General Data Protection Regulation (GDPR)

Building on its BCR heritage, Helix has kept data privacy as a priority and has invested considerable time and resources in its General Data Protection Regulation (GDPR) compliance program, ensuring Helix is and remain fully compliant.

As part of this program, Helix has reviewed its software products, solutions and services so as to address its processor’s obligations.

Helix provides assistance to its customers with regard to their obligations under GDPR, such as data subject requests (access, rectification, objection, erasure, etc.), records of processing activities and data protection impact assessments (DPIA).

European Union and United Kingdom data protection laws, including the General Data Protection Regulation, prohibits personal data transfers outside the EU and UK unless an adequate level of data protection is provided, based on appropriate and effective safeguards.

This Q&A answers key questions about Customer EU and UK personal data transfers in the context of Helix services. It is provided as of the date of publication of this document and is not to be considered as legal advice.

1. Does Helix transfer Customer EU/UK personal data subject to transfer restrictions?

Yes, depending on the services, Helix may transfer Customer personal data outside the EU or the UK, according to Helix’s Data Processing Agreement (DPA). Some of the countries to which Helix may transfer personal data are not regarded by EU/UK data protection law as providing an adequate level of data protection.

Helix operations located in such countries may be involved in the resolution of customer support requests, which may include Customer EU personal data. Another example would be where Customer selects a Helix data center in such a country to host UK personal data.

2. Does Helix provide adequate personal data transfer mechanisms?

Yes. Before transferring data on behalf of its Customers, Helix implements adequate transfer mechanisms provided by the GDPR, such as the EU Standard Contractual Clauses (SCCs) and the UK International data transfer addendum (IDTA).

As a member of BMC, Helix also benefits from BMC’s EU and UK Binding Corporate Rules (BCR), approved by EU and UK Supervisory Authorities. The list of entities bound by the BMC’s EU and UK BCRs is published on BMC’s BCR webpage. BMC’s BCR and other adequate transfer mechanisms are incorporated in Helix’s Data Processing Agreement (DPA).

More details on data transfers are included in services agreements and orders, depending on the type of services.

3. How would Helix address binding data disclosure requests from public authorities?

In case of a data disclosure requested by a national enforcement authority or agency related to Customer personal data, Helix would comply with Rule 12B of BMC’s BCRs and Clause 15 of the SCCs, and therefore put the disclosure request on hold, promptly notify its Customer, its EU Lead Supervisory Authority and/or the ICO, and the Customer’s Supervisory Authority, unless prohibited from doing so by the requesting authority or agency.

If prohibited from taking these steps by the requesting authority or agency, Helix will diligently inform such authority or agency of its obligations under EU and UK data protection law to obtain the right to waive the prohibition. Where it cannot be waived despite Helix's best efforts, Helix will provide the competent Supervisory Authorities with an annual report providing general information about the received requests for disclosure, to the extent Helix is authorized to do so.

4. Has Helix implemented supplementary measures to restrict access to Customer personal data, as a consequence of the “Schrems II” ruling?

Yes.

On July 16, 2020, the European Court of Justice (ECJ) invalidated the Privacy Shield, a transatlantic legal framework for personal data transfers from the EU to the US, and required organizations to implement mechanisms effectively ensuring a level of protection equivalent to the EU (“Schrems II” ruling).

In accordance with the European Data Protection Board’s Recommendations 01/2020 on measures that supplement transfer tools, Helix has implemented supplementary measures to support compliance with EU data protection law and restrict unlawful access to Customer personal data, which include:

  • Transparency towards customers in case of a data disclosure request from a public authority, as set out by the BCRs and SCCs;
  • Challenge unlawful requests to disclose customer data, as set out by Helix’s Data Processing Agreement (DPA);
  • Helix’s Data Processing Agreement (DPA);
  • Customer data minimization policies, such as Helix’s Support Privacy Policy;
  • Technical measures such as data encryption, with decryption keys exclusively retained by customer, depending on the Helix services used.

More details on Helix’s Security & Privacy posture can be found on our Trust Center.

5. Can access to Customer data be limited to certain territories or countries?

Yes, depending on the Helix services. Helix has a broad global distribution of personnel and data center regions, allowing a range of options that Customers can use (including encryption options, such as Customer controlled keys) to protect or restrict Customer or Helix access to Customer data for specified locations. Helix internal entities are used for general service operations such as backups, patching and upgrades. In addition, automation is widely used where possible to prevent human effort. For further information please contact your Helix representative.

Rev. 2026-03-16