The GDPR guide to legal translation
The GDPR imposes strict obligations on the processing of personal data, including during translation projects. This Asiatis guide details the best practices.
Does the GDPR apply to translations?
Yes, whenever the translated documents contain personal data:
- Contracts naming natural persons (names, addresses, contact details)
- HR files (employment contracts, payslips, appraisals)
- Medical records (clinical protocols, patient files)
- Litigation (briefs, exhibits, correspondence)
Important: Under the GDPR, the translation agency is considered a processor (Article 28). It must provide sufficient guarantees.
The translation agency's obligations
Data processing agreement
GDPR Article 28: a written contract detailing the subject matter, duration, nature of processing and types of data.
Technical measures
Encryption, pseudonymization, access control and logging of data access.
Data location
EU hosting or Standard Contractual Clauses for transfers outside the EU.
Breach notification
Obligation to inform the client in the event of a data breach (within 72 hours).
International transfers
If translators are located outside the EU, additional safeguards are required:
- Standard Contractual Clauses (SCCs): European Commission templates approved in June 2021.
- Adequacy decision: some countries (Canada, Japan, post-Brexit UK) recognized as offering equivalent protection.
- Binding Corporate Rules: for international groups with in-house translators.
The Asiatis commitment
Asiatis guarantees GDPR compliance for all of its translation projects:
- Servers hosted in France (OVH, Scaleway)
- Systematic NDAs with every translator
- Standard Contractual Clauses available on request
- DPO reachable at: dpo@asiatis.com
For your sensitive legal projects, see our legal translation service.
Sensitive documents to translate?
Asiatis has sworn translators and guarantees GDPR compliance. Request a confidential quote.