Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/Data in telecom/Governance, privacy and checks/Cross-border data transfers for global carriers and MVNOs
1/4+150 XP

Governance, privacy and checks

10Cross-border data transfers for global carriers and MVNOs+15011Consent architecture for telecom marketing and third-party sharing+15012Running a telecom data governance operating model+15013Auditing telecom data pipelines for regulatory readiness+150

Cross-border data transfers for global carriers and MVNOs

# Cross-border data transfers for global carriers and MVNOs

A subscriber from Nairobi lands at Frankfurt airport, turns on roaming, and makes a call. Within seconds, a CDR (call detail record: metadatametadataDonnées sur les données, informations décrivant le contexte, la structure, la provenance et les caractéristiques d'un asset de données (auteur, date, format, source, définition). showing who called whom, when, for how long, and from which cell tower) generated by Safaricom's network gets shared with Deutsche Telekom for billing reconciliation. That single record just crossed a legal fault line most telecom staff never think about: a cross-border personal data transfer, and it may have triggered obligations under Kenya's Data Protection Act and the EU's GDPR (General Data Protection Regulation) simultaneously.

This lesson teaches you to tell the difference between transfer mechanisms that do real legal work and paperwork that exists mostly for show.

Why CDRs and roaming data are personal data

A CDR looks technical, but regulators treat it as personal data because it can identify a subscriber and reveal location, contacts, and behavior patterns. Under GDPR (Article 4), personal data includes anything linkable to an identified or identifiable person, IMSI numbers and MSISDNs (the subscriber's phone number identifier) included.

This matters because the moment that CDR leaves Kenya and lands on a German operator's billing system, it is a "transfer of personal data to a third country" under GDPR Chapter V, and Kenya's Protection Act (2019), enforced by the Office of the Data Protection Commissioner (ODPC), imposes its own cross-border transfer conditions.

own Dataown DataData collected directly from your own customers and prospects through your own channels: your most reliable and privacy-compliant source.Voir la définition complète →

The three real mechanisms, and what each actually requires

1. Adequacy decisions. The European Commission can declare a country's data protection regime "adequate," meaning data can flow there without extra safeguards, as if it were still inside the EU/EEA. As of early 2026, adequacy covers a short list including Japan, South Korea, UK, and Canada (commercial organizations); Kenya is not on that list. Check the current roster on the European Commission's adequacy decisions page.

No adequacy decision for Kenya means the Safaricom-to-Deutsche Telekom flow needs a different mechanism.

2. Standard Contractual Clauses (SCCs). These are pre-approved contract templates issued by the European Commission that both parties sign, legally binding the non-EU recipient to GDPR-equivalent protections. For our roaming example, Safaricom and Deutsche Telekom would embed SCCs into their roaming agreement (often via the GSMA's standard IOT, Inter-Operator Tariff, agreements that already reference data protection annexes).

SCCs are the actual workhorse of telecom data transfers. GSMA (the mobile operator trade body) roaming frameworks like AA.14 and BA.27 build data protection language into commercial roaming contracts by default.

3. Localization carve-outs. Some jurisdictions require certain data categories to stay on domestic soil, full stop, no transfer mechanism cures it. Examples: Russia's data localization law requires personal data of Russian citizens to be first recorded on servers in Russia. India's telecom and financial sector rules impose sector-specific storage requirements. Nigeria's Data Protection Act (2023) and NDPC (Nigeria Data Protection Commission) guidance restrict certain government and critical data from leaving the country without approval.

Carve-outs override SCCs. If a carve-out applies, no contract clause makes the transfer legal.

Where transfer mechanisms are theater

Here is the applied skill: spotting when a "compliance" step is real versus decorative.

Theater example 1: SCCs signed but never operationalized. A carrier signs SCCs with a roaming partner but never runs the required Transfer Impact Assessment (TIA), a documented check of whether the destination country's laws (e.g., surveillance access) undermine the contractual promises. Post the *Schrems II* ruling (Court of Justice of the EU, 2020), SCCs alone are legally insufficient; you must assess and document that the destination actually offers effective protection. Signed paper without a TIA is a checkbox, not a control.

Theater example 2: Adequacy assumed, not verified. Teams sometimes assume "the UK is fine, it's basically still in Europe." The UK's post-Brexit adequacy status is real but was time-limited and subject to renewal review; treating it as permanent without monitoring is a governance gap.

