

GDPR: QUESTIONS AND ANSWERS
Category:
Standard Contractual Clauses (SCC)
What are Standard Contractual Clauses?
What Standard Contractual Clauses have been adopted by the European Commission?
What are the benefits of SCC?
What process was used by the European Commission in developing the SCC?
Will the European Commission assess after some time how the new SCCs work in practice?
Are there specific requirements for the conclusion by the SCCs?
Can the contents of the SCC be changed?
Is it possible to add additional clauses to the SCC or to include the SCC in the main agreement?
Can the parties remove modules and__UPTH_1__ options that are not applicable in a particular case?
How to include the content of the SCC in the main contract?
What is the purpose of the docking clause
How does the docking clause work in practice? Are there any formal requirements for new parties to a contract?
What happens when a new party joins the SCC?
What is the difference between SCCs adopted by the national supervisory authorities and SCCs adopted by the Commission?
In what form should the administrator's instructions be communicated to the processor?
Does the processor have an obligation to inform the controller of the subprocessor it is engaging?
What happens if an administrator objects to subprocessor changes in the event of a general authorisation to involve subprocessors?
Within what period does the controller have to notify the controller of the data protection breach?
In addition to auditing, how else can a processor demonstrate compliance with the requirements of the SCC?
What's new compared to the previous SCCs?
Whether data transmitters and data receivers that continue to use
What transfers can SCC be used for?
Can SCCs be used to transfer data to administrators or processors who undertake processing operations directly subject to the GDPR?
Can SCCs be used to transfer personal data to an international organisation?
Can the SCC only be used for international data transfers under the GDPR?
What modules are available and how do you choose the right one?
Can multiple modules be used by the same parties at the same time?
How can compliance with Article 28 be ensured?
In which cases should module 4 (transmission of data by the data processor to the controller) be used?
Where can I obtain information that my data is transferred outside Europe on the basis of the SCC?

