← Back to Shieldome
Transfer Impact Assessment
Last updated: August 7, 2026 · Version 2.0
Prepared by: NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC — [email protected]
Scope: This Transfer Impact Assessment (TIA) evaluates the risks associated
with transfers of Personal Data from Serbia to the United States via Resend Inc. (email
delivery) and Google LLC (OAuth authentication). It is provided to satisfy due-diligence
requirements of EU Controllers who engage Shieldome and who rely on SCCs for sub-processor
transfers to the US.
1. Purpose and Methodology
This TIA has been prepared in accordance with:
- The European Data Protection Board (EDPB) Recommendations 01/2020 on measures that
supplement transfer tools to ensure compliance with the EU level of protection of
personal data;
- The requirements of EU Commission Implementing Decision (EU) 2021/914 (Standard
Contractual Clauses), which conditions the effectiveness of SCCs on an assessment of
whether the law or practice of the third country impairs the SCCs' effectiveness;
- The Serbian Law on Personal Data Protection (LPDP, Official Gazette RS, No. 87/2018),
which substantially mirrors the GDPR.
The methodology follows the six-step framework recommended by the EDPB: (1) identify
the transfer, (2) identify the transfer tool, (3) assess the third country law, (4) assess
whether the tool is effective, (5) identify and adopt supplementary measures if needed,
(6) take formal procedural steps.
2. Data Flows and Transfer Overview
| Transfer |
From |
To |
Tool |
Data Involved |
Transfer 1 Email delivery |
NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC (Serbia) Processing on behalf of EU Controllers |
Resend Inc. (United States) |
EU SCCs (Module 2) Controller→Processor |
Email address, full name, notification content (scan complete, alert, billing
receipt). No scan results or vulnerability data. |
Transfer 2 OAuth authentication |
NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC (Serbia) Processing on behalf of EU Controllers |
Google LLC (United States) |
EU SCCs (incorporated in Google's DPA) |
OAuth token exchange only: email address and display name returned by Google
for account identification. No scan data, billing data, or vulnerability findings. |
3. EU/EEA Data Storage (No Transfer)
All Customer account data and scan data is stored in AWS eu-central-1
(Frankfurt, Germany), within the European Economic Area. This storage does not
constitute an international transfer. No data is routed through or stored in non-EEA AWS
regions.
Access by Shieldome's personnel in Serbia to data stored in Frankfurt is covered by the
EU adequacy decision for Serbia (Commission Decision 2013/65/EU) and does not constitute a
transfer requiring additional safeguards.
The adequacy decision means that Serbian-team access to EU-stored data is treated the
same as access from within the EU. No additional transfer mechanism is required for this
access path.
4. Serbian Legal Framework
Serbia is the location of Shieldome as Processor. The Serbian legal context is relevant
to assessing whether government access to Personal Data processed by Shieldome could impair
the effectiveness of the SCCs.
4.1 Data Protection Law
Serbia's Law on Personal Data Protection (LPDP, 2018) is substantively equivalent to the
GDPR. It was the basis for the EU adequacy decision. The Serbian Commissioner for Personal
Data Protection (Poverenik) acts as an independent supervisory authority with
enforcement powers comparable to EU DPAs.
4.2 Government Access and Surveillance Law
- Serbia has no equivalent of the US FISA Section 702 or Executive
Order 12333 bulk surveillance programmes that were central to the invalidation of
Privacy Shield in Schrems II.
- Serbia has no equivalent of the US CLOUD Act. Serbian law does not
permit US-style extraterritorial compelled disclosure orders against Serbian entities.
- Law enforcement access to personal data in Serbia requires a judicial
authorisation (court order or similar warrant) based on reasonable suspicion of
a specific offence. Bulk or generalised access is not permitted.
- Serbia is a Council of Europe member state and a signatory to the Budapest Convention
on Cybercrime, which includes proportionality requirements for data access by authorities.
- Serbian intelligence services operate under parliamentary oversight and are subject to
constitutional protections on privacy equivalent to those in EU Member States.