Theater example 3: Anonymization claims that aren't. Some MVNOs (Mobile Virtual Network Operators, companies that resell network capacity from an MNO, Mobile Network Operator, without owning infrastructure) claim CDR data shared for analytics is "anonymized" and therefore outside GDPR entirely. If the dataset retains cell-tower-level granularity and timestamps, re-identification is often trivial (a known finding from mobility data research, e.g., studies referenced by MIT's work on unicity of human mobility traces). Calling it anonymized when it's merely pseudonymized is a real compliance risk, not a solved one.

A real, non-theater case: in 2021 the Kenyan ODPC and telecom regulator scrutiny around SIM registration data pushed Safaricom to tighten how subscriber data was shared with third parties, showing local enforcement does have teeth even without EU-style fines.

A practical audit checklist

When you inherit a roaming or interconnect data flowdata flowAn automated sequence of steps that moves data from source to destination: ingestion, transformation, validation, and loading, so it arrives clean and ready to use.Voir la définition complète →, run these checks before assuming a mechanism is valid:

Transfer Audit Checklist (data flow: Origin MNO -> Destination Partner)

1. Data mapping
   - What fields are in the CDR/record? (IMSI, location, call content?)
   - Is it personal data under both origin and destination law?

2. Mechanism check
   - Is there an adequacy decision covering destination? (Y/N, cite source)
   - If no: are SCCs signed AND is there a documented Transfer Impact Assessment?
   - Does any localization law apply to this data category? (carve-out check)

3. Operational verification
   - Encryption in transit? (yes/no, protocol)
   - Retention period matches contract terms?
   - Sub-processors (e.g., billing clearinghouses like BICS or Syniverse) covered
     by the same SCCs, or is there a gap?

4. Governance sign-off
   - DPO (Data Protection Officer) reviewed and dated?
   - Renewal/monitoring trigger set (e.g., adequacy status review date)?

Note step 3's mention of clearinghouses: roaming data often does not go carrier-to-carrier directly. Intermediaries like Syniverse or BICS handle CDR exchange and settlement, meaning your transfer chain has more hops, and more potential gaps, than the two-party contract suggests.

Vérification des acquis

1. Why do regulators classify a CDR (call detail record) as personal data rather than mere network metadata?

2. A Kenyan MNO's roaming CDR is shared with a German operator for billing reconciliation. Which statement best captures the legal complexity of this scenario?

3. What is the practical legal effect of the European Commission granting a country an 'adequacy decision'?

CHOIX MULTIPLES

4. Select ALL correct answers about why a roaming CDR shared between a Kenyan and a German carrier constitutes a 'cross-border personal data transfer' with real legal consequences.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers describing the distinction the lesson draws between transfer mechanisms that 'do real legal work' versus 'paperwork that exists mostly for show'.

Sélectionnez toutes les réponses correctes.

What good governance looks like in practice

Mature telecom groups treat cross-border transfer compliance as an ongoing operational process, not a one-time legal sign-off:

  • Data flow inventories updated when new roaming partners or MVNO agreements are onboarded, not just at initial launch.
  • Standing legal monitoring of adequacy decision changes (the EU periodically reviews and can revoke adequacy, as it did with parts of the US Privacy Shield framework in 2020, replaced later by the EU-US Data Privacy Framework in 2023).
  • Joint audits with clearinghouses since CDR data typically transits third-party settlement platforms outside the direct MNO-to-MNO relationship.
  • Sector regulator alignment: telecom regulators (Kenya's Communications Authority, Germany's Bundesnetzagentur) often have separate rules layered on top of general data protection law, so telecom-specific licensing conditions must be checked alongside GDPR/DPA analysis.

🎬 [VIDEO: "GDPR International Data Transfers Explained" - youtube.com/results?search_query=GDPR+international+data+transfers+explained - a walkthrough of adequacy, SCCs, and Schrems II from a data protection training channel]

Key Takeaways

  • A roaming CDR crossing borders is a personal data transfer under GDPR and many national laws simultaneously; treat it as a legal event, not just a technical handoff.
  • Three mechanisms matter: adequacy decisions (blanket approval for specific countries), SCCs (contractual fallback, the telecom industry workhorse), and localization carve-outs (which override everything else when triggered).
  • SCCs without a documented Transfer Impact Assessment are compliance theater post-Schrems II; the paperwork must be backed by an actual assessment of destination-country law.
  • Anonymization claims on mobility/CDR data deserve scrutiny: high-granularity location and timestamp data is frequently re-identifiable, meaning it may still be personal data.
  • Real audits must trace the full chain, including clearinghouses like Syniverse or BICS, not just the two named parties in the roaming contract.

Suivant

Consent architecture for telecom marketing and third-party sharing