← All PLC Flashcard Decks

Cross-Border Data Transfers & Compliance Flashcards

9 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 9 Cross-Border Data Transfers & Compliance flashcards as text
  1. What mechanism is commonly used under GDPR for lawful data transfers outside the EU?

    Answer: Standard Contractual Clauses

    Standard Contractual Clauses (SCCs) are pre-approved model clauses provided by the European Commission that organizations can use to legally transfer personal data from the EU/EEA to countries not deemed to offer adequate data protection. They impose contractual obligations on both the data exporter and importer to ensure appropriate safeguards for the transferred data. SCCs are a widely used mechanism to comply with GDPR's requirements for international data transfers.

  2. What did the Schrems II ruling invalidate?

    Answer: Privacy Shield

    The Schrems II ruling by the Court of Justice of the European Union (CJEU) invalidated the EU-U.S. Privacy Shield framework. The court found that the protections offered by the Privacy Shield for EU data subjects' data transferred to the U.S. were insufficient, particularly concerning U.S. government surveillance programs. This decision significantly impacted transatlantic data transfers and emphasized the need for robust safeguards.

  3. Which entity evaluates whether a non-EU country provides adequate protection?

    Answer: European Commission

    The European Commission is the executive arm of the European Union and is responsible for assessing whether a non-EU country provides an "adequate level of data protection." An adequacy decision means that personal data can flow from the EU/EEA to that third country without needing additional safeguards. This assessment considers the country's domestic law, international commitments, and the existence of independent supervisory authorities.

  4. Which is a lawful basis for data transfer under GDPR when no adequacy decision exists?

    Answer: Binding Corporate Rules

    Binding Corporate Rules (BCRs) are internal codes of conduct approved by data protection authorities that allow multinational companies to transfer personal data internationally within their corporate group. They provide a robust legal framework for data transfers to countries without an adequacy decision, ensuring all entities within the group adhere to the same high standards of data protection. BCRs are a complex but effective mechanism for intra-group transfers.

  5. What must organizations do before transferring data using SCCs?

    Answer: Conduct a Transfer Impact Assessment

    Following the Schrems II ruling, organizations using Standard Contractual Clauses (SCCs) are now required to conduct a Transfer Impact Assessment (TIA). This assessment evaluates whether the laws and practices of the recipient country might undermine the protections guaranteed by the SCCs, particularly regarding government access to data. If risks are identified, supplementary measures must be implemented to ensure an equivalent level of protection for the transferred data.

  6. Which document outlines internal rules for cross-border data transfers within multinational companies?

    Answer: Binding Corporate Rules

    Binding Corporate Rules (BCRs) are a set of internal, legally binding rules adopted by multinational corporations to govern their transfers of personal data from the EU/EEA to their entities located outside the EU/EEA. They serve as a robust mechanism to ensure that all intra-group data transfers comply with GDPR standards, especially when no adequacy decision exists for the recipient country. BCRs are approved by data protection authorities and provide a comprehensive framework for data protection within a corporate group.

  7. Which of the following is NOT a requirement for an adequacy decision?

    Answer: Political alignment with EU

    When the European Commission assesses a non-EU country for an adequacy decision, it primarily focuses on the country's data protection laws, the existence of independent supervisory authorities, and its international commitments regarding human rights and data protection. While political relations might exist, "political alignment with EU" is not a formal criterion for determining an adequate level of data protection. The assessment is strictly based on the legal framework and practical safeguards for personal data.

  8. When is explicit consent required for international data transfer?

    Answer: When no safeguards apply

    Under GDPR, explicit consent is generally required for international data transfers only as a derogation (exception) when no other appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules, are in place. This means that if an organization cannot rely on any other legal basis or safeguard, they must obtain explicit, informed, and specific consent from the data subject for the transfer. This is typically a last resort due to the high bar for explicit consent.

  9. What is a risk of non-compliance in cross-border data transfers?

    Answer: Fines and legal actions

    Non-compliance with cross-border data transfer regulations, such as those under GDPR, carries significant risks for organizations. These risks include substantial administrative fines, which can be millions of euros or a percentage of global annual turnover, as well as legal actions from supervisory authorities or data subjects. Additionally, non-compliance can lead to reputational damage and a loss of customer trust.