24.11.2012 Views

Regulation of Transborder Data Flows under ... - Tilburg University

Regulation of Transborder Data Flows under ... - Tilburg University

Regulation of Transborder Data Flows under ... - Tilburg University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Kuner/<strong>Regulation</strong> <strong>of</strong> <strong>Transborder</strong> <strong>Data</strong> <strong>Flows</strong> <strong>under</strong> <strong>Data</strong> Protection and Privacy Law 85<br />

C. Other important instruments<br />

Name Source Text or translation (excerpts; notes are given in italics)<br />

European<br />

Union<br />

(voluntary<br />

measures)<br />

Binding Corporate<br />

Rules: Article 29<br />

Working Party,<br />

‘Working Document<br />

setting up a framework<br />

for Binding Corporate<br />

Rules’ (WP 154, 24<br />

June 2008), at 7<br />

Standard Contractual<br />

Clauses:<br />

Commission Decision<br />

(EC) 2010/87/EU <strong>of</strong> 5<br />

February 2010 on<br />

standard contractual<br />

clauses for the transfer<br />

<strong>of</strong> personal data to<br />

processors established<br />

in third countries<br />

<strong>under</strong> Directive (EC)<br />

95/46/EC <strong>of</strong> the<br />

European Parliament<br />

and <strong>of</strong> the Council,<br />

[2010] OJ L39/5<br />

Commission Decision<br />

(EC) 2004/915 <strong>of</strong> 27<br />

December 2004<br />

amending Decision<br />

(EC) 2001/497 as<br />

regards the<br />

introduction <strong>of</strong> an<br />

alternative set <strong>of</strong><br />

standard contractual<br />

clauses for the transfer<br />

<strong>of</strong> personal data to<br />

third countries, [2004]<br />

OJ L385/74<br />

Safe Harbor Privacy<br />

Principles issued by<br />

the US Department <strong>of</strong><br />

Commerce on July 21,<br />

2000, and recognized<br />

as ‘adequate’ <strong>under</strong><br />

European Commission<br />

Binding corporate rules must contain ‘an explanation <strong>of</strong> the measures in<br />

place to restrict transfers and onward transfers outside <strong>of</strong> the group’, and<br />

a commitment that all transfers to external controllers and processors<br />

located outside <strong>of</strong> the EU must respect EU rules on transborder data<br />

flows.<br />

Clause 11: The non-EU data importer must not transfer the data to a subprocessor<br />

unless EU-based legal standards are complied with.<br />

Clause II(h): The non-EU data importer must process the personal data<br />

transferred in accordance with EU-based legal standards.<br />

Clause II(i): The non-EU data importer must not transfer the data to a<br />

third party located outside the EEA unless EU-based legal standards are<br />

complied with.<br />

ONWARD TRANSFER: To disclose information to a third party,<br />

organizations must apply the Notice and Choice Principles. Where an<br />

organization wishes to transfer information to a third party that is acting<br />

as an agent, as described in the endnote, it may do so if it first either<br />

ascertains that the third party subscribes to the Principles or is subject to<br />

the Directive or another adequacy finding or enters into a written<br />

agreement with such third party requiring that the third party provide at

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!