Wednesday, 15 November 2023

Thank you and farewell

After a period of silence it's now time to close this blog.  I've lost the motivation I once had to put my head above the data protection parapet. I'm no longer deeply engaged in issues that filled my working life and these days am much more interested in providing a decent home for my puppy. Others can engage in endless battles with people whose views are so very different to my own. I'm happy with the changes I've managed to make over the years and will remain deeply frustrated that at other times I failed to act in ways that might have made lives easier for other people. Occasionally the stress of dealing with issues that I still find hard to talk about affected me very deeply. But most times I've had a hugely enjoyable career.

I've reached the stage where I no longer want to work as a data protection professional. I can't motivate myself to maintain or even pretend to have an interest in matters that many data protection professionals feel they need to be concerned about. Looking back at my work pattern and output I have realised that so much of the daily grind was so unnecessary.

Thank you for your good wishes and support over the years that the blog has been active. 


Friday, 22 July 2022

Personal Data Breach Notification – it's time to scrap the unfair rules that have been imposed on Communication Service providers

 

In August 2013 the European Commission introduced new rules to require Communication Service Providers to report all personal data breaches, no matter how minor, to local data protection regulators within 24 hours of the incident being detected [Art 2]. Reporting delays would result in providers being subject to ICO fines. Significant breaches were also required to be reported to the impacted individuals [Art 3].

The new rules also required the European Commission to report by 2016 on the effectiveness of these new rules and their impact on providers, subscribers and individuals. On the basis of that report, the Commission would review the rules. I’m not aware that such a report was ever published, however. If it was, I can't find it

This was the European Commission’s first attempt at mandatory breach notification. The coming into force of the GDPR resulted in breach notification rules being extended to organisations in all economic sectors, although these organisations were permitted a longer time to report (within 72 hours of the incident being detected) and they were able to use their discretion not to notify data protection regulators of minor incidents. 

I’m well aware of the huge administrative burdens that these rules imposed on providers, and the awful pressure (and long hours) put on people who often worked late into the night to submit (mostly) pointless breach reports on the ICO’s breach portal every day. Yes, it gives the ICO’s enforcement staff something to do each day, but I trust that the ICO’s new strategy will recognise the futility of this mindless work, and that it can see the value in being able to redeploy staff to more significant tasks.

It’s time for a Brexit dividend. 

It’s time that organisations in all economic sectors are subjected to the same breach notification rules.

It’s time for the Data Protection and Digital Information Bill to be amended to abolish the old rules and require providers to adopt the data breach reporting rules that apply in all other sectors. 

It's time for the DCMS to admit that it was a mistake not to include this provision in the Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019. It's depressing to read the draft SI's Explanatory Memorandum and learn that no formal consultation took place with providers on this specific matter. Evidently the unfair breach reporting rules are deficiencies that are 'minor in nature' - so providers should put up with them.

I say no, these unfair rules should go.

Goodbye and good riddance, Commission Regulation 611/2013!

Sunday, 21 March 2021

My Top Tips for the UK’s Next Information Commissioner

 


The UK’s data protection community isn't easy to please. Privacy is big business these days, and many of its opinion formers take to social media platforms to generate noise and controversy. 

 

Why? 

 

Because noise and controversy sells. It sells seats at privacy conferences and it sells consulting time – which can be dangerous when there are no entry barriers to the privacy consulting trade. Noise and controversy are also the lifeblood of the privacy NGOs. Most exist to please their funders, so expect fireworks from these folks, too. 

 

Amidst the privacy hype and noise, here are my top tips to make your life less challenging than it otherwise will be:

 

1.    Work from Wilmslow. Many privacy pros may work remotely, but you've been selected to set an example and to lead from the front. You will have a huge team at your disposal and they need to know that you’re as committed to Wilmslow as they are.

2.    Embrace conflict. Whatever you try, you’re likely to be opposed, either from the privacy pragmatists or the privacy Taliban. Don’t take conflict personally. You’re just doing your job.

3.    Expect to be opposed from within the ICO, as well as from without. The organisation has grown so fast that it’s impossible to expect everyone in it to share the same outlook as you. You may not even realise how you are being undermined you until some brave DPO quietly shares with you their experiences of working with your staff.

4.    Don't think you will get it right all the time. Key parts of privacy laws are in a right mess, and any attempt to help clarify or simplify the law can easily backfire, especially if it requires primary legislation.

