International Data Transfers (7) Flashcards
What are the 3 options for data transfers outside of the EEA?
- Adequacy decision
- Appropriate safeguards (enforceable rights and legal remedies)
- Derogations
(should be considered in this order)
Is the controller under obligation to inform data subjects about data transfers?
Yes
must communicate: existence or absence of adequacy decision, intent to transfer, safeguards being used
What is adequacy under GDPR?
adequate level of data protection as determined by the European Commission for a country, territory, sector and IO, that allows for transferring without the need for additional authorization
What is the criteria for adequacy?
respect of rule of law
access to justice
international human rights standards
general and sectoral laws and case law
effective and enforceable rights for individuals
data protection rules
other international commitments
Which countries are deemed adequate by European Commission?
andorra, argentina, canada (with exceptions), faroe islands, guernsey, israel, isle of man, japan, jersey, new zealand, south korea, switzerland, UK, uruguay
What happened in Schrems v Data Protection Commissioner?
Reject Safe Harbor as adequacy determination
Schrems was a Facebook user in Austria, complained to Irish SA that Facebook Ireland was improperly transferring his data to the US where it could be accessed by NSA.
What was the subsequent ruling in Schrems 2?
CJEU invalidated the Privacy Shield citing that:
- US surveillance was not limited to what was strictly necessary and proportional
- EU data subjects lacked actionable judicial redress and no right to remedy
- need for case by case assessments of sufficiency of foreign protections
What is “essential equivalence’’?
Equivalence between EU law and where you’re transferring
Does the UK have adequacy?
Yes, under the GDPR and the Law Enforcement DIrective
What is the name of the privacy regulation in the UK?
UK Data Protection Act (2018)
What are appropriate safeguards under Article 46?
Approved codes of conduct and certification mechanisms
Binding corporate rules
Standard contractual clauses
Ad hoc contractual clauses
Reliance on international agreements
What are standard contractual clauses?
Model Clauses
Standard form that is non-negotiable, to allow a company in the EEA that wants to send data to a company outside EEA
Still companies must conduct case-by-case assessments on the laws in each recipient country to ensure essential equivalence to EU law for personal data transferred under SCCs or BCRs
What is a TIA?
Transfer Impact Assessment
process of assessing data protection equivalence (industry term)
What are codes of conduct as an appropriate safeguard for data transfers?
compliance-signaling tools for controllers and processors
created/revised by other bodies in representation of controllers/processors
binding and enforceable
What are certification mechanisms as appropriate safeguards for data transfers?
recognized by the GDPR as acceptable mechanisms for demonstrating compliance
may be issued by accredited bodies, supervisory authorities and the EDPB
good for no more than 3 years
consequences for non-compliance