×
Wednesday, September 30, 2026

New Standard Contractual Clauses Analysis of Cross Border Data - The National Law Review

The following is part of Greenberg Traurig’s ongoing series analyzing cross-border data transfers in light of the new Standard Contractual Clauses approved by the European Commission in June 2021.

  • Background. Company A is an EEA controller that utilizes Company Z, a processor based in Country Q. Company Z does not have a legal presence in Country R,but does have an employee that is on a personal vacation in Country R and receives personal information while on vacation.

  • Transfer 1: SCC Module 2. The cross-border transfer of personal data from the EEA to Country Q should utilize the SCC Module 2 designed for transfers from a controller to a non-EEA processor.

  • Transfer 2: No Mechanism Needed. The EDPB has suggested that when a company transmits personal data to an employee that is located outside of the EEA the transmission does not constitute a “transfer” of personal information for purposes of Chapter V of the GDPR because the data has not been sent to a separate controller or processor.[1] While the EDPB provided, as an example, the use-case whereby an employee travels for work to India where he or she remotely accesses personal data from the EEA, this rationale presumably also applies to other remote-work situations such as where an employee goes on a personal vacation in a non-EEA country, or where the remote employee downloads personal data (as opposed to remotely accessing such data). Although the example provided by the EDPB also involved a European company...



Read Full Story: https://news.google.com/__i/rss/rd/articles/CBMibWh0dHBzOi8vd3d3Lm5hdGxhd3Jld...