Data Transfer Risk Assessment

Data Transfer Risk Assessment

By EmilyGDPR | GDPR in Practice | 24 May 2023


This blog post focuses on transfer risk assessments (TRAs), starting with the background that led to their implementation and then addressing the following inquiries:

  • What is the purpose of a TRA?
  • Who is subject to TRAs?
  • Why is it significant?
  • How is a TRA conducted?
  • What are the main difficulties in conducting a TRA?

Background

In July 2020, the Court of Justice of the European Union (CJEU) rendered a judgment known as Schrems II, stating that the EU-U.S. Privacy Shield is no longer sufficient for facilitating personal data transfers to the United States.

The CJEU also ruled that while standard contractual clauses (SCCs) remain valid, additional clauses must be added to ensure adequate protection for personal data transfers.

Furthermore, each transfer must be individually assessed to determine if the personal data will be adequately safeguarded.

Consequently, data exporters utilizing SCCs or any other transfer mechanism must conduct a risk assessment before transferring personal data to any third country that lacks an adequacy decision.

What is a TRA?

A Transfer Risk Assessment (TRA) is an evaluation that allows data exporters to determine if the proposed mechanism for transferring international data adheres to the GDPR principles and ensures adequate protection based on the specific circumstances of the transfer. This assessment considers the nature of the personal data being transferred and the destination country.

Who Does it Apply to?

All data exporters based in the UK are required to conduct a risk assessment for all "restricted" data transfers. The UK Information Commissioner's Office (ICO) defines a transfer as restricted if it meets the following criteria:

  • The personal data being transferred falls under the scope of the UK GDPR.
  • The data exporter is sending data or granting access to a data receiver/importer not subject to the UK GDPR.
  • The importer is a separate entity or individual, including companies within the same corporate group.

Restricted transfers are permissible under the UK GDPR if appropriate safeguards outlined in Article 46 are in place. The ICO has released revised SCCs in the form of a model international data transfer agreement (IDTA) to facilitate routine data transfers to third countries.

Recognizing the potential complexity of conducting a TRA, the ICO has recently published a helpful tool to assist with the assessment.

Why is the TRA Important?

The TRA holds significant importance in ensuring GDPR compliance under the UK GDPR. It serves to prevent the circumvention of data protection rights when transferring data to a third country. While the IDTA may cover the involved parties in a specific transfer arrangement, it may not comprehensively address all risks present in third countries or regulate the actions of statutory agencies with access to the transferred personal data.

As third-country transfer safeguards cannot consider the specifics of all legal regimes, data exporters, in collaboration with importers, must assess the protections applicable in the destination country on a case-by-case basis.

For UK data exporters, the TRA is important as it determines whether the IDTA alone provides adequate safeguards for the restricted transfer or if additional steps and protections are necessary.

How is a TRA Conducted in line with Data Protection Principles?

Data exporters are expected by the ICO to ensure that the International Data Transfer Agreement (IDTA) used provides adequate protection for data subjects involved in a restricted transfer, aligning with the relevant data protection principles in the UK.

The TRA should assess three main areas:

1. The specifics of the restricted transfer, including:

  • Type and categories of personal data being transferred
  • Entities involved in the transfer
  • Sector of the transfer
  • Technological and organizational security measures implemented by the importer
  • Storage location of the data and potential remote access
  • Data movement under importer's control
  • Possibility of data being further shared with another entity
  • Purpose, format, and method of transfer.

2. The particular facts about the destination country, including:

  • Existence of partial UK adequacy regulations for that country
  • Human rights record
  • Legal and court system and its similarity to the UK system
  • Recognition and enforcement of overseas judgments
  • Laws and practices regarding third-party access, including public authority surveillance.

3. The potential impact on data subjects and any identified risks of harm to them. It is also important to ensure that the level of protection does not decrease over time.

Additional considerations for the data importer include whether the level of protection is compromised by:

  • Changes to the importer's processing methods
  • Changes to the legal framework in the destination country
  • Technological advancements enabling the bypassing of security measures.

During the TRA, it is advisable to focus on relevant parts of the destination country's legal regime for the restricted transfer. It's worth noting that the use of the ICO's TRA tool is not mandatory, but conducting a risk assessment is essential.

What are the Main Challenges in Conducting a TRA?

Unlike the UK, many jurisdictions, such as the EU and the United States, may not have robust law enforcement regimes and clear national security laws. Some jurisdictions deliberately maintain opaque and secret national security laws, posing a significant challenge for UK data exporters conducting TRAs.

Despite the ICO's efforts in providing the IDTA and TRA tool, conducting a TRA can be burdensome for both small and large data exporters. Larger exporters often have to handle hundreds or even thousands of data transfers to multiple third-country destinations.

Three principal challenges faced by UK data exporters are:

  1. Limited internal resources and knowledge of destination countries' legal regimes, particularly for smaller to medium-sized exporters.
  2. Difficulties in navigating complex and opaque laws to ensure adequate data protection.
  3. The need for strong collaboration with the data importer to monitor changes in the destination country's legal regime and data handling practices.

How do you rate this article?

0


EmilyGDPR
EmilyGDPR

I'm a longstanding GDPR/data protection/privacy specialist with huge experience of both in-house and private practice, gained working across a range of sectors including hi-tech science, media, publishing, higher education and IT.


GDPR in Practice
GDPR in Practice

I'm a longstanding GDPR/data protection/privacy specialist with huge experience of both in-house and private practice, gained working across a range of sectors including hi-tech science, media, publishing, higher education and IT. Here I'm sharing my thoughts on GDPR.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.