← Back to Shieldome

Transfer Impact Assessment

Last updated: August 7, 2026 · Version 2.0
Prepared by: NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC — [email protected]

Scope: This Transfer Impact Assessment (TIA) evaluates the risks associated with transfers of Personal Data from Serbia to the United States via Resend Inc. (email delivery) and Google LLC (OAuth authentication). It is provided to satisfy due-diligence requirements of EU Controllers who engage Shieldome and who rely on SCCs for sub-processor transfers to the US.
Contents
  1. Purpose and Methodology
  2. Data Flows and Transfer Overview
  3. EU/EEA Data Storage (No Transfer)
  4. Serbian Legal Framework
  5. Transfer Assessment: Resend Inc. (US)
  6. Transfer Assessment: Google LLC (US)
  7. Supplementary Measures
  8. Conclusion and Overall Risk Rating
  9. Review Schedule

1. Purpose and Methodology

This TIA has been prepared in accordance with:

  • The European Data Protection Board (EDPB) Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data;
  • The requirements of EU Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses), which conditions the effectiveness of SCCs on an assessment of whether the law or practice of the third country impairs the SCCs' effectiveness;
  • The Serbian Law on Personal Data Protection (LPDP, Official Gazette RS, No. 87/2018), which substantially mirrors the GDPR.

The methodology follows the six-step framework recommended by the EDPB: (1) identify the transfer, (2) identify the transfer tool, (3) assess the third country law, (4) assess whether the tool is effective, (5) identify and adopt supplementary measures if needed, (6) take formal procedural steps.

2. Data Flows and Transfer Overview

Transfer From To Tool Data Involved
Transfer 1
Email delivery
NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC (Serbia)
Processing on behalf of EU Controllers
Resend Inc. (United States) EU SCCs (Module 2)
Controller→Processor
Email address, full name, notification content (scan complete, alert, billing receipt). No scan results or vulnerability data.
Transfer 2
OAuth authentication
NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC (Serbia)
Processing on behalf of EU Controllers
Google LLC (United States) EU SCCs (incorporated in Google's DPA) OAuth token exchange only: email address and display name returned by Google for account identification. No scan data, billing data, or vulnerability findings.

3. EU/EEA Data Storage (No Transfer)

All Customer account data and scan data is stored in AWS eu-central-1 (Frankfurt, Germany), within the European Economic Area. This storage does not constitute an international transfer. No data is routed through or stored in non-EEA AWS regions.

Access by Shieldome's personnel in Serbia to data stored in Frankfurt is covered by the EU adequacy decision for Serbia (Commission Decision 2013/65/EU) and does not constitute a transfer requiring additional safeguards.

The adequacy decision means that Serbian-team access to EU-stored data is treated the same as access from within the EU. No additional transfer mechanism is required for this access path.

4. Serbian Legal Framework

Serbia is the location of Shieldome as Processor. The Serbian legal context is relevant to assessing whether government access to Personal Data processed by Shieldome could impair the effectiveness of the SCCs.

4.1 Data Protection Law

Serbia's Law on Personal Data Protection (LPDP, 2018) is substantively equivalent to the GDPR. It was the basis for the EU adequacy decision. The Serbian Commissioner for Personal Data Protection (Poverenik) acts as an independent supervisory authority with enforcement powers comparable to EU DPAs.

4.2 Government Access and Surveillance Law

  • Serbia has no equivalent of the US FISA Section 702 or Executive Order 12333 bulk surveillance programmes that were central to the invalidation of Privacy Shield in Schrems II.
  • Serbia has no equivalent of the US CLOUD Act. Serbian law does not permit US-style extraterritorial compelled disclosure orders against Serbian entities.
  • Law enforcement access to personal data in Serbia requires a judicial authorisation (court order or similar warrant) based on reasonable suspicion of a specific offence. Bulk or generalised access is not permitted.
  • Serbia is a Council of Europe member state and a signatory to the Budapest Convention on Cybercrime, which includes proportionality requirements for data access by authorities.
  • Serbian intelligence services operate under parliamentary oversight and are subject to constitutional protections on privacy equivalent to those in EU Member States.

