Skip to main content
Try Lexiel for freeTry now →
25 minSofía + Adrián

International Transfers and DPO

Transfers outside the EEA, standard contractual clauses, adequacy decisions, Schrems II, when to appoint a DPO, DPO functions and external vs internal DPO.

International data transfers (Arts. 44-49 GDPR)

Any flow of personal data from the European Economic Area (EEA) to a third country is considered an international transfer requiring specific safeguards.

Mechanisms to legitimize transfers

The GDPR establishes a three-level system:

1. Adequacy decisions (Art. 45): The European Commission determines certain countries offer equivalent protection. Countries include: UK, Switzerland, Japan, Canada, Argentina, Uruguay, Israel, South Korea, and since July 2023, the United States (under the EU-US Data Privacy Framework).

2. Standard Contractual Clauses (Art. 46): The most used mechanism when no adequacy decision exists. Since June 2021, a new modular set of SCCs (Decision 2021/914) replaces previous versions.

3. Derogations (Art. 49): Only for occasional transfers: explicit informed consent, contract execution, public interest, legal claims defense.

Schrems II: practical implications

The Schrems II ruling (C-311/18, July 2020) invalidated the EU-US Privacy Shield and established that SCCs require a prior Transfer Impact Assessment (TIA) of the recipient country's legislation.


The Data Protection Officer (DPO)

When mandatory (Art. 37 GDPR)

DPO appointment is mandatory when:

  1. Processing by a public authority or body
  2. Core activities require regular and systematic monitoring at large scale
  3. Core activities consist of large-scale processing of sensitive data

DPO functions (Art. 39)

Inform and advise, supervise compliance, cooperate with supervisory authority, advise on DPIAs.

External vs internal DPO

External: greater independence, fee-based, better for SMEs. Internal: deeper business knowledge, fixed salary, better for large enterprises.

Video coming soon

For now you can read the written content below

Module quiz

1

A Spanish firm uses a cloud storage service with US servers. Since July 2023, what mechanism covers this transfer?

2

What did the Schrems II ruling establish regarding Standard Contractual Clauses?

3

When is it mandatory to appoint a DPO in a law firm?

4

What is an advantage of an external DPO over an internal one for a medium-sized firm?

5

A firm wants to send case files to a correspondent in Brazil. What does it need?

Have your own legal questions?

The Individual Plan gives you 50 queries/month with answers verified against official legal sources.

Try free for 14 days
International Transfers and DPO | Lexiel Academy