Skip to main content

On-demand webinar coming soon...

Blog

EU-US data transfers: Is BYOK the answer?

Data transfers to the US have recently come under scrutiny in Europe. Is Bring Your Own Key the solution?

February 21, 2022

orange gradient

Nearly two years on, the fallout from the Schrems II decision is continuing to cause organizations difficulties with international data transfers – especially when transferring data to the US. This is in part down to the legal framework of the US enabling government surveillance agencies access to personal information upon request and as such there has been widespread debate about the effectiveness of additional measures for protecting personal data.

This issue was recently put under the spotlight again when the Austrian Data Protection Authority (DSB) issued a decision in a case brought against an analytics service provider. The DSB found the operator of an EU website to have violated Article 44 of the General Data Protection Regulation (GDPR) by transferring personal data through the analytics service provider to the US without providing a level of protection that is essentially equivalent to that guaranteed in the EEA. In the case, it was noted that the analytics service provider had relied on Article 46 standard contractual clauses (SCCs) and technical measures that included encryption at rest to protect the personal data. The DSB found that the latter cannot be effective due to the US-based analytics provider having the ability to revert encrypted data to plain text as well as their obligation to provide access to US surveillance agencies on request, thus nullifying any legal protection that encryption provides.

While discussions are ongoing regarding a new transfer agreement between the EU and the US, organizations need to ensure that the protections they are currently applying to personal data are adequate. This is where Bring Your Own Key (BYOK) could be the solution for many EU organizations transferring personal data to the US. But what is BYOK? And how can it help businesses transfer personal data from the EU to the US given the complexity of the post-Schrems data transfer landscape?

What is Bring Your Own Key?

BYOK is a method that organizations can employ to manage their encryption keys when hosting data with cloud service providers. BYOK gives organizations greater control over access to encrypted data by making the creation and storage of encryption keys separate from the cloud host. As a result, the organization has its own key to ‘unlock’ the encrypted data stored in the cloud.

Keeping access to encryption keys separate from encrypted data can be beneficial in several circumstances. In the event of a security incident, for example. BYOK quashes scenarios where personal data falls into the wrong hands and is subsequently decrypted to reveal personally identifiable information by removing the possibility of the hackers having the means to revert the data into plain text.

The benefits of BYOK protocols can also be seen when protecting personal data during international data transfers. The recent analytics service provider case highlighted the importance of ensuring that encrypted personal data cannot be reverted to plain text by third parties subsequently protecting it from government access in third countries.

It is worth noting that the security of the encryption keys is of paramount importance when utilizing BYOK. Not securing the encryption key appropriately would be like keeping your PIN and credit card in the same place.

How can you leverage BYOK for data transfers?

BYOK could be used as a solution for many businesses transferring data internationally if control over access to the encryption key remains with the data exporter who would not be subject to government surveillance requests from the third country. In the case that was recently ruled upon by the DSB, if the EU website operator had implemented a BYOK protocol and retained sole control of the encryption key, the US surveillance agencies would have had to meet a significantly high legal threshold to successfully request the data from the EU exporter.

The idea of keeping control over encryption keys in the jurisdiction where the data exporter is based extends beyond the recent case brought before the DSB and can be applied to several scenarios where personal information is transferred from the EU to a third country.

For example, a vendor based in a third country may be obligated to hand over access to the encrypted personal data in the event of a government agency request. However, in this example, an EU-based data exporter has no obligation to hand over the encryption key to a third-country government agency without a lawful warrant that would be subject to the review and lawfulness test under the applicable EU laws – including the GDPR. Therefore, the vendor in such a scenario has no means to decrypt the personal data. The personal data remains safely encrypted and there is no legal way for the government agency to access personally identifiable information without also submitting a request to the EU exporter and passing the threshold for lawful request under the EU laws.

Does OneTrust support BYOK?

As a cloud service provider, OneTrust enables its customers to bring their own keys to encrypted data stored with us. When hosting data in our cloud environments OneTrust customers can manage their encryption keys via a secure OneTrust vault, helping to maintain control of creating, disabling, and revoking access. This can also prevent unauthorized third parties from having the ability to decrypt customer data including the potential to limit OneTrust’s access to the data.

Speak to one of our experts today and learn more about how OneTrust helps with implementing BYOK protocols.


