Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

German DPAs Auditing 500 Companies International Data Transfer Practices

By Squire Patton Boggs & Dr. Annette Demmel on November 3, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

Data protection cloud

On November 3,  ten of the German Data Protection Supervisory Authorities (“DPAs”) announced they will be working together to select approximately 500 companies in Germany to audit for international personal data transfers for the purpose of raising awareness of data protection law. Over the coming days, the investigations will be initiated with a questionnaire.  The DPAs claim they are conducting these audits because they are concerned that companies may not be aware they are transferring data outside of the EU due to the proliferation of cloud-based products and services. They assert the objective of the audit is to examine whether these transmissions are permissible under data protection law.

Next Steps

While the announcement notes this is an issue for both large and small businesses, the DPAs have not stated whether the investigations will be random or specifically targeted.  Thus, any company doing business in Germany is on notice and should determine whether they are transferring data outside of the European Economic Area. If so, companies should confirm that they have EU-U.S. Privacy Shield, EU Standard Contractual Clauses, Binding Corporate Rules, or consent from the data subject in place for these international data transfers. If none of these transfer mechanisms are in place, companies would be wise to immediately amend their contracts with EU Standard Contractual Clauses.

 Mitigation

Though the DPAs claim they want to raise awareness regarding data protection law, it remains unclear whether they will or will not fine companies found in violation of the law. Companies are urged to treat these audit questionnaires very seriously as German DPAs are able to assess a fine up to ‎€300,000 for unlawful data transfers.

By implementing a transfer mechanism, companies may be able to mitigate potential fines. This year, the Hamburg DPA announced they would audit cross-border data transfers to the US and three companies that were found in violation were able to reduce their fines significantly (‎between €8,000 to ‎€11,000 per company) by implementing Standard Contractual Clauses for cross-border transfers during the proceedings. However, multiple German DPAs have expressed their intent to penalize unlawful data transfers more harshly in the future so companies should be prepared for heftier fines if found in violation.

Photo of Dr. Annette Demmel Dr. Annette Demmel
Read more about Dr. Annette DemmelEmail
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Global IP & Technology Law Blog
  • Organization:
    Squire Patton Boggs
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo