01/02/22 – If you or your organisation transfers, or may transfer, personal data to third countries, i.e. countries that are not considered to have an ‘adequate’ level of data protection (which currently includes the U.S.), then read on. If not, then feel free to skip.
Back in August last year we looked at a brand new international data transfer agreement (‘IDTA’) template, together with a new international data transfer addendum to be used with EU SCCs (‘Addendum’), that the ICO published as part of its consultation on ‘how organisations can continue to protect people’s personal data when it’s transferred outside of the UK’.
The ICO’s consultation closed on 7th October 2021, and on 28th January 2022 the Department for Culture, Media and Sport (DCMS) laid the final versions of the IDTA, the Addendum, plus the transitional provisions before Parliament. Unless the relevant statutory instrument is ‘objected to’ (which, given its subject matter, is very unlikely), the IDTA, the Addendum and the transitional provisions will come into force on 21 March 2022.
UK data exporters who enter into agreements with their data importers based on the old EU SCCs (i.e. Standard Contractual Clauses issued under European Commission Decisions 2001/497/EC and 2010/87/EU) on or before 21st September 2022 may, if the subject matter of the processing remains unchanged, continue to rely on those agreements until 21st March 2024. Note that this only applies where the agreements based on the old EU SCCs were modified to ‘fit’ post-Brexit UK data protection laws, and will not apply to EU SCCs entered into prior to Brexit.
Although the ICO have not yet published the responses from the consultation, the changes to the IDTA are limited with the main ones being:
Tags: data transfers, gdpr, ICO, idta, international data transfers, SCCs, Schrems II
Posted in Privacy, Updates | No Comments »
Part 1 and Part 2 of the What’s been happening with SCCs? updates have tracked the EU’s and the UK’s progress in developing standard contractual clauses (SCCs) to deal with the transfer of personal data to third countries, i.e. countries that are not considered to have an ‘adequate’ level of data protection, as well as the publication of the new EU SCCs. This update focuses on the UK SCCs.
On 11th August 2021 the ICO launched a consultation on ‘how organisations can continue to protect people’s personal data when it’s transferred outside of the UK‘. As part of the consultation the ICO published its proposal for UK standard contractual clauses in the form of a brand new international data transfer agreement (IDTA), as well as its new Transfer Risk Assessment (TRA) and tool. The ICO is also requesting comments on an update of its existing guidance on international transfers. The consultation closes on 7th October 2021.
All very interesting I’m sure. But is any of this relevant to me?
Short version is that if you’re transferring UK citizens’ personal data to a ‘third country’ (i.e. a country which is not considered by the UK to have ‘adequate’ data protection laws (full list here), then yes. You will need to use one of the transfer mechanisms (or ‘appropriate safeguards‘) set out in Article 46 of the GDPR (now incorporated into UK law as the UK GDPR, as amended). And although the UK GDPR provides for a variety of transfer mechanisms, for most businesses the only practical option in these circumstances will be for both the (UK) data exporter and (third country) data importer to enter into an IDTA, having first completed a Transfer Risk Assessment (TRA).
Bear in mind that for these purposes:
Ah, ok. So what do I need to know?
The new IDTA and TRA requirements will not not become law until the end of 2021 or, more likely, spring 2022. Between now and then the situation is a bit of a mess. UK law provides that the old EU SCCs must continue to be used as the Article 46 transfer mechanism, even after 27 September 2021 when they cease to be lawful for new EU cross-border data transfers. Although some commentators have suggested that, in a post-Schrems II world, a better approach is for UK data exporters to use the new EU SCCs until the new IDTA is adopted, my view is that for the time being most UK data exporters should stay compliant with UK law and either make Brexit-required changes to their existing SCCs or, for new transfers, put in place a data transfer agreement based on the old EU SCCs.
The timelines for UK data exporters being legally required to use the new IDTA for international data transfers will be 3 months for new transfers and 21 months for existing transfers, each period running 40 days from the date on which the IDTA is laid before Parliament as a regulation.
Some high-level comments on the IDTA:
And some comments on the TRA:
Hmm… 49-page risk assessments and 43-page data transfer agreements. Doesn’t exactly sound ‘agile’?
You’re referring to the comments of the UK culture secretary, Oliver Dowden, who suggested in his article in the FT last February that that the UK can now be more ‘agile’ when it comes to ‘[striking] our own international data partnerships with some of the world’s fastest growing economies’.
If we accept the importance of ensuring a meaningful level of protection for UK citizens’ data when shared with third parties outside the UK then we either have to provide a mechanism which gives organisations the ability to put in place a framework to ensure a meaningful level of protection, or we go down the data localisation route and make it unlawful for personal data to be transferred from the UK to any ‘third country’.
Despite the reservations mentioned above, the ICO have in my view done a good job striking a balance between the need for ‘agility’, and the need to provide meaningful protection of personal data in a world which, for the most part, falls far behind the ‘gold standard’ of EU and now UK data protection. But the elephant in the room remains why the ICO (or appropriate government department) cannot provide UK data exporters carrying out a TRA with guidelines regarding each third country’s legal framework, third-party surveillance rights and safeguards, and their similarity to those in the UK. It will be interesting to see if this is addressed by the consultation.
Tags: data transfers, gdpr, ICO, idta, international data transfer agreement, modular SCCs, SCCs, Schrems II, Standard Contractual Clauses, transfer impact assessment, UK gdpr
Posted in Privacy, Updates | No Comments »