SlideShare a Scribd company logo
1 of 13
GDPR
Transfer of personal data outside
the European Economic Area
Rutger Ketting
Introduction
1. Introduction
2. Adequacy decisions
3. Transfer mechanisms
4. Derogation of specific situations
5. EU – US Privacy Shield
Adequacy decisions
• Decision of the European Commission that third country ensures adequate level of
protection of personal data.
• General approval, no specific authorisation required for individual transfers.
• Adequacy decisions for (https://ec.europa.eu/info/strategy/justice-and-fundamental-
rights/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-
eu-countries_en):
– Andorra
– Argentina
– Canada
– Faroer Islands
– Guernsey
– Israel
– Isle of Man
– Jersey
– New Zealand
– Switzerland
– Uruguay and the US (limited to the Privacy Shield framework)
• Adequacy talks are ongoing with Japan and South Korea.
• Decisions do not cover exchange of data in law enforcement sector.
3
Transfer mechanisms
4
Existing mechanisms
1. Standard contractual clauses
2. Binding corporate rules
New mechanisms
1. Standard contractual clauses certified by national DPA
2. Approved code of conduct
3. Approved certification mechanism
Standard contractual clauses
• Adopted by the EU Commission or adopted by the supervisory authority and
approved by the EU Commission.
• SCC adopted by the Commision under the Data Protection Directive
(95/46/EC) remain valid until amended/replaced/repealed.
• SCC currently available (https://ec.europa.eu/info/strategy/justice-and-
fundamental-rights/data-protection/data-transfers-outside-eu/model-contracts-
transfer-personal-data-third-countries_en )
– EU controller to non-EU or EEA controller
• decision 2001/497/EC
• decision 2004/915/EC
– EU controller to non-EU or EEA processor
• decision 2010/87/EU
5
Binding corporate rules
• International rules for data transfers within multinational companies. i.e.
internal code of conduct.
• Binding corporatie rules must:
– contain privacy principles (e.g. transparancy, data quality, security)
– contain tools of effectiveness (audit, training, compliancy systems)
– be binding and enforced by every member of the group of undertakings concerned
– Expressly confer enforceable rights on data subjects
– Meet requirements set out in working papers adopted by WP 29 (WP 153)
• Article 47 (2) GDPR contains minimum requirements
• Binding corporate rules must be approved by competent supervisory authority
6
Binding corporate rules
• Approximately 90 corporations with BCR’s:
7
Codes of conduct
• Associations and other bodies representing categories of controllers or
processors may prepare codes of conduct.
• Approval by competent supervisory authority is required.
• Controllers/processors in third countries must make binding and
enforceable commitments via contractual or other legally binding
instruments to provide for the appropriate safeguards required by the
code of conduct including the safeguards with regard to the rights of data
subjects.
8
Certification
• Certification by certification bodies that are accredited by the competent
supervisory authority or the national accreditation body pursuant to regulation
No 765/2008).
• Certification shall be voluntary.
• Controllers/processors in third countries must make binding and enforceable
commitments via contractual or other legally binding instruments to provide
for the appropriate safeguards required for the certification including the
safeguards with regard to the rights of data subjects.
9
Derogation for specific situations
– Explicit consent: Data subject has provided explicit consent after having been
informed of possible risks of transfer due to absence of adequacy
decision/appropriate safeguards (not applicable for public authorities in the exercise
of their public powers); or
– Necessity: The transfer is necessary for:
• the performance of a contract between the data subject and the controller or for the
implementation of precontractual measures at the data subject’s request (not
applicable for public authorities in the exercise of their public powers); or
• the conclusion or performance of a contract concluded in the interest of the data
subject between the controller and another legal or natural person. (not applicable
for public authorities in the exercise of their public powers); or
• important reasons of public interest recognised by Union Law or member state law to
which the controller is subject. Law must set limits to transfer; or
• Establishment, excersise or defence of legal claims; or
– Vital interest: The transfer is necessary in order to protect the vital interrest of the
data subject or other persons, where the data subject is physically or legally
incapable of giving consent; or
– Public registers: The transfer is made from a register which according to Union or
member state law is intended to provide information to the public.
10
Derogation for specific situations
– Extra exception (NEW under GDPR)
Requirements:
• The transfer is non-repetitive; and
• Concerns a limited number of data subjects; and
• And is necessary for the purposes of compelling legitimate interests pursued by
the controller which are not overridden by the interests and rights and freedoms of
the data subject; and
• The controller has assessed all circumstances surrounding the transfer and has
provided suitable safeguards with regard to the protection of data.
• When this exception is used, the controller shall inform the supervisory authority
of the transfer and shall inform the data subject of the legitimate compelling
interests pursued.
11
US-EU Privacy Shield Framework
• Adopted 12 July 2016, Effective 1 August 2016
• Agreement between EU and US.
– Only applies to US Companies that have registered to by on the privacy shield list
(https://www.privacyshield.gov/list ).
– Registration requires self-certification that company meets the high data protection
standards set out by the arrangement. Registration must be renewed every year.
– strong data protection obligations on companies receiving personal data from the
EU.
– Enforcement by US Department of Commerce and the Federal Trade Commission
(FTC).
– Increased cooperation with the European Data Protection Authorities.
– safeguards on US government access to data.
– effective protection and redress for individuals.
– an annual joint review by EU and US to monitor the correct application of the
arrangement.
• Replaces Safe Harbor Principles (declared invalid by European Court of
Justice decision of 6 October 2015).
• Challenges pending (first challenge dismissed on procedural grounds in
November 2017).
12
Contact details
13
Company details
Nysingh advocaten – notarissen N.V.
Phone: 0031 38 425 92 00
Website: www.nysingh.nl
Personal details
Rutger Ketting
Mobile: 0031 6 306 48 127
Email: R.Ketting@nysingh.nl