5.    The UK may have left the EU, but it hasn't (yet) escaped from the acquis of European privacy law. In helping deliver the Government’s National Data Strategy, it’s OK to embrace a ‘UK First’ approach. You are the UK’s Information Commissioner. You are not someone who has been parachuted in to challenge British values.

6.    Relax. The £200,000 salary won’t adequately compensate you for what you will experience, but you’ll only serve a single seven-year term in office. By the end, you’ll (probably) have received a nice gong and a lucrative offer from another organisation.  

 

 

 

 

source:

https://tinyurl.com/5x635y55


Monday, 9 November 2020

The EU’s draft Data Governance Act: an own goal?


The EU’s draft Data Governance Act is designed to facilitate the greater sharing of non-Personal data within the EU. Such big data ought to provide new insights and benefit the lives of EU citizens, the EU thinking goes. 

 

The Act is also designed to prevent access and use by non-EU based data intermediaries such as those that may be established in the UK, or elsewhere in the world. 

 

Will this prohibition result in UK-based organisations operating at a competitive disadvantage? They won’t be entitled at act as data intermediaries. Conversely, the EU-established data intermediaries will face difficulties in tapping the deep talent pool of non-EU based information experts.  

 

Might this prohibition result in UK-focussed data services operating at a comparative disadvantage? The AI-based service models that will be developed for the benefit of UK citizens won’t be able to take advantage of the training data available to EU-focussed service providers.

 

Why is it in the best interests of the EU to adopt this protectionist model? Isn’t it better for the EU to develop a partnership model with, rather than discriminate against non EU-based entities?

 

Discrimination based on the geographic location of the data intermediary / service provider reinforces the concept of a ‘Fortress Europe’. EU member states will run the risk of operating within a walled garden that delivers fewer benefits to citizens than would be the case if there were no barriers. I remember the direction that populations migrated when the Iron Curtain fell in 1991. They travelled west, towards a society that offered greater choices and a higher quality of services. Very few travelled to the east, further into the Soviet Union.

 

The EU has managed, with the passing of the GDPR, to adopt data protection standards that are virtually impossible for many organisations to fully comply with. Accordingly, I wouldn't be at all surprised if the EU were to follow it up with legislation that made it equally hard for European citizens to be able to take full advantage of the insights that can flow from the processing of non-personal data.



Friday, 16 October 2020

Is it still necessary for data protection laws to have particular processing rules for specific types pf personal data?


I think not.

 

1.    European laws have special rules for the processing of “sensitive data” or “special category data” regardless of the context within which the data will be processed. This has been the case in the UK since the coming into force of the first (1984) Data Protection Act. But, just because it is an established concept, there is no reason not to ask whether the distinction is still appropriate.

 

2.    The existing list of special category data, which has its origins in the types of characteristics that were used in the last century to discriminate against minority groups, does not properly reflect today’s values. It is difficult, say, to justify the exclusion of an individual’s financial details, or their web browsing history, given the increasingly on-line lives that most UK citizens lead. If asked, many people might argue that such information was far more sensitive than information relating to their trade union membership, ethnic origin or religion.

 

3.    Some countries that have already enacted data protection laws that do not recognise the concept of special category data. Indonesia, Hong Kong and Singapore are examples of such countries. I am not aware of calls from citizens of those countries to amend local laws to develop special rules for particular categories of personal data.

 

4.    Some countries have extended their lists of special category data beyond those set out in European law. Some countries include financial information. Kenya’s definition includes an individual’s property details, marital status, family details including the names of their children, parents, spouse or spouses. However, it is not yet clear how this expanded definition actually improves privacy protections for individuals.

 

5.    The key practical impact of the processing of special category data for data controllers is that an additional processing condition needs to be identified – but in my experience, Governments have historically been quite willing to pass secondary legislation to create a new condition to legitimise the processing when it has been too hard to link the processing purpose with an existing condition, and when consent is not an appropriate option. Eliminating this category of personal data will negate the need for secondary legislation to be developed.

 

6.    Eliminating the definition of this category of data will not, of itself, reduce the privacy protections that individuals enjoy. The UK GDPR does not alter the wording of the first half of Article 24 of the GDPR. Data controllers should still be required to take into account “the nature, scope context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.”  Article 24 goes on to provide that controllers must also “implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation.” In my view, it is entirely possible for the UK to implement appropriate measures which provide robust privacy safeguards even if Article 9 of the GDPR is removed from UK law. 



