Schrems II: Eight Actions to Take Now

The proliferation of data protection and privacy laws creates a difficult regulatory landscape for Data Protection Officers and organisations to navigate. What is certain is that GDPR, CCPA, LGPD and all the other regulations signal a shifting mentality that places major importance on personal data protection and privacy.

On July 16, the Court of Justice of the European Union (CJEU) weighed-in issuing a major decision, the so called “Schrems II”, that shook up the landscape for organisations that transfer data out of the EU.

Here are the highlights you need to know, followed by eight actions to comply with the Court’s decision.

Wrangu’s Privacy Hub can help with your privacy and data protection concerns and assist your organisation with multi-regulation support.

The EU-US Privacy Shield is Invalid

Privacy Shield served as the “adequacy” determination protecting data transfers of personal data from the EU to the US. This means that companies relying on Privacy Shield are no longer in compliance with European law.

Standard Contractual Clauses are Valid, but…

The second big decision held standard contractual clauses (SCCs) were valid, but with a big qualifier. SCCs are valid only under the condition that they provide “essential equivalency” with GDPR. This requires a case-by-case analysis of the circumstances surrounding data transfers out of the EU putting in place supplementary measures to ensure the “adequate” level of protection guaranteed under EU law.

While the ruling concerned data transfers from the EU to the US, all third country transfers are implicated if the country where the data is being transferred does not have an adequacy determination.

The ruling took effect immediately without a grace period and has left many companies scrambling.

So, what now?

In its decision the CJEU raised concerns regarding the overreach of U.S. government surveillance practices and lack of judicial redress for EU data subjects. The judgment reiterated organisations assess prior to transferring data whether there is the presence of “enforceable rights” and “effective legal remedies” while stressing the relevancy of the GDPR. Art. 45(2) criteria for adequacy decisions.

Broadly speaking there remain two alternative transfer mechanisms. Those are transfers (i) made pursuant to SCCs or Binding Corporate Rules (BCRs), or (ii) made pursuant to GDPR Art. 49 derogations for the transfer of personal data.

Eight Actions to Take

1.     Map and analyse data flows that involve transfers of personal data outside the EU, and confirm which transfer mechanism they are relying on.

2.     Identify which data transfers rely on the Privacy Shield and consider alternative mechanisms.

3.     Evaluate whether SCCs or BCRs may be relied on. Organisations must determine that adequate protection equivalent to the GDPR is observed.

4.     If there is no “essential equivalency” using SCCs or BCRs, evaluate whether GDPR Art. 49 derogations may be used. The principle derogations are explicit consent and performance of a contract to which the individual is a party.

5.     Consider data privacy management software to deliver efficiency, transparency, and risk reduction across all activities.

6.     Track, store, and update all contracts, agreements, and consent forms.

7.     Transparency is your friend. Pinpoint if data transfers have been subject to requests by public authorities in the past.

8.     Continue Monitoring Developments. In light of the decision it is increasingly important for organisations to create a culture that understands and values principles of data protection and privacy. While regulations create a burden, they also create an opportunity for organisations as a competitive advantage by building a trusted brand.

Learn more about how Privacy Hub by Wrangu can support your organisation and solve your DPO challenges with multi-regulation support including US Privacy Laws, EU (GDPR), Brazil (LGPD), Turkey (LPPD), and others.

 

Author