More Related Content

What's hot

Francesca Fanucci, Ppt
Francesca Fanucci, PptFrancesca Fanucci, Ppt
Francesca Fanucci, Ppt
guestbc7697
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Ppt
guestbc7697
 
International privacy with kevin haley
International privacy with kevin haleyInternational privacy with kevin haley
International privacy with kevin haley
Sarah Fletcher
 
Uia presentation Eng
Uia presentation EngUia presentation Eng
Uia presentation Eng
Fabio Marazzi
 

What's hot (18)

Francesca Fanucci, Ppt
Francesca Fanucci, PptFrancesca Fanucci, Ppt
Francesca Fanucci, Ppt
 
Maeve Mc Donagh
Maeve Mc DonaghMaeve Mc Donagh
Maeve Mc Donagh
 
Thomas M. Susman,Ppt
Thomas M. Susman,PptThomas M. Susman,Ppt
Thomas M. Susman,Ppt
 
Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery? Will the GDPR Kibosh EU-US Discovery?
Will the GDPR Kibosh EU-US Discovery?
 
Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?Data Protection Guide – What are your rights as a citizen?
Data Protection Guide – What are your rights as a citizen?
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 
Transatlantic data flows following the Schrems II judgment
Transatlantic data flows following the Schrems II judgmentTransatlantic data flows following the Schrems II judgment
Transatlantic data flows following the Schrems II judgment
 
Cours CyberSécurité - Privacy
Cours CyberSécurité - PrivacyCours CyberSécurité - Privacy
Cours CyberSécurité - Privacy
 
VIAF GDPR
VIAF GDPRVIAF GDPR
VIAF GDPR
 
Communications data retention in an evolving Internet
Communications data retention in an evolving InternetCommunications data retention in an evolving Internet
Communications data retention in an evolving Internet
 
1º Palestra sobre Proteção de Dados Pessoais
1º Palestra sobre Proteção de Dados Pessoais1º Palestra sobre Proteção de Dados Pessoais
1º Palestra sobre Proteção de Dados Pessoais
 
International privacy with kevin haley
International privacy with kevin haleyInternational privacy with kevin haley
International privacy with kevin haley
 
Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16Martha Buyer V SCTC day conference 24 feb16
Martha Buyer V SCTC day conference 24 feb16
 
Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16Patricia Ayojedi V SCTC day Cloud 24 feb16
Patricia Ayojedi V SCTC day Cloud 24 feb16
 
Financial services club, 17 january 2018
Financial services club, 17 january 2018Financial services club, 17 january 2018
Financial services club, 17 january 2018
 
Cross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy ShieldCross Border Data Transfers and the Privacy Shield
Cross Border Data Transfers and the Privacy Shield
 
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
The EU Data Protection Reform's Impact on Cross Border e-Discovery: new Devel...
 
Uia presentation Eng
Uia presentation EngUia presentation Eng
Uia presentation Eng
 

Similar to The GDPR: What About Data Stored or Transmitted Outside the EU?

Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Constantine Karbaliotis
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
VYTIS MALECKAS
 

Similar to The GDPR: What About Data Stored or Transmitted Outside the EU? (20)

Data transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPRData transfers to countries outside the EU/EEA under the GDPR
Data transfers to countries outside the EU/EEA under the GDPR
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")The General Data Protection Regulation ("GDPR")
The General Data Protection Regulation ("GDPR")
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
Revising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPRRevising policies and procedures under the new EU GDPR
Revising policies and procedures under the new EU GDPR
 
EU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketingEU GDPR and you: requirements for marketing
EU GDPR and you: requirements for marketing
 
Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214Francoise Gilbert Proposed EU Data Protection Regulation-20120214
Francoise Gilbert Proposed EU Data Protection Regulation-20120214
 
Safe Harbor Webinar
Safe Harbor WebinarSafe Harbor Webinar
Safe Harbor Webinar
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?EY General Data Protection Regulation: Are you ready?
EY General Data Protection Regulation: Are you ready?
 
Members evening - data protection
Members evening - data protectionMembers evening - data protection
Members evening - data protection
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
CIO Summit talk: EU GDPR
CIO Summit talk: EU GDPRCIO Summit talk: EU GDPR
CIO Summit talk: EU GDPR
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 Introduction to EU General Data Protection Regulation: Planning, Implementat... Introduction to EU General Data Protection Regulation: Planning, Implementat...
Introduction to EU General Data Protection Regulation: Planning, Implementat...
 
EU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection ChangesEU Trade Secrets Directive & Data Protection Changes
EU Trade Secrets Directive & Data Protection Changes
 

Recently uploaded

一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
ss
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
mefyqyn
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
Airst S
 
Sanctions and types of Sanctions in Ibnternational law along with its scope a...
Sanctions and types of Sanctions in Ibnternational law along with its scope a...Sanctions and types of Sanctions in Ibnternational law along with its scope a...
Sanctions and types of Sanctions in Ibnternational law along with its scope a...
uttamuditi
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
F La
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
e9733fc35af6
 

Recently uploaded (20)

一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
 
Assignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpcAssignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpc
 
Skill Development in Law, Para Legal & other Fields and Export of Trained Man...
Skill Development in Law, Para Legal & other Fields and Export of Trained Man...Skill Development in Law, Para Legal & other Fields and Export of Trained Man...
Skill Development in Law, Para Legal & other Fields and Export of Trained Man...
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?Who is Spencer McDaniel? And Does He Actually Exist?
Who is Spencer McDaniel? And Does He Actually Exist?
 
Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理一比一原版赫尔大学毕业证如何办理
一比一原版赫尔大学毕业证如何办理
 
Common Legal Risks in Hiring and Firing Practices.pdf
Common Legal Risks in Hiring and Firing Practices.pdfCommon Legal Risks in Hiring and Firing Practices.pdf
Common Legal Risks in Hiring and Firing Practices.pdf
 
Jim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docxJim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docx
 
Sanctions and types of Sanctions in Ibnternational law along with its scope a...
Sanctions and types of Sanctions in Ibnternational law along with its scope a...Sanctions and types of Sanctions in Ibnternational law along with its scope a...
Sanctions and types of Sanctions in Ibnternational law along with its scope a...
 
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdfposts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
 
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
一比一原版(Monash毕业证书)澳洲莫纳什大学毕业证如何办理
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
Petitioner Moot Memorial including Charges and Argument Advanced.docx
Petitioner Moot Memorial including Charges and Argument Advanced.docxPetitioner Moot Memorial including Charges and Argument Advanced.docx
Petitioner Moot Memorial including Charges and Argument Advanced.docx
 
Career As Legal Reporters for Law Students
Career As Legal Reporters for Law StudentsCareer As Legal Reporters for Law Students
Career As Legal Reporters for Law Students
 
Mischief Rule of Interpretation of statutes
Mischief Rule of Interpretation of statutesMischief Rule of Interpretation of statutes
Mischief Rule of Interpretation of statutes
 

The GDPR: What About Data Stored or Transmitted Outside the EU?

