A United States software vendor hosts a cloud-based clinical trial management platform that collects personal data from research subjects located across European Union member states. All trial telemetry processed in the US data center is encrypted at rest using AES-256. However, the organization relies solely on standard commercial service agreements for cross-border data movement. Which of the following mechanisms is required under the General Data Protection Regulation (GDPR) to lawfully authorize this ongoing transfer of personal data to a third country lacking an adequacy decision?
- Executing Standard Contractual Clauses alongside a Transfer Impact Assessment to evaluate local surveillance law protectionsAnswer
- BAchieving ISO/IEC 27001 certification for the cloud infrastructure to automatically establish statutory data adequacy
- CExecuting Business Associate Agreements with European healthcare clients to extend HIPAA legal jurisdiction internationally
- DReassigning data controller duties to the infrastructure cloud hosting provider to transfer primary regulatory liability
Answer
Executing Standard Contractual Clauses (SCCs) alongside a Transfer Impact Assessment (TIA) to evaluate local surveillance law protections
Under GDPR Chapter V, when personal data of EU data subjects is transferred to a country that lacks an official adequacy decision, organizations must implement approved safeguards. Executing Standard Contractual Clauses (SCCs) combined with conducting a Transfer Impact Assessment (TIA) ensures that valid legal commitments are in place and that supplementary measures are evaluated to protect data against third-country surveillance laws.
Step-by-Step Solution
Key Concept
GDPR International Data Transfer Safeguards and Mechanisms