Multi Company, one in the EU. Question about data privacy

We are a US company that has a sister company in Germany. We are on prem with our server in USA. We want to bring the Germany company onto our epicor but they are concerned with GDPR regulations for data leaving the EU. They would be a separate company in our instance of Epicor.

How do other companies handle this?
What can I say to ease concerns so I can get them on Epicor.

I think it depends on two things -

  • is there a single parent company and in which country?

  • is your Epicor site license a USA site license or an EU site - or do you have two?

We are a US parent company of multiple US/UK/NL companies in a single database MC environment. We went through the GDPR arguments with our UK folks years ago when it first started, and there are a few sections to be applied here. I cant’ name them by section # or quote verbatim, but here’s the gist that we stand on:

First - the GDPR allows for PID to the extent that it is necessary “for the transaction” and no more. We don’t collect anything about our customers/contacts/suppliers other than the necessary name, contact and address information - GDPR allows that and does NOT have to be anonymized upon request.

Second - thought the corporate ownership, software architecture and licensing model, and intercompany activity, GDPR allows for the centralization of data off-shore as long as you can adequately attest to the backup and security measures you have in place - I think that is via a “promise’ by the designated Data Protection Officer(?) required by GDPR.

There’s probably more to it but that’s what I can recall right now. Hope that helps.

Thats similar to what Gemini was telling me too. Thanks Mike.

Just have to be careful with employee’s information. We only put names in for the EU team, and those can be de-identified on request (system stores EmpID anyway).

We also have a replica of our DB in the EU for compliance purposes.

The best bet is going to be to educate yourself and then consult some legal advice. Lots of other things can play into this, like @Doug.C’s operating environment might not be the same as ours, or his lawyers are puckered up a bit tighter than ours.

If you’re doing any sort of web-based direct to consumer transactions, then GDPR is a whole lot worse for you.

GDPR was written so that they could come at you for anything as long as they worded it right, and it handed all the power to the “consumer”. But companies are generally/notoriously sloppy with privacy and security - and unscrupulous if they can make a buck - so I understand it.