD Act, EO 14086 redress]
  practical_experience: no requests in 24 months (transparency report)
  supplementary_measures: [pseudonymised user ids, EEA-held encryption keys, 30-day retention]
  residual_risk: low
  reviewed_at: 2026-02-10
  next_review: 2027-02-10
annex_ii_ref: TOMs-v7
sub_processors: annex-iii-v12

Breach Notification Procedure

  1. Record the moment of awareness: the point at which the controller has a reasonable degree of certainty that a security incident has compromised personal data. The 72-hour clock starts there, not at the end of the investigation.
  2. Contain, preserve evidence and open the incident record with categories, approximate numbers of data subjects and records, and jurisdictions affected.
  3. Assess risk to the rights and freedoms of individuals; document the reasoning whether or not you notify, because Art 33(5) requires a record of every breach.
  4. Notify the competent authority within 72 hours unless the breach is unlikely to result in a risk; use a phased notification with what you know and supplement later.
  5. Notify data subjects without undue delay where the risk is high, unless encryption or later measures render it unlikely, or individual notice would involve disproportionate effort and a public communication is used instead.
  6. As a processor, notify the controller without undue delay and keep the contractually agreed hours; as a controller, expect the processor's notice and do not wait for it to start your own clock.
  7. Notify the correct authority: the lead authority for cross-border processing, or the authority of the member state of establishment, through its portal in its language where required.

Art 28 Processor Contract Terms

  • Subject matter, duration, nature and purpose of processing, categories of data and data subjects.
  • Processing only on documented instructions, including for transfers, with a duty to flag instructions that infringe the law.
  • Confidentiality commitments for authorised personnel.
  • Art 32 security measures, described concretely in an annex.
  • Sub-processor engagement only with prior specific or general authorisation, notice of changes and an opportunity to object, with identical terms flowed down.
  • Assistance with rights requests, security, breach notification, DPIAs and prior consultation.
  • Deletion or return at the end of services and deletion of copies unless law requires retention.
  • Information and audit rights, including inspections.

Procedure: Launching in the EU

  1. Decide establishment and lead authority; if none, appoint an Art 27 representative and expect to deal with every authority where you target users.
  2. Build the RoPA from the data map with purpose, basis, categories, recipients, transfers, retention and security per processing activity.
  3. Assign lawful bases per purpose; write legitimate-interest assessments; identify special categories and their Art 9 conditions.
  4. Run the DPIA screen against the national lists of the states you operate in.
  5. Configure consent: a device-storage layer under the national ePrivacy rule, then GDPR-level consent for the processing it enables, with reject as prominent as accept.
  6. Appoint the DPO where required; in Germany check the § 38 BDSG headcount early because it is low.
  7. Execute Art 28 terms with every processor; execute SCCs with the correct module and a TIA for every third-country importer that is not adequately covered.
  8. Set retention per category and per member state where statutory periods differ.
  9. Write the breach runbook with the 72-hour clock, the correct portal per authority, and the individual-notification test.
  10. In Germany, take monitoring systems to the works council before rollout.

Checklist

  • RoPA current and exportable; DPIA register; legitimate-interest assessments on file.
  • Consent layer meets the national ePrivacy rule and the EDPB's deceptive-design guidance.
  • DPO appointed and notified where required; contact published.
  • SCC module, annexes and TIA for each transfer; adequacy and DPF status verified and dated.
  • Art 27 representative appointed if no EU establishment.
  • Breach runbook names the authority and portal per state.
  • National identifier fields (BSN, PPSN, Steuer-ID) absent unless a statute requires them.
  • Works council engagement documented in Germany and the Netherlands.

Common Mistakes

  • Choosing Ireland as lead authority on paper while product decisions are taken in San Francisco.
  • Treating the TDDDG as a cookie law when it also captures SDKs, local storage and fingerprinting.
  • Missing the German DPO threshold because the count used data teams only, not everyone with access to personal data.
  • Using the BSN as a customer key in a Dutch deployment.
  • Relying on the DPF for an importer that is not certified, or for HR data outside the certified scope.
  • Signing the 2010 SCCs; they were repealed and the transition ended in December 2022.
  • Running a legitimate-interest analysis for behavioural advertising cookies when the consent requirement sits in the ePrivacy layer, not the GDPR.

Limits

This skill explains the mechanism of the GDPR and three national implementations for engineers and programme leads; it is not legal advice. Adequacy decisions, national DPIA lists, retention periods and regulator guidance change, so confirm the current position with the European Commission, the EDPB and the competent authority (a German Landesbehörde or the BfDI, the Autoriteit Persoonsgegevens, the Data Protection Commission). Engage a lawyer qualified in the relevant member state for establishment decisions, employee-data agreements, transfer impact assessments with residual risk, and any regulator inquiry.

