SlideShare a Scribd company logo
1
1
© 2021 TrustArc Inc. Proprietary and Confidential Information.
International Data Transfer Update
18 August 2021
2
2
Thank You for Joining “International Data Transfer Update”
● We will be starting a couple minutes after the hour
● This webinar will be recorded and the recording and slides sent out later today
● Please use the GoToWebinar control panel on the right hand side to submit any
questions for the speakers
3
3
Speaker
Paul Breitbarth
Director, EU Policy & Strategy
TrustArc
4
4
Agenda
● EU Data Transfer Enforcement Update
● EU Standard Contractual Clauses and Transfer Risk Assessment (reminder)
● UK International Data Transfer Agreements and Transfer Risk Assessment
● Other International Data Transfer Mechanisms
● Q&A
5
5
EU Data Transfer
Enforcement Update
6
6
EU Data Transfer Enforcement Update
● The operator transferred over 12.5 million images of license plate data to a data processor with employees in
China without having a data processing agreement in place, a basis for transferring the personal data to a
country without adequate protection (no exceptions applied to the processing), or conducting a risk assessment
to determine the risk of processing or whether further security measures are warranted
● The Norwegian DPA announced the intention to fine the company 5 mln NOK (~ €500.000) A final decision will
be made following the submission of further comments by the operator.
● Aggravating factors:
○ the volume of processing;
○ the violations constitute a breach of the basic requirements of the GDPR;
○ the duration of the infringement; and
○ negligence to transfer personal data without a processing agreement or basis for transfer to China
Norway Toll Road Operator
7
7
EU Data Transfer Enforcement Update
● The Hamburg DPA issued an official warning to the Office of the Senate (Senatskanzlei) for using an on-demand
option in online communication platform Zoom, possibly for webinars or other online meetings with postponed
viewing options. Only press release available.
● The investigation showed that the Hamburg authorities have not met the threshold for EU-U.S. data transfers as
explained in the recent EDPB guidance. The DPA also criticizes the lack of cooperation of the authorities with the
investigation.
● “A data transfer to the U.S. is only possible under very strict conditions, that are not met by the planned use of
Zoom by the Hamburg authorities. The personal data of Senate staff and external partners would risk to be
subject to unwarranted government surveillance in the US, against which no redress mechanisms exist”.
● Consent or other exemptions ruled out as valid option for transfer in this situation.
● Very strict interpretation of the guidance by the Hamburg DPA.
Use of Zoom by Hamburg Public Authorities
8
8
Post Schrems-II Enforcement
● DPAs focus so far on data transfers to the United States and China based on SCCs. The
main checks seem to be:
○ What kind of personal data is transferred to a third country, with a focus on
special categories of personal data;
○ If a data transfer risk assessment has been completed; and
○ If, when using a contractual safeguard, supplementary measures have been
considered and put in place.
● Other forms of enforcement action cannot be ruled
out. Investigations may be ongoing without having
been announced.
Observations on Enforcement to Date
9
9
EU Standard Contractual Clauses and
Transfer Risk Assessment (reminder)
10
10
EU SCCs and Transfer Risk Assessment
Section I
● Clause 1 - Purpose and scope
● Clause 2 – Effect and invariability of the Clauses
● Clause 3 – Third-party beneficiaries
● Clause 4 - Interpretation
● Clause 5 - Hierarchy
● Clause 6 - Description of the Transfer
● Clause 7 - Docking Clause
Section II - Obligations of the Parties
● Clause 8 - Data Protection Safeguards
○ Module 1: C-C
○ Module 2: C-P
○ Module 3: P-P
○ Module 4: P-C
● Clause 9 – Use of sub-processors
● Clause 10 – Data subject rights
● Clause 11 – Redress
● Clause 12 - Liability
● Clause 13 - Supervision
11
11
EU SCCs and Transfer Risk Assessment
Section III – Local laws and obligations in case of access
by public authorities
● Clause 14 - Local Laws Affecting Compliance
with the Clauses
● Clause 15 – Obligations of the importer in case of
access by public authorities
Section IV - Final Provisions
● Clause 16 - Non-compliance
● Clause 17 - Governing Law
● Clause 18 - Choice of Forum and Jurisdiction
●
Appendix
Annex I
A. List of Parties
B. Description of Transfer
C. Competent Supervisory Authority
Annex II - Technical and Organisational Measures
Annex III - List of Sub-processors
12
12
EU SCCs and Transfer Risk Assessment
Scope of application
Art. 3(2) GDPR applicable
Offering goods/services
Monitoring behaviour
↓
Full GDPR applies
(Includes art. 32 - Security)
Art. 3(2) GDPR applicable
Offering goods/services
Monitoring behaviour
↓
No transfer options but
