# Cross-border client data under GDPR, sector rules and client contracts
A partner in the Frankfurt office of a global consulting firm emails a spreadsheet of client employee data to a colleague in the Mumbai delivery centre, who needs it to finish a workforce analytics deliverable due in New York the next morning. Three jurisdictions, one file, and at least four overlapping rulebooks now apply to it. This is the daily reality of professional services work, and it is where data governancedata governanceData governance is the set of policies, roles, and processes that ensure data is accurate, secure, well-defined, and used responsibly across an organization.Voir la définition complète → stops being theoretical.
This lesson walks through that stack: GDPR, sector confidentiality duties, and the contract clauses clients negotiate on top. We look at where they reinforce each other, and where they quietly contradict.
Picture a real-shape engagement: a US-headquartered client, a German subsidiary supplying the data, and an Indian delivery team doing the analysis.
Layer 1: GDPR. The General Data Protection Regulation (EU regulation, in force since 2018) governs personal data of people in the EU, regardless of where the processing happens. The German subsidiary's HR data is squarely in scope. Moving it to India is an "international data transfer" and needs a legal mechanism: Standard Contractual Clauses (SCCs, EU Commission-approved contract templates) or an adequacy decision (a European Commission finding that a country's laws offer equivalent protection; India does not currently have one).
Layer 2: sector confidentiality duties. Professional services firms carry duties independent of privacy law. Auditors have statutory confidentiality obligations under national companies acts and professional codes (e.g., the IESBA Code of Ethics for accountants, ifac.org). Law firms have attorney-client privilege and bar-rule confidentiality that can be stricter than GDPR and does not expire when a matter closes. Management consultants typically rely on contractual confidentiality alone, which is weaker than either.
Layer 3: client contract clauses. Beyond law, the master service agreement (MSA) often adds its own rules: data residency requirements ("all data must stay within the EU"), named-individual access lists, breach notification windows shorter than GDPR's, or an outright ban on subcontracting to certain countries.
The three layers rarely say the same thing. The contract might forbid India processing altogether, even though GDPR would permit it with SCCs in place.
Some requirements are genuinely aligned and firms can build one control that satisfies all three.
Conflicts are the real governance work. Three recurring patterns:
1. Data residency vs. delivery model. A client contract says "no processing outside the EU." The firm's global delivery model routes analytics work through Mumbai or Manila. Resolution requires either a contractual carve-out negotiated up front, or restructuring the engagement to keep EU personal data on EU-based teams (common in banking and public sector work).
2. Retention periods. GDPR's storage limitation principle says keep personal data no longer than necessary. But an auditor's professional standards (e.g., under the PCAOB in the US or the equivalent EU audit regulation) may require retaining audit working papers for 7 to 10 years. Law firms face similar tension: GDPR says delete, professional indemnity insurers say keep records for the limitation period on negligence claims (often 6 years in the UK, longer for latent defects). Sector law generally overrides GDPR's default here because GDPR itself permits retention where another EU or member state law requires it (Article 6(1)(c)).
3. Subject access requests vs. privilege. Under GDPR Article 15, an individual can request a copy of their personal data. If that data sits inside a law firm's privileged legal advice, privilege can lawfully limit what must be disclosed. Firms need a documented policy for this, not an ad hoc judgment call each time, because getting it wrong risks either a privilege waiver or a regulatory complaint.
Since the *Schrems II* ruling (Court of Justice of the EU, 2020), SCCs alone are not automatically sufficient. Firms must run a Transfer Impact Assessment (TIA): a documented check of whether the destination country's surveillance laws could let its government access the data despite the contract.
A simplified version of what a TIA actually checks:
Transfer Impact Assessment — quick checklist
1. Destination country: does it have an EU adequacy decision? (Y/N)
2. If N, are SCCs (or Binding Corporate Rules) signed and current?
3. Does destination law allow government access without judicial oversight
comparable to the EU standard? (review sources: country surveillance law)
4. Supplementary measures in place? (encryption at rest/in transit,
pseudonymisation, split-key access)
5. Residual risk: document and get sign-off from DPO or legalFor the India-Germany-US example, a firm's Data Protection Officer (DPO, the person required under GDPR Article 37 for many controllers and processors) would need this on file before the Mumbai team touches the German file, not after.
The European Data Protection Board publishes guidance on TIAs and international transfers that is the current reference point.
Vérification des acquis
1. Why does moving the German subsidiary's HR data to the Mumbai delivery centre trigger GDPR obligations, even though the processing itself occurs outside the EU?
2. What is the core function of Standard Contractual Clauses (SCCs) in the scenario described?
3. How does attorney-client privilege for law firms typically differ from GDPR obligations in terms of duration and scope?
4. Select ALL correct answers about why the Frankfurt-to-Mumbai file transfer involves 'overlapping rulebooks' rather than a single compliance check.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about international data transfer mechanisms under GDPR.
Sélectionnez toutes les réponses correctes.
Governance only matters if it's tested. Four checks worth running on any cross-border professional services engagement:
Data flow mapping. Before work starts, diagram where the data physically goes: intake, storage, processing location, output, deletion. Most firms discover their actual data flowdata flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.Voir la définition complète → doesn't match what the contract describes. This is the single highest-value audit step and takes a few hours, not weeks.
Clause reconciliation. Line up the MSA's data clauses against GDPR requirements and sector rules in a table. Flag conflicts explicitly rather than assuming the strictest one silently wins. Legal and the engagement partner should sign off on the resolution, in writing.
Access control audit. Pull the actual list of who has system access to a client file and compare it to who's contractually authorised. Overprovisioned access (a common finding: junior staff or offshore teams retaining access after rotating off an engagement) is the most frequent real-world gap.
Vendor and subprocessor check. If the firm uses cloud tools (Microsoft 365, Salesforce, an AI-assisted drafting tool), each is a subprocessor under GDPR and needs its own dataown dataData collected directly from your own customers and prospects through your own channels: your most reliable and privacy-compliant source.Voir la définition complète → processing agreement (DPA) and, if outside the EU, its own transfer mechanism. Firms rolling out generative AI tools in 2026 are finding this is where governance gaps show up fastest, since AI vendors' data handling terms vary widely and change often.