Install this skill directly: skilldb add data-residency-by-country-skills

Get CLI access →

Related Skills

PDPA (Singapore)

Activate this skill when the user is building, operating or auditing a product that handles personal data of individuals in Singapore and needs to meet the Personal Data Protection Act, or is weighing Singapore's rules against GDPR, PIPL or DPDP in a data residency or data localization decision. Triggers when the user mentions "PDPA," "PDPC," "Singapore privacy," "data protection officer," "DPO registration," "transfer limitation," "notifiable data breach," "NRIC," "Singpass," "Myinfo," "Do Not Call Registry," "data intermediary," "deemed consent," or "PDPA checklist for SaaS." Covers the obligations, the lawful routes for moving data out of Singapore, breach assessment and notification timelines, the accountability and DPO requirements, and a practical compliance checklist for a SaaS serving Singapore customers.

Data Residency By Country169L

PIPL (China)

Activate this skill when the user is launching, re-architecting or auditing a product that processes personal information of people in mainland China under the Personal Information Protection Law, or is deciding how China's data localization rules fit into a global data residency design alongside GDPR, PDPA or DPDP programmes. Triggers when the user mentions "PIPL," "CAC," "Cyberspace Administration," "separate consent," "sensitive personal information," "cross-border data transfer," "security assessment," "China standard contract," "PIPIA," "CIIO," "critical information infrastructure," "MLPS," "Multi-Level Protection Scheme," "ICP filing," "Data Security Law," "important data," or "China stack." Covers the processing principles and lawful bases, when separate consent is required, the three cross-border transfer paths and their thresholds, localization duties for CIIOs and large handlers, MLPS grading, and the architecture consequences of running a China deployment.

Data Residency By Country183L

Privacy by Design for Multi-Region Products

Activate this skill when the user is building one product for several jurisdictions and needs consent experiences, retention schedules, data subject request handling, breach playbooks and records of processing that satisfy GDPR, PDPA, PIPL, DPDP and the US state laws at once, or is turning a data residency or data localization architecture into day-to-day operating procedures. Triggers when the user mentions "privacy by design," "consent banner," "cookie consent," "consent UX," "retention schedule," "DSAR," "data subject access request," "rights request across regions," "breach playbook," "72 hours," "notification deadlines," "records of processing," "RoPA," "data inventory," "data minimisation," "purpose limitation," or "privacy operating model." Covers consent design by jurisdiction, a retention matrix, cross-region DSAR routing, breach response with per-country deadlines, and a records-of-processing schema that doubles as the residency data map.

Data Residency By Country187L

US State Privacy Laws

Activate this skill when the user must comply with the California Consumer Privacy Act as amended by the CPRA and the growing set of US state comprehensive privacy laws, needs to layer sector rules such as HIPAA, GLBA and COPPA on top, or is placing the US inside a data residency programme that also covers GDPR, PDPA, PIPL or DPDP and wants a design that works across many states. Triggers when the user mentions "CCPA," "CPRA," "CPPA," "state privacy laws," "Global Privacy Control," "GPC," "Do Not Sell or Share," "opt-out preference signal," "universal opt-out mechanism," "sensitive personal information," "data protection assessment," "HIPAA," "GLBA," "COPPA," "BIPA," "My Health My Data," "data broker registration," or "data localization in the US." Covers CCPA/CPRA and the state patchwork in principle, sector overlays, opt-out signals, and how to design once for many states.

Data Residency By Country167L

Cross-Border Transfer Mechanisms

Activate this skill when the user needs to move personal data lawfully between countries and must choose and document the mechanism: Standard Contractual Clauses, Binding Corporate Rules, certifications, adequacy decisions, transfer impact assessments or China's standard contract, or when a data residency programme must decide which flows can leave a region under GDPR, PDPA, PIPL or DPDP and which data localization rule stops them. Triggers when the user mentions "cross-border transfer," "international data transfer," "SCCs," "Standard Contractual Clauses," "BCRs," "Binding Corporate Rules," "adequacy decision," "Data Privacy Framework," "transfer impact assessment," "TIA," "supplementary measures," "IDTA," "UK Addendum," "China standard contract," "CAC security assessment," "APEC CBPR," "ASEAN MCCs," or "transfer decision tree." Covers each mechanism, how to run a TIA, the China standard contract and filing, the Singapore and India routes, and a decision tree for picking the mechanism per flow.

Data Residency By Country169L

Data Residency Architecture

Activate this skill when the user is designing or auditing the technical architecture that keeps a tenant's data inside a country or region, whether the driver is a data localization law such as PIPL or the RBI's payment rules, a data residency commitment in an enterprise contract, or a transfer restriction under GDPR, PDPA or DPDP. Triggers when the user mentions "data residency," "region pinning," "tenant sharding," "cell-based architecture," "per-region keys," "KMS," "BYOK," "HYOK," "cross-region replication," "backup residency," "log leakage," "telemetry leakage," "CDN and edge," "edge caching of personal data," "support access," "customer lockbox," "data sovereignty," "CLOUD Act," "org policy," "SCP," or "proving residency to auditors." Covers region pinning, tenant-to-region mapping, per-region key management, backups and disaster recovery, the leakage paths in logs, telemetry, CDNs and support tooling, and the evidence pack that satisfies auditors.

Data Residency By Country190L