What was the purpose of the 1995 Data Protection Directive?
Set the foundation for EU data privacy laws.
What was the Safe Harbor Agreement?
2000 U.S.-E.U. agreement allowing data transfers if US companies followed EU-like privacy protections.
Why was Safe Harbor invalidated?
Schrems I case following Snowden’s 2013 revelations about NSA surveillance.
What replaced Safe Harbor in 2016?
E.U.-U.S. Privacy Shield
What happened in Schrems II?
What is the E.U.-U.S. Data Privacy Framework?
2023 agreement addressing concerns from Schrems II, includes EO 14086.
What is EO 14086?
What is a ‘third country’ under EU law?
Country outside EEA without an adequacy decision.
What are the three legal bases for EEA data transfers?
What are Standard Contractual Clauses ?
(SCCs)
Contractual promises by companies to follow EU data protection law.
What are Binding Corporate Rules?
(BCRs)
DPA-approved rules allowing intra-group data transfers under strict conditions.
What is a derogation under EU data transfer rules?
Legal exception
Examples: explicit consent or legal necessity, for occasional transfers
What is the Global CBPR Forum?
Cross-border privacy certification system, based on APEC principles.
What does the OECD Declaration on Data Access cover?
Government access to private data.
Examples: legal basis, transparency, oversight, remedies.
What is the GDPR?
Which countries are part of the EEA?
EU + Norway, Iceland, Liechtenstein
What are key provisions of GDPR?
What is personal data under GDPR?
Data related to an identified or identifiable person.
What is sensitive personal data?
What is required to process sensitive data?
Explicit consent for specific purpose.
Who is a data subject?
The individual whose data is collected.
What are the four consent requirements under GDPR?
What info must be disclosed by data controller for informed consent?
What is a Data Protection Authority?
(DPA)
Independent national bodies that enforce GDPR and offer guidance.