Information note on data transfers under the GDPR in the event of a no-deal Brexit
Information n ote on data transfers under the GDPR in the event of a no - deal Brexit Adopted on 12 February 2019 Updated on 4 October 2019 Introduction In the absenc e of an agreement between the EEA and the UK ( n o - deal Brexit), the UK will become a third country from 00.00 am CET on 1st November 2019 . This means that the transfer of personal data to the UK has to be based on one of the following instruments 1 as of 1st November 2019 : - Standard or ad hoc Data Protection Clauses -…
How it connects
Related across sources
Full text 8 sections
00 am CET on 1st November 2019 . This means that the transfer of personal data to the UK has to be based on one of the following instruments 1 as of 1st November 2019 : - Standard or ad hoc Data Protection Clauses - Binding Corporate Rules - Codes of Conduct and Certification Mechanisms - Derogations 2 This note provides information to commercial and public organisations on the se transfer instruments under the GDPR for the transfer of personal data to the UK in the event of a no - deal Brexit The EDPB builds upon the guidance provided on this matter by supervisory authorities and by the Euro pean Commission (EC) . EEA organisations may turn, if necessary, to the national supervisory authorities competent to oversee the related processing activities . 1 See Chapter V of GDPR. 2 These can be used only i n the absence of Standard Data Protection Clauses or other alternative appropriate safeguards .
2 I. 5 steps organisations should take to prepare for a no - deal Brexit When transferring data to the UK, you should : I I . Data transfers from the EEA to the UK 1 . Available transfer instruments In the absence of an adequacy decision 3 at the time of the Brexit, the following are the available data transfer instruments. a . Standard and ad hoc Data Protection Clauses You and your UK counterpart may agree on the use of Standard Data Protection Clauses approved by the European Commission. The se contracts offer the additional adequate safeguards with respect to data protection that are needed in case of a t ransfer of personal data to any third country . 3 An adequacy decision is a decision adopted by the European Commission on the basis of article 45 GDPR (for example, the adequacy decision on Japan adopted by the Commission on 23rd January 2019. Previously, the EC had also adopted adequacy decisions on th ird countries such as Argentina, New Zealand and Israel, amongst others).
At the moment, there is no such an adequacy decision in place for the UK. • Identify what processing activities will imply a personal data transfer to the UK 1 • Determine the appropriate data transfer instrument for your situation (see below) 2 • Implement the chosen data transfer instrument to be ready for 1st November 201 9 3 • Indicate in your internal documentation that transfers will be made to the UK 4 • Update your privacy notice accordingly to inform individuals 5 3 Three set s of Standard Data Protection Clauses are currently available: • EEA controller to third country (e . g. UK) controller : 2 s ets are available: o 2001/497/EC o 2004/915/EC • EEA controller to third country (e . g. UK) processor o 2010/87/E U It is important to note that the Standard Data Protection Clauses may not be modified and must be signed as provided. However, th e se contracts may be included in a wider contract and additional clauses might be added provided that they do not contradict, directly or indirectly, the Standard Data Protection Clauses adopted by the European Commission .
Considering the timeframe before the 1st November 2019 , the EDP B acknowledges that the Standard Data Protection Clauses is a ready - to - use instrument. Any further modifications to the Standard Data Protection Clauses will imply that this will be considered as ad - hoc contractual clauses . This can provide appropriate sa feguards taking into account your particular situation. Prior to any transfer, these tailored contractual clauses must be authorised by the competent national supervisory authority, following an opinion of the EDPB . b. Binding Corporate Rules Binding Co rporate Rules are personal data protection policies adhered to by group of undertakings (i . e. multinationals) in order to provide appropriate safeguards for transfers of personal data within the gr oup, including outside of the EEA . You may have already in place BCRs or cooperate with processors which make use of BCRs for Processors.
Organisations may still rely on these BCRs authorised under the former Directive 95/46/EC which remain valid under the GDPR 4 . These BCRs need however to be updated to be fully in line with the GDPR provisions. If you do not have BCRs in place, they must be approved by the competent national supervisory authority, following an opinion of the EDPB . You can find further explanations on the conditions to apply for Bindi ng Corporate Rules on the EDPB website . 5 GDPR . Please note that BCRs authorised under former Directive 95/46/EC remained valid under the GDPR, but need to be updated to be fully in line with GDPR provisions. 4 c. Codes of conduct and certification mechanisms A c ode of conduct or a certification mechanism can offer appropriate safeguards for transfers of personal data if they contain binding and enforceable commitments by the organisation in the third country for the benefit of the individuals .
These tools are new under the GDPR an d the EDPB is working on guidelines in order to give more explana tions on the harmonized conditions and procedure for using these tools. 2 . ) or transfer the data on the basis of an adeq uacy decision. They must therefore be interpreted restrictively and mainly relate to processing activities that are occasional and non - repetitive 5 . These derogations include amongst others according to article 49 GDPR: • where an individual has explicitly consented to the proposed transfer after having been provided with all necessary information about the ris ks associated with the transfer; • where the transfer is necessary for the performance or the conclusion of a contract between the individual and the co ntroller or the contract is concluded in the interest of the individual; • if the data transfer is necessary for important reasons of public interest ; • if the data transfer is necessary for the purposes of compelling legitimate interests of the organisation.
You can find further explanations on available derogations and how to apply them in the EDPB G uideline s on A rticle 49 of GDPR . 3. Instruments exclusively available to public authorities or bodies Public authorities may consider to use the mechanisms which the GDPR considers more ap propriate to their situation. One option is to use a legally binding and enforceable instrument, such as an administrative agreement, a bilateral or multilateral international agreement. The agreement must be binding and enforceable for the signatories. The second option is to use ad ministrative arrangements, such as Memoranda of Un d erstanding, which although not legally binding must however provide for enforceable and effective data subject rights. The administrative arrangements are subject to an authorisation by the competent natio nal supervisory authority, following an opinion of the EDPB . 1 GDPR 5 In addition, the abovementioned derogations are also available for transfers by public authorities, subject to the application of the relevant conditions.
For public authorities exercising cri minal law enforcement functions 6 , addition al transfer tools are available 7 . II I . Data transfers from the UK to EEA Members According to the UK Government , the current practice, whic h permits personal data to flow freely from the UK to the EEA , w ill continue in the event of a no - deal Brexit 8 . To this end, the UK G overnment’s and the ICO’s website should be regularly consulted. For the European Data Protection Board The Chair (Andrea Jeli nek) _________________________ 6 Which fall under the scope of the Law Enforcement Dir ective. 7 S ee Article 37 and 38 LED . For instance, transfers may take place when the EU authority concludes that appropriate safeguards exist in the third country following a (self - )assessment of all circumstances surrounding the transfer. Moreover, additi onal derogations for specific situations may be applicable (see Article 38 LED). uk/government/pu blications/data - protection - if - theres - no - brexit - deal/data - protection - if - theres - no - brexit - deal