adequacy
No direct GDPR application
↓
Chapter V GDPR applies
Transfer Mechanism needed
(§7) The standard contractual clauses may be used for such transfers only to the extent that the
processing by the importer does not fall within the scope of [the GDPR]. This also includes the
transfer of personal data by a controller or processor not established in the Union, to the extent that
the processing is subject to [the GDPR] (pursuant to Article 3(2) thereof), because it relates to the
offering of goods or services to data subjects in the Union or the monitoring of their behaviour as far as
it takes place within the Union.
13
13
EU SCCs and Transfer Risk Assessment
27 June 2021
The new SCCs entered into
force and can be used
Until 27 September 2021
The old SCCs may still be
used in new contracts
27 December 2022
The old SCCs will lose their
validity - contracts need
to be updated.
14
14
EU SCCs and Transfer Risk Assessment
Know your transfers
Reassess all data processing
operations on a
case-by-case basis
Identify the transfer tools
you are relying on
“Appropriate Safeguards”?
Assess which instrument is
most effective in light of all
circumstances of the
transfer
1 2 3
Adopt Supplementary
Measures
Obtain DPA Approval
If the transfer mechanism
requires you to do so
BCRs, ad hoc clauses, etc.
Review and Update
Like all accountability
measures, regular reviews
and updates are needed
4 5 6
Assess the legislation in, and international commitments of, the third country where the data are flowing to
15
15
https://trustarc.com/international-data-transfers/
16
16
Public Resources
17
17
UK International Data Transfer Agreements
and Transfer Risk Assessment
18
18
UK IDTA and Transfer Risk Assessment
Part I - Tables
● Table 1: Parties and signatures
● Table 2: Transfer Details
○ Governing law
○ Controller/Processor
○ Linked Agreement(s)
○ Onward Transfer Allowance
● Table 3: Transferred Data
● Table 4: Security Requirements
Part II - Extra Protection Clauses
● Technical Security Protections
● Organisational Protections
● Contractual Protections
Part III - Commercial Clauses
● Optional
Part IV - Mandatory Clauses
● Appropriate Safeguards
● Mandatory Review (at least annual)
● Exporter and Importer Obligations
● Onward Transfers
● Individual Rights
● Third Party Access (Government Access)
● Data Breaches
● Oversight & Redress
● Glossary
ICO Consultation
19
19
UK IDTA and Transfer Risk Assessment
ICO Consultation
Assessing the Transfer
Is there a restricted transfer
that is not of high risk to
individuals?
Can the IDTA likely
be enforced?
If not, can additional
safeguards help?
Appropriate Protection
from 3rd Party Access?
Transfer can continue if no
or low risk of harm to
individuals.
1 2 3
The UK Transfer Risk Assessment Tool
To be used for routine transfers only. More complex
transfers require a more detailed risk assessment
Restricted Transfer: only when the UK GDPR applies to a
processing operation, and data is sent to, or accessed from,
a non-adequate country, and the importer is a separate
company or individual. A UK processor sending data back to
a non-UK controller is NOT a restricted transfer.
Low Risk of Harm: there is more than a minimal risk of the
relevant event occurring which may infringe data subject
rights and even if that relevant event does happen, the
impact on data subjects would not cause them significant
harm.
20
20
UK IDTA and Transfer Risk Assessment
● ICO considering to also allow for Addenda to other approved model data transfer agreements as
“appropriate safeguard” under art. 46 UK GDPR.
○ European Union (SCCs)
○ New Zealand
○ ASEAN (Association of Southeast Asian Nations)
● Draft Addendum for use with EU SCCs part of the consultation process
○ Language of the EU SCCs is “deemed to be amended to the extent necessary” to meet the UK
requirements.
■ E.g. references to the EU are changed to the UK
○ Not required for EU-UK data transfers (because of adequacy)
● Helpful option (?) for contracts dealing with multiple global jurisdictions.
ICO Consultation
Consultation until 7 October 2021, 5pm BST
21
21
Other International Data
Transfer Mechanisms
22
22
Other International Data Transfer Mechanisms
● Abu Dhabi Global Market Office of Data Protection adopted SCCs on 11 August 2021
○ Based on the ADGM 2021 Data Protection Regulations
○ Align closely with recently updated EU SCCs
○ Contracts need to be updated by 14 February 2022
● Other jurisdictions which have model clauses in force include:
○ New Zealand
○ Dubai International Financial Market
○ ASEAN
● Over 100 countries have data transfer restrictions in place, but not all have (yet) developed model
clauses.
23
23
Q&A
24
24
Thank You!
See http://www.trustarc.com/insightseries for the
2021 Privacy Insight Series and past webinar
recordings.
If you would like to learn more about how TrustArc can support you with
compliance, please reach out to sales@trustarc.com for a free demo.

