UK data protection law restricts the transfer of personal data to countries outside the UK. The restriction, together with fast-moving developments to the rules, can present a challenge for international commerce, global data processing and international outsourcing activities.
This course provides a practical approach to the different mechanisms available to comply with the data protection rules relating to international data transfers. It assists delegates to understand the legal options when considering international transfers and to identify the most appropriate solution to the challenges faced by their organisation.
The course covers:
- identifying a restricted transfer of personal data
- the countries that have been determined as “adequate” for the purposes of international transfers
- the options for ensuring that transfers are lawful
- how to undertake a transfer risk assessment (‘TRA’)
- standard contractual clauses (‘SCCs’) as a method of overcoming the restrictions, and the key provisions of UK-approved SCCs
- other safeguarding methods for legitimising international transfers, including binding corporate rules, codes of conduct and certifications
- options and risks for transfers to the United States
- exceptions to the need for safeguards, including the feasibility of seeking consent, or assessing whether a transfer is necessary for a contract with an individual
- the advantages and disadvantages of the various legitimising options in different contexts, such as regular intra-group transfers, outsourcing of functions, use of cloud providers, and one-off transfers
Delegates will assess the rules and options in the context of practical scenarios, and will acquire the knowledge needed to determine the effective methods for ensuring the lawfulness of international transfers in different contexts in their own organisation.
It is recommended that delegates attending this session have a solid knowledge of general data protection legal requirements. Delegates with no existing knowledge may find it helpful to attend Data Protection Essential Knowledge – Level 1 and Data Protection Essential Knowledge – Level 2 before attending this training course.
Attendance on the Classroom and Virtual(Teams) formats of this course can be used as credit towards gaining the Practitioner Certificate in Data Protection (PC.dp.).
“I found the course materials, case studies, slides & quizzes particularly useful. The training was well thought out, well taught and detailed. Great session.”