Skip to content
iGaming Cyprus

iGaming international data transfers: vendor assessment

An international data-transfer assessment starts with where personal data goes and who can access it. A cloud hosting location alone does not answer the question. Review support access, sub-processors and group sharing as well as the primary storage region.

iGaming Cyprus · Last updated:

What should the transfer map show?

Identify the exporting and receiving entities, data categories, purpose, countries and access arrangements. The European Commission publishes standard contractual clauses for relevant international transfers under the GDPR.

A Cyprus operator using a European data centre may still have overseas support or analytics access. Ask suppliers to describe those arrangements explicitly. A statement that data is “hosted in Europe” is insufficient to map the full processing chain.

How should the legal mechanism be selected?

Assess whether an applicable adequacy decision or another permitted mechanism covers the transfer. Where standard contractual clauses are used, select and complete the relevant arrangement for the actual parties and processing.

The clauses are not a substitute for understanding the transfer. Review the circumstances, applicable requirements and any supplementary safeguards needed. Avoid signing a generic attachment with blank descriptions of the data and recipients.

What questions should suppliers answer?

Use the questions below as an evidence request rather than treating a questionnaire score as automatic approval.

  • Which legal entities receive or access the data?
  • Which countries and sub-processors are involved?
  • What data is transferred and for which purpose?
  • Which transfer mechanism is relied on?
  • What technical and organisational safeguards apply?
  • How are onward transfers and changes communicated?
  • How can the operator obtain, return or delete its records?

What practical safeguards should be considered?

Consider minimisation, access restrictions, logging and appropriate encryption alongside the legal arrangement. Their suitability depends on the processing purpose and architecture.

For example, an overseas support team may need a limited diagnostic view rather than copies of identity documents. Redesigning access can reduce the transfer’s scope. Do not claim that encryption solves every issue without examining who can access the keys and plaintext.

When does the assessment need updating?

Review changes in recipients, countries, services, sub-processors and relevant law. A transfer map becomes unreliable if a vendor silently changes its support model.

Keep an owner and review record for each material arrangement. Link the assessment to procurement and change management so a new vendor cannot bypass it. Where the facts or legal position are uncertain, record the open issue and resolve it before expanding access.

Frequently asked questions

No. Remote access, onward transfers and other recipients must also be mapped.

No. The actual transfer circumstances and required safeguards still need evaluation.

Sources and scope

  1. European Commission — standard contractual clauses
  2. EDPB — legal basis

This guide was prepared with AI assistance using the linked sources. It provides general information and practical preparation suggestions, not a legal opinion for a particular business. No personal professional review is claimed.

Get the right structure for your case

Book a free, no-obligation consultation. We’ll confirm the right Cyprus company + licence setup and a fixed fee for your business.

Book my free consultation30 minutes · no obligation · talk to a qualified Cyprus advocate.
Not ready to talk? Get the 2026 licence comparison by email

Receive links to the licensing and cost guides, with the requirements to check before choosing a structure.

One requested guide email. No mailing-list subscription. Privacy

Book my free consultation