Datafication 7 Transfers Flashcards
Transfer tools Art. 44
toolkit of mechanisms to transfer pd to 3rd country which are or intend processing
third country
outside EU & Iceland, Lichtenstein Norway etc.
e.g. CJEU case: is posting of pd on website = transfer to 3rd country as it makes data accessible to people in 3rd country?
- No, not intended to cover that by legislature
- then every posting on website = transfer to all 3rd countries
Transfer tools Chapter 5 Art. 45 - 50
- Adequacy decisions Art. 45
- Appropriate safeguards Art. 46
- Derogations
Adequacy decisions Art. 45
- EU Commission recognized countries to provide adequate protection
- essentially equivalent guarantees as in EU ensured by law for fundamental rights & freedoms
Adequacy decisions Art. 45 - requirement for transfering
Transfers without any specific authorization
Adequacy decisions Art. 45 - adoption of adequacy decision involves
- Proposal from European Commission
- Opinion of European Data Protection Board
- Approval from representatives of EU countries
- Adoption of decision by European Commission
Adequacy decisions Art. 45 - powers to withdraw etc.
At any time: European Parliament & Council can request maintain, amend, or withdraw if country exceed powers provided in regulation
Adequacy decisions Art. 45 - countries
Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, UK, Uruguay
Appropriate safeguards Art. 46
- data controller or processor provided one:
- Standard contractual clauses (SCC)
- Binding corporate rules art. 47
- Approved codes of conduct & certification mechanisms
- Ad hoc contractual clauses (must have Supervisory Authority authorization)
- Reliance on international agreement
Standard contractual clauses (SCC) = Model Clauses
- EU Commission decides that SCCs = sufficient safeguards for international data transfer
- 2 SCCs sets to transfer data from dc in EU to dc outside EU / EEA
- 1 CC set to transfer data from dc in EU to dp outside EU / EEA
Binding corporate rules art. 47
- internal rules for transfers
- within a group of undertakings engaged in joint economic activity (multinational companies and governed by code of conduct)
- to countries that do not provide adequate level of protection
Binding corporate rules art. 47 - requirement
- shall be approved by SA if corporate rules …
a) are legally binding & apply to all members of group
b) include enforceable rights on ds with regard to processing of their pd
c) and fulfill requirements in Art. 47(2) - list of content
Binding corporate rules art. 47 - content (must include)
- Privacy principles (e.g. transparency, data quality, security)
- Tools of effectiveness (e.g. audits, trainings)
- Element providing that rules are binding
Binding corporate rules art. 47 - con
main company is liable for what other parties do, very expensive