Insights and updates

From emerging regulation to deal mechanics, we write about the questions founders and investors actually ask — practical analysis you can put to work.

ADM (Automated Decision-Making)

Automated Decision-Making (ADM) covers decisions about individuals made solely by automated means — including profiling — without meaningful human involvement (GDPR Article 22).

DPF (EU-US Data Privacy Framework)

The EU-US Data Privacy Framework (DPF) is the European Commission’s July 2023 adequacy decision (and the parallel UK Extension and Swiss-US Framework) that permits transfers of personal data from the EU/EEA to certified US organisations without additional SCCs or TIAs for those specific transfers.

TIA (Transfer Impact Assessment)

A TIA documents whether the destination country’s laws let your data importer honour SCC safeguards — the Schrems II legacy, now echoed in KVKK’s 2024 regime. The five sections of a defensible assessment.

Subcontractor Employer (Alt İşveren) — Turkey

Under Turkish Labour Law (4857 Sayılı İş Kanunu) Article 2(6)-(7), an alt işveren (subcontractor employer) is an employer that undertakes a specific portion of the principal employer’s (asıl işveren) production or service operations, in connection with auxiliary tasks or specialised areas requiri…

BCR (Binding Corporate Rules)

Binding Corporate Rules (BCRs) are internal data protection rules adopted by multinational groups to legitimise intra-group transfers of personal data from the EU/EEA to third-country group entities (GDPR Article 47).

SCC (Standard Contractual Clauses)

Standard Contractual Clauses (SCCs) are pre-approved EU contractual templates that legitimise transfers of personal data from the EU/EEA to “third countries” lacking an adequacy decision (GDPR Article 46(2)(c)).

Sub-Processor

A sub-processor is a third party engaged by a processor to perform some or all of the processing on behalf of the controller (GDPR Article 28).