A SaaS privacy notice lists EU processors but is silent about recipients in third countries and related transfer safeguards. What notice deficiency is most relevant?
Select an answer to reveal the explanation.
Short Explanation
If data leave the EEA, say so—and say how you protect the trip. Hiding third-country recipients undercuts transparency. Naming EU processors is good, but transfer disclosure still matters when data go further.
Full Explanation
Articles 13 and 14 require information about recipients or categories of recipients and, where applicable, the fact of transfers to third countries or international organisations, including the existence or absence of an adequacy decision and reference to appropriate safeguards. Silence on international transfers where they occur is a material notice gap. Extreme personal contact dumps or annexing entire treaties are not mandated substitutes.