More Related Content

What's hot

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
Qualsys Ltd
 
GDPR
GDPRGDPR
GDPR
Gopi PD
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
Priyanka Aash
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
WilmerHale
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
Caroline Boscher
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
Sudarsan Reddy
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
Jean Luc Creppy
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
Jane Lambert
 
GDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdfGDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdf
Andrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
PECB
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
The Pathway Group
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection ActSaimaRafiq
 
Data protection
Data protectionData protection
Data protection
RaviPrashant5
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
SPIN Chennai
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
Tushar Rajput
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
DipanjanDey12
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
Cvent
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
Priyab Satoshi
 
Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy Introduction
G Prachi
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
RahulGarg294918
 

What's hot (20)

GDPR: Training Materials by Qualsys
GDPR: Training Materials  by QualsysGDPR: Training Materials  by Qualsys
GDPR: Training Materials by Qualsys
 
GDPR
GDPRGDPR
GDPR
 
Gdpr overview ciso platform presentation
Gdpr overview ciso platform presentationGdpr overview ciso platform presentation
Gdpr overview ciso platform presentation
 
Privacy and Data Security
Privacy and Data SecurityPrivacy and Data Security
Privacy and Data Security
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Gdpr presentation
Gdpr presentationGdpr presentation
Gdpr presentation
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
GDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdfGDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdf
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
The Data Protection Act
The Data Protection ActThe Data Protection Act
The Data Protection Act
 
Data protection
Data protectionData protection
Data protection
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
Introduction to GDPR
Introduction to GDPRIntroduction to GDPR
Introduction to GDPR
 
Data Privacy Introduction
Data Privacy IntroductionData Privacy Introduction
Data Privacy Introduction
 
skillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptxskillcast-gdpr-training-presentation-q320.pptx
skillcast-gdpr-training-presentation-q320.pptx
 

Similar to International Data Transfer Update

EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
TrustArc
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand
TrustArc
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
TrustArc
 
Brexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveBrexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK Perspective
TrustArc
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
TrustArc
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015Jan Dhont
 
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
NETWAYS
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
TrustArc
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement action
TrustArc
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
IT Governance Ltd
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013IgorMate
 
Recent eu data_initiatives_in_context_infographic
Recent eu data_initiatives_in_context_infographicRecent eu data_initiatives_in_context_infographic
Recent eu data_initiatives_in_context_infographic
marino54
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreements
Tommy Vandepitte
 
20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements
Brussels Legal Hackers
 
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc
 
EU regulatory agenda 2018 2019
EU regulatory agenda 2018 2019EU regulatory agenda 2018 2019
EU regulatory agenda 2018 2019
Roger Coenen
 
Case by case - moving data centres to Romania
Case by case - moving data centres to RomaniaCase by case - moving data centres to Romania
Case by case - moving data centres to Romania
Țuca Zbârcea & Asociații
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
nuances
 
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security PrinciplesLisa Catanzaro
 
The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?
TAG Alliances
 

Similar to International Data Transfer Update (20)

EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
EU Update: Applying the new SCCs, or ‘just’ the complete GDPR?
 
