Article
EDPB Defines a "Transfer" Under the GDPR
goodwinprivacyblog.com
Quoted on this wiki
Every place a page here uses this source, in the order the words come in it.
Background “However, the GDPR also significantly extended the territorial scope of EEA data protection laws by applying directly to organizations outside the EEA that offer goods or services in the EEA, monitor behavior in the EEA, or process personal data in connection with an EEA establishment.” The Guidelines answer the first question in the affirmative – disclosure of personal data to non-EEA controllers and processors constitutes a transfer even if the recipient is subject to the GDPR. But helpfully for consumer-facing businesses, the EDPB does not consider the collection of personal data directly from individuals in the EEA to be a transfer.
Background “However, the GDPR also significantly extended the territorial scope of EEA data protection laws by applying directly to organizations outside the EEA that offer goods or services in the EEA, monitor behavior in the EEA, or process personal data in connection with an EEA establishment.” The Guidelines answer the first question in the affirmative – disclosure of personal data to non-EEA controllers and processors constitutes a transfer even if the recipient is subject to the GDPR. But helpfully for consumer-facing businesses, the EDPB does not consider the collection of personal data directly from individuals in the EEA to be a transfer.
Risk Assessment is Required Even Where There is No Transfer “The Guidelines emphasise that even if there is no data transfer (e.g., non-EU businesses collecting personal data directly from EU consumers or travelling employees accessing Company systems from third countries), a controller or processor that is subject to GDPR remains accountable for its processing activities generally.” Key Questions Remain
Below we summarize the key takeaways for each criterion. “The “exporting” controller or processor must be subject to the GDPR for the given processing.” Organizations outside the EEA can be “exporters” if they are subject to the GDPR and will need to comply with the GDPR’s data transfer rules. Because the GDPR applies directly to organizations outside the EEA in some circumstances, those organizations will need to have a transfer mechanism to share personal data with another party outside the EEA.
It is not a transfer when a data subject provides personal information “directly and on his/her own initiative” to an organization outside the European Economic Area (“EEA”). “An EEA controller or processor sharing personal data with a non-EEA controller or processor engages in a transfer, regardless of whether or not the receiving entity is subject to the GDPR.” For there to be a “transfer,” there must be “two different (separate) parties (each of them a controller, joint controller or processor).” Access to personal data within the same controller or processor– such as where an employee of a controller or processor travels to a third country with his/her laptop – is not a transfer.
Key Takeaways “It is not a transfer when a data subject provides personal information “directly and on his/her own initiative” to an organization outside the European Economic Area (“EEA”).” An EEA controller or processor sharing personal data with a non-EEA controller or processor engages in a transfer, regardless of whether or not the receiving entity is subject to the GDPR. However, the EDPB recognizes that transfers to data importers that are directly subject to the GDPR require fewer protections. The current set of Standard Contractual Clauses (“SCCs”) apply only where the importer is not subject to the GDPR. Businesses should expect a new set of SCCs to govern transfers from the EEA to a foreign data importer who is already subject to GDPR.
It is not a transfer when a data subject provides personal information “directly and on his/her own initiative” to an organization outside the European Economic Area (“EEA”). “The current set of Standard Contractual Clauses (“SCCs”) apply only where the importer is not subject to the GDPR.” For there to be a “transfer,” there must be “two different (separate) parties (each of them a controller, joint controller or processor).” Access to personal data within the same controller or processor– such as where an employee of a controller or processor travels to a third country with his/her laptop – is not a transfer.