Transfer Impact Assessments
Documenting safeguards for international data transfers.
Transfer Impact Assessments (TIAs)
Assessment Date: March 30, 2026
Next Review Date: March 30, 2027
Assessor: Jason Zigelbaum, CEO, Zigpoll (Argonautic LLC)
1. Overview
These Transfer Impact Assessments are prepared pursuant to § 9 of the Zigpoll Data Processing Addendum and in accordance with the recommendations of the European Data Protection Board (EDPB Recommendations 01/2020 on supplementary measures). They assess the legal framework and practical circumstances of each international data transfer to determine whether the safeguards relied upon (Standard Contractual Clauses and/or the EU-US Data Privacy Framework) provide an essentially equivalent level of protection to that guaranteed within the EEA.
All sub-processors listed below receive personal data transferred from the European Economic Area (EEA) to the United States. The legal basis for each transfer is Article 46(2)(c) GDPR (Standard Contractual Clauses) and, where applicable, Article 45 GDPR (adequacy decision pursuant to the EU-US Data Privacy Framework).
2. Assessment Methodology
Each TIA evaluates the following factors:
- Nature of the data transferred: Categories and sensitivity of personal data.
- Legal framework of the recipient country: Relevant surveillance laws, government access powers, and available legal remedies for data subjects.
- Transfer mechanism: SCCs, EU-US DPF certification, or both.
- Supplementary measures: Technical, organisational, and contractual safeguards in place.
- Practical experience: Whether the data importer has received government access requests and how they were handled.
- Overall risk assessment: Conclusion on whether the transfer provides essentially equivalent protection.
3. US Legal Framework Assessment
The following assessment of the US legal framework applies to all sub-processors below and is referenced in each individual TIA rather than repeated.
3.1 Relevant Legislation
- FISA Section 702: Permits targeted surveillance of non-US persons located outside the US for foreign intelligence purposes. Applies to "electronic communication service providers" as defined under 50 U.S.C. § 1881(b)(4).
- Executive Order 12333: Authorises intelligence collection activities. Does not compel private companies to cooperate but may involve collection from infrastructure.
- Executive Order 14086 (October 2022): Introduces proportionality requirements for US signals intelligence activities and establishes the Data Protection Review Court (DPRC) as a redress mechanism for EU data subjects. This EO formed the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework (July 2023).
- CLOUD Act: Permits US law enforcement to compel disclosure of data held by US providers regardless of storage location, subject to a valid warrant or subpoena.
3.2 Mitigating Factors
- The EU-US Data Privacy Framework adequacy decision (C(2023) 4745, July 10, 2023) recognises that EO 14086 provides sufficient safeguards, including proportionality, necessity, and an independent redress mechanism (DPRC).
- FISA 702 applies to "electronic communication service providers." Infrastructure providers (AWS, MongoDB, Redis) processing data on behalf of customers are generally not considered targets under 702 for bulk collection of customer data.
- The data processed by Zigpoll (survey responses, engagement metrics, order metadata) is commercial in nature and of low intelligence value, significantly reducing the practical likelihood of government access requests.
3.3 Data Subject Redress
EU data subjects may lodge complaints regarding US intelligence activities through their national data protection authority, which will transmit the complaint to the US via the EU-designated authority. Complaints are reviewed by the Civil Liberties Protection Officer (CLPO) and, on appeal, by the Data Protection Review Court (DPRC).
4. Amazon Web Services (AWS)
| Data Importer | Amazon Web Services, Inc. |
| Role | Sub-processor (Hosting & Storage) |
| Data Location | United States (us-east-1) |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) + EU-US Data Privacy Framework |
| DPF Certified | Yes — Amazon.com, Inc. is listed on the Data Privacy Framework List maintained by the US Department of Commerce. |
Data Transferred
All personal data processed by Zigpoll is hosted on AWS infrastructure, including survey responses, account data, engagement metrics, and associated metadata. Data is stored in encrypted volumes (EBS, S3) within the us-east-1 region.
Supplementary Measures
- Encryption at rest: AES-256 via AWS KMS with customer-managed keys. AWS cannot access plaintext data without key authorisation.
- Encryption in transit: TLS 1.2+ for all data transmission between services and to/from end users.
- Access controls: IAM policies enforce least-privilege access. MFA required for all administrative access.
- Certifications: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, C5, PCI DSS Level 1.
- Government access transparency: AWS publishes an Information Request Report detailing law enforcement and government requests received.
- Contractual commitments: AWS commits to challenging overbroad or conflicting government requests and notifying customers where legally permitted.
Risk Assessment
Risk Level: Low. AWS is DPF-certified, provides strong encryption with customer-controlled keys (rendering data unintelligible to third parties including AWS), and the commercial nature of the data makes targeted government access highly unlikely. The combination of SCCs, DPF certification, and technical measures provides an essentially equivalent level of protection.