The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand The Conversation Continues: Where International Data Transfers Stand
The Conversation Continues: Where International Data Transfers Stand
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
Brexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK PerspectiveBrexit Data Protection Update: The EU, US and UK Perspective
Brexit Data Protection Update: The EU, US and UK Perspective
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
2015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 050520152015-0318 GAC Presentation - BCR - 05052015
2015-0318 GAC Presentation - BCR - 05052015
 
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
OSDC 2012 | Data Protection, Software Licences and other Legal Issues in the ...
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
LGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement actionLGPD is Here: What to know to understand compliance and enforcement action
LGPD is Here: What to know to understand compliance and enforcement action
 
GDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud ProvidersGDPR: Requirements for Cloud Providers
GDPR: Requirements for Cloud Providers
 
Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013Cloud computing in Hungarian financial industry 2013
Cloud computing in Hungarian financial industry 2013
 
Recent eu data_initiatives_in_context_infographic
Recent eu data_initiatives_in_context_infographicRecent eu data_initiatives_in_context_infographic
Recent eu data_initiatives_in_context_infographic
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreements
 
20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements20180619 Controller-to-Processor agreements
20180619 Controller-to-Processor agreements
 
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR ReformsTrustArc Webinar: UK's Post-Brexit GDPR Reforms
TrustArc Webinar: UK's Post-Brexit GDPR Reforms
 
EU regulatory agenda 2018 2019
EU regulatory agenda 2018 2019EU regulatory agenda 2018 2019
EU regulatory agenda 2018 2019
 
Case by case - moving data centres to Romania
Case by case - moving data centres to RomaniaCase by case - moving data centres to Romania
Case by case - moving data centres to Romania
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
20150630_D6 1_Legal and EthicalFrameworkand Privacy and Security Principles
 
The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?The GDPR: What About Data Stored or Transmitted Outside the EU?
The GDPR: What About Data Stored or Transmitted Outside the EU?
 

More from TrustArc

TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
TrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
TrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
TrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
TrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
TrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
TrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
TrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
TrustArc
 

More from TrustArc (20)

TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 

Recently uploaded

Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
g2nightmarescribd
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
Product School
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
Cheryl Hung
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Product School
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
Product School
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Jeffrey Haguewood
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
RTTS
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
DianaGray10
 

Recently uploaded (20)

Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
Slack (or Teams) Automation for Bonterra Impact Management (fka Social Soluti...
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4UiPath Test Automation using UiPath Test Suite series, part 4
UiPath Test Automation using UiPath Test Suite series, part 4
 

