Cross-Border Data Transfers Flashcards
6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cross-Border Data Transfers flashcards as text
Under GDPR, which mechanism allows a US company to legally receive personal data from the EU without an adequacy decision?
Answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses are EU-approved contractual templates that provide a valid transfer mechanism after Privacy Shield was invalidated by Schrems II.
What is the primary purpose of an adequacy decision issued by the European Commission?
Answer: To recognize that a third country provides a comparable level of data protection to the EU
An adequacy decision means the EU has determined that a non-EU country's laws offer protection equivalent to EU standards, permitting free data flows to that country.
Binding Corporate Rules (BCRs) are MOST appropriate for which scenario?
Answer: Intra-group data transfers among entities within a multinational corporation
BCRs are approved internal data protection policies that allow multinational groups to transfer personal data among their own affiliated entities across borders.
Which US framework was created to facilitate commercial data transfers with the EU following Schrems II?
Answer: EU-US Data Privacy Framework
The EU-US Data Privacy Framework (2023) replaced Privacy Shield as the mechanism enabling US organizations to receive EU personal data after self-certification.
A CDPSE professional must conduct a Transfer Impact Assessment (TIA). What is the main purpose of this assessment?
Answer: To evaluate whether the legal protections in the destination country adequately protect transferred data
A TIA assesses whether the destination country's laws or practices could undermine the protections provided by the transfer mechanism, such as SCCs.
Which international framework provides a cross-border privacy rules system primarily for APEC member economies?
Answer: APEC Cross-Border Privacy Rules (CBPR)
The APEC CBPR system is a voluntary accountability-based mechanism that allows certified organizations to transfer data among participating APEC economies.