How to choose the appropriate legal basis for transferring personal data outside the EEA

07 January 2020

Why is there a separate regulation regarding the transfer of data outside the EEA (and thus outside the countries of the European Union, Norway, Iceland, and Liechtenstein)? The answer can be found in Recital 116 of the GDPR: "The transfer of personal data to third countries may increase the risk that individuals will not be able to exercise their rights to data protection, in particular to protect against unlawful processing or disclosure of such information. At the same time, supervisory authorities may consider that they are unable to investigate a complaint or conduct proceedings regarding activities that take place outside their jurisdiction." For this reason, in the event of an intention to transfer personal data outside the EEA, the provisions of Articles 44–50 of the GDPR must be implemented. The following steps may facilitate this process.

Step 1: Determining the Details of Data Transfers Outside the EEA

According to Recital 101 of the GDPR, Articles 44–50 of the GDPR apply when personal data is or is to be processed after being transferred outside the EEA. This concerns the transfer of data to data controllers, data processors, or other recipients outside the EEA. The transfer must be active. If your last action is disclosing data in Poland (e.g., on your website), the mere possibility of access from third countries does not mean that you are transferring data outside the EEA. As stated by the European Data Protection Supervisor (EDPS), we transfer data outside the EEA if we do so intentionally or if our intention is to make the data available to individuals outside the EEA.

Example:
As indicated by the EDPS, hacking into a website or the mere fact that due to the structure of the network data may cross the borders of the EEA does not yet mean that data is being transferred outside the EEA.

Tip:
If in your case data is being transferred outside the EEA, as part of the first step, you should identify in what context, to what extent, with what frequency, and to which third countries or international organizations the data is to be transferred.

A thorough description of data flows outside the EEA does not necessarily mean moving on to the next step. It may reveal that the data transfer would be unjustified or too broad in scope – for this reason, the analysis should be conducted before the transfer begins.

READ MORE: How to Incorporate Privacy by Design?

Step 2: Identifying Risks Associated with Data Processing Outside the EEA

Before we consider the formal legal basis, let us assess whether personal data will indeed be secure after the transfer. If we are uncertain, regardless of the legal basis, we should not risk compromising information security and causing harm to the individuals whose data is concerned.

Example:
If we entrust the processing of data to a data processor outside the EEA, in addition to the appropriate legal basis and data processing agreement, we should ensure that it implements appropriate security measures – for instance, by requesting the completion of a checklist.

The threats do not only concern the data processor to whom we transfer the data but also the jurisdiction in which it operates. Even a trusted contractor may be subject to legal obligations that differ from Polish realities or may process data in a country where data protection principles do not essentially apply.

READ MORE: DPIA - we provide a form

Step 3: selection of the legal basis ensuring the highest degree of compliance

The most ambiguities arise in the third step, namely the selection of the appropriate legal basis. Before we proceed to the suggested order of legal bases for most processing operations, let us recall the following exceptions:

  • GDPR Bulletin
    Receive a package of free GDPR guides and micro-trainings
    Join the ranks of our newsletter readers, receive a free package, and stay informed.
    RECEIVE PACKAGE
    Art. 85 sec. 2 GDPR provides for the possibility for individual countries to adopt exceptions for the processing of data for journalistic purposes or for academic, artistic, or literary expression. At the time of publication of this article, there are no such provisions, but the legal status in this regard should be monitored.
  • Art. 49 para. 1 lit. g GDPR provides for an exception when the transfer occurs from a register that, according to the law of the Union or a Member State, is intended to serve as a source of information for the general public and is accessible to the general public or to any person who can demonstrate a legitimate interest – but only to the extent that the conditions for such access specified in the law of the Union or in the law of the Member State are met in the given case.
  • Even in the absence of other legal grounds, transfers necessary for important public interest reasons are permissible, provided that such public interest is recognized in the law of the Union or in the law of the Member State to which the data controller is subject (art. 49 para. 1 lit. d and art. 49 para. 4 GDPR). Examples are indicated in Recital 112 of the GDPR: “These exceptions should particularly apply to data transfers required and necessary for important public interest reasons, for example, for international data exchange between competition authorities, tax authorities or customs authorities, financial supervisory authorities, services responsible for social security matters or public health, for instance in the case of establishing contacts in infectious disease outbreaks or to reduce or eliminate doping in sports.”

GDPR. Support is useful!

In relation to all other cases of personal data transfers, we should choose a basis that ensures the highest level of personal data protection, considering that:

  • it is safest to transfer data if the European Commission determines that a third country, territory, or a specific sector or sectors in that third country, or a given international organization provides an adequate level of protection (art. 45 para. 1 and – in the case of decisions made before the GDPR – art. 45 para. 9 GDPR);
  • In the absence of a decision from the Commission, we recommend using standard contractual clauses (Article 46(2)(c) or (d) GDPR). These are clauses approved by the Commission, available on its website (here in Polish). The clauses only cover the transfer of data between the parties to the contracts – two data controllers or a data controller and a data processor. Therefore, there is no possibility of automatically using the clauses in the case of further outsourcing of processing (the clauses in this regard have not progressed beyond the draft stage). In the case of the public sector, however, a more appropriate legal basis is a legally binding and enforceable instrument between public authorities or entities (Article 46(2)(a) GDPR).