5. MongoDB Atlas
| Data Importer | MongoDB, Inc. |
| Role | Sub-processor (Database Services) |
| Data Location | United States (hosted on AWS) |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) |
| DPF Certified | No |
Data Transferred
Survey responses, account records, configuration data, and associated metadata are stored in MongoDB Atlas clusters. This includes personal data such as email addresses, order references, device identifiers, and survey response content.
Supplementary Measures
- Encryption at rest: AES-256 encryption applied to all data stored on disk, including backups and snapshots.
- Encryption in transit: TLS 1.2+ enforced for all client-to-cluster and cluster-to-cluster communications.
- Network isolation: Atlas clusters run within dedicated VPCs with IP access lists restricting connections to authorised sources only.
- Authentication: SCRAM-SHA-256 authentication with role-based database access controls.
- Certifications: SOC 2 Type II, ISO 27001, HIPAA eligible, CSA STAR.
- Contractual commitments: MongoDB's DPA includes commitments to challenge government access requests and provide notification where legally permitted.
Risk Assessment
Risk Level: Low. Although MongoDB is not DPF-certified, strong technical measures (encryption, network isolation, access controls) significantly limit the practical ability of any third party to access data in intelligible form. The underlying infrastructure is AWS (DPF-certified). The commercial, low-sensitivity nature of the data further reduces risk. SCCs combined with these supplementary measures provide essentially equivalent protection.
6. Redis Labs
| Data Importer | Redis Ltd. |
| Role | Sub-processor (Database Services — Caching & Session Storage) |
| Data Location | United States (hosted on AWS) |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) |
| DPF Certified | No |
Data Transferred
Transient session data, caching layers, and rate-limiting metadata. Personal data in Redis is ephemeral and typically limited to session tokens and temporary identifiers. Data is not persisted long-term.
Supplementary Measures
- Encryption at rest: AES-256 encryption for persistent storage.
- Encryption in transit: TLS 1.2+ enforced for all client connections.
- Network isolation: Redis instances run within private VPCs. Public access is disabled; connections are restricted to authorised application servers only.
- Data minimisation: Only transient operational data is stored. TTL (time-to-live) policies ensure automatic expiration.
- Certifications: SOC 2 Type II, ISO 27001.
Risk Assessment
Risk Level: Very Low. Data stored in Redis is ephemeral and transient by design. The limited volume and short retention of personal data, combined with encryption and network isolation, make meaningful government access to identifiable personal data extremely unlikely. SCCs with supplementary technical measures provide essentially equivalent protection.
7. Cloudflare Inc.
| Data Importer | Cloudflare, Inc. |
| Role | Sub-processor (CDN & Security) |
| Data Location | EU / US (global edge network; origin servers in US) |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) + EU-US Data Privacy Framework |
| DPF Certified | Yes — Cloudflare, Inc. is listed on the Data Privacy Framework List. |
Data Transferred
HTTP request metadata (IP addresses, user-agent strings, request URLs, timestamps) is processed as traffic passes through Cloudflare's network. Cloudflare acts as a reverse proxy; request and response bodies transit through its edge but are not stored persistently.
Supplementary Measures
- Encryption in transit: TLS 1.3 with full (strict) SSL mode between Cloudflare edge and origin servers.
- Minimal data retention: HTTP logs are retained for a limited period (configurable; default 72 hours) and used solely for security and performance purposes.
- EU data localisation: Cloudflare offers a Data Localisation Suite to restrict processing of metadata to EU data centres where required.
- Government access transparency: Cloudflare publishes a semi-annual transparency report and has a stated policy of challenging overbroad requests and notifying customers where permitted.
- Certifications: SOC 2 Type II, ISO 27001, PCI DSS Level 1.
Risk Assessment
Risk Level: Low. Cloudflare is DPF-certified. Personal data exposure is limited to request metadata with short retention windows. The combination of DPF certification, SCCs, encryption, and transparency practices provides essentially equivalent protection.
8. Twilio SendGrid
| Data Importer | Twilio Inc. (SendGrid) |
| Role | Sub-processor (Transactional Email) |
| Data Location | United States |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) |
| DPF Certified | No |
Data Transferred
Email addresses, email subject lines, email body content (survey invitations, notification messages), and delivery metadata (timestamps, delivery status, open/click tracking where enabled by Controller).
Supplementary Measures
- Encryption in transit: TLS enforced for API connections and opportunistic TLS for SMTP delivery.
- Data retention: Email content is retained for a limited period for delivery and troubleshooting purposes, then purged. SendGrid does not store email content indefinitely.
- Access controls: API key authentication with IP access management. Role-based access within SendGrid accounts.
- Certifications: SOC 2 Type II, ISO 27001.
- Contractual commitments: Twilio's DPA incorporates SCCs and includes commitments to contest government requests and notify customers where legally permitted.
Risk Assessment
Risk Level: Low. Email data transiting through SendGrid is limited to transactional messages (survey invitations, notifications). Content retention is short-lived. Twilio maintains robust security certifications and contractual commitments. SCCs with supplementary measures provide essentially equivalent protection.
