Best Practice Update

International Data Transfers (part 1):  Navigating Cross-Border Data Transfers: Understanding EU SCCs, UK Addendum, and UK IDTA

The first in a seriers on International Data Transfers..
Navigating Cross-Border Data Transfers: Understanding EU SCCs, UK Addendum, and UK IDTA

In the ever-evolving landscape of global data protection, we are continually challenged to ensure the secure and lawful transfer of personal data across borders. The European Union (EU) has long been a frontrunner in establishing data protection standards, and its regulations have far-reaching implications for those engaged in cross-border data transfers.

Whilst you may think that you do not transfer data overseas and therefore do not need to consider this, many of the suppliers used in schools do.

  • Two crucial mechanisms that play a pivotal role in this scenario are the EU Standard Contractual Clauses (SCCs), the UK Addendum and the UK International Data Transfer Agreement (IDTA). In this blog, we will delve into these mechanisms, aiming to demystify their significance and shed light on how they influence our data protection practices:
EU Standard Contractual Clauses (SCCs):

The EU SCCs have been a fundamental tool for ensuring the lawful transfer of personal data outside the European Economic Area (EEA). These standard contractual clauses, approved by the European Commission, set out a legal framework that binds both the data exporter and the data importer to uphold EU-level data protection standards and avoid the need for lengthy bespoke Data Processing Agreements.

The SCCs address key principles such as purpose limitation, data minimisation, and the rights of data subjects, providing a standardized approach to safeguarding personal data in transit.

UK Addendum:

As the United Kingdom formally exited the EU, it has charted its course in data protection. The UK Addendum is a crucial element in this regard, serving as an additional layer to the existing EU SCCs when transferring personal data from the UK to a third country. Organisations engaging in such transfers must ensure compliance with both the EU SCCs and the UK Addendum, navigating the intricacies of dual regulatory landscapes.

The UK Addendum aligns with the principles outlined in the EU SCCs, emphasising the need for data protection measures that meet the UK's high standards. Organisations need to incorporate the UK Addendum into their data transfer agreements to seamlessly adhere to both EU and UK data protection requirements.

UK International Data Transfer Agreement (IDTA):

To streamline international data transfers post-Brexit, the UK has now introduced the International Data Transfer Agreement (IDTA). This framework facilitates the exchange of personal data between organisations within the UK and counterparts outside the country. The IDTA incorporates principles akin to the EU SCCs, ensuring that data protection standards are maintained during cross-border transfers.

Organisations can leverage the UK IDTA as an alternative to the EU SCCs when transferring data from the UK to a third country. 

In the intricate world of cross-border data transfers, staying abreast of regulatory developments is paramount for organisations striving to maintain compliance and uphold data protection standards.

The EU SCCs, UK Addendum, and UK IDTA represent vital tools in this ongoing journey, offering a structured framework to navigate the complexities of international data transfers.

If you have any questions surrounding your existing contractual relationships with suppliers where international data transfers are required or are considering a new supplier based overseas, please get in touch. We would be happy to support you in conducting due diligence to ensure an appropriate legal framework is in place to facilitate a secure data transfer.

Robot wearing an orange hoodie holding a piece of paper with the words Data Protection education is transparent text

This week the IAPP published a set of AI privacy risks in the wake of concerns over how AI should be regulated.  There are moves to regulate AI, such as the EU AI Act, however  because AI remains quite an unknown quantity, there is a lot of unease and uncertainty around it's use, ethics, privacy and intellectual property.

  1. School Focus: St Bernadette's Catholic Primary School | Brighton
  2. Guardians of Privacy: 16. Social Media Checklist
  3. Guardians of Privacy: 15. Navigating Social Media in Educational Settings Summary
  4. Guardians of Privacy: 14. Social Media and Cyber Bullying
  5. Guardians of Privacy: 13. Social Media, Copyright and Intellectual Property
  6. Guardians of Privacy: 12. Social Media and Going Viral
  7. Guardians of Privacy: 11. Staff Social Media Accounts
  8. Guardians of Privacy: 10. Social Media and Cookies
  9. Guardians of Privacy: 9. Social Media and Morality
  10. New Resources for Schools from the ICO
  11. Guardians of Privacy: 8. Social Media Policies
  12. Guardians of Privacy: 7. Social Media Data Retention
  13. Guardians of Privacy: 6. Posting Safely
  14. Guardians of Privacy: 5. Social Media and Consent
  15. Guardians of Privacy: 4. Social Media Access Control
  16. Guardians of Privacy: 3. Social Media Channels
  17. Guardians of Privacy: 2. Law and Regulations
  18. The ICO reprimands a Multi Academy Trust
  19. Guidance for the use of school email and applying email retention in schools
  20. Data Protection Tips for Early Years Settings
  21. Children's Privacy around the world is a puzzle
  22. Trust Initial Plan Checklist Update
  23. Records Management Best Practice Update
  24. What do I need to redact?
  25. Trust Initial Plan for Data Protection Compliance (for Multi Academy Trusts)
  26. Google for Education Resources: Helping IT Admins meet DfE digital and technology standards
  27. Lettings Best Practice and Guidance
  28. Considerations when migrating to a new MIS
  29. Public bodies and sensitive data
  30. Get a DPE Badge for your website!
  31. ICO: 10 Step guide to sharing information to safeguard children
  32. Help after a Cyber Attack/Incident
  33. Data Protection and Cyber Security (Inset Day) Training Ideas
  34. How KCSIE is linked to Cyber Strategy
  35. Handling Freedom of Information Requests the right way
  36. Where's Harry the Hacker?
  37. The ICO Reprimands a school
  38. Redaction Guidelines Updated
  39. Using WhatsApp in Schools
  40. How to contact us for support, subject access requests, data breaches and FOI's
  41. FOI: Reinforced Autoclaved Aerated Concrete
  42. FOI: Henry Jackson Society
  43. FOI: Vaccination Justifications
  44. How the Record of Processing Can Help You
  45. What does a Data Protection Officer Do?
  46. Carrying out Supplier Due Diligence
  47. How Long Should You Keep Personal Data For?
  48. B&H FoI: Racist/religious incidents/bullying
  49. Protocol for Setting Up and Delivery of Online Teaching and Learning
  50. Class Dojo International Data Sharing
  51. Model Publication Scheme: Amendments, Improvements and Updates
  52. Transparency
  53. Research projects and GDPR
  54. Secure file transfer of files using Royal Mail
  55. Emergency contacts and consent
  56. Key elements of a successful DPIA
  57. FOI Publication Schemes
  58. Best Practice for Managing Photos and Video
  59. New Drip Feeds: Recognise and Respond to Subject Access Request
  60. When to contact the Data Protection Officer?
  61. National child measurement programme
  62. Headteacher fined for breach of data protection legislation
  63. Acceptable Use Policy

Search