International Data Transfer Update

  • 1. 1 1 © 2021 TrustArc Inc. Proprietary and Confidential Information. International Data Transfer Update 18 August 2021
  • 2. 2 2 Thank You for Joining “International Data Transfer Update” ● We will be starting a couple minutes after the hour ● This webinar will be recorded and the recording and slides sent out later today ● Please use the GoToWebinar control panel on the right hand side to submit any questions for the speakers
  • 3. 3 3 Speaker Paul Breitbarth Director, EU Policy & Strategy TrustArc
  • 4. 4 4 Agenda ● EU Data Transfer Enforcement Update ● EU Standard Contractual Clauses and Transfer Risk Assessment (reminder) ● UK International Data Transfer Agreements and Transfer Risk Assessment ● Other International Data Transfer Mechanisms ● Q&A
  • 6. 6 6 EU Data Transfer Enforcement Update ● The operator transferred over 12.5 million images of license plate data to a data processor with employees in China without having a data processing agreement in place, a basis for transferring the personal data to a country without adequate protection (no exceptions applied to the processing), or conducting a risk assessment to determine the risk of processing or whether further security measures are warranted ● The Norwegian DPA announced the intention to fine the company 5 mln NOK (~ €500.000) A final decision will be made following the submission of further comments by the operator. ● Aggravating factors: ○ the volume of processing; ○ the violations constitute a breach of the basic requirements of the GDPR; ○ the duration of the infringement; and ○ negligence to transfer personal data without a processing agreement or basis for transfer to China Norway Toll Road Operator
  • 7. 7 7 EU Data Transfer Enforcement Update ● The Hamburg DPA issued an official warning to the Office of the Senate (Senatskanzlei) for using an on-demand option in online communication platform Zoom, possibly for webinars or other online meetings with postponed viewing options. Only press release available. ● The investigation showed that the Hamburg authorities have not met the threshold for EU-U.S. data transfers as explained in the recent EDPB guidance. The DPA also criticizes the lack of cooperation of the authorities with the investigation. ● “A data transfer to the U.S. is only possible under very strict conditions, that are not met by the planned use of Zoom by the Hamburg authorities. The personal data of Senate staff and external partners would risk to be subject to unwarranted government surveillance in the US, against which no redress mechanisms exist”. ● Consent or other exemptions ruled out as valid option for transfer in this situation. ● Very strict interpretation of the guidance by the Hamburg DPA. Use of Zoom by Hamburg Public Authorities
  • 8. 8 8 Post Schrems-II Enforcement ● DPAs focus so far on data transfers to the United States and China based on SCCs. The main checks seem to be: ○ What kind of personal data is transferred to a third country, with a focus on special categories of personal data; ○ If a data transfer risk assessment has been completed; and ○ If, when using a contractual safeguard, supplementary measures have been considered and put in place. ● Other forms of enforcement action cannot be ruled out. Investigations may be ongoing without having been announced. Observations on Enforcement to Date
  • 9. 9 9 EU Standard Contractual Clauses and Transfer Risk Assessment (reminder)
  • 10. 10 10 EU SCCs and Transfer Risk Assessment Section I ● Clause 1 - Purpose and scope ● Clause 2 – Effect and invariability of the Clauses ● Clause 3 – Third-party beneficiaries ● Clause 4 - Interpretation ● Clause 5 - Hierarchy ● Clause 6 - Description of the Transfer ● Clause 7 - Docking Clause Section II - Obligations of the Parties ● Clause 8 - Data Protection Safeguards ○ Module 1: C-C ○ Module 2: C-P ○ Module 3: P-P ○ Module 4: P-C ● Clause 9 – Use of sub-processors ● Clause 10 – Data subject rights ● Clause 11 – Redress ● Clause 12 - Liability ● Clause 13 - Supervision
  • 11. 11 11 EU SCCs and Transfer Risk Assessment Section III – Local laws and obligations in case of access by public authorities ● Clause 14 - Local Laws Affecting Compliance with the Clauses ● Clause 15 – Obligations of the importer in case of access by public authorities Section IV - Final Provisions ● Clause 16 - Non-compliance ● Clause 17 - Governing Law ● Clause 18 - Choice of Forum and Jurisdiction ● Appendix Annex I A. List of Parties B. Description of Transfer C. Competent Supervisory Authority Annex II - Technical and Organisational Measures Annex III - List of Sub-processors
