GDPR: Is JotForm in the EU-U.S. Privacy Shield list?

  • comwell
    Asked on April 26, 2018 at 5:05 AM
    Hello
     
    In regard to our continued use of Jotform, after may 25th. I have been informed by our legal advice, that since Jotform is not on the EU-U.S. Privacy Shield list, we have to ask you to fill out and sign the attached standard EU contract, regarding data through third party countries.
     
    The fact that we use your servers in Germany, does not guarantee, that our data does not pass through the US on its way - according to our legal advice.
     
    Another way to continue our business with you, is if you can provide a EU sister company, that we can sign our DPA with?
     
    Since I am not able to upload the pdf in this jotform, please use this dropbox link to retrieve the Contract: https://www.dropbox.com/s/ein9uwf4dll1anq/EU%20Standard%20Contractual%20Clauses%20Jotform%202018.pdf?dl=0
     
     
     
     
    -- 
    Med venlig hilsen/Best regards
    Comwell a-s 
     
    Thomas Reimer
    Webmaster 
    Bomhusvej 13, 2100 København Ø 
    Tel direct: +45 4547 3071 
    Switchboard: +45 4541 0033 
    Mobile: +45 3017 2160
    www.comwell.dk <http://www.comwell.dk/>

    CVR: 73233410 
  • Kiran Support Team Lead
    Replied on April 26, 2018 at 8:21 AM

    I believe that you are referring to GDPR compliance. Please note that JotForm is now  GDPR compliant form builder. Please refer to the link below that can help you with more information on JotForm GDPR compliance.

    https://www.jotform.com/gdpr-compliance/

    If you want a DPA to be signed, please submit the form provided in the link https://www.jotform.com/gdpr-compliance/dpa/.

    Please get back to us if you need any further assistance. We will be happy to help. 

     

  • comwell
    Replied on April 26, 2018 at 9:00 AM

    Hi again.


    We are already familiar with your pages about GDPR and we have signed the DPA - but our lawyers cannot approve, since your company is not on the EU-US Privacy shield list. 


    There is no mention, at least, on your website?


    i am very pleased with Jotform, but will be forced to stop using it, if we do not meet one of the above demands, as our company will not allow.


    You do not comment on the question, if data from EU still pass through the US, even if we choose the German servers?

  • Kiran Support Team Lead
    Replied on April 26, 2018 at 10:13 AM

    if data from EU still pass through the US, even if we choose the German servers?

    Once the data is moved to EU servers, the data can be accessed from EU server only.

    Also, let me forward the thread about EU-US Privacy shield list to our backend team so that we can get the correct information in this regard. 

    Thank you for your patience and understanding. 

  • comwell
    Replied on May 7, 2018 at 7:01 AM

    hi again

    Anything new regarding the question if Jotform will be on the EU-US Privacy shield list before the 25th of may?

  • Kiran Support Team Lead
    Replied on May 7, 2018 at 7:21 AM

    Unfortunately, there is no update yet on this. Let me send a note to our backend team to check further. If there is any update, you'll be posted here.

    Thank you!

  • Rose
    Replied on May 9, 2018 at 10:35 AM

    Document was sent to reimer@comwell.dk. Please check and let us know if you have further questions.

  • comwell
    Replied on May 15, 2018 at 7:33 AM

    Hi an thank you for the references to your sub contractors, google and amazon.

    Unfortunately, they are still subcontractors, and not regarding Jotform as the main company, according to our legal counselling. Therefore we still need you to fill out and sign the linked EU document, to be able to work with jotform after the 25th of may.

    Can you reply quickly to whether this is possible, or if we have to start looking for another vendor in europe?

    the document is; 


    EU Standard Contractual Clauses Jotform 2018.pdf

    The link to file is here: https://www.dropbox.com/s/ein9uwf4dll1anq/EU%20Standard%20Contractual%20Clauses%20Jotform%202018.pdf?dl=0


  • Kiran Support Team Lead
    Replied on May 15, 2018 at 8:37 AM

    Your response has been received by our backend team and I'll let them to answer your query.

    Thank you for your patience.

  • SarahJScottPhotography
    Replied on May 17, 2018 at 5:09 PM

    Hi,


    I posted separately, but I have also been advised the same and if you are not planning to be part of the EU/US privacy shield, there are various contractual clauses that I would need to get signed (in addition to the data processing agreement).


    Thanks

    Sarah

  • Elton Support Team Lead
    Replied on May 17, 2018 at 6:32 PM

    Hi Sarah,

    Your question has been answered in your other thread here https://www.jotform.com/answers/1475933. Kindly check.

  • comwell
    Replied on May 18, 2018 at 7:03 AM

    yes but I cannot login as Sarah, and desperately need answers to

  • Jed_C
    Replied on May 18, 2018 at 8:49 AM

    Please try viewing the answers for Sarah in this thread here https://www.jotform.com/answers/1475933 again. Which is also a similar question in this thread here https://www.jotform.com/answers/1452470.

  • comwell
    Replied on May 18, 2018 at 9:08 AM

    Hi Again

    Thank you for your answer. It still does not answer the question if Jotform is or will be on the EU-US Privacy shield list!

    Though data is on a european server, Jotform is a US company, residing in the US. Since the Mother Company is registered in the US, having data centers in Europe is not enough, to have Jotform accepted as a business parter by us, to meet GDPR compliance. 

    The only way, if you are not on the Shield list before the 25.th, is to sign afforementioned document from the EU, which will Whitelist you for us to work with.

    I do not understand why you cannot just answer my question, so i either can continue with jotform, or hurry to find another vendor, who meets the GDPR compliance demands.


  • Kiran Support Team Lead
    Replied on May 18, 2018 at 10:00 AM

    I understand. Unfortunately, there is no update yet from the backend team. We have already notified about your question. As soon as we have any information in this regard, we'll update you here.

    We appreciate your patience and understanding. Thank you!

  • SarahJScottPhotography
    Replied on May 20, 2018 at 4:41 PM

    Hey, I am in the same position. Unfortunately, I will not be able to continue using your services if you do not sign the additional contractual clauses (I appreciate this is fairly annoying!) as despite the GDPR compliance/data processor agreement you are not part of the EU/US privacy shield...

    Would appreciate an update when you have one!

    thanks

    Sarah

  • jonathan
    Replied on May 20, 2018 at 6:41 PM

    @SarahJScottPhotography

    I created your post on a separate thread here https://www.jotform.com/answers/1477837

    We will attend to it shortly.


  • Kiran Support Team Lead
    Replied on June 25, 2018 at 7:49 AM

    @Thomas,

    I was informed that a document has already been sent to you to answer your question. We request you to check and get back to us if you need any further assistance. We will be happy to assist. 

    Thanks!

  • Rose
    Replied on July 5, 2018 at 8:36 AM

    Hi There,

    JotForm is certified under Privacy Shield now.  You can find more information at GDPR page under Privacy Shield section. 
     
    Regards.