Case Law Digest 2021: Transfers of personal data to third countries
From Lindqvist to Schrems II: case law of the CJEU on transfers of personal data to third countries
The transfer of personal data outside of the EU is only allowed under certain conditions as set out in Directive 95/46/EC and also in the General Data Protection Regulation which will be fully applicable as of May 2018. If a country is deemed by the European Commission to offer an adequate level of protection, it will be subject to the same rules as an EU Member State, which means that the recipient of the data in that state will not be obliged to take specific measures to allow for the transfer. Transferring data to a country without an adequacy decision requires appropriate safeguards, such as standard contractual clauses or binding corporate rules. Derogations to this rule can be obtained in very specific cases. The European Data Protection Board, of which the EDPS is a member, will provide the Commission with Opinions on this subject.
From Lindqvist to Schrems II: case law of the CJEU on transfers of personal data to third countries
EDPS Decision authorising, subject to conditions, the use of the administrative arrangement between the European Commission and the Turkish Medicines and Medical Devices Agency in the context of the Turkish participation in the EU regulatory system for medical devices Eudamed (Case 2021-0347)
The year 2020 was unique for the world and, by extension, for the European Data Protection Supervisor (EDPS). Like many other organisations, the EDPS had to adapt its working methods as an employer, but also its work since the COVID-19 health crisis strengthened the call for the protection of individuals' privacy.
This Annual Report provides an insight into all EDPS activities in 2020.
HTML Version: EN
EDPS Formal comments on the Proposal for a Regulation of the European Parliament and of the Council on serious cross-border threats to health and repealing Decision No 1082/2013/EU
EDPB - EDPS Joint Opinion 1/2021 on the European Commission’s Implementing Decision on standard contractual clauses between controllers and processors for the matters referred to in Article 28 (7) of Regulation (EU) 2016/679 and Article 29 (7) of Regulation (EU) 2018/1725