
Introduction
A leading global automotive manufacturer, with its European hub based in Belgium, coordinates the distribution of vehicles across Europe and works closely with the manufacturer in Japan, which is behind both the vehicles and the connected technology inside the vehicles.
The problem
Modern vehicles continuously exchange data with external systems to enable connected services, resulting in a constant flow of data between Japan and Europe. Building a documented, defensible picture of those flows, and managing a shift of processing to Europe, required a structured approach. The data flows between Japan and Europe existed. The business ran on them. But the documented, defensible picture behind them had to be built.
Which personal data crossed borders, in which systems, and for which purpose; from telematics and connected-services data to customer, service, and warranty data? Which transfer rules applied in which direction? And who was responsible for what under Articles 26 and 28 GDPR, the Japanese manufacturer, the European entity, or both?
At the same time, for a growing number of processes around connected services and customer-facing platforms, the centre of gravity was shifting from Japan to Europe. That shift brought real consequences: roles, governance, contracts, and data protection impact assessments all needed to be in place before platforms went live... not retrofitted afterwards.
How we solved it
Map every data flow between Japan, Europe, and third countries
Datatrust Associates documented all data flows through the Article 30 record of processing activities and supporting data-flow maps; showing what moves where, under which legal basis, and why. This gave the European entity the factual foundation everything else depends on: no flow assumed, none undocumented.
Build a layered transfer strategy verified per provider
DTA assigned a transfer instrument to each flow. Where the EU–Japan adequacy decision applies, it is used. For transfers to the United States, DTA verified per provider whether the recipient is actually certified under the EU–U.S. Data Privacy Framework for the data concerned; where not, DTA applied the 2021 Standard Contractual Clauses, each supported by its own transfer impact assessment and supplementary measures in line with Schrems II and EDPB Recommendations 01/2020. No flow rests on an assumed or unverified mechanism.
Allocate roles, then contract them
For each processing operation, DTA determined the controller, joint-controller, and processor roles and translated those into the corresponding Article 26 and Article 28 agreements within the group and with technology partners, including the sub-processor chains behind them. Responsibility is allocated in writing before processing begins, not discovered afterwards.
Manage the shift to Europe as a project, not an incident
For processing relocating from Japan, DTA prepared the full governance layer: records, transparency, retention, security, rights handling. This alongside the technical migration, and validated it at management level before go-live. Where risk profiles warrant it, a data protection impact assessment under Article 35 precedes the launch.
Deliver decision-ready advice at every step
DTA submitted every step to the European entity's management as a documented yes/no decision; keeping the DPO's advisory role and the organisation's decision-making cleanly separated. The result is an audit trail that shows not only what was decided, but that it was decided consciously.
The results
This engagement delivered what most international companies struggle to build: a transfer framework that is documented, verified, and management-validated.
A structured, management-validated transfer framework
Flows are mapped and documented, transfer instruments assessed and assigned per provider, and responsibilities allocated in writing. The manufacturer can now demonstrate compliance.
The shift to Europe managed as a planned transition
The relocation of processing to Europe is no longer a compliance risk to absorb. Governance is prepared alongside the technical migration, so the European entity takes on the accountability that comes with being controller consciously, not by default.
A foundation ready for what comes next
The framework already supports preparation for the next wave of European rules for connected vehicles, including the EU Data Act (Regulation (EU) 2023/2854), whose design obligations under Article 3(1) apply to connected products placed on the market after 12 September 2026.
Key Learnings
International data transfers are manageable, but only when you know exactly what you're dealing with. This engagement showed what it takes to build a framework that holds up in practice.
Map
Before you govern. Without a clear picture of which data moves where and why, transfer instruments and role allocations are guesswork. The Article 30 record and data-flow maps were were the foundation everything else was built on.
Verify
Don't assume. Adequacy decisions and frameworks like the EU–U.S. Data Privacy Framework have scope conditions. DTA checked each provider individually. A mechanism that covers most of a transfer is not a mechanism that covers that transfer.
Roles
Follow decisions, not geography. Moving processing to Europe does not automatically change who is the controller. As the European entity increasingly designs and operates processes, it increasingly determines their purposes and the accountability obligations attach. The point is to make that shift consciously, not to discover it afterwards.
More case studies
We deliver impact where it matters most.


From fragmented controls to scalable regulatory data quality
Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.


Managing GDPR compliance across a complex stakeholder landscape
Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.


From regulatory scrutiny to demonstrated compliance
LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.