
Any transfer of personal data to third countries outside the EU shall comply with the GDPR provisions. Which of the following is not a valid mechanism for transborder data flow? (Wentz QOTD)
A. Adequacy decisions
B. EU-US privacy shield
C. Standard contractual clauses
D. Derogations for specific situations
Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.
My suggested answer is B. EU-US privacy shield.
Wentz’s book, The Effective CISSP: Security and Risk Management, helps CISSP and CISM aspirants build a solid conceptual security model. It is a tutorial for information security and a supplement to the official study guides for the CISSP and CISM exams and an informative reference for security professionals.
The EU-U.S. Privacy Shield was revoked and invalidated:
On July 16, 2020, the Court of Justice of the European Union issued a judgment declaring as “invalid” the European Commission’s Decision (EU) 2016/1250 of 12 July 2016 on the adequacy of the protection provided by the EU-U.S. Privacy Shield. As a result of that decision, the EU-U.S. Privacy Shield Framework is no longer a valid mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States. This decision does not relieve participants in the EU-U.S. Privacy Shield of their obligations under the EU-U.S. Privacy Shield Framework.
Source: The International Trade Administration (ITA), U.S. Department of Commerce
General Data Protection Regulation (GDPR)
“Chapter 5 – Transfers of personal data to third countries or international organisations” mentions a couple of mechanisms that allow personal data to be transferred outside the EU area.
- Art. 45 GDPR – Transfers on the basis of an adequacy decision
According to Art. 46 GDPR – Transfers subject to appropriate safeguards, it reads “In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.”
- Art. 47 GDPR – Binding corporate rules
- Art. 49 GDPR – Derogations for specific situations
- Standard data protection clauses (standard contractual clauses) adopted by the Commission in accordance with the examination procedure referred to in Article 93(2); or adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);
- An approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor
- an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor
Reference
- Declaration on Transborder Data Flows (OECD)
- Regulation of Transborder Data Flows under Data Protection and Privacy Law – PAST, PRESENT AND FUTURE
- International Safe Harbor Privacy Principles
- International dimension of data protection
- Art. 44 GDPR – General principle for transfers
- Adequacy decisions
- Standard Contractual Clauses (SCC)
- Binding Corporate Rules (BCR)
- Commercial sector: EU-US Privacy Shield
- Microsoft Products and Services Data Protection Addendum (DPA)
- FAQs – EU-U.S. Privacy Shield Program Update
將個人數據傳輸到歐盟以外的第三國應遵守 GDPR 規定。 以下哪項不是有效的跨境數據流動機制? (Wentz QOTD)
A. 充分性決定 (adequacy decisions)
B. 歐盟-美國隱私盾 (privacy shield)
C. 標準合同條款
D. 針對特定情況的豁免 (derogations)