Binding corporate rules (BCR) also provide an appropriate legal basis (Article 47 GDPR). As stated in Recital 110 of the GDPR, this basis concerns a group of enterprises or a group of entrepreneurs conducting joint business activities. Decisions are approved by supervisory authorities – examples can be found on the archived GIODO website or the UK authority (ICO). The draft of the rules and the application to the lead supervisory authority can be prepared based on the “Working Document on Binding Corporate Rules for Data Controllers” or the “Working Document on Binding Corporate Rules for Data Processors” (in English). The rules for processing the application by the authority are described in the “Working Document on the Procedure for Approving Binding Corporate Rules for Data Controllers and Data Processors” (wp263 rev.01).

Next, the following legal bases should be considered:

  • necessity for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the request of the data subject (Article 49(1)(b) GDPR), or necessity for the conclusion or performance of a contract concluded in the interest of the data subject between the data controller and another natural or legal person (Article 49(1)(c) GDPR) – we can speak of necessity when we identify a close and significant link between the transfer of data and the purposes of the contract (for more, see our article: „How to conclude contracts online to ensure they are valid (not only) under GDPR?”, discussing the EDPB Guidelines 2/2019 on the processing of personal data in accordance with Article 6(1)(b) GDPR in the context of providing online services to data subjects). In the event of a dispute, however, it will be crucial to demonstrate a „close and significant link” between the transfer of data and the contract concluded by the data controller with another natural or legal person – in the interest of the data subject. As stated in the EDPB Guidelines 2/2018 on the exceptions established in Article 49 GDPR: „This exception cannot be applied, for example, if a group of companies has centralized payment and human resources management functions for all employees in a third country for business purposes, as there is no direct or objective link between the performance of an employment contract and such a transfer”;
  • necessity for the establishment, exercise, or defense of legal claims (Article 49(1)(e) GDPR) – in the guidelines 2/2018, the EDPB clarified: “The exception cannot be applied to justify the transfer of personal data solely based on the possibility that legal proceedings or formal procedures may be initiated in the future.” […] the relevant proceedings must have a legal basis, including a formal procedure defined by law, but it is not necessarily limited to judicial or administrative proceedings.” At the same time, according to Article 49(3) GDPR, this exception may be applied to activities carried out by public authorities in the exercise of their public rights;
  • necessity for the protection of vital interests of the data subject or another person, where the data subject is physically or legally incapable of giving consent (Article 49(1)(f) GDPR) – according to the guidelines 2/2018, the exception applies “when data is transferred in a situation threatening health, if such transfer is deemed necessary to ensure essential medical care. In this regard, it must be legally permissible, for example, to transfer data (including certain personal data) if the data subject is unconscious while outside the EU and requires immediate medical care, and only the data transferring entity (i.e., that person's doctor), practicing in an EU member state, is able to provide such data. In such cases, the law provides that the risk of serious harm to the data subject outweighs data protection considerations.”;
  • consent of the data subject (Article 49(1)(a) GDPR) – specifically for the transfer of their data outside the EEA, with an awareness of the potential risks due to the absence of a decision determining an adequate level of protection and the lack of appropriate safeguards.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to fulfill the role of Data Protection Officer. We invite you!
CHOOSE A DATE
If the aforementioned grounds do not apply to your situation, then in accordance with Article 49(1) second paragraph of the GDPR, “the transfer to a third country or an international organization may only take place if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for important legally justified interests pursued by the data controller, which are not overridden by the interests or rights and freedoms of the data subjects, and the data controller has assessed all circumstances of the data transfer and, based on this assessment, has provided appropriate safeguards for the protection of personal data. The data controller informs the supervisory authority about the transfer.” As stated in Recital 113 of the GDPR, when applying this exception, “the data controller should pay particular attention to the nature of the personal data, the purpose and duration of the proposed processing operation or operations, and the situation in the country of origin, the third country, and the country of final destination. […] When it comes to the purposes of scientific or historical research or statistical purposes, the legitimate social expectations regarding the advancement of knowledge should be taken into account.”

Both the exceptions regarding consent for transfer and agreements with the data subject or in the interest of that person (Article 49(1)(a)-(c) of the GDPR), as well as Article 49(1) second paragraph of the GDPR, do not apply to activities carried out by public authorities in the exercise of their public powers (Article 49(3) of the GDPR). If we transfer personal data for the purpose of executing a judgment of a court or tribunal or a decision of a third country authority, then Article 48 of the GDPR requires that the basis for such transfer be an international agreement in force between the requesting third country and the Union or a Member State.

Summary

Transferring personal data to third countries and international organizations can be much easier if we apply a clear procedure, which can be summarized as follows:

  1. assessing whether data is being transferred outside the EEA, and if so, indicating in what context, scope, with what frequency, and to which third countries or international organizations the data is to be transferred,
  2. determining any potential risks to personal data processed after transfer to the EEA and limiting transfers solely to cases where we can ensure an adequate level of security (preferably as part of conducting a Data Protection Impact Assessment – DPIA),
  3. establishing the legal bases for transfers outside the EEA, selected from the options indicated above.

In addition to the above steps, it is important to consider the fact of transferring data outside the EEA in privacy notices, records of processing activities, and other documents intended to ensure compliance with the GDPR (e.g., consent clauses for the processing of personal data).

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.