Awareness Lessons
4 months ago
CNPD Refuses to Investigate Rocketreach Over GDPR Data Sales
Rocketreach, a foreign company selling personal data of EU residents without a legal basis, escaped regulatory scrutiny because it lacked an EU establishment and a designated EU representative — both requirements under GDPR Articles 3 and 27. The Luxembourg CNPD acknowledged potential GDPR violations but declined to investigate due to these jurisdictional gaps. This case highlights a critical enforcement loophole: non-EU companies can process and monetize EU personal data while remaining practically unaccountable if they ignore GDPR establishment requirements. The decision undermines data subject rights and erodes trust in GDPR as a globally enforceable framework.
Tactical Insight
Immediate actions
- Verify that any third-party data broker or vendor processing EU personal data has a designated EU representative as required by GDPR Article 27.
- Conduct a data flow audit to identify personal data being shared with or sourced from foreign entities lacking GDPR compliance documentation.
Regulatory & contractual controls
- Include mandatory GDPR compliance clauses (legal basis, DPA agreements) in all contracts with external data processors or brokers.
- Report non-compliant foreign data brokers to both the relevant lead supervisory authority and the EDPB to trigger coordinated enforcement action.
- Avoid purchasing or using data from brokers who cannot demonstrate a lawful basis for processing EU personal data.
Long-term improvements
- Advocate internally and externally for EDPB guidance that closes the enforcement gap for non-EU-established entities processing EU data.
- Maintain an up-to-date Records of Processing Activities (RoPA) log identifying all external data sources and their legal bases.
- Implement periodic third-party risk assessments specifically evaluating GDPR jurisdictional compliance of data suppliers.