← All CDPSE Flashcard Decks

Cross-Border Data Transfers Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Cross-Border Data Transfers flashcards as text
  1. What did the Court of Justice of the EU (CJEU) determine in the Schrems II ruling regarding Privacy Shield?

    Answer: Privacy Shield was invalidated due to inadequate US surveillance law protections

    The CJEU invalidated Privacy Shield in 2020 because US surveillance laws did not provide EU residents with effective remedies equivalent to EU rights.

  2. When using SCCs for a data transfer, what additional step may be required following the Schrems II ruling?

    Answer: Conducting a Transfer Impact Assessment to verify the SCCs remain effective

    Post-Schrems II, organizations must conduct a TIA to determine whether local laws in the destination country could nullify SCC protections in practice.

  3. Which derogation under GDPR Article 49 permits a cross-border data transfer without an adequacy decision or appropriate safeguards?

    Answer: Vital interests of the data subject

    Article 49 allows transfers where necessary to protect the vital interests of the data subject or another person when the data subject cannot give consent, among other limited derogations.

  4. A cloud vendor stores EU customer data on US servers. Which document MUST exist to make this transfer lawful under GDPR?

    Answer: A valid data transfer mechanism such as SCCs incorporated in the Data Processing Agreement

    A valid transfer mechanism—most commonly SCCs incorporated into a DPA—is legally required for any transfer of EU personal data to a country lacking an adequacy decision.

  5. What is the role of supplementary measures in cross-border data transfers under SCCs?

    Answer: To provide additional technical or contractual protections when the destination country's laws may undermine SCC guarantees

    Supplementary measures—such as encryption, pseudonymization, or additional contractual commitments—strengthen SCC protections where destination country laws pose elevated risks.

  6. Which US state privacy law includes provisions specifically addressing cross-border data transfers and requires data transfer impact assessments?

    Answer: Colorado Privacy Act (CPA)

    The Colorado Privacy Act requires controllers to conduct and document data protection assessments for processing that presents a heightened risk, including cross-border transfers.