Transferring Personal Data Outside of the EEA

|
|
|
PUBLISHED on
22
July
2022
SUMMARY

This blog looks at a very specific area of the GDPR - Article 28 and data transfer outside of the EEA.  One of the ways in which you can legitimise an ex-EEA data transfer is by using the standard contractual clauses (SCCs).

Article 28 mandates a number of requirements that must be placed on data processors, by data controllers, via a contract.  The question is, are the SCCs sufficient to meet these requirements?  Whilst the SCCs are pretty comprehensive, they were drafted before the GDPR came into effect and, as a result, not all of the requirements of Article 28 are addressed by the SCCs.

So, what can you do?

The challenge with the SCCs is that they must be used verbatim.  Any change to the wording, even if it has no material effect on the interpretation, means that the parties cannot claim to be using the SCCs.  However, it is permissible to add clauses or incorporate the SCCs in a broader contract, ’provided nothing in the other contract or additional clauses alters the effect of any of the model clauses’.

So, if you are outsourcing data processing to processors outside the EEA and transferring PII, then you should supplement, and not solely rely on, the SCCs.  The specific gaps between Article 28 and the SCCs are, broadly speaking, that the SCCs (and Appendix where applicable) do not:

  • Address the duration of processing
  • Contain a requirement for the data importer to commit to confidentiality
  • Contain a requirement to support the response to a data subject request
  • Comply with the timing or cooperation requirements relating to a data breach
  • Address the processor participating in a data protection impact assessment (DPIA)
  • Address all audit requirements Address onward transfer of data outside of the EEA.

Do you need assistance in improving your GDPR compliance position?

URM can offer a host of consultancy services to improve your DP policies, privacy notices, DPIAs, ROPAs, data retention schedules and training programmes etc.
Thumbnail of the Blog Illustration
Data Protection
Published on
26/2/2025
Apple Removes Advanced Data Protection Tool from UK

URM’s blog explores Apple’s removal of its ADP tool following a dispute with the UK government & the ongoing struggle between privacy and law enforcement.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
14/3/2024
URM Analyses ICO’s Enforcement Actions Since the GDPR was Introduced in 2018

URM’s blog breaks down which Articles of the GDPR have seen the greatest number of enforcement actions by the ICO, and which have gone largely unenforced.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
12/2/2024
Deadline Approaches for Updating Contracts Containing Old EU Standard Contractual Clauses (SCCs)

URM’s blog discusses changes to the SCCs British organisations can use to legitimise restricted transfers of data under the UK GDPR

Read more
The feedback on URM’s report was that it was the best document the developer had ever received due to it being so concise and clear. He has saved it on his desktop and suggested that the business should use a similar template for internal docs. This great feedback reflects not only on the URM penetration tester who conducted the test, but also on the senior members of URM’s Cyber Team for all the work they have put in to producing such a brilliant reporting template.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.