Boardroom Answers · Security & Compliance · Compliance, Regulatory & Legal
You're hosting my European board's data in Japan. Walk me through your Article 44 transfer basis — and don't tell me "the cloud is global.?
The question a Chief Privacy Officer / DPO asks.
The short answer
Japan holds an EU adequacy decision, so the Tokyo transfer is lawful under Article 45 without SCC gymnastics — and if you need data that never leaves the EU, our own code (residencyOffered) forbids us claiming that until the EU cell, already built and config-ready, is provisioned on committed demand.
The full executive answer
The transfer basis is stronger than most vendors' because of a specific legal fact: Japan holds a European Commission adequacy decision — one of the short list of countries the EU has formally determined provides essentially equivalent protection — so an EU-to-Japan transfer under Article 45 does not require Standard Contractual Clauses or transfer impact assessments the way a US transfer does. Our production cell runs on AWS in Tokyo (ap-northeast-1) via Supabase, with encryption in transit (TLS 1.2+) and at rest (AES-256). For the sub-processor chain, where processing touches entities outside adequacy protection — the AI providers, for instance — our DPA flows down Standard Contractual Clauses under Article 46 as the fallback mechanism, alongside the technical supplementary measures (PII redaction before any AI call, encryption, pseudonymisation) that Schrems II analysis expects.
Now the part I'll say before you probe for it: if your requirement is not "lawful transfer" but "data never leaves the EU," we cannot satisfy that today, and our own code refuses to let us pretend otherwise. The architecture is multi-region by design — EU and India cells are fully coded and configuration-ready — but they are not provisioned, and a function in our codebase called residencyOffered() gates every marketing and onboarding surface so the product is structurally incapable of offering a residency choice that isn't physically live. There's even a guard that throws an error if anyone tries to pin an organisation to a non-provisioned region. We built honesty about this into the software because a false residency claim is the kind of thing that ends vendor relationships and DPO careers alike.
The path: an EU cell is provisioned on committed demand — it's configuration and cost, not engineering, with a realistic stand-up measured in weeks — and an anchor European customer's contract is exactly the trigger. Until then, the honest offering is adequacy-based transfer to Japan with full Chapter V compliance, DPA transparency about every sub-processor's location, and your right to object to changes. For India: DPDP's transfer regime currently operates on a government blacklist basis, and Japan is not restricted — the same architecture serves, with the India cell ready when data-localisation rules or customer requirements demand it.
Grounded in: GDPR Art. 45 (Japan adequacy decision, 2019), Art. 46 (SCCs), Chapter V generally; Schrems II (C-311/18) supplementary measures; India DPDP Act 2023 s.16 (transfer restrictions).
The natural next questions
Related governed answers
- Under Article 30 I must maintain records of processing, and as my processor you feed those records. Can you actually tell me what personal data you process, where, and why — or will I get a shrug?
- Your DPA lands on my desk tomorrow. What Article 28 terms will I find, and which ones will your engineering actually honour rather than merely promise?
- Enumerate every third party that touches my data. Vendors always forget two — don't be that vendor.?
Want this answered live, on your data?