You may also like

eBook

Privacy & Data Governance

Data governance across industries: Leveraging your organization's most valuable asset

Download our new eBook and learn how to leverage the value of data governance across industries, including financial services, healthcare, retail, and manufacturing.

April 17, 2024

Learn more

Infographic

Data Discovery & Classification

Data governance in manufacturing: Challenges and use cases

Learn the impact a data governance program has in manufacturing and how it enables greater efficiency across your supply chain

February 26, 2024

Learn more

Infographic

Data Discovery & Classification

What to look for in a data discovery solution

Make sure you choose the right data discovery solution for your organization with our comprehensive breakdown of key benefits and features to look for.

February 20, 2024

Learn more

Infographic

Data Discovery & Classification

Data governance in retail: Challenges and use cases

Learn how data governance can help manage the high volume and sensitivity of data that runs through your retail operations.

February 12, 2024

Learn more

Infographic

Data Discovery & Classification

Data governance in healthcare: Challenges and use cases

Learn how data governance can help your healthcare organization effectively manage its protected health information (PHI) and other sensitive data.

February 08, 2024

Learn more

Infographic

Data Discovery & Classification

Data governance in financial services: Challenges and use cases

Learn how data governance can help address common challenges in the financial services industry and protect your most critical information.

January 12, 2024

Learn more

Webinar

Data Discovery & Security

A guided tour of OneTrust Data Discovery magic

Our expert speaker will demonstrate how common real-world data challenges can be identified, addressed, and reported on, leading to better data governance, security, and alignment with business goals. 

October 26, 2023

Learn more

Webinar

Data Discovery & Security

Data minimization and risk assessment in data discovery

Explore the concept of data minimization and its crucial role in enhancing security, privacy, and reducing risk.

October 19, 2023

Learn more

Webinar

Data Discovery & Security

Data Discovery Dispelled: Unmasking the mysteries of data

Join us for a journey into the heart of data management as we explore the depths of data within organizations and shed light on how technology can enhance data security, privacy, and compliance.

October 12, 2023

Learn more

Webinar

Data Discovery & Security

Data Discovery Dispelled: Data's dark corners

Join the first part of our Data Discovery Dispelled webinar series where we will discuss the hidden sensitive information that could pose risks for your organization.

October 12, 2023

Learn more

Report

Data Discovery & Security

OneTrust named a strong performer in 2023 Forrester Data Governance Wave​

Download The Forrester WaveTM: Data Governance Solutions, Q3 2023 report to see why OneTrust was named a strong performer.

September 26, 2023

Learn more

Data Sheet

Data Discovery & Security

Data Discovery and Security

Explore our OneTrust Data Discovery and Security data sheet to learn how you can discover and control your data while enabling your teams.

September 18, 2023

Learn more

eBook

Data Discovery & Classification

Ultimate guide to building a data governance program

Download this eBook and learn practical methods in building a flexible data governance program that aligns with your business.

August 14, 2023

Learn more

Webinar

Data Discovery & Classification

Live demo: OneTrust Data Discovery

See how OneTrust Data Discovery can help your organization achieve complete data visibility to empower your security program and reduce risk.

June 23, 2023

Learn more

Webinar

Data Discovery & Classification

Data responsibility: The information security professional’s higher purpose

Join OneTrust and KPMG for a dialogue with Information Security leaders on managing the balance between risk and reward when handling sensitive customer information.

June 20, 2023

Learn more

Webinar

Data Discovery & Classification

OneTrust Data Discovery Day: A deep dive into automating data discovery and classification

Join us for a two-hour deep dive into data discovery and how OneTrust helps privacy, IT, and security teams understaind their data and achieve risk reduction goals.

June 13, 2023

Learn more

Infographic

Data Discovery & Classification

How OneTrust Data Discovery integrates with Microsoft 365

Explore three key integration capabilities of OneTrust Data Discovery and Microsoft 365.

June 13, 2023 3 min read

Learn more

Report

Privacy & Data Governance

Gartner® Innovation Insights: Data Security Posture Management (DSPM)

Read this report from Gartner® that highlights some of the key capabilities needed in a DSPM.

 

May 30, 2023

Learn more

Webinar

Trust Intelligence

How the Onetrust platform is innovating to unlock the value of trust

Join this webinar to learn how OneTrust is enhancing its privacy management, data governance, and consent and preferences solutions to help organizations tackle data sprawl and enable regulatory agility.