  • 1. GDPR Transfer of personal data outside the European Economic Area Rutger Ketting
  • 2. Introduction 1. Introduction 2. Adequacy decisions 3. Transfer mechanisms 4. Derogation of specific situations 5. EU – US Privacy Shield
  • 3. Adequacy decisions • Decision of the European Commission that third country ensures adequate level of protection of personal data. • General approval, no specific authorisation required for individual transfers. • Adequacy decisions for (https://ec.europa.eu/info/strategy/justice-and-fundamental- rights/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non- eu-countries_en): – Andorra – Argentina – Canada – Faroer Islands – Guernsey – Israel – Isle of Man – Jersey – New Zealand – Switzerland – Uruguay and the US (limited to the Privacy Shield framework) • Adequacy talks are ongoing with Japan and South Korea. • Decisions do not cover exchange of data in law enforcement sector. 3
  • 4. Transfer mechanisms 4 Existing mechanisms 1. Standard contractual clauses 2. Binding corporate rules New mechanisms 1. Standard contractual clauses certified by national DPA 2. Approved code of conduct 3. Approved certification mechanism
  • 5. Standard contractual clauses • Adopted by the EU Commission or adopted by the supervisory authority and approved by the EU Commission. • SCC adopted by the Commision under the Data Protection Directive (95/46/EC) remain valid until amended/replaced/repealed. • SCC currently available (https://ec.europa.eu/info/strategy/justice-and- fundamental-rights/data-protection/data-transfers-outside-eu/model-contracts- transfer-personal-data-third-countries_en ) – EU controller to non-EU or EEA controller • decision 2001/497/EC • decision 2004/915/EC – EU controller to non-EU or EEA processor • decision 2010/87/EU 5
  • 6. Binding corporate rules • International rules for data transfers within multinational companies. i.e. internal code of conduct. • Binding corporatie rules must: – contain privacy principles (e.g. transparancy, data quality, security) – contain tools of effectiveness (audit, training, compliancy systems) – be binding and enforced by every member of the group of undertakings concerned – Expressly confer enforceable rights on data subjects – Meet requirements set out in working papers adopted by WP 29 (WP 153) • Article 47 (2) GDPR contains minimum requirements • Binding corporate rules must be approved by competent supervisory authority 6
  • 7. Binding corporate rules • Approximately 90 corporations with BCR’s: 7
  • 8. Codes of conduct • Associations and other bodies representing categories of controllers or processors may prepare codes of conduct. • Approval by competent supervisory authority is required. • Controllers/processors in third countries must make binding and enforceable commitments via contractual or other legally binding instruments to provide for the appropriate safeguards required by the code of conduct including the safeguards with regard to the rights of data subjects. 8
  • 9. Certification • Certification by certification bodies that are accredited by the competent supervisory authority or the national accreditation body pursuant to regulation No 765/2008). • Certification shall be voluntary. • Controllers/processors in third countries must make binding and enforceable commitments via contractual or other legally binding instruments to provide for the appropriate safeguards required for the certification including the safeguards with regard to the rights of data subjects. 9
  • 10. Derogation for specific situations – Explicit consent: Data subject has provided explicit consent after having been informed of possible risks of transfer due to absence of adequacy decision/appropriate safeguards (not applicable for public authorities in the exercise of their public powers); or – Necessity: The transfer is necessary for: • the performance of a contract between the data subject and the controller or for the implementation of precontractual measures at the data subject’s request (not applicable for public authorities in the exercise of their public powers); or • the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another legal or natural person. (not applicable for public authorities in the exercise of their public powers); or • important reasons of public interest recognised by Union Law or member state law to which the controller is subject. Law must set limits to transfer; or • Establishment, excersise or defence of legal claims; or – Vital interest: The transfer is necessary in order to protect the vital interrest of the data subject or other persons, where the data subject is physically or legally incapable of giving consent; or – Public registers: The transfer is made from a register which according to Union or member state law is intended to provide information to the public. 10
  • 11. Derogation for specific situations – Extra exception (NEW under GDPR) Requirements: • The transfer is non-repetitive; and • Concerns a limited number of data subjects; and • And is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests and rights and freedoms of the data subject; and • The controller has assessed all circumstances surrounding the transfer and has provided suitable safeguards with regard to the protection of data. • When this exception is used, the controller shall inform the supervisory authority of the transfer and shall inform the data subject of the legitimate compelling interests pursued. 11
  • 12. US-EU Privacy Shield Framework • Adopted 12 July 2016, Effective 1 August 2016 • Agreement between EU and US. – Only applies to US Companies that have registered to by on the privacy shield list (https://www.privacyshield.gov/list ). – Registration requires self-certification that company meets the high data protection standards set out by the arrangement. Registration must be renewed every year. – strong data protection obligations on companies receiving personal data from the EU. – Enforcement by US Department of Commerce and the Federal Trade Commission (FTC). – Increased cooperation with the European Data Protection Authorities. – safeguards on US government access to data. – effective protection and redress for individuals. – an annual joint review by EU and US to monitor the correct application of the arrangement. • Replaces Safe Harbor Principles (declared invalid by European Court of Justice decision of 6 October 2015). • Challenges pending (first challenge dismissed on procedural grounds in November 2017). 12
  • 13. Contact details 13 Company details Nysingh advocaten – notarissen N.V. Phone: 0031 38 425 92 00 Website: www.nysingh.nl Personal details Rutger Ketting Mobile: 0031 6 306 48 127 Email: R.Ketting@nysingh.nl