4.3 Assessment
The Serbian legal framework does not present material risks to the effectiveness of
transfer safeguards. The adequacy decision itself reflects the European Commission's
assessment that Serbia provides an equivalent level of protection to the EU.
5. Transfer Assessment: Resend Inc. (US)
5.1 US Legal Framework Relevant to Resend
The United States does not have a comprehensive federal data protection law equivalent
to the GDPR. Key surveillance laws relevant to US-based providers include:
- FISA Section 702 (50 U.S.C. § 1881a): Permits the NSA to
compel US-based electronic communications service providers to disclose communications
of non-US persons located outside the US. The scope of "electronic communications service
provider" covers email providers.
- Executive Order 12333: Authorises foreign intelligence collection
outside the US, including in transit.
- CLOUD Act (2018): Permits US law enforcement to seek stored
communications from US-based providers with a US court order.
US Executive Order 14086 (2022) introduced enhanced safeguards for EU data including
a Data Protection Review Court for EU residents to challenge US intelligence access.
This partially restores the legal framework that was found deficient in Schrems II
but does not fully eliminate the risk of FISA 702 access.
5.2 Data Minimisation Assessment
Data transferred
Email address, full name, notification content
(e.g., "Your scan of example.com is complete — 2 findings detected")
Special categories?
None
Scan data transferred?
No — vulnerability details, scan results, and IP addresses
of scan targets are NOT included in email notifications
Volume
Individual transactional emails only; no bulk export of
user databases to Resend
Sensitive financial data?
Billing receipts include plan name and amount; no full card
numbers or bank account details
Identifiability
Email address identifies the user; no additional data
enabling aggregation into a broader profile
5.3 Likelihood of Government Access
- FISA 702 targets communications of specific non-US persons of foreign intelligence
interest. Shieldome's customers are businesses and professionals conducting authorised
security assessments. This is not a profile that would attract foreign intelligence
interest.
- The data transferred consists of minimal PII (email + name + notification text).
Even if accessed, it would yield no meaningful intelligence value and would reveal
no sensitive personal details about the subject.
- Resend as an email delivery provider handles the same category of data as any
transactional email service. The risk of targeted government access to routine
"scan complete" notifications is assessed as negligible.
- Resend has published commitments to transparency (annual transparency report) and
to challenge overbroad government requests where legally permitted.
5.4 Risk Rating: Resend
Transfer risk rating
LOW
The data transferred to Resend is minimal (email, name, notification text),
contains no special categories, no financial detail, and no scan data. The likelihood of
targeted government access to routine transactional email metadata is negligible. SCCs,
combined with contractual minimisation commitments, provide an effective transfer safeguard.
Transfer may proceed.
6. Transfer Assessment: Google LLC (US)
6.1 Scope of Transfer
The transfer to Google occurs only when a user elects to use "Sign in with Google"
(OAuth 2.0) as their authentication method. This is an optional feature; users may instead
register with email and password.
The OAuth flow involves:
- The user's browser redirects to Google's authorisation endpoint.
- Google authenticates the user and returns an OAuth authorisation code to Shieldome.
- Shieldome exchanges the code for a token and retrieves the user's email address
and display name from Google's API.
- Shieldome uses the email address and name to create or identify the user's account.
6.2 Data Minimisation Assessment
Data transferred to Google
OAuth authorisation code only; no Personal Data is sent
to Google by Shieldome
Data received from Google
Email address and display name — minimum necessary to
identify the account
Scan data transferred?
No scan data, vulnerability findings, billing records,
or any other Customer data is transmitted to Google
Ongoing data sharing with Google?
No — the OAuth exchange occurs only at login. Shieldome
does not share user activity or scan data with Google on an ongoing basis
Google's own processing
Google processes the OAuth request under its own privacy
policy and terms; Shieldome is not responsible for Google's independent processing
of the user's Google Account data
6.3 Likelihood of Government Access
- The data exchanged with Google during the OAuth flow (email + name) is the same
minimal identifier data that a user's Google Account already contains. No incremental
disclosure of sensitive data occurs.