Tuesday, 13 October 2020

Why have I joined the LinkedIn Data Protection Reform Group?


1.    There is an ongoing debate on the rights that data controllers should have, compared with the rights that private individuals should have. There’s also an ongoing debate on what role our national Data Protection supervisory authority should play in developing and enforcing privacy laws. Opposing views are passionately, genuinely and sincerely held, & I see little prospect of agreement on a middle course. But, I see no reason for declining to contribute to policy discussions just because I know that others will disagree with me.

 

2.    Many opinion formers believe the GDPR is a gold standard containing data protection requirements that all countries should aspire to, and that any deviation from the GDPR necessarily dilutes privacy protections / rights to an unacceptably low level. I disagree. I see the GDPR as a step too far. The provisions impose very considerable administrative burdens on many data controllers, not all of which do much, if anything, to respect legitimate privacy rights.

 

3.    During the long discussions in the early part of the last decade which eventually led to political agreement amongst EU nations that the GDPR should be adopted, the UK’s negotiating team frequently argued against the imposition of onerous and bureaucratic provisions which set out in considerable detail how organisations should be required to run their privacy programmes. The UK now has an opportunity to review these initial reservations and develop laws that allow a more pragmatic approach which still delivers robust privacy protections for individuals. Some commentators do not wish to reopen these discussions. I disagree. Where there is evidence that the current provisions are unduly onerous or unworkable, we should ask whether there a business case exists to alter them.

 

4.    Complexity is costly.  The more complex the rules are, the more resources may be required to provide assurance about the extent the organisation fully complies with the rules. Complexity provides consulting organisations with a stream of work, but it hinders smaller organisations that can’t access tailored compliance advice. Complexity also frustrates individuals who try to exercise information rights, only to learn that obscure exceptions to the rules actually result in them having fewer rights than they realised. 

 

5.    Data protection should be fun. Our relationship to work is one of the most important things in our lives. We should query the motives of those that have used the GDPR to develop vast bureaucracies that are ultimately pointless. While the key to corporate success is convincing people that you are worthwhile, I meet an increasing number of privacy professionals are experiencing burnout. They feel trapped in a system that makes their work seem both joyless and endless.  

 

Sunday, 4 October 2020

Revise the GDPR


We are what we are
We don't want praise, we don't want pity
We bang our own drum
Some think it's noise, we think it's pretty
We promise that your human rights we will not mangle
We're the ones that try to see things from a different angle
Join us we’re going far
Join us and shout out
Revise the GDPR

 

We are what we are
And what we are needs no excuses
We’ll find a new way 
To cut out spam, stop data abuses
Our private lives, there's no consent you get no look in
Our private lives, you can't tell anyone where we’ve been 
Life's not worth a damn till we can shout out
We are what we are


We know what we want

Revise the GDPR

 

 

Thank you for the inspiration: Jerry Herman



 

Friday, 2 October 2020

My (data) fine is enormous


I am he as you are he as you are me and we are all together
See how they stun the world and my mum, see how they fine
I'm crying

 

Sitting in the courthouse, waiting for the man to come
Covid mask and goggles, stupid bloody Tuesday
Man, you been a naughty boy, you set your cookies wrong

 

I am the bad man, I spammed some good men
My fine is enormous, goo goo g'joob

 

Mister lead prosecutor sitting
Pretty little lawyers in a row
See how they drone “he should have known,” see how they fine
I'm crying, I'm crying
I'm crying, I'm crying

 

Instagram emojis 

Springing out from every screen
Acting like a fishwife, pornographic poses
Boy, you been a naughty girl you let your knickers down

 

I am the bad man, I spammed some good men
My fine is enormous, goo goo g'joob

 

Scrolling through new adult websites waiting for the one
Maria from Leeds, click accept
Far too old, I could have wept

 

I am the bad man, I spammed some good men
My fine is enormous, goo goo g'joob g'goo goo g'joob

 

Expert textpert smarmy barmy
Don't you think that lawyer laughs at you?
See how they smile, just fees on their mind
See how they charge
I'm crying

 

Hey Maria Pilchard,

Want a present for your baby shower?
Curtains for your bedroom, buy a family heirloom 
Have another go at blocking Edgar Allan Poe

I am the bad man, I spammed some good men
My fine is enormous, goo goo g'joob g'goo goo g'joob
Goo goo g'joob g'goo goo g'joob g'goo

