×
Wednesday, September 30, 2026

EU's Standard Contractual Clauses for Cross Boarder Data Transfers - The National Law Review

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

  • Background. Company A is an EEA controller that utilizes Company Z, a processor based in Country Q. Company Z does not have a legal presence in Country R, but does have an employee that works remotely from Country R (e.g., a remote worker).

  • Transfer 1: SCC Module 2. The cross-border transfer of personal data from the EEA to Country Q should utilize the SCC Module 2 designed for transfers from a controller to a non-EEA processor.

  • Transfer 2: No Mechanism Needed. The EDPB has suggested that when a company transmits personal data to an employee that is located outside of the EEA the transmission does not constitute a “transfer” of personal information for purposes of Chapter V of the GDPR because the data has not been sent to a separate controller or processor.[1] While the EDPB provided, as an example, the use-case whereby an employee travels for work to India where they remotely accesses personal data from the EEA, this rationale presumably also applies to other remote-work situations such as where an employee resides in a non-EEA country, or where the remote employee downloads personal data (as opposed to remotely accessing such data). While the example provided by the EDPB involved a European company sending data to an employee outside of the EEA, the rationale utilized...



Read Full Story: https://news.google.com/__i/rss/rd/articles/CBMicmh0dHBzOi8vd3d3Lm5hdGxhd3Jld...