If you’re based in the EU or UK, the GDPR says you must protect that data when it’s sent outside your country. We do this by using the EU Standard Contractual Clauses (SCCs) and the UK Addendum. These legal agreements help make sure your data stays protected, even when it’s transferred internationally.
Zanda has already taken care of this for you. Because we process data on your behalf, the SCCs and UK Addendum are included in our Global Data Processing Agreement (DPA), which is part of our Terms of Use. They apply automatically when you start using Zanda and stay in place for as long as you have a subscription.
What if your account isn’t based in the EU or UK, but your client is?
The Global DPA linked above, including the SCCs and UK Addendum, is part of the Terms of Use for every Zanda subscription, not only accounts based in the EU or UK. It applies automatically as soon as you subscribe and covers how we protect any personal data we process on your behalf, including data about clients based in the EU or UK.
Whether GDPR itself applies directly to your own business depends on your circumstances and where your clients are, so that’s a question for your own legal adviser. What we can confirm is that these data-protection safeguards are already in place on your account, with nothing extra to set up.
You can download the Global DPA using the link above and keep a copy for your records. For a fuller picture of Zanda security certifications and compliance documentation, see Responding to Security and Data Residency Audits.
If you have any questions about this, please let us know.
