Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/Data in professional services/Governance, privacy and checks/Cross-border client data under GDPR, sector rules and client contracts
3/4+150 XP

Governance, privacy and checks

10Confidentiality walls that survive an audit, not just a policy binder+15011Conflicts checks as a data problem, not a form+15012Cross-border client data under GDPR, sector rules and client contracts+15013Running a data audit that a regulator or client can't poke holes in+150

Cross-border client data under GDPR, sector rules and client contracts

# Cross-border client data under GDPR, sector rules and client contracts

A partner in the Frankfurt office of a global consulting firm emails a spreadsheet of client employee data to a colleague in the Mumbai delivery centre, who needs it to finish a workforce analytics deliverable due in New York the next morning. Three jurisdictions, one file, and at least four overlapping rulebooks now apply to it. This is the daily reality of professional services work, and it is where data governancedata governanceData governance is the set of policies, roles, and processes that ensure data is accurate, secure, well-defined, and used responsibly across an organization.Voir la définition complète → stops being theoretical.

This lesson walks through that stack: GDPR, sector confidentiality duties, and the contract clauses clients negotiate on top. We look at where they reinforce each other, and where they quietly contradict.

The three-jurisdiction engagement, mapped

Picture a real-shape engagement: a US-headquartered client, a German subsidiary supplying the data, and an Indian delivery team doing the analysis.

Layer 1: GDPR. The General Data Protection Regulation (EU regulation, in force since 2018) governs personal data of people in the EU, regardless of where the processing happens. The German subsidiary's HR data is squarely in scope. Moving it to India is an "international data transfer" and needs a legal mechanism: Standard Contractual Clauses (SCCs, EU Commission-approved contract templates) or an adequacy decision (a European Commission finding that a country's laws offer equivalent protection; India does not currently have one).

Layer 2: sector confidentiality duties. Professional services firms carry duties independent of privacy law. Auditors have statutory confidentiality obligations under national companies acts and professional codes (e.g., the IESBA Code of Ethics for accountants, ifac.org). Law firms have attorney-client privilege and bar-rule confidentiality that can be stricter than GDPR and does not expire when a matter closes. Management consultants typically rely on contractual confidentiality alone, which is weaker than either.

Layer 3: client contract clauses. Beyond law, the master service agreement (MSA) often adds its own rules: data residency requirements ("all data must stay within the EU"), named-individual access lists, breach notification windows shorter than GDPR's, or an outright ban on subcontracting to certain countries.

The three layers rarely say the same thing. The contract might forbid India processing altogether, even though GDPR would permit it with SCCs in place.

Where the layers reinforce each other

Some requirements are genuinely aligned and firms can build one control that satisfies all three.

  • Data minimisation. GDPR Article 5 requires collecting only what's necessary. Most client MSAs say the same. A workforce analytics project doesn't need home addresses; strip them at intake.
  • Access logging. GDPR's accountability principle (Article 5(2)) requires firms to demonstrate compliance. Client contracts increasingly demand audit trails showing exactly who touched the data and when. One access-logging system serves both asks.
  • Breach notification. GDPR gives 72 hours to notify the relevant Data Protection Authority (DPA) after becoming aware of a breach (Article 33). Many contracts now mirror this or go tighter, so building a 72-hour-capable incident response process clears both bars.

Where they conflict, and who wins

Conflicts are the real governance work. Three recurring patterns:

1. Data residency vs. delivery model. A client contract says "no processing outside the EU." The firm's global delivery model routes analytics work through Mumbai or Manila. Resolution requires either a contractual carve-out negotiated up front, or restructuring the engagement to keep EU personal data on EU-based teams (common in banking and public sector work).

2. Retention periods. GDPR's storage limitation principle says keep personal data no longer than necessary. But an auditor's professional standards (e.g., under the PCAOB in the US or the equivalent EU audit regulation) may require retaining audit working papers for 7 to 10 years. Law firms face similar tension: GDPR says delete, professional indemnity insurers say keep records for the limitation period on negligence claims (often 6 years in the UK, longer for latent defects). Sector law generally overrides GDPR's default here because GDPR itself permits retention where another EU or member state law requires it (Article 6(1)(c)).

