Transfers of Personal Data
Due to changing regulations, the transfer of personal data is becoming more complicated for global companies. Before such transfers take place, specific assessments and measures, as well as monitoring compliance are required. This is especially the case regarding international transfers of personal data. We have a global process in place to make sure we are well prepared for these challenges and to ensure our vendors and external parties processing personal data are committed and provide sufficient assurance to process personal data in line with such requirements as well.
Check below how we ensure personal data transfer compliance, as well as what we expect from our vendors and external parties processing personal data.
We continuously enhance and update our operations with new and revised processes to comply with the latest regulatory requirements.
We have introduced an internal, comprehensive process regarding privacy contracting and international transfers of personal data which is followed by the entire ABB group. We also have a set of contractually binding rules regarding how personal data is shared within the ABB group itself (please visit the Summary of ABB Corporate Rules for more details).
Our Privacy Management Team (in close collaboration with other internal stakeholders, such as business representatives, information security team and country privacy leads) conducts Transfer Impact Assessments (TIAs), in case of transfers of personal data, to:
- map the transfers (identify destination countries, types of data and individuals affected, as well as other actors such as organizations involved in the transfer and further processing of data)
- establish the appropriate transfer compliance mechanism (such as Standard Contractual Clauses recognized under the EU and Swiss data protection law, if necessary, complemented by additional provisions and clauses to comply with other regulatory requirements)
- assess the law and practices of relevant destination countries to ensure that the transfer compliance mechanism is effective
- identify and adopt data protection measures
- to fulfil other requirements, where relevant.
Outcomes of the TIAs are well documented and specific recommendations implemented before transferring personal data. However, with this our efforts do not stop, as we continuously monitor compliance and, when needed, modify our assessments, and react to changing situations (such as with additional supplementary data protection measures or limiting or terminating transfers, if necessary).
We expect from our vendors and external parties processing personal data to be well prepared and have sufficient expertise, experience, and resources to process personal data in a compliant way and to be able to provide us with assurance and legally binding commitments regarding the same before personal data is shared and processed.
This includes, but is not limited to:
- providing the relevant documentation and information regarding operations involving personal data and related compliance requirements (such as e.g., privacy notices or policies, where relevant, contract templates, as well as specific contractual terms and provisions), destination countries for personal data, specific risks, and measures to ensure security and compliance
- being able to demonstrate having in place sufficiently trained personal with dedicated privacy and security responsibilities
- contributing to our Transfer Impact Assessment process as well as being able to share the relevant assessment from their own side (vendor/external party side)
- working with ABB in good faith to negotiate and sign appropriate contractual provisions, including, where relevant, data protection or data processing agreement with appropriate additional standard clauses, so as to ensure compliance, protect the privacy, and, at the same time, provide reasonable and just balance between rights and obligations of both parties (although we use on number of occasions our own templates we expect our vendors to be able to share their own contract templates in advance so as to assess their level of privacy compliance preparedness)
- openness regarding the technical and process set up and willingness to collaborate with our privacy and information security team to implement specific measures and adjustments to protect personal data and privacy of individuals.
Our People, Technology and Operations protect personal data. Privacy and data protection are core ABB values and embedded in our corporate policies. For more information, please go to: https://www.abb.com/global/en/company/privacy or contact us at privacy@abb.com.