Restriction on Third-Country Access Without EU Legal Authorization, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 48.

Assessment Step

1
Restriction on Third-Country Access Without EU Legal Authorization (RestrictiononThird-CountryAccessWithoutEULegalAuthorization)
Does the entity refrain from disclosing personal data to a third-country authority unless the disclosure is authorized by Union or Member State law and complies with the international transfer conditions in Chapter 5 of the GDPR?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Restriction on Third-Country Access Without EU Legal Authorization
The data controller and the data processor must not disclose personal data to a third-country authority based on a judgment or decision of that authority unless the disclosure is authorized by Union or Member State law, and the transfer complies with the conditions for international transfers set out in Chapter 5 of the GDPR.
Citation
GDPR
Art. 48, Recital 115