9. Sentry Inc.
| Data Importer | Functional Software, Inc. (dba Sentry) |
| Role | Sub-processor (Error Monitoring) |
| Data Location | EU / US |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) + EU-US Data Privacy Framework |
| DPF Certified | Yes — Functional Software, Inc. is listed on the Data Privacy Framework List. |
Data Transferred
Application error reports, stack traces, browser/device metadata, and IP addresses. Personal data is incidentally included when error contexts contain user-identifiable information (e.g., user IDs or email addresses present in request parameters at the time of an error).
Supplementary Measures
- Data scrubbing: Sentry SDK is configured with automatic PII scrubbing to strip sensitive fields (passwords, credit card numbers, authentication tokens) before transmission.
- Encryption: TLS 1.2+ in transit; AES-256 at rest.
- Data retention: Error events are retained for 90 days by default, then automatically purged.
- EU data storage: Sentry offers EU data residency, allowing error data to be stored within the EU.
- Certifications: SOC 2 Type II, ISO 27001.
Risk Assessment
Risk Level: Very Low. Sentry is DPF-certified. Personal data exposure is minimal and incidental (error metadata only). PII scrubbing further reduces the volume of personal data transmitted. Short retention periods and DPF certification, combined with SCCs, provide essentially equivalent protection.
10. Google LLC (Analytics)
| Data Importer | Google LLC |
| Role | Sub-processor (Analytics / Reporting) |
| Data Location | EU / US (Google global infrastructure) |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) + EU-US Data Privacy Framework |
| DPF Certified | Yes — Google LLC is listed on the Data Privacy Framework List. |
Data Transferred
Website visitor analytics data including IP addresses (anonymised where configured), device and browser information, page views, referral sources, session duration, and interaction events. No direct identifiers (names, email addresses) are sent to Google Analytics.
Supplementary Measures
- IP anonymisation: Google Analytics is configured to truncate IP addresses before storage, reducing identifiability.
- Data retention controls: Retention period is configured to the minimum necessary. Automatic deletion of user-level and event-level data upon expiry.
- Data sharing disabled: Data sharing with Google for benchmarking and other purposes is disabled.
- Encryption: TLS in transit; encryption at rest across Google infrastructure.
- Government access transparency: Google publishes a semi-annual Transparency Report detailing government data requests.
- Certifications: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, FedRAMP.
Risk Assessment
Risk Level: Low. Google is DPF-certified. Analytics data is pseudonymised (no direct identifiers transmitted) and IP addresses are truncated. Google's extensive certifications, transparency reporting, and DPF participation, combined with SCCs, provide essentially equivalent protection.
11. OpenAI
| Data Importer | OpenAI, L.L.C. |
| Role | Sub-processor (AI Infrastructure) |
| Data Location | United States |
| Transfer Mechanism | SCCs (Module 3: processor-to-processor) |
| DPF Certified | No |
Data Transferred
Survey response text and prompts submitted to OpenAI's API for AI-powered analysis features (e.g., response summarisation, sentiment analysis). Data may include free-text survey responses which could contain personal data entered by respondents.
Supplementary Measures
- Zero data retention (API): OpenAI's API is configured with zero data retention — inputs and outputs are not stored by OpenAI and are not used for model training.
- Encryption in transit: TLS 1.2+ enforced for all API communications.
- No persistent storage: API requests are processed in memory and not written to persistent storage by OpenAI (under the zero-retention configuration).
- Data minimisation: Only the minimum necessary survey content is transmitted. Direct identifiers (email addresses, names) are stripped from prompts where feasible before submission.
- Certifications: SOC 2 Type II.
- Contractual commitments: OpenAI's DPA includes SCCs and commitments regarding data handling, government access, and notification obligations.
Risk Assessment
Risk Level: Low. The zero data retention policy means personal data is not stored by OpenAI after processing, making government access to historical data impossible. Data is processed transiently in memory only. Combined with encryption, data minimisation, and SCCs, these measures provide essentially equivalent protection.
12. Overall Conclusion
Based on this assessment, we conclude that the international transfers of personal data to the sub-processors listed above are lawful under Article 46 GDPR and provide an essentially equivalent level of protection to that available within the EEA. This conclusion is based on:
- The EU-US Data Privacy Framework adequacy decision for DPF-certified importers (AWS, Cloudflare, Sentry, Google);
- Standard Contractual Clauses executed with all sub-processors;
- The protections introduced by Executive Order 14086, including proportionality requirements and the DPRC redress mechanism;
- Robust supplementary technical measures (encryption at rest and in transit, network isolation, access controls, data minimisation) implemented across all sub-processors;
- The commercial, low-sensitivity nature of the personal data processed (survey responses, engagement metrics, order metadata), which presents minimal risk of government interest; and
- Short or zero data retention periods for several sub-processors, limiting the window of exposure.
This assessment will be reviewed annually or when a material change occurs in the legal framework, sub-processor arrangements, or nature of the data processed. The next scheduled review is March 30, 2027.