Last year, the Court of Justice of the European Union (CJEU) ruled in the case “Schrems II“ ruling not only declared the transfer of personal data to the U.S. under the so-called Privacy Shield to be unlawful&but also determined that the instrument of Standard Data Protection Clauses (SDPCs) is not always sufficient under data protection law for data transfers to third countries.
On June 4, 2021, the European Commission therefore published &revised SCCs, which are intended to be in accordance with the GDPR and the requirements set forth in the “Schrems II” decision. Speaking to media representatives Didier Reynders, EU Commissioner for Justice and the Rule of Law, stated that improvements had been made in particular with regard to the aspects of transparency and accountability. This is intended to provide companies that transfer personal data to countries outside Europe with better legal recourse and more effective data protection measures.
In this context, Reynders once again emphasized that it remains the responsibility of companies to assess, when &transfer to third countries to assess whether standard data protection clauses are sufficient or whether additional measures are necessary to ensure an adequate level of data protection. As possible additional measures to protect personal data—for example, from government access—Reynders cited encryption or anonymization of the data.
A new feature of the new SDK is its modular structure, which addresses the possible configurations among the parties involved in transfers to third countries. While previous versions were still divided into two separate document templates, the new SDK requires the use of the corresponding modules. There are four modules in total:
Module 1: Transfers from Controllers to Controllers
Module 2: Transfers from Controllers to Processors
Module 3: Transfers from data controllers to data controllers
Module 4: Transfers from data processors to data controllers
Within these modules, it may be necessary to select suboptions, as is the case, for example, in Clause 9 (Use of Subprocessors) for Module 2: Pursuant to Clause 9(a) of the SDK, the controller may decide whether the processor must obtain prior authorization for the use of subprocessors (Option 1) or not (Option 2).
Once the clauses have been finalized with the correct modules and options, the appendices still need to be completed. This is where the bulk of the work takes place, as the annexes require information about data processing (Annex I) and, if applicable, a list of subprocessors (Annex III).
Annex II (Technical and organizational measures, including those to ensure data security) is particularly important. For Module 1 – 3, specific (not general) technical and organizational measures must be specified for each data transfer or category of data transfer. Annex II also lists possible measures for this purpose. However, this is merely a list of examples that is neither exhaustive nor should it be understood as a “to-do list” of necessary measures. This means that the contracting parties must thoroughly examine the data processing and define specific safeguards to ensure an adequate level of protection. In doing so, the nature, scope, circumstances, and purpose of the processing, as well as risks to the rights and freedoms of natural persons, must be taken into account. In this respect, Annex II will be the key to the SDKs.
Those working in data protection-related fields have long anticipated the update to the SDKs. This is because the first versions of the SDK were developed in 2010 under the Data Protection Directive and had not yet been updated in accordance with either the GDPR or the Schrems II ruling. In this respect, a new version of the SDK was long overdue.
Since the new version of the SDK has to “catch up” on roughly 11 years of rapidly evolving data protection law, it was to be expected that it would become more complex. This complexity is already reflected in its structure, which, however, also brings the advantage of new, regulated scenarios. The extent of this complexity and the practicality of the individual provisions of the SDK will become clear in future application practices.
One challenge will be defining appropriate technical and organizational measures. The Commission emphasizes that data protection must be taken seriously and that simple encryption or measures from a generic TOM catalog are not sufficient. Rather, stakeholders must jointly design the technical and organizational measures and work together to ensure an adequate level of data protection. It is to be hoped, however, that the European Data Protection Board or the national supervisory authorities will provide further guidance.
The original SDK (Decision 2001/497/EC and Decision 2010/87/EU) will be repealed on September 27, 2021 (Article 4(3) of the Implementing Decision on Standard Contractual Clauses).
For SDKs that have already been concluded and are based on the original SDK template, the European Commission has established a transition period of 18 months. (Article 4(4) of the Implementing Decision on Standard Contractual Clauses). The period ends on September 27, 2022.