GDPR · Domain 4
International Data Transfers
About 15% of the exam
The transfer toolkit
- Adequacy, Article 45
- the Commission finds protection equivalent
- Standard clauses, Article 46
- Commission text in four modules
- Binding corporate rules
- approved rules inside one group
- Codes and certification
- binding commitments by the importer
- Administrative arrangements
- public bodies with enforceable rights
- Derogations, Article 49
- narrow exceptions, occasional use only
Movement inside the European Economic Area is not a transfer, and an adequacy decision covers only the scope that decision describes
After Schrems II
- Privacy Shield fell in July 2020
- Clauses survived but carry a duty
- Assess the destination country's surveillance laws
- Add supplementary measures where protection falls short
- Suspend the transfer if nothing works
- Foreign intelligence access was the core concern
- Essential equivalence, not identical rules
The 2023 Data Privacy Framework restored adequacy for self certified United States organizations and created a review court for European complaints
Transfer impact assessment
- Map the actual data flow
- Describe the transfer and its purpose
- Assess the destination legal regime
- Check the importer's practical experience
- Choose supplementary measures
- Document and review
- Repeat it when the laws change
- Keep it alongside the contract
Supplementary measures
- Strong encryption with keys held here
- Pseudonymization the importer cannot reverse
- Split processing across separate providers
- Transparency reports on government access
- Duty to challenge disproportionate requests
- Policies for handling access demands
The 2021 clauses
- Module one, controller to controller
- Module two, controller to processor
- Module three, processor to processor
- Module four, processor to controller
- A docking clause lets parties join
- Do not edit the fixed text
Article 49 derogations
- Explicit consent after warning of risks
- Necessary to perform a contract
- Important reasons of public interest
- Establishing or defending legal claims
- Vital interests where consent is impossible
- Public registers within their legal limits
Binding corporate rules
What they are
- Group wide rules for intra group transfers
- Approved by the lead authority
- Backed by the consistency mechanism
- Enforceable rights for individuals
What they cost
- A long approval process
- Board level binding commitments
- Audit and training programs required
- Destination law assessments still needed
Common transfer scenarios
- Cloud storage abroad
- a transfer needing a mechanism
- Remote support access
- access from abroad counts too
- Group personnel system
- corporate rules or standard clauses
- Recipient in an adequate country
- no extra mechanism required
- Onward transfer by importer
- authorization plus equivalent safeguards
- Litigation disclosure abroad
- the legal claims derogation may apply
The residual derogation
- A last resort when nothing fits
- Not repetitive and limited in number
- Compelling legitimate interests of the controller
- Interests must not be overridden
- Suitable safeguards recorded in the register
- Tell the supervisory authority about it
Getting it right
- Map flows before choosing a mechanism
- Chapter five sits on top of Article 6
- Check sub processor locations every year
- Watch for adequacy decisions under review
- Keep the assessment evidence current
Transfer errors auditors find
- Old clauses never migrated to 2021
- An assessment written once and forgotten
- Derogations used for routine bulk transfers
- Support teams abroad missing from the map
- Encryption keys handed to the importer
Rapid recall: chapter five
- Article 44
- the general principle
- Article 45
- adequacy decisions
- Article 46
- appropriate safeguards
- Article 47
- binding corporate rules
- Article 48
- foreign court and authority orders
- Article 49
- derogations for specific situations
Names to know
- Schrems I
- Safe Harbor struck down
- Schrems II
- Privacy Shield struck down
- Data Privacy Framework
- adequacy for self certified firms
- Review court
- hears European intelligence access complaints
- Essential equivalence
- the standard third countries meet
Choosing a mechanism, step by step
- Confirm a transfer is happening
- Check for an adequacy decision
- Pick clauses, rules or a code
- Run the transfer impact assessment
- Add supplementary measures
- Sign, record and review
- Derogations come last, never first
- Onward transfers need their own cover
- Suspension is a real obligation
- Authorities can order flows stopped
Reference strip: adequacy, clauses, rules, assessment, derogations
Adequacy
- The Commission decides, then reviews
- Covers only its stated scope
- No extra mechanism needed
Clauses
- Four modules since 2021
- Fixed text, variable annexes
- A docking clause admits parties
Corporate rules
- Intra group transfers only
- Approved by a lead authority
- Assessment duties still apply
Assessment
- Law plus practical experience
- Documented before the transfer
- Revisited when conditions change
Derogations
- Occasional and non repetitive
- Explicit consent needs risk warning
- Never a routine transfer route
Quick exam traps
- Trap: Standard contractual clauses on their own are always enough after Schrems II
- Trap: Data landed in an adequate country can be onward transferred freely
- Trap: Remote access from a third country is not a transfer
- Trap: Explicit consent is a practical basis for routine bulk transfers
- Trap: Transfers between member states need a chapter five mechanism
- Trap: Encryption always rescues a failed transfer impact assessment
- Trap: Binding corporate rules remove the need to assess destination law
cybercertprep.com · original revision sheet written from the public body of knowledge