GDPR GDPR International Data Transfers 1 — Questions and Answers
Question 1: Which GDPR mechanism allows personal data to be transferred to a third country that the European Commission has deemed to provide adequate protection?
- Standard Contractual Clauses
- Adequacy Decision (Correct answer)
- Binding Corporate Rules
- Derogations under Article 49
Correct answer: Adequacy Decision
An adequacy decision by the European Commission certifies that a third country offers a level of data protection essentially equivalent to the EU's, allowing free data flows.
Question 2: What are Standard Contractual Clauses (SCCs) under GDPR?
- Internal company policies for data transfers
- Pre-approved contractual templates adopted by the European Commission to safeguard cross-border data flows (Correct answer)
- Agreements between EU member states for sharing government data
- Clauses required in all employment contracts involving personal data
Correct answer: Pre-approved contractual templates adopted by the European Commission to safeguard cross-border data flows
SCCs are standardized contract clauses pre-approved by the European Commission that organizations can adopt to ensure adequate safeguards when transferring data outside the EEA.
Question 3: Under GDPR Article 47, Binding Corporate Rules (BCRs) must be approved by:
- The European Data Protection Board alone
- The relevant national supervisory authority and recognized by other EEA authorities (Correct answer)
- The organization's DPO and CEO
- Only the data subjects whose data is being transferred
Correct answer: The relevant national supervisory authority and recognized by other EEA authorities
BCRs must be approved by the lead supervisory authority of the organization and are then mutually recognized by other EEA supervisory authorities through a consistency mechanism.
Question 4: Following the Schrems II ruling (C-311/18), what happened to the EU-US Privacy Shield?
- It was upheld and remains valid
- It was invalidated by the Court of Justice of the EU (Correct answer)
- It was replaced by BCRs
- It was transferred to the EDPB for management
Correct answer: It was invalidated by the Court of Justice of the EU
The CJEU invalidated the EU-US Privacy Shield in July 2020, finding that US surveillance laws did not provide equivalent protection to EU data subjects' rights.
Question 5: What supplementary measure might organizations adopt when SCCs alone are insufficient after a Schrems II transfer impact assessment?
- Requesting a new adequacy decision for every transfer
- Applying end-to-end encryption so that data is unintelligible to the importing country's authorities (Correct answer)
- Requiring data subjects to waive their GDPR rights
- Filing a complaint with the EDPB
Correct answer: Applying end-to-end encryption so that data is unintelligible to the importing country's authorities
Encryption that renders data unintelligible to third-country authorities is a recognized technical supplementary measure that can shore up inadequate SCC protections.
Question 6: Under GDPR Article 49, which derogation permits a one-off international data transfer in the absence of adequacy or safeguards?
- The transfer is necessary for the performance of a contract between the data subject and the controller (Correct answer)
- The transfer serves the controller's legitimate interests exclusively
- The transfer involves only anonymized data
- The transfer is for academic research purposes only
Correct answer: The transfer is necessary for the performance of a contract between the data subject and the controller
Article 49(1)(b) allows transfers necessary for the performance of a contract between the data subject and the controller, even without adequacy or SCCs, as a limited derogation.
Which GDPR mechanism allows personal data to be transferred to a third country that the European Commission has deemed to provide adequate protection?