Photo of Carsten A. Kociok

Carsten A. Kociok

Carsten Kociok is a partner in the Technology, Financial Services and Data Privacy Practice in Berlin and Co-Head of Greenberg Traurig’s global Fintech Group. He advises national and international clients across all industries, including financial services, information technology, artificial intelligence, ecommerce, media, health care, telecoms, retail and real estate, on a wide variety of complex commercial and regulatory matters.

Carsten is a leading technology lawyer, ranked consistently in Band 1 for Fintech Legal in Germany since 2020. He has in-depth and wide-ranging experience in the areas of privacy and cybersecurity, payments law, financial services, e-money products, blockchain technology, and financial and banking regulation, as well as in artificial intelligence regulation - including compliance with the EU AI Act - and the integration of AI technologies into existing software systems.

Carsten regularly assists clients in licensing projects and audit proceedings with financial regulators and advises on the contractual and regulatory aspects of developing, implementing and operating financial technology products and transactions.

On the data privacy side, Carsten counsels clients on complex data-driven business models and regulatory matters, including on international data transfers, data privacy compliance, monetization of data, artificial intelligence, litigation, cybersecurity and data breach response.

Carsten regularly lectures and publishes on various FinTech and data privacy topics. Prior to joining the firm, Carsten worked at Olswang Germany for eight years and in the Capital Transaction Practice Group of an international law firm in New York.

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

Visual Description and Implications
Transfers from a US Controller to EEA processors (Renvois) - Controller (US)→Processor (EEA) (on deck) (Basic Renvoi)
  • Cross border transfers in the United States don’t need a SCC. Company A is not required under U.S. law or the GDPR

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

Visual Description and Implications
Transfers from a US Controller to EEA processors (Renvois) Controller (US)→ Processor (Non-EEA)→Sub-processor (EEA)→Controller (US)
  • Cross border transfers from the United States don’t need a SCC. Company A is not required under U.S. law or the GDPR

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

Visual Description and Implications
Transfers from a US Controller to EEA processors (Renvois) Controller (US)  Processor (US)  Sub-processor (EEA)  Controller (US)
  • Cross border transfers in the United States don’t need an SCC. Company A is not required under U.S. law or the GDPR

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June of 2021.

Visual

Summary

  • Cross border transfers in the United States don’t need a SCC. Company A is not required under U.S. law or the GDPR to

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June of 2021.

Visual Summary
Overview of situation.  Company A in the EEA retains Company Z-1 in the US to process personal data.  Company Z-1 intends to

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June of 2021.

Visual Summary
  • 1st Transfer: SCC Module 2. Initial cross-border transfer from EEA to Country Q utilizes the SCC Module 2 designed for transfers from

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses, approved by the European Commission in June 2021.

Visual Summary
Transfers from EEA Controller to non-EEA Processor: Controller A (EEA)→Processor Z (US) →Processor X (US) →Controller A (EEA)
  • 1st Transfer: SCC Module 2. Initial cross-border transfer from EEA to United States utilizes the SCC Module 2 designed for transfers from

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses, approved by the European Commission in June 2021.

Visual Summary
Transfers from EEA Controller to non-EEA Processor: Controller A (EEA)→ Processor Z (non-EEA) → Controller A (EEA)
  • 1st Transfer: SCC Module 2. Initial cross-border transfer from EEA to a non-EEA country utilizes the SCC Module 2 designed for transfers

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses, approved by the European Commission in June 2021.

Visual Summary
Transfers from EEA Controller to non-EEA Processor: Controller A (EEA) → Processor Z (US) → Controller A (EEA)
  • 1st Transfer: SCC Module 2.  Initial cross-border transfer from EEA to United States utilizes SCC Module 2 designed for transfers from a

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

Visual Implications
  • Background. Company Z-1 and Company Z-2 are corporate affiliates who are under common ownership or control, but are separate legal entities. Data is