  • 12. 12 12 EU SCCs and Transfer Risk Assessment Scope of application Art. 3(2) GDPR applicable Offering goods/services Monitoring behaviour ↓ Full GDPR applies (Includes art. 32 - Security) Art. 3(2) GDPR applicable Offering goods/services Monitoring behaviour ↓ No transfer options but adequacy No direct GDPR application ↓ Chapter V GDPR applies Transfer Mechanism needed (§7) The standard contractual clauses may be used for such transfers only to the extent that the processing by the importer does not fall within the scope of [the GDPR]. This also includes the transfer of personal data by a controller or processor not established in the Union, to the extent that the processing is subject to [the GDPR] (pursuant to Article 3(2) thereof), because it relates to the offering of goods or services to data subjects in the Union or the monitoring of their behaviour as far as it takes place within the Union.
  • 13. 13 13 EU SCCs and Transfer Risk Assessment 27 June 2021 The new SCCs entered into force and can be used Until 27 September 2021 The old SCCs may still be used in new contracts 27 December 2022 The old SCCs will lose their validity - contracts need to be updated.
  • 14. 14 14 EU SCCs and Transfer Risk Assessment Know your transfers Reassess all data processing operations on a case-by-case basis Identify the transfer tools you are relying on “Appropriate Safeguards”? Assess which instrument is most effective in light of all circumstances of the transfer 1 2 3 Adopt Supplementary Measures Obtain DPA Approval If the transfer mechanism requires you to do so BCRs, ad hoc clauses, etc. Review and Update Like all accountability measures, regular reviews and updates are needed 4 5 6 Assess the legislation in, and international commitments of, the third country where the data are flowing to
  • 17. 17 17 UK International Data Transfer Agreements and Transfer Risk Assessment
  • 18. 18 18 UK IDTA and Transfer Risk Assessment Part I - Tables ● Table 1: Parties and signatures ● Table 2: Transfer Details ○ Governing law ○ Controller/Processor ○ Linked Agreement(s) ○ Onward Transfer Allowance ● Table 3: Transferred Data ● Table 4: Security Requirements Part II - Extra Protection Clauses ● Technical Security Protections ● Organisational Protections ● Contractual Protections Part III - Commercial Clauses ● Optional Part IV - Mandatory Clauses ● Appropriate Safeguards ● Mandatory Review (at least annual) ● Exporter and Importer Obligations ● Onward Transfers ● Individual Rights ● Third Party Access (Government Access) ● Data Breaches ● Oversight & Redress ● Glossary ICO Consultation
  • 19. 19 19 UK IDTA and Transfer Risk Assessment ICO Consultation Assessing the Transfer Is there a restricted transfer that is not of high risk to individuals? Can the IDTA likely be enforced? If not, can additional safeguards help? Appropriate Protection from 3rd Party Access? Transfer can continue if no or low risk of harm to individuals. 1 2 3 The UK Transfer Risk Assessment Tool To be used for routine transfers only. More complex transfers require a more detailed risk assessment Restricted Transfer: only when the UK GDPR applies to a processing operation, and data is sent to, or accessed from, a non-adequate country, and the importer is a separate company or individual. A UK processor sending data back to a non-UK controller is NOT a restricted transfer. Low Risk of Harm: there is more than a minimal risk of the relevant event occurring which may infringe data subject rights and even if that relevant event does happen, the impact on data subjects would not cause them significant harm.
  • 20. 20 20 UK IDTA and Transfer Risk Assessment ● ICO considering to also allow for Addenda to other approved model data transfer agreements as “appropriate safeguard” under art. 46 UK GDPR. ○ European Union (SCCs) ○ New Zealand ○ ASEAN (Association of Southeast Asian Nations) ● Draft Addendum for use with EU SCCs part of the consultation process ○ Language of the EU SCCs is “deemed to be amended to the extent necessary” to meet the UK requirements. ■ E.g. references to the EU are changed to the UK ○ Not required for EU-UK data transfers (because of adequacy) ● Helpful option (?) for contracts dealing with multiple global jurisdictions. ICO Consultation Consultation until 7 October 2021, 5pm BST
  • 22. 22 22 Other International Data Transfer Mechanisms ● Abu Dhabi Global Market Office of Data Protection adopted SCCs on 11 August 2021 ○ Based on the ADGM 2021 Data Protection Regulations ○ Align closely with recently updated EU SCCs ○ Contracts need to be updated by 14 February 2022 ● Other jurisdictions which have model clauses in force include: ○ New Zealand ○ Dubai International Financial Market ○ ASEAN ● Over 100 countries have data transfer restrictions in place, but not all have (yet) developed model clauses.
  • 24. 24 24 Thank You! See http://www.trustarc.com/insightseries for the 2021 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.