The organization should record transfers of personal data to and from third parties. The organization should also ensure the cooperation of the relevant parties in order to enable the implementation of requests regarding obligations related to data subjects in the future as well.
The principle of data minimization must be taken into account in recordings concerning transfers and only the information that is actually needed must be kept.
The organization has identified possible transfers of personal data between jurisdictions.
There are identified and documented legal bases for transfers of personal data between jurisdictions.
GDPR defines the conditions for the lawful transfer of personal data outside the EU or the EEA.
The organization shall document all data transfers and the applicable transfer criteria. Data transfers can occur, for example, based on the location of the data system, the data processing partner or the recipient of the data disclosure.