×
Wednesday, September 30, 2026

EU's Standard Contractual Clauses Apply to Data from Business Trips - The National Law Review

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

  • Background. Company A is an EEA controller that utilizes Company Z, a processor based in Country Q. Company Z does not have a legal presence in Country R, but does have an employee that is on a business trip in Country R and receives personal information while on that trip.

  • Transfer 1: SCC Module 2. The cross-border transfer of personal data from the EEA to Country Q should utilize the SCC Module 2 designed for transfers from a controller to a non-EEA processor.

  • Transfer 2: No Mechanism Needed. The EDPB has suggested that when a company transmits personal data to an employee that is located outside of the EEA the transmission does not constitute a “transfer” of personal information for purposes of Chapter V of the GDPR because the data has not been sent to a separate controller or processor.[1] The EDPB provided, as an example, the use-case whereby an employee travels for work to India where he or she remotely accesses personal data from the EEA. While the example provided by the EDPB involved a European company sending data to an employee outside of the EEA, the rationale utilized by the EDPB presumably applies where a company located in Country Q sends data to an employee located in Country R.

  • Transfer Impact Assessments. Clause 14 of the SCCs requires both parties...



Read Full Story: https://news.google.com/__i/rss/rd/articles/CBMibmh0dHBzOi8vd3d3Lm5hdGxhd3Jld...