GDPR GDPR International Data Transfers 2 — Questions and Answers
Question 1: Which GDPR article sets the general prohibition on transferring personal data to third countries?
- Article 5
- Article 44 (Correct answer)
- Article 35
- Article 83
Correct answer: Article 44
Article 44 establishes the general principle that any transfer of personal data to a third country or international organization may only take place subject to GDPR Chapter V conditions.
Question 2: A US-based cloud provider processes EU customer data. Which transfer tool would a US company most commonly use post-Privacy Shield?
- BCRs
- SCCs (Standard Contractual Clauses) (Correct answer)
- Article 49 derogations
- Adequacy decision for the US
Correct answer: SCCs (Standard Contractual Clauses)
Since Privacy Shield was invalidated, SCCs have become the primary mechanism US processors use to legally receive EU personal data.
Question 3: What is a Transfer Impact Assessment (TIA)?
- An internal audit of all personal data held by a processor
- An evaluation of whether the legal system of a destination country undermines the effectiveness of transfer safeguards (Correct answer)
- A DPA's inspection of a company's international transfer practices
- A formal DPIA required before any cross-border transfer
Correct answer: An evaluation of whether the legal system of a destination country undermines the effectiveness of transfer safeguards
A TIA assesses the laws and practices of the destination country to determine whether they undermine the protections offered by the chosen transfer mechanism such as SCCs.
Question 4: Which country currently has a formal EU adequacy decision, making data transfers from the EU to that country permissible without additional safeguards?
- United States
- China
- Japan (Correct answer)
- Russia
Correct answer: Japan
Japan has an adequacy decision from the European Commission, meaning EU personal data can flow to Japan without requiring SCCs or BCRs.
Question 5: An organization wants to allow intra-group data transfers to subsidiaries in non-adequate countries. What is the most appropriate GDPR mechanism?
- Standard Contractual Clauses for each subsidiary pair
- A single set of Binding Corporate Rules approved by the lead DPA (Correct answer)
- Consent from each individual data subject
- Relying on Article 49 derogations for all transfers
Correct answer: A single set of Binding Corporate Rules approved by the lead DPA
BCRs provide a single, internally binding framework for multinational corporate groups, avoiding the need for separate SCCs between every pair of group entities.
Question 6: Under the EU-US Data Privacy Framework (DPF) adopted in 2023, how do US organizations participate?
- By signing SCCs with every EU partner
- By self-certifying compliance with DPF principles through the US Department of Commerce (Correct answer)
- By obtaining BCR approval from a US regulator
- By applying for an adequacy decision individually
Correct answer: By self-certifying compliance with DPF principles through the US Department of Commerce
US organizations join the DPF by self-certifying their commitment to DPF principles with the US Department of Commerce, enabling EU data transfers without additional safeguards.
Which GDPR article sets the general prohibition on transferring personal data to third countries?