โ† All CDPSE Flashcard Decks

Cross-Border Data Transfers Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cross-Border Data Transfers flashcards as text
  1. Which body must approve Binding Corporate Rules submitted by EU-based multinational organizations?

    Answer: The competent national Data Protection Authority and the European Data Protection Board

    BCRs must be approved by the lead supervisory authority in cooperation with the EDPB under the consistency mechanism established by GDPR.

  2. What is the key distinction between a data processor and a data controller in a cross-border transfer scenario?

    Answer: The controller determines the purpose and means of processing; the processor acts on the controller's instructions

    The controller decides why and how data is processed and bears primary accountability for ensuring transfers are lawful; processors act under contractual instructions from the controller.

  3. Under HIPAA, when a US healthcare provider shares protected health information (PHI) with a foreign business associate, what document is required?

    Answer: Business Associate Agreement (BAA)

    HIPAA requires a Business Associate Agreement with any entity that processes PHI on behalf of a covered entity, regardless of whether the associate is domestic or foreign.

  4. What is the main privacy concern with 'data localization' laws enacted by certain countries?

    Answer: They may fragment the internet and create compliance conflicts for multinational organizations operating under multiple jurisdictions

    Data localization laws requiring that data remain within national borders create jurisdictional conflicts and compliance challenges for multinationals subject to the laws of multiple countries.

  5. Which of the following is a key requirement for an organization to self-certify under the EU-US Data Privacy Framework?

    Answer: Committing to the DPF principles and registering with the US Department of Commerce

    Organizations participate in the EU-US DPF by self-certifying their adherence to the DPF Principles through the US Department of Commerce and renewing annually.

  6. A multinational company conducts a Transfer Impact Assessment and finds that the destination country has broad government surveillance laws. What is the MOST appropriate next step?

    Answer: Implement supplementary technical measures such as end-to-end encryption before transferring

    When surveillance laws threaten the effectiveness of SCCs, supplementary measures like robust encryption ensure the data remains protected even if intercepted by government authorities.