Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 5365
Next
In Process
Peter
Peter

Peter

  • 1 Question
  • 1 Answer
  • 0 Best Answers
  • 0 Points
View Profile
  • 0
Asked: March 24, 20212021-03-24T23:41:21+01:00 2021-03-24T23:41:21+01:00In: GDPR, Privacy Management

New International Transfers

  • 0

With a lack of true guidance from the European Commission and/or the EPDB in how to make the assessment required to ensure art 46 is effective in practise following Schrems II for countries without Adequacy Decisions. There is a wider industry concern with it being left up to companies it will lead to a clear difference in the assessments which is counter to the objectives of GDPR initially. That said from a company perspective how are people managing it? Do you get legal advice for each location? Or alternative? The required scope for the assessments aren’t feasible for smaller companies so looking to understand how it is being managed. Not making the transfers is not a business option.

  • 3 3 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    3 Answers

    • Voted
    • Oldest
    • Recent
    1. Simon

      Simon

      • 1 Question
      • 18 Answers
      • 0 Best Answers
      • 19 Points
      View Profile
      Simon Bronze contributor
      2021-03-25T10:09:30+01:00Added an answer on March 25, 2021 at 10:09 am

      Even if you don’t feel you can make the best informed assessment of risk, you must make an assessment – one of the points that the BayLDA made re use of MailChimp was that the data controller had not assessed the risks or additional measures that could be put in place. https://gdprhub.eu/index.php?title=BayLDA_-_LDA-1085.1-12159/20-IDV

      There are some really good resources to help you assess the risks which may help you understand foreign privacy legal and surveillance frameworks – they will give you a springboard if nothing else.
      DLA Piper – https://www.dlapiperdataprotection.com/
      Citizen Lab (part of Toronto Uni studying the interactions between surveillance, privacy, and technology – https://citizenlab.ca/
      EPIC – https://epic.org/

      I ask a couple of questions:
      Does third country have a respect for human rights (per ECHR)?
      Are there specific privacy laws? How do those laws measure up?
      Does surveillance go beyond what is necessary to safeguard national security, defence.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • Peter

        Peter

        • 1 Question
        • 1 Answer
        • 0 Best Answers
        • 0 Points
        View Profile
        Peter
        2021-03-25T14:25:18+01:00Replied to answer on March 25, 2021 at 2:25 pm

        Thanks for those resources, I am aware of the DLA Piper resource already but good to know it is recommended by others as well.

        My main concern is that how can an organisation that does not have a legal department or funds to engage one properly answer questions such as what laws are in other countries and how they are enacted and also enforced? It seems a very high bar that could take a significantly long time to just google and then rely on the various public information being right.

        It seems like this is a no-win situation for smaller organisations as we have to go through it but the chances of getting it right are so low that you are penalised in spending significant resource to do it and it offers little protection as if ever challenged it will likely be picked apart quite easily.

        • 0
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn
    2. Dean

      Dean

      • 0 Questions
      • 41 Answers
      • 0 Best Answers
      • 41 Points
      View Profile
      Dean Silver contributor
      2021-03-29T11:08:07+01:00Added an answer on March 29, 2021 at 11:08 am

      Hi Peter.

      It can seem overwhelming, knowing where to start or deciding how much resource to bake into the privacy framework. I think the feedback that Simon has provided is valuable, and if you’re able to use free resources like DLA Piper or other Privacy focussed lawyers, then that is a useful resource.

      I’m not sure whether you’ve seen the resource that Max Shrems and noyb have made available, but there are steps to follow and model assessments that you can use to determine if there are appropriate safeguards in place within a Third Country. Here is the link to the steps and the downloadable model assessments: https://noyb.eu/en/next-steps-eu-companies-faqs

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.