 

 

Thank you for the inspiration: John Lennon, Paul McCartney & John Bowman

 

 


Sunday, 13 September 2020

Breaching the GDPR

 


Early train from Euston, just a croissant and two teas

Didn't get to eat last night

Who today will I see pleading on their knees
Liz, I had a dreadful fright
I've breached the GDPR
You don't know how lucky you are, boys
Breaching the GDPR

 

Been away so long I barely know the place
BC, it's good to be back home
Don't make me pack my case
Honey disconnect the phone
I'm fed up with the GDPR’s ploys
You don't know how lucky you are, boys
Breaching the GD

Breaching the GD

Breaching the GDPR

Well paid lawyers really knock me out
Leaving my team far behind
Privacy geeks make me scream and shout
Max Schrems is always on my my my my my my my mind
Oh, come on
Will I miss you when I’ve gone
Yeah, yeah, yeah, yeah

I'm fed up with the GDPR’s ploys
You don't know how lucky you are, boys
Breaching the GDPR

 

Show me your spreadsheets – all objectives coloured green 
Despite your breach there’s not a red box to be seen
You’re good at compliance – almost visionary
Let them off the hook, a fine isn’t necessary

Walking to the station, need a sandwich and a tea

Shouldn’t get so uptight 
I guess they don’t really care much for me
Wilmslow is not a delight
I’m done with the GDPR’s ploys
Hey, you don't know how lucky you are, boys
Stuff the GDPR

 

Thank you for the inspiration: John Lennon, Paul McCartney

 


Friday, 11 September 2020

Adequacy

 


In data protection law, transfers of personal data must be safeguarded by written contracts between the parties. If the personal data is transferred from the EU to a country which the European Commission has not been recognised as having adequate data protection standards, special clauses, known as SCCs are usually inserted in these contracts. In July 2020, a decision by the European Court of Justice made it virtually impossible for companies to determine whether the SCCs must be supplemented by additional clauses to ensure the personal data is appropriately protected.

 

From the beginning of 2021, the UK Government will have the ability to make it easier for UK data exporters to know what the UK’s data protection rules are. This ode assumes that the UK Government will rise to the challenge.  

 

My my
At Waterloo, Max Shrems we didn’t surrender
Oh yeah
And we will meet our destiny in quite a cunning way
The statute book on our shelf
Is always repeating itself

Adequacy – You were defeated, we won the war
Adequacy - Promise to love us for ever more
Adequacy - Couldn't escape if you wanted to
Adequacy - Knowing our fate is to be with you
Adequacy - Finally facing your Waterloo

 

My my
Noyb tried to hold us back, but we were stronger
Oh yeah
And now it seems your only chance is giving up the fight
How could you ever refuse
Shouldn’t claim that you win when you lose

Adequacy – We are the ones that will make it clear
Adequacy – Saying the words they all want to hear
Adequacy – Contracting with us is such a breeze
Adequacy – Doing away with SCCs
Adequacy - Finally facing your Waterloo

 

How could you ever refuse
Shouldn’t claim that you win when you lose

 

 

Thank you for the inspiration: Benny Goran Bror Andersson, Stig Anderson, Bjoern K. Ulvaeus, Lo-jung Chen, He Cheng, Yi Jia & John Bowman



Friday, 21 August 2020

What mixture of leadership styles should a decent data protection officer display?

 


I was recently asked this question and found it hard to answer. It takes a lot to be a decent DPO.  So much depends on the culture of the organisation and the resources available to the DPO. Notwithstanding the specific obligations that are set out in Section 4 of the General Data Protection Regulation, I’ve known some that operate as one-man-bands, working in virtual isolation from the rest of the organisation. I’ve known others who manage small and, in some cases, larger teams. I’ve also known privacy professionals who have directed or supported short-lived GDPR privacy transformation project teams that were created purely to help the organisation comply more completely with data protection laws and requirements.

 

The organisational psychologist Heather Bingham has drawn my attention to a list of common leadership styles that I'll be referring to in this article.

 

I’ve known privacy professionals who have failed because they have displayed a toxic mixture of some of these styles. 

 

I’ve also known privacy professionals who have felt that they have failed because, when joining a new organisation, they had not altered what was a winning combination in a previous role to the culture that prevailed within their new organisation.