May 24, 2023

Learn more

Data Sheet

Data Discovery & Security

Employee onboarding and offboarding management

Download our onboarding and offboarding management data sheet and learn how OneTrust Certification Automation can help reduce your risk exposure and improve compliance.

May 17, 2023

Learn more

White Paper

AI Governance

Navigating responsible AI: A privacy professional's guide

Download our white paper and learn how privacy teams help organizations establish and implement polices that ensure AI applications are responsible and ethical. 

May 03, 2023

Learn more

Infographic

Data Discovery & Classification

The CISO challenge: Data. Threats. Regulations.

Unstructured data poses risks due to its open access and lack of governance, and CISOs need to implement measures to track, de-risk, and protect it.

March 03, 2023

Learn more

Webinar

Data Discovery & Security

Insights & analytics: Digging into the data to measure and accelerate trust programs webinar

See how OneTrust Insights and Analytics empowers privacy, marketing, data, and security teams with reporting functionality using solution-based dashboards.

August 02, 2022

Learn more

Webinar

Data Discovery & Security

Rethinking trusted data

Join us for a discussion on the latest trends in trusted data and how you can take critical steps to build trust in data practices

May 24, 2022

Learn more

Webinar

Data Discovery & Security

Optimizing data usage through integrated data privacy and governance

Join us for a discussion on driving better business use and outcomes from data while ensuring regulatory requirements are met.

May 24, 2022

Learn more

Webinar

Data Discovery & Security

Build your foundation through data discovery & mapping

In this webinar we cover how data discover and mapping helps you streamline compliance with US privacy laws such as the CPRA, the CDPA, and Colorado's Privacy Act.

March 24, 2022

Learn more

Webinar

Data Discovery & Security

UK DSAR Automation: How Data Discovery enhances your DSAR workflow

Learn how OneTrust Data Discovery enhances DSAR workflow and automates the DSAR lifecycle in this webinar.

March 18, 2022

Learn more

Webinar

Data Discovery & Security

Data Discovery South Africa: How to create value and demonstrate trust through your data?

Watch this webinar and discover how automated data discovery is helping clients in South Africa create value and demonstrate trust. 

March 10, 2022

Learn more

Webinar

Data Discovery & Security

Data Discovery Türkiye: How to create value and demonstrate trust through your data?

Watch this webinar and discover how automated data discovery is helping clients in Türkiye create value and demonstrate trust. 

March 09, 2022

Learn more

Webinar

Data Discovery & Security

Data Discovery Hungary: How to create value and demonstrate trust through your data? | Resources | OneTrust

Watch this webinar and discover how automated data discovery is helping clients in Hungary create value and demonstrate trust.

March 08, 2022

Learn more

Webinar

Data Discovery & Security

Data Discovery Romania: How to create value and demonstrate trust through your data?

Watch this webinar and discover how automated data discovery is helping clients in Romania create value and demonstrate trust. 

March 08, 2022

Learn more

Webinar

Data Discovery & Security

Data Discovery Israel: How to create value and demonstrate trust through your data?

Watch this webinar and discover how automated data discovery is helping clients in Israel create value and demonstrate trust. 

March 05, 2022

Learn more

Webinar

Data Discovery & Security

Privacy automation: bridging the gap between compliance & data governance to deliver trusted public services

Learn how you can take the first steps towards data intelligence and advance your privacy program to the next phase of automation and maturity.

January 18, 2022

Learn more

Webinar

Data Discovery & Security

Automating the classification and mapping of sensitive data​

In this free webinar, learn how to automate the classification and mapping of sensitive data and speed compliance.

January 10, 2022

Learn more

Webinar

Data Discovery & Security

3 keys to a unified data governance program

Learn how properly governed data leads to better data quality, increased data intelligence and more trusted data. 

August 27, 2021

Learn more

Infographic

Data Discovery & Security

The 4 pillars of data intelligence

Learn the Four Pillars of Data Intelligence and discover how to develop an effective data program.

August 02, 2021

Learn more

Webinar

Data Discovery & Security

Data intelligence: Using and improving your data

In the final webinar in the series, we explore the final step on the path towards data intelligence - using and improving your data.

July 19, 2021

Learn more