- Google is among the largest recipients of FISA 702 orders globally. However, the
data that Shieldome exchanges with Google (login identifiers) is not data that would
be of foreign intelligence interest independent of the user's broader Google Account.
- Google maintains transparency reporting, publishes National Security Letter counts,
and has publicly committed to challenging overbroad government data requests.
- The European Commission's adequacy decision for the EU-US Data Privacy Framework
(where Google is certified) reflects an assessment that enhanced protections under
EO 14086 reduce — though do not eliminate — the risk of bulk surveillance.
- The risk of government access to Shieldome-specific OAuth login identifiers via
Google is assessed as remote given the non-sensitive nature of the data and the
profile of Shieldome's user base.
6.4 Risk Rating: Google
Transfer risk rating
LOW
The transfer to Google is limited to an OAuth token exchange yielding
only email address and display name. No scan data, billing data, or vulnerability findings
are transmitted. The data involved carries negligible intelligence value independent of the
user's existing Google Account. SCCs (incorporated in Google's DPA) provide an effective
transfer safeguard for this minimal, point-in-time exchange. Transfer may proceed.
7. Supplementary Measures
In addition to the SCCs, the following supplementary measures are in place to reduce
the risk of government access impairing the effectiveness of the transfer safeguards:
| Measure | Applies to | Description |
| Data minimisation |
Resend, Google |
Only the minimum necessary Personal Data is included in each transfer.
Vulnerability findings, scan results, IP addresses, and billing details are not
included in email notifications sent to Resend. No scan data is sent to Google. |
| Encryption in transit |
Resend, Google |
All API calls to Resend and Google use HTTPS/TLS 1.2+. Data is not accessible
in plaintext during transmission. |
| Contractual commitments |
Resend, Google |
Both sub-processors are bound by SCCs requiring them to notify Shieldome of
government access requests and to challenge overbroad requests where legally
permitted. |
| Purpose limitation |
Resend, Google |
Data transferred to Resend is used solely for email delivery; data exchanged
with Google is used solely for OAuth authentication. Neither sub-processor may
use the data for their own commercial purposes beyond service provision. |
| Alternative login option |
Google |
Users who prefer not to use Google OAuth may register and authenticate using
email and password exclusively, with no data transferred to Google. |
8. Conclusion and Overall Risk Rating
Overall TIA conclusion
LOW RISK — Transfers may proceed
Both transfers (to Resend and to Google) involve minimal Personal Data with low
sensitivity and negligible intelligence value. The Serbian legal framework does not
present risks comparable to those identified in Schrems II. SCCs combined with
the supplementary measures described above are assessed to provide an effective level
of protection equivalent to that in the EU/EEA. The transfers may proceed under the
SCCs currently in place.
| Factor |
Resend (US) |
Google (US) |
| Data sensitivity |
Low (email, name, notification text) |
Very low (email, name — login identifiers only) |
| Special categories? |
None |
None |
| Scan/vulnerability data transferred? |
No |
No |
| Transfer mechanism |
EU SCCs 2021/914 Module 2 |
EU SCCs (Google DPA) |
| Likelihood of targeted government access |
Negligible |
Negligible |
| Supplementary measures in place? |
Yes |
Yes |
| Overall risk rating |
LOW |
LOW |
9. Review Schedule
This TIA will be reviewed:
- Annually as part of Shieldome's annual security assessment cycle;
- Upon any material change to the data transferred, the sub-processors
involved, or the legal framework in Serbia or the United States (including any new
court decisions or legislation materially affecting surveillance law);
- Upon a significant change in the EU-US legal landscape (e.g.,
invalidation of the EU-US Data Privacy Framework or significant changes to EO 14086).
The next scheduled review is August 2027. The current version of this
TIA is maintained at
/legal/transfer_impact_assessment.html.
This TIA reflects Shieldome's good-faith assessment as of August 7, 2026. EU Controllers
engaging Shieldome are responsible for conducting their own TIA assessment based on their
own circumstances and the nature of their data. This document is provided as supporting
documentation to assist that assessment. For questions or to obtain the supporting
information referenced herein, contact
[email protected].