 

Autocratic

Some organisations have a very hierarchical and deferential culture. Job grade is seen as more important than actual technical knowledge, so the purpose of the DPO may be primarily to reduce quite complicated concepts to simple PowerPoint presentations for more senior people with little technical knowledge to skim read and formally approve whatever recommendations the DPO had drafted. The autocratic DPO may exist because virtually no one else in the organisation has sufficient knowledge – or interest – in data protection matters, so their decisions will be very rarely challenged. While competent DPOs may have the technical knowledge and experience to make quick decisions quickly, they can also easily be overwhelmed with requests for advice and support. It’s hard to motivate staff in privacy teams if all the decisions are going to be taken by an autocratic DPO. 

 

Charismatic

Great DPOshave vision and can influence and inspire others. This requires a mixture of technical skills and also a willingness to accept a relatively high privacy risk. What advice or action really is appropriate, given the circumstances? It is not always the best approach simply to reply on every piece of advice that is uttered by staff working for data protection supervisory authorities. Regulatory opinions are what they say they are – only opinions. Ultimately, only the courts can determine the true extent of privacy law. This approach requires DPOs to develop their own ethical approach to key issues of the day, and then sell this approach to the organisation. The late comedian Ken Dodd once remarked that he never took his audience for granted. For each performance he felt he needed to start afresh and woo them. The same approach is often adopted by charismatic DPOs. 

 

Transformational

Some DPOs focus on outcomes. Teams must strive to work harder each year. More Subject Access Requests, for example, must be completed within the statutory time limits. Fewer privacy breaches must be identified. Records of Processing Activities must be regularly audited. A higher proportion of staff must pass the annual privacy learning programme’s knowledge test. Turnarounds for Privacy Impact Assessments must be improved, year on year. The daily grind of privacy work can be relentless, and while privacy metrics might improve, the morale of the staff at the privacy grindstone may not. 

 

Laissez-faire

An important way to promote accountability throughout an organisation is to educate and then devolve privacy decisions to others. This gives them an opportunity to better appreciate the privacy consequences of the decisions they take, particularly if they are then required to accept responsibility – and perhaps even apologise personally to those who have suffered as a result of their misjudgements. I’ve found that this approach also gives individuals a greater sense of pride in their daily work and in the decisions they take.  With effective supervision from the DPO, organisations can develop a strong culture of compliance that stands a good chance of being maintained when said DPO departs for pastures new.

 

Transactional

I’ve met few privacy staff who have job profiles that are supported by comprehensive operating instructions which explain precisely how each privacy task for which they are responsible should be completed. The absence of comprehensive sets of operating instructions can lead to inconsistencies in approach within privacy teams. When Privacy Impact or Privacy Breach Assessments, for example, are carried out by different members of staff, perhaps working in different locations, a lack of clear instructions explaining how to weight particular privacy risks can result in very different sets of privacy recommendations being made. Effective DPOs will ensure that comprehensive manuals exist to safeguard against inconsistent approaches. This approach enables staff to feel more confident that they are doing the right thing when they carry out their privacy tasks. 

 

Supportive

Many DPOs find the time to coach their colleagues and direct reports, which is often the only way that they are eventually able to offload some their privacy work to anyone else within the organisation. Nurturing these supportive relationships takes considerable effort, though. It often takes some time for the privacy message to sink in. Some elements of privacy law, including a good few of the technical requirements that are set out in the GDPR, are not easy to comprehend.  DPOs many also find great value in engaging with support networks created by organisations such as the Data Protection Forum, NADPO and the IAPP KnowledgeNets. There is safety in numbers – or at least safety in appreciating that a DPO’s approach to a particular privacy issue is very similar to that adopted by their professional colleagues. 

 

Democratic

Some DPOs prefer an inclusive approach, where all the key decisions are taken by committees.A weakness with this approach is that key decisions can be delayed until the issues have been considered by the committee members. There is also a risk that other corporate stakeholders, if their personalities are sufficiently strong, can override the reasoned assessments that DPOs make when forming their recommendations. DPOs must always know when to accept that their advice will be ignored. But so long as this has been properly documented, and the advice had correctly interpreted the law, the organisation can’t then lay all the blame on the DPO should a data protection supervisory authority decide to take enforcement action for a privacy transgression that results from the organisation’s failure to act in accordance with the advice.

 

 

I’ve also met privacy professionals who are just too tired to care too much about how they perform their day job. The demands placed upon them by their employers, and by virtue of the GDPR, have in some cases been overwhelming. Burnout certainly exists within the privacy profession.  