4.3 Assessment

The Serbian legal framework does not present material risks to the effectiveness of transfer safeguards. The adequacy decision itself reflects the European Commission's assessment that Serbia provides an equivalent level of protection to the EU.

5. Transfer Assessment: Resend Inc. (US)

5.1 US Legal Framework Relevant to Resend

The United States does not have a comprehensive federal data protection law equivalent to the GDPR. Key surveillance laws relevant to US-based providers include:

  • FISA Section 702 (50 U.S.C. § 1881a): Permits the NSA to compel US-based electronic communications service providers to disclose communications of non-US persons located outside the US. The scope of "electronic communications service provider" covers email providers.
  • Executive Order 12333: Authorises foreign intelligence collection outside the US, including in transit.
  • CLOUD Act (2018): Permits US law enforcement to seek stored communications from US-based providers with a US court order.

US Executive Order 14086 (2022) introduced enhanced safeguards for EU data including a Data Protection Review Court for EU residents to challenge US intelligence access. This partially restores the legal framework that was found deficient in Schrems II but does not fully eliminate the risk of FISA 702 access.

5.2 Data Minimisation Assessment

Data transferred Email address, full name, notification content (e.g., "Your scan of example.com is complete — 2 findings detected")
Special categories? None
Scan data transferred? No — vulnerability details, scan results, and IP addresses of scan targets are NOT included in email notifications
Volume Individual transactional emails only; no bulk export of user databases to Resend
Sensitive financial data? Billing receipts include plan name and amount; no full card numbers or bank account details
Identifiability Email address identifies the user; no additional data enabling aggregation into a broader profile

5.3 Likelihood of Government Access

  • FISA 702 targets communications of specific non-US persons of foreign intelligence interest. Shieldome's customers are businesses and professionals conducting authorised security assessments. This is not a profile that would attract foreign intelligence interest.
  • The data transferred consists of minimal PII (email + name + notification text). Even if accessed, it would yield no meaningful intelligence value and would reveal no sensitive personal details about the subject.
  • Resend as an email delivery provider handles the same category of data as any transactional email service. The risk of targeted government access to routine "scan complete" notifications is assessed as negligible.
  • Resend has published commitments to transparency (annual transparency report) and to challenge overbroad government requests where legally permitted.

5.4 Risk Rating: Resend

Transfer risk rating

LOW

The data transferred to Resend is minimal (email, name, notification text), contains no special categories, no financial detail, and no scan data. The likelihood of targeted government access to routine transactional email metadata is negligible. SCCs, combined with contractual minimisation commitments, provide an effective transfer safeguard. Transfer may proceed.

6. Transfer Assessment: Google LLC (US)

6.1 Scope of Transfer

The transfer to Google occurs only when a user elects to use "Sign in with Google" (OAuth 2.0) as their authentication method. This is an optional feature; users may instead register with email and password.

The OAuth flow involves:

  1. The user's browser redirects to Google's authorisation endpoint.
  2. Google authenticates the user and returns an OAuth authorisation code to Shieldome.
  3. Shieldome exchanges the code for a token and retrieves the user's email address and display name from Google's API.
  4. Shieldome uses the email address and name to create or identify the user's account.

6.2 Data Minimisation Assessment

Data transferred to Google OAuth authorisation code only; no Personal Data is sent to Google by Shieldome
Data received from Google Email address and display name — minimum necessary to identify the account
Scan data transferred? No scan data, vulnerability findings, billing records, or any other Customer data is transmitted to Google
Ongoing data sharing with Google? No — the OAuth exchange occurs only at login. Shieldome does not share user activity or scan data with Google on an ongoing basis
Google's own processing Google processes the OAuth request under its own privacy policy and terms; Shieldome is not responsible for Google's independent processing of the user's Google Account data

