Post-Schrems II: New SCC Requirements

Following the “Schrems II” decision early this year invalidating the Privacy Shield, and with it data transfers from the EU to the US. Many companies awaited guidance on additional safeguards for standard contractual clauses (SCCs) ensuring data could continue to be transferred abroad.

On November 12, 2020, the European Commission published a draft implementing decision on new SCCs for transfers of personal data to third countries. The clauses are an attempt to reflect what is required under the “Schrems II” decision providing the necessary safeguards for data transfers abroad to countries without an “adequacy decision.”

The recommendations drew heavily on the European Data Protection Board’s recommendations on supplementary measures and the EU essential guarantees. These two documents came out days before the Commission published its draft proposals. The documents outline the assessment process regarding the adequacy of foreign protections for personal data sent abroad as well as EU approved safeguards companies can implement where foreign laws are lacking.

Wrangu’s Privacy Hub can help with your privacy and data protection concerns and assist your organization with multi-regulation support.

The draft proposal is updated to address four data transfer scenarios so parties can tailor their contracts to their unique context. The relationships envisioned are controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. While the first two scenarios are accommodated by current SCCs, the last two are not.

The new requirements are currently in the consultation period lasting through December 10th. Once in final form, the Commission will formally adopt the decision and clauses. As currently proposed the draft law calls for a one-year transition period. During that time all existing SCCs will need to be phased out and replaced within 12 months of the decision’s adoption. Existing contracts using the old SCC forms will remain effective during this period provided the contract remains unchanged. If a contract is revised or adapted the new clauses must be implemented.

This blog post will discuss the modernized approach outlined in the draft proposal and conclude with the six step process in the EDPB’s framework for evaluating data transfers abroad.

A Modernized Approach

Prior to the recent draft decision, the European Commission addressed only two types of data flow scenarios: an EU-based data controller exporting data outside of the EU to other controllers or processors. In the new draft the Commission addressed the practical situation on the ground closing the gap that existed where no legal mechanism covered data transfers from EU processors to controllers or sub-processors outside of the EU. The new SCCs also provide a mechanism for two or more parties to adhere to or accede to a single set of contractual clauses as data exporter or data importer.

The draft clauses retain the requirement that data exporters consider the level of protection afforded personal data in the third country where the data is transferred. The draft clauses are also extra-territorial imposing an obligation on the data importer, by contractual clause, to notify the data exporter where they could not apply with a contract (for example in cases of national security requests), and a corresponding obligation on the part of the data exporter to terminate such transfers where the importer is unable to comply with the contract. If the data exporter wishes to continue to transfer data, they must notify the Supervisory Authority who will make a determination whether the data may continue to be transferred to the importer in the third country.

Organisations exporting data are additionally required to conduct a transfer impact assessment considering the data protection and national security laws of the third country, and make the assessment available to the Supervisory Authority on request.

In conducting the transfer impact assessment, the Commission permits data importers to consider the practical likelihood of government access request by evaluating the “relevant practical experience indicating the existence or absence of prior instances of requests” from public authorities.

EDPB Six-Step Process for Evaluating Data Transfers Abroad

1. Map Your Transfers: If the country where the data is transferred is deemed adequate no additional steps are necessary except to continue monitoring the validity of the adequacy decision     

2. Verify And Record The Transfer Mechanism Your Organisation Relies On

· SCCs

· Binding Corporate Rules (BCRs)

· Consent

· Article 49 derogations

3. Assess the Adequacy Of The Third Countries Data Protection Laws:

In this third step there is a discrepancy between the EDPB recommendations and the EU Commissions draft. The EDPB cautions against relying on factors such as the likelihood of public authorities’ requesting access to your data. The EU Commission on the other hand has said such considerations are relevant.

4. Identify and Adopt Supplementary Measures: Bring the level of protection of the data transferred up to the “EU standard of essential equivalence.” Employ:

· Technical Safeguards: Encryption or Pseudonymization

· Contractual Safeguards: Data importer’s commitment to transparency, challenging government requests, notification where compliance with a contract is restricted, and preventing “back doors” for government access

· Organisational Measures: Internal policies allocating responsibility and responding to government requests

5. Document Your Organisation’s Approach And Take Formal Procedural Steps Adopting Supplementary Measures

When contracting with data exporters in third countries contractual provisions should include:

· Data processing is based on clear, precise and accessible rules in the contract

· The necessity and proportionality of objectives are outlined explaining why the data is being transferred or processed abroad

· An independent oversight mechanism should exist

· Effective remedies must be available to the individual

6. Reassess Your Organisation’s Approach On A Regular Basis

Conclusion

New privacy laws are keeping privacy professionals busy. Fortunately the EDPB laid out guidelines for complying in the new regulatory environment helping organisations stay on top of privacy developments. As the draft comment period ends, Wrangu will continue to monitor the situation and help you and your organisation stay on top of new privacy regulations.

Author