Module 7: International Data Transfers Flashcards

1
Q

What is an adequacy decision?

A

An adequacy decision permits a cross-border data transfer outside the EU, or onward transfer from or to a party outside the EU without further authorisation from a national supervisory authority (Article 45(1), GDPR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who has the power to enforce an adequacy decision?

A

The European Commission has the power to determine whether a third country has an adequate level of data protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the criteria for an adequacy decision?

A

respect of the rule of law
access to justice
international human rights standards, general and sectoral laws and case laws
effective and enforceable rights for individuals
data protection rules and professional rules
security measures and other international commitments or obligations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Example of countries with adequacy decisions in place with the EU

A

New Zealand, Andorra, Canada, Japan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What was the EU - US Privacy Shield (now invalidated)?

A

An invalidated adequacy decision.
Applied to organisations under FTC enforcement and acted as voluntary self certification programs, through commitment, publicity, public disclosure, implementation and renewal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What were the 7 principles of privacy shield?

A
The seven privacy shield principles included:
Notice
Choice
Accountability for onward transfer
Security
Data integrity and purpose limitation
Access
Recourse, enforcement and liability

Additional Privacy Shield provisions included an annual joint review and limited, proportionate surveillance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are appropriate safeguards?

A

Standard data protection clauses and approved codes of conduct and certification mechanisms.
Includes ad hoc contractual clauses, and international agreements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are codes of conduct and what do they do?

A

Codes of conduct are created or revised by regulators and associations and other bodies representing controllers or processors for GDPR application, helping controllers and processors to demonstrate compliance, creating marketing efficiencies and facilitating international data transfers.
They are binding and enforceable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are certification mechanisms and what do they do?

A

Certification mechanisms may be issued by accredited certification bodies, competent supervisory authorities or the EDPB for assisting controllers and processors in same situations as through codes of conduct and by additionally demonstrating compliance with Article 25 (data protection by design and by default)
These are good for no more than 3 years, but may be renewed. There are consequences for non-compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are binding corporate rules and what do they do?

A

Apply to companies engaged in joint economic activity, corporate groups and groups of enterprises, and controllers/processors
Are internal and legally binding rules that expressly confer enforceable rights of data subjects
Are actioned through standard applications, with approval by supervisory authorities and detailed conditions for transfers (outlined in Article 47)
Are used to give flexibility and due to low administrative burden post implementation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the derogations relating to international data. transfers?

A
Derogations regarding international data transfers under Article 49 of the GDPR include:
Consent
Performance of contract
Public interest
Establishment, exercising or defense of legal claims
Vital interests
Transfer from register
Legitimate interests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the restrictions of international data transfers?

A

Foreign law enforcement requests

Important reasons of public interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly