Free PLC Cross-Border Data Transfers & Compliance Questions and Answers — Questions and Answers
Question 1: What mechanism is commonly used under GDPR for lawful data transfers outside the EU?
- EU Safe Harbor
- Privacy Badge
- Standard Contractual Clauses (Correct answer)
- Voluntary Codes of Conduct
Correct answer: Standard Contractual Clauses
Standard Contractual Clauses (SCCs) are pre-approved model clauses provided by the European Commission that organizations can use to legally transfer personal data from the EU/EEA to countries not deemed to offer adequate data protection. They impose contractual obligations on both the data exporter and importer to ensure appropriate safeguards for the transferred data. SCCs are a widely used mechanism to comply with GDPR's requirements for international data transfers.
Question 2: What did the Schrems II ruling invalidate?
- Safe Harbor Agreement
- Standard Contractual Clauses
- Privacy Shield (Correct answer)
- GDPR
Correct answer: Privacy Shield
The Schrems II ruling by the Court of Justice of the European Union (CJEU) invalidated the EU-U.S. Privacy Shield framework. The court found that the protections offered by the Privacy Shield for EU data subjects' data transferred to the U.S. were insufficient, particularly concerning U.S. government surveillance programs. This decision significantly impacted transatlantic data transfers and emphasized the need for robust safeguards.
Question 3: Which entity evaluates whether a non-EU country provides adequate protection?
- European Commission (Correct answer)
- Data Protection Officer
- European Parliament
- Supervisory Authority
Correct answer: European Commission
The European Commission is the executive arm of the European Union and is responsible for assessing whether a non-EU country provides an "adequate level of data protection." An adequacy decision means that personal data can flow from the EU/EEA to that third country without needing additional safeguards. This assessment considers the country's domestic law, international commitments, and the existence of independent supervisory authorities.
Question 4: Which is a lawful basis for data transfer under GDPR when no adequacy decision exists?
- Privacy Consent Shield
- Binding Corporate Rules (Correct answer)
- Global Certification
- Safe Harbor
Correct answer: Binding Corporate Rules
Binding Corporate Rules (BCRs) are internal codes of conduct approved by data protection authorities that allow multinational companies to transfer personal data internationally within their corporate group. They provide a robust legal framework for data transfers to countries without an adequacy decision, ensuring all entities within the group adhere to the same high standards of data protection. BCRs are a complex but effective mechanism for intra-group transfers.
Question 5: What must organizations do before transferring data using SCCs?
- Notify the European Commission
- Obtain ISO certification
- Conduct a Transfer Impact Assessment (Correct answer)
- Use Privacy Shield
Correct answer: Conduct a Transfer Impact Assessment
Following the Schrems II ruling, organizations using Standard Contractual Clauses (SCCs) are now required to conduct a Transfer Impact Assessment (TIA). This assessment evaluates whether the laws and practices of the recipient country might undermine the protections guaranteed by the SCCs, particularly regarding government access to data. If risks are identified, supplementary measures must be implemented to ensure an equivalent level of protection for the transferred data.
Question 6: Which document outlines internal rules for cross-border data transfers within multinational companies?
- Privacy Charter
- Binding Corporate Rules (Correct answer)
- Data Impact Framework
- Standard Contractual Clauses
Correct answer: Binding Corporate Rules
Binding Corporate Rules (BCRs) are a set of internal, legally binding rules adopted by multinational corporations to govern their transfers of personal data from the EU/EEA to their entities located outside the EU/EEA. They serve as a robust mechanism to ensure that all intra-group data transfers comply with GDPR standards, especially when no adequacy decision exists for the recipient country. BCRs are approved by data protection authorities and provide a comprehensive framework for data protection within a corporate group.
Question 7: Which of the following is NOT a requirement for an adequacy decision?
- Rule of law and data protection safeguards
- Existence of supervisory authorities
- Political alignment with EU (Correct answer)
- International commitments
Correct answer: Political alignment with EU
When the European Commission assesses a non-EU country for an adequacy decision, it primarily focuses on the country's data protection laws, the existence of independent supervisory authorities, and its international commitments regarding human rights and data protection. While political relations might exist, "political alignment with EU" is not a formal criterion for determining an adequate level of data protection. The assessment is strictly based on the legal framework and practical safeguards for personal data.
Question 8: When is explicit consent required for international data transfer?
- When a TIA exists
- When no safeguards apply (Correct answer)
- If data is anonymized
- If a DPO signs off
Correct answer: When no safeguards apply
Under GDPR, explicit consent is generally required for international data transfers only as a derogation (exception) when no other appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules, are in place. This means that if an organization cannot rely on any other legal basis or safeguard, they must obtain explicit, informed, and specific consent from the data subject for the transfer. This is typically a last resort due to the high bar for explicit consent.
Question 9: What is a risk of non-compliance in cross-border data transfers?
- License revocation only
- No business impact
- Fines and legal actions (Correct answer)
- Verbal warning
Correct answer: Fines and legal actions
Non-compliance with cross-border data transfer regulations, such as those under GDPR, carries significant risks for organizations. These risks include substantial administrative fines, which can be millions of euros or a percentage of global annual turnover, as well as legal actions from supervisory authorities or data subjects. Additionally, non-compliance can lead to reputational damage and a loss of customer trust.
What mechanism is commonly used under GDPR for lawful data transfers outside the EU?