transfers of personal data from the third country or an international organisation to another
third country or to another international organisation. All provisions in this Chapter shall be
applied in order to ensure that the level of protection of natural persons guaranteed by this
Regulation is not undermined.
Art. 45 contains a procedure for the Commission to declare protective regime of
personal data in a third country “adequate” with the rules applicable in the EEA.
Adequacy decisions constitute per se a valid reason for transferring data to a third
country without a need for any further safeguards. The same procedure of declaring
adequacy of protection applied even before the GDPR came into effect and one
adequacy decision had already been taken down by the CJEU in a broadly
medialised case C-362/14 Maximillian Schrems v Data Protection Commissioner,
joined by Digital Rights Ireland Ltd.
Besides adequacy decisions, the GDPR formulates a handful of further legal titles
for transfers of personal data to third countries. They are listed in Art. 46 of the
GDPR that reads as follows:
1. In the absence of a decision pursuant to Article 45(3), a controller or processor may
transfer personal data to a third country or an international organisation only if the
controller or processor has provided appropriate safeguards, and on condition that
enforceable data subject rights and effective legal remedies for data subjects are available.
2. The appropriate safeguards referred to in paragraph 1 may be provided for, without
requiring any specific authorisation from a supervisory authority, by:
(a) a legally binding and enforceable instrument between public authorities or bodies;
(b) binding corporate rules in accordance with Article 47;
(c) standard data protection clauses adopted by the Commission in accordance with the
examination procedure referred to in Article 93(2);
(d) standard data protection clauses adopted by a supervisory authority and approved by
the Commission pursuant to the examination procedure referred to in Article 93(2);
(e) an approved code of conduct pursuant to Article 40 together with binding and
enforceable commitments of the controller or processor in the third country to
apply the appropriate safeguards, including as regards data subjects’ rights; or
(f) an approved certification mechanism pursuant to Article 42 together with binding and
enforceable commitments of the controller or processor in the third country to apply
the appropriate safeguards, including as regards data subjects’ rights.
3. Subject to the authorisation from the competent supervisory authority, the appropriate
safeguards referred to in paragraph 1 may also be provided for, in particular, by:
(a) contractual clauses between the controller or processor and the controller, processor
or the recipient of the personal data in the third country or international organisation;
or
(b) provisions to be inserted into administrative arrangements between public authorities
or bodies which include enforceable and effective data subject rights.
The GDPR also lays down procedural principle of one-stop shop for cases when
data processing takes place in multiple EU jurisdictions at the same time. In that
case, the GDPR constitutes the “lead supervisory authority” that coordinates investigation and issues a decision that is “directed towards the main or single establishment of the controller or processor” (see Para 126 of the Recital to the GDPR).
National Report: Czech Republic
155
Précédent

- 164/540

Suivant