CDPSE Cross-Border Data Transfers 1 — Questions and Answers
Question 1: Under GDPR, which mechanism allows a US company to legally receive personal data from the EU without an adequacy decision?
- Privacy Shield
- Standard Contractual Clauses (SCCs) (Correct answer)
- Safe Harbor Agreement
- APEC CBPR
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses are EU-approved contractual templates that provide a valid transfer mechanism after Privacy Shield was invalidated by Schrems II.
Question 2: What is the primary purpose of an adequacy decision issued by the European Commission?
- To certify a company's internal privacy program
- To recognize that a third country provides a comparable level of data protection to the EU (Correct answer)
- To authorize cross-border data sharing between two companies
- To replace the need for Data Processing Agreements
Correct answer: To recognize that a third country provides a comparable level of data protection to the EU
An adequacy decision means the EU has determined that a non-EU country's laws offer protection equivalent to EU standards, permitting free data flows to that country.
Question 3: Binding Corporate Rules (BCRs) are MOST appropriate for which scenario?
- Data transfers between unrelated businesses in different countries
- Intra-group data transfers among entities within a multinational corporation (Correct answer)
- Data transfers to government agencies in non-adequate countries
- Transfers of anonymized research data to universities
Correct answer: Intra-group data transfers among entities within a multinational corporation
BCRs are approved internal data protection policies that allow multinational groups to transfer personal data among their own affiliated entities across borders.
Question 4: Which US framework was created to facilitate commercial data transfers with the EU following Schrems II?
- CCPA Privacy Certification
- EU-US Data Privacy Framework (Correct answer)
- APEC CBPR System
- NIST Privacy Framework
Correct answer: EU-US Data Privacy Framework
The EU-US Data Privacy Framework (2023) replaced Privacy Shield as the mechanism enabling US organizations to receive EU personal data after self-certification.
Question 5: A CDPSE professional must conduct a Transfer Impact Assessment (TIA). What is the main purpose of this assessment?
- To calculate the financial cost of international data transfers
- To evaluate whether the legal protections in the destination country adequately protect transferred data (Correct answer)
- To determine the bandwidth requirements for the data transfer
- To obtain board approval for international operations
Correct answer: To evaluate whether the legal protections in the destination country adequately protect transferred data
A TIA assesses whether the destination country's laws or practices could undermine the protections provided by the transfer mechanism, such as SCCs.
Question 6: Which international framework provides a cross-border privacy rules system primarily for APEC member economies?
- GDPR
- APEC Cross-Border Privacy Rules (CBPR) (Correct answer)
- Convention 108+
- OECD Privacy Guidelines
Correct answer: APEC Cross-Border Privacy Rules (CBPR)
The APEC CBPR system is a voluntary accountability-based mechanism that allows certified organizations to transfer data among participating APEC economies.
Under GDPR, which mechanism allows a US company to legally receive personal data from the EU without an adequacy decision?