The European and international transfer of data is one of the main topics since the coming into force of the General Data Protection Regulation (GDPR).
Recently, the European Data Protection Board (EDPB) launched the consultation on Guidelines 04/2021 on codes of conduct as tools for Transfers (end date of the consultation: October 2021) and on Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR (end date of the consultation: January 2022).
The first guidelines aim at clarifying Articles 40(3) and 46(2)(e) of the GDPR relating to codes of conduct as appropriate safeguards for transfers of personal data to third countries and complementing the previous EDPB Guidelines on codes of conduct published in 2019.
The second guidelines aim at assisting controllers and processors in the European Union in identifying whether a processing operation constitutes an international transfer and at providing a common understanding of the concept of international transfer. The Guidelines specify three cumulative criteria that qualify a processing as a transfer: (1) the data exporter (a controller or processor) is subject to the GDPR for the given processing; (2) the data exporter transmits or makes available the personal data to the data importer (another controller, joint controller or processor); (3) the data importer is in a third country or is an international organisation.
The ongoing consultation is aimed at gathering comments and contributions from the public before finalising the Guidelines.
