Implementation of Appropriate Safeguards for International Transfers, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 46(1).

Assessment Step

1
Implementation of Appropriate Safeguards for International Transfers (ImplementationofAppropriateSafeguardsforInternationalTransfers)
When transferring personal data to a third country or international organisation without an adequacy decision, does the entity provide appropriate safeguards and ensure that enforceable rights and effective legal remedies are available to data subjects?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Implementation of Appropriate Safeguards for International Transfers
In the absence of an adequacy decision, the data controller and the data processor may transfer personal data to a third country or international organisation only if they have provided appropriate safeguards, and on the condition that enforceable data subject rights and effective legal remedies for data subjects are available.
Citation
GDPR
Art. 46(1), Recital 108