6.3 Likelihood of Government Access

  • The data exchanged with Google during the OAuth flow (email + name) is the same minimal identifier data that a user's Google Account already contains. No incremental disclosure of sensitive data occurs.
  • Google is among the largest recipients of FISA 702 orders globally. However, the data that Shieldome exchanges with Google (login identifiers) is not data that would be of foreign intelligence interest independent of the user's broader Google Account.
  • Google maintains transparency reporting, publishes National Security Letter counts, and has publicly committed to challenging overbroad government data requests.
  • The European Commission's adequacy decision for the EU-US Data Privacy Framework (where Google is certified) reflects an assessment that enhanced protections under EO 14086 reduce — though do not eliminate — the risk of bulk surveillance.
  • The risk of government access to Shieldome-specific OAuth login identifiers via Google is assessed as remote given the non-sensitive nature of the data and the profile of Shieldome's user base.

6.4 Risk Rating: Google

Transfer risk rating

LOW

The transfer to Google is limited to an OAuth token exchange yielding only email address and display name. No scan data, billing data, or vulnerability findings are transmitted. The data involved carries negligible intelligence value independent of the user's existing Google Account. SCCs (incorporated in Google's DPA) provide an effective transfer safeguard for this minimal, point-in-time exchange. Transfer may proceed.

7. Supplementary Measures

In addition to the SCCs, the following supplementary measures are in place to reduce the risk of government access impairing the effectiveness of the transfer safeguards:

MeasureApplies toDescription
Data minimisation Resend, Google Only the minimum necessary Personal Data is included in each transfer. Vulnerability findings, scan results, IP addresses, and billing details are not included in email notifications sent to Resend. No scan data is sent to Google.
Encryption in transit Resend, Google All API calls to Resend and Google use HTTPS/TLS 1.2+. Data is not accessible in plaintext during transmission.
Contractual commitments Resend, Google Both sub-processors are bound by SCCs requiring them to notify Shieldome of government access requests and to challenge overbroad requests where legally permitted.
Purpose limitation Resend, Google Data transferred to Resend is used solely for email delivery; data exchanged with Google is used solely for OAuth authentication. Neither sub-processor may use the data for their own commercial purposes beyond service provision.
Alternative login option Google Users who prefer not to use Google OAuth may register and authenticate using email and password exclusively, with no data transferred to Google.

8. Conclusion and Overall Risk Rating

Overall TIA conclusion

LOW RISK — Transfers may proceed

Both transfers (to Resend and to Google) involve minimal Personal Data with low sensitivity and negligible intelligence value. The Serbian legal framework does not present risks comparable to those identified in Schrems II. SCCs combined with the supplementary measures described above are assessed to provide an effective level of protection equivalent to that in the EU/EEA. The transfers may proceed under the SCCs currently in place.

Factor Resend (US) Google (US)
Data sensitivity Low (email, name, notification text) Very low (email, name — login identifiers only)
Special categories? None None
Scan/vulnerability data transferred? No No
Transfer mechanism EU SCCs 2021/914 Module 2 EU SCCs (Google DPA)
Likelihood of targeted government access Negligible Negligible
Supplementary measures in place? Yes Yes
Overall risk rating LOW LOW

9. Review Schedule

This TIA will be reviewed:

  • Annually as part of Shieldome's annual security assessment cycle;
  • Upon any material change to the data transferred, the sub-processors involved, or the legal framework in Serbia or the United States (including any new court decisions or legislation materially affecting surveillance law);
  • Upon a significant change in the EU-US legal landscape (e.g., invalidation of the EU-US Data Privacy Framework or significant changes to EO 14086).

The next scheduled review is August 2027. The current version of this TIA is maintained at /legal/transfer_impact_assessment.html.

This TIA reflects Shieldome's good-faith assessment as of August 7, 2026. EU Controllers engaging Shieldome are responsible for conducting their own TIA assessment based on their own circumstances and the nature of their data. This document is provided as supporting documentation to assist that assessment. For questions or to obtain the supporting information referenced herein, contact [email protected].