 

Wednesday, 19 August 2020

International data transfers: an opinion the EDPB (probably) won’t publish

One of the consequences of the Scherms II decision is that EU organisations need to take greater care in determining how best to protect the flows of personal data outside the EU. This means more than just considering whether Standard Contractual Clauses (SCCs) need to be incorporated in the contracts that the data exporters negotiate with the data importers. Historically, most data flows from the EU to non-adequate countries have been safeguarded though the use of SCCs. 

 

Following the decision, life isn’t as simple as that. The CJEU has said that EU organisations relying on SCCs must also, prior to transferring personal data, evaluate whether there is a an “adequate level of protection” for personal data in the importing jurisdiction, and implement additional safeguards if there is not.  Data exports must cease when there are no additional safeguards that would ensure an “adequate level of protection.” 

 

A non-exhaustive list of elements that should be taken into account by the European Commission (EC) when assessing adequacy is set out in Article 45.2 of the GDPR. Article 45.3 requires each assessment to be regularly reviewed, at least every 4 years. Presumably EU exporting organisations should also adopt this approach.

 

This will cause an immense amount of work for each EU exporting organisation. In reality, it is likely that only the largest organisations will have the resources to commission such work, and each organisation could well use different criteria, in addition to the non-exhaustive list of elements set out in Article 45.2,  to determine what an “adequate level of protection” actually means in practice. Such work will lead to chaos and inconsistency. This is surely not what the creators of the level EU data protection field had in mind. 

 

The decision also highlights the role of EU data protection supervisory authorities in assessing, and where necessary suspending or prohibiting data transfers to importing jurisdictions “where they take the view that the SCCs are not or cannot be complied with in that country and that the protection of the data transferred that is required by EU law cannot be ensured by other means.”

 

Given the role the decision requires the supervisory authorities to play, there will be intense interest in understanding precisely how the European Data Protection Board (EDPB) will encourage the supervisory authorities to adopt a consistent approach across the EU.  

 

In particular, the EDPB may be asked to publish an opinion which categorises Non-EU countries as follows:

 

1.    Countries that provide an adequate level of protection and where additional safeguards are not required;

2.    Countries that that provide an adequate level of protection when SCCs are put in place;

3.    Countries that that provide an adequate level of protection when SCCs and other specified safeguards are put in place;

4.    Countries that do not have provide an adequate level of protection even when SCCs and other specified safeguards are put in place.

 

There are more than 100 countries that have enacted data protection laws. But what work has been commissioned by the EC (or the EDPB or its predecessor body, the Article 29 Working Party) to determine which laws are of an ‘adequate’ standard? In the past 20 years, the EC has managed to reach adequacy decisions on a pathetically small proportion (perhaps some 15%) of the non-EU countries that have data protection laws: 

 

            2000    Switzerland

            2001    Canada

            2003    Argentina & Guernsey

            2004    Isle of Man

            2008    Jersey

            2010    Andorra & the Faroe Islands 

            2011    Israel 

            2012    New Zealand & Uruguay

            2019      Japan 

 

Almost half of the decisions relate to tiny countries with relatively small volumes of personal data flows: Andorra (population 78,000); Faroe Islands (population 52,000); Guernsey (population 63k); Isle of Man (population 83,000); and Jersey (population 107,000). Work on carrying out assessments of the data protection laws of many of the EC’s key trading partners does not appear to have commenced.

 

Such an opinion would be of immense value to EU organisations in helping them develop a consistent approach to transborder data flows, but it would be political dynamite. Which countries would the EDPB dare describe as not providing an adequate level of protection even when SCCs and other specified safeguards are put in place? Given the international trade repercussions for the EC, it would be a brave decision to put any country into that category. 

 

But what additional safeguards are necessary to supplement SCCs and when need they be put in place? Given how inflexible so many parts of the GDPR are, it would be surprising that there was not a demand from some stakeholders for new rules to be established to address the privacy risks of the countries that fell within these categories.

 

If it is left to the EDPB to recommend an approach and to categorise non-EU countries as I have suggested, I suspect that political considerations will result in EU organisations waiting a very long time before such an opinion would emerge. 

 

 

 

[Image credit: thanks to the CNIL for their helpful guide to data protection laws around the world. Other organisations, such as DLAPiper, have great on-line resources, too]