Data Processing Agreement FAQ
Data Storage; Data Exports
Can my data be stored in the EU? (8)
Yes, BambooHR maintains a data center in the EU (Ireland) where client data can be stored.
Can BambooHR commit to only store our data in the EU and never transfer it elsewhere? (8)
BambooHR does have a data center located in the EU (Ireland), and to assist with compliance, we can store client data in that data center. As outlined in our DPA, section 8, we reserve the ability to move the data if necessary and have an appropriate transfer mechanism in place in the revised Standard Contractual Clauses (SCCs) and UK Addendum. At this time, we could only foresee needing to "transfer" the data in the event of an issue with the EU data center and we need to transfer the data to protect and preserve it or to service your account and provide the services to you either ourselves or via our subprocessors. But given that merely having access to data or making it available to a party outside of the EU could be deemed a “transfer” under current regulatory guidance, we don't want to be in a situation in which we can't move the data if we need to in order to protect it or can't serve you because a "transfer" cannot occur. Our company and employees are located in the US, and so any support/implementation for your account will take place in the US. But as stated, we have a valid transfer mechanism in place in the revised SCCs and UK Addendum so that the data is protected as required by the GDPR if a "transfer" were to occur.
What transfer mechanism does BambooHR use for data transfers outside of the EU, Switzerland, or the UK? (1.4)
BambooHR uses the revised SCCs or Model Clauses for data transfers outside the EU, Switzerland, or the UK. BambooHR has also incorporated the UK Addendum to the SCCs into its Data Processing Agreement.
What safeguards are in place for data transfers outside of the EU, Switzerland, or the UK? (8)
If a transfer becomes necessary, BambooHR maintains several safeguards to ensure the protection of data including:
- Encryption
- Transparency Obligations
- Contractual Obligations
- Organizational Measures
- Access Control of Processing Areas
- Access Control to Data Processing Systems
- Access Control to Specific Areas of Data Processing Systems
- Transmission Controls
- Input Controls
- Job Control
- Availability Control
- Separation of Processing for Different Purposes
- Testing
Please see our Transfer Impact Assessment (TIA) found in our Safebase Profile as well as our Disclosure Report and Annex III of the DPA which contains additional descriptions of our supplementary measures.