CDPSE Cross-Border Data Transfers 2 — Questions and Answers
Question 1: What did the Court of Justice of the EU (CJEU) determine in the Schrems II ruling regarding Privacy Shield?
- Privacy Shield was strengthened with additional safeguards
- Privacy Shield was invalidated due to inadequate US surveillance law protections (Correct answer)
- Privacy Shield was replaced by Standard Contractual Clauses automatically
- Privacy Shield was limited to B2B transfers only
Correct answer: Privacy Shield was invalidated due to inadequate US surveillance law protections
The CJEU invalidated Privacy Shield in 2020 because US surveillance laws did not provide EU residents with effective remedies equivalent to EU rights.
Question 2: When using SCCs for a data transfer, what additional step may be required following the Schrems II ruling?
- Filing a notification with the local data protection authority
- Conducting a Transfer Impact Assessment to verify the SCCs remain effective (Correct answer)
- Encrypting all data before transfer using government-approved algorithms
- Obtaining a waiver from the European Data Protection Board
Correct answer: Conducting a Transfer Impact Assessment to verify the SCCs remain effective
Post-Schrems II, organizations must conduct a TIA to determine whether local laws in the destination country could nullify SCC protections in practice.
Question 3: Which derogation under GDPR Article 49 permits a cross-border data transfer without an adequacy decision or appropriate safeguards?
- Vital interests of the data subject (Correct answer)
- Commercial necessity of the data controller
- Request by a foreign government agency
- Operational efficiency of the organization
Correct answer: Vital interests of the data subject
Article 49 allows transfers where necessary to protect the vital interests of the data subject or another person when the data subject cannot give consent, among other limited derogations.
Question 4: A cloud vendor stores EU customer data on US servers. Which document MUST exist to make this transfer lawful under GDPR?
- A software license agreement
- A valid data transfer mechanism such as SCCs incorporated in the Data Processing Agreement (Correct answer)
- An ISO 27001 certification from the cloud vendor
- A bilateral trade agreement between the EU and US
Correct answer: A valid data transfer mechanism such as SCCs incorporated in the Data Processing Agreement
A valid transfer mechanism—most commonly SCCs incorporated into a DPA—is legally required for any transfer of EU personal data to a country lacking an adequacy decision.
Question 5: What is the role of supplementary measures in cross-border data transfers under SCCs?
- To replace SCCs when they are too complex to implement
- To provide additional technical or contractual protections when the destination country's laws may undermine SCC guarantees (Correct answer)
- To reduce the cost of compliance with transfer rules
- To notify data subjects about international transfers automatically
Correct answer: To provide additional technical or contractual protections when the destination country's laws may undermine SCC guarantees
Supplementary measures—such as encryption, pseudonymization, or additional contractual commitments—strengthen SCC protections where destination country laws pose elevated risks.
Question 6: Which US state privacy law includes provisions specifically addressing cross-border data transfers and requires data transfer impact assessments?
- California Consumer Privacy Act (CCPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA) (Correct answer)
- Utah Consumer Privacy Act (UCPA)
Correct answer: Colorado Privacy Act (CPA)
The Colorado Privacy Act requires controllers to conduct and document data protection assessments for processing that presents a heightened risk, including cross-border transfers.
What did the Court of Justice of the EU (CJEU) determine in the Schrems II ruling regarding Privacy Shield?