3. Subject access requests vs. privilege. Under GDPR Article 15, an individual can request a copy of their personal data. If that data sits inside a law firm's privileged legal advice, privilege can lawfully limit what must be disclosed. Firms need a documented policy for this, not an ad hoc judgment call each time, because getting it wrong risks either a privilege waiver or a regulatory complaint.

The transfer mechanism problem, concretely

Since the *Schrems II* ruling (Court of Justice of the EU, 2020), SCCs alone are not automatically sufficient. Firms must run a Transfer Impact Assessment (TIA): a documented check of whether the destination country's surveillance laws could let its government access the data despite the contract.

A simplified version of what a TIA actually checks:

Transfer Impact Assessment — quick checklist
1. Destination country: does it have an EU adequacy decision? (Y/N)
2. If N, are SCCs (or Binding Corporate Rules) signed and current?
3. Does destination law allow government access without judicial oversight
   comparable to the EU standard? (review sources: country surveillance law)
4. Supplementary measures in place? (encryption at rest/in transit,
   pseudonymisation, split-key access)
5. Residual risk: document and get sign-off from DPO or legal

For the India-Germany-US example, a firm's Data Protection Officer (DPO, the person required under GDPR Article 37 for many controllers and processors) would need this on file before the Mumbai team touches the German file, not after.

The European Data Protection Board publishes guidance on TIAs and international transfers that is the current reference point.

Vérification des acquis

1. Why does moving the German subsidiary's HR data to the Mumbai delivery centre trigger GDPR obligations, even though the processing itself occurs outside the EU?

2. What is the core function of Standard Contractual Clauses (SCCs) in the scenario described?

3. How does attorney-client privilege for law firms typically differ from GDPR obligations in terms of duration and scope?

CHOIX MULTIPLES

4. Select ALL correct answers about why the Frankfurt-to-Mumbai file transfer involves 'overlapping rulebooks' rather than a single compliance check.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers about international data transfer mechanisms under GDPR.

Sélectionnez toutes les réponses correctes.

Practical checks and audits to run

Governance only matters if it's tested. Four checks worth running on any cross-border professional services engagement:

Data flow mapping. Before work starts, diagram where the data physically goes: intake, storage, processing location, output, deletion. Most firms discover their actual data flowdata flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.Voir la définition complète → doesn't match what the contract describes. This is the single highest-value audit step and takes a few hours, not weeks.

Clause reconciliation. Line up the MSA's data clauses against GDPR requirements and sector rules in a table. Flag conflicts explicitly rather than assuming the strictest one silently wins. Legal and the engagement partner should sign off on the resolution, in writing.

Access control audit. Pull the actual list of who has system access to a client file and compare it to who's contractually authorised. Overprovisioned access (a common finding: junior staff or offshore teams retaining access after rotating off an engagement) is the most frequent real-world gap.

Vendor and subprocessor check. If the firm uses cloud tools (Microsoft 365, Salesforce, an AI-assisted drafting tool), each is a subprocessor under GDPR and needs its own dataown dataData collected directly from your own customers and prospects through your own channels: your most reliable and privacy-compliant source.Voir la définition complète → processing agreement (DPA) and, if outside the EU, its own transfer mechanism. Firms rolling out generative AI tools in 2026 are finding this is where governance gaps show up fastest, since AI vendors' data handling terms vary widely and change often.

Key Takeaways

  • Cross-border professional services engagements sit under at least three rule layers at once: GDPR, sector confidentiality duties (audit, legal privilege, professional codes), and client contract clauses. They frequently conflict, and firms need a documented resolution, not an assumption.
  • International transfers of EU personal data require a legal mechanism (SCCs or an adequacy decision) plus, since *Schrems II* (2020), a Transfer Impact Assessment documenting real-world surveillance risk in the destination country.
  • Retention conflicts are common and usually resolve in favour of sector law: GDPR itself permits longer retention where another law (audit, professional indemnity) requires it.
  • Run data flowdata flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.Voir la définition complète → mapping, clause reconciliation, access audits, and subprocessor/vendor DPA checks on every multinational engagement, ideally before work starts, not after a client asks.
  • AI tools and cloud vendors are subprocessors under GDPR. Each one added to a delivery workflow needs its own DPA and transfer check, a fast-growing governance gap in 2026 engagements.

Précédent

Conflicts checks as a data problem, not a form

Suivant

Running a data audit that a regulator or client can't poke holes in