International Data Transfers (7) Flashcards

1
Q

What are the 3 options for data transfers outside of the EEA?

A
  1. Adequacy decision
  2. Appropriate safeguards (enforceable rights and legal remedies)
  3. Derogations

(should be considered in this order)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Is the controller under obligation to inform data subjects about data transfers?

A

Yes

must communicate: existence or absence of adequacy decision, intent to transfer, safeguards being used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is adequacy under GDPR?

A

adequate level of data protection as determined by the European Commission for a country, territory, sector and IO, that allows for transferring without the need for additional authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the criteria for adequacy?

A

respect of rule of law
access to justice
international human rights standards
general and sectoral laws and case law
effective and enforceable rights for individuals
data protection rules
other international commitments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which countries are deemed adequate by European Commission?

A

andorra, argentina, canada (with exceptions), faroe islands, guernsey, israel, isle of man, japan, jersey, new zealand, south korea, switzerland, UK, uruguay

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What happened in Schrems v Data Protection Commissioner?

A

Reject Safe Harbor as adequacy determination

Schrems was a Facebook user in Austria, complained to Irish SA that Facebook Ireland was improperly transferring his data to the US where it could be accessed by NSA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What was the subsequent ruling in Schrems 2?

A

CJEU invalidated the Privacy Shield citing that:

  • US surveillance was not limited to what was strictly necessary and proportional
  • EU data subjects lacked actionable judicial redress and no right to remedy
  • need for case by case assessments of sufficiency of foreign protections
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is “essential equivalence’’?

A

Equivalence between EU law and where you’re transferring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does the UK have adequacy?

A

Yes, under the GDPR and the Law Enforcement DIrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the name of the privacy regulation in the UK?

A

UK Data Protection Act (2018)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are appropriate safeguards under Article 46?

A

Approved codes of conduct and certification mechanisms
Binding corporate rules
Standard contractual clauses
Ad hoc contractual clauses
Reliance on international agreements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are standard contractual clauses?

A

Model Clauses

Standard form that is non-negotiable, to allow a company in the EEA that wants to send data to a company outside EEA

Still companies must conduct case-by-case assessments on the laws in each recipient country to ensure essential equivalence to EU law for personal data transferred under SCCs or BCRs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a TIA?

A

Transfer Impact Assessment

process of assessing data protection equivalence (industry term)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are codes of conduct as an appropriate safeguard for data transfers?

A

compliance-signaling tools for controllers and processors

created/revised by other bodies in representation of controllers/processors
binding and enforceable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are certification mechanisms as appropriate safeguards for data transfers?

A

recognized by the GDPR as acceptable mechanisms for demonstrating compliance

may be issued by accredited bodies, supervisory authorities and the EDPB
good for no more than 3 years
consequences for non-compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are Binding Corporate Rules?

A

internal and legally binding rules between companies engaged in joint economic activity, corporate groups or controllers and processors

17
Q

What are derogations under Article 49?

A

an exemption from prohibition on transferring personal data outside EEA
a last resort for limited circumstances / specific conditions, narrowly interpreted

18
Q

What are the potential conditions for derogations?

A
  1. explicit consent from data subject
  2. necessary for performance of a contract or conclusion of a contract
  3. public interest
  4. establishment, exercise, or defense of legal claims
  5. vital interests
  6. transfer from a register of public information
  7. legitimate interests of controller
19
Q

What are the step by step recommendations for data transfers post Schrems II?

A

Step 1: know your transfers (document and map PI transferred)
Step 2: identify your transfer mechanism (tools under Chapter 5 GDPR). If country is adequate, no further steps.

Step 3: assess sufficiency of non EEA protections (is there a law or practice that might infringe on effectiveness of safeguards)
Step 4: identify and adopt supplementary measures
Step 5: take formal procedural steps to adopt supplementary measure
Step 6: re-evaluate level of protection at appropriate intervals

20
Q

What are the European Essential Guarantees?

A

1) processing based on clear, precise and accessible rules
2) necessity and proportionality need to be demonstrated with regard to legitimate objective
3) independent oversight mechanism
4) effective remedies available to individual

21
Q

What needs to take place for the movement of data to be considered a “transfer”?

A

substantive processing operation is conducted on the personal data in a third country

22
Q

What does the EC take into account when considering the adequacy of level of protection for a transfer?

A
  1. rule of law
  2. indepedent supervisory authority
  3. international committments entered into by the country
23
Q

What were the 7 principles of the Privacy Shield?

A
  1. Notice
  2. Choice
  3. Accountability for onward transfer
  4. Security
  5. Data integrity and purpose limitation
  6. Access
  7. Recourse, enforcement, liability
24
Q

What steps did the Privacy Shield require companies to take to self-certify compliance?

A
  1. internal compliance assessment to determine ablity to comply with principles
  2. register wih 3rd party arbitration provider for complaints from EU individuals
  3. adopt a privacy shield notice and publish online
25
Q

What are possible mechanisms to safeguard international transfers?

A

legally binding and enforceable instrument between public bodies

Binding Corporate Rules

Standard data protection clauses

Codes of Conduct

Certification Mechanism

Contractual Clauses

26
Q

What are the steps of the Transfer Impact Assessment?

A
  1. Know your transfers
  2. Identify transfer tools
  3. Assess effectiveness of transfer tool (article 46)
  4. Adopt supplementary measures
  5. Procedural steps to supplementary measures
  6. Reevaluate at appropriate intervals
27
Q

What elements must full and valid BCRs include?

A

Structure and contact details of corporate group
Data transfers, type of data, processing, purposes, data subjects, third party countries
Legally binding nature of BCRs
Application of data protection principles
Rights of data subjects
Acceptance of liability for breaches
Information provision to data subjects
Tasks of Data Protection Officer
Complaint procedures
Verification of compliance with BCRs
Reporting and recording changes to rules
Cooperation with SA
Reporting to SA
Data Protection training