Module 06 · GDPR in Procurement

Data transfers, breaches and sanctions

Transfers outside the EU - After Schrems II

Objective: Secure data transfers outside the EU and master the data breach notification process.

Sources

If your supplier is based outside the EU/EEA or uses sub-processors outside the EU, appropriate safeguards are mandatory:

🌐

Adequacy decision

The European Commission has recognised the country's adequate level of protection (e.g., Japan, Canada, United Kingdom, United States via the Data Privacy Framework)

📄

Standard Contractual Clauses (SCCs)

Standard clauses adopted by the European Commission. Must be supplemented by a TIA (Transfer Impact Assessment)

📋

Binding Corporate Rules (BCRs)

For multinational groups transferring data between entities within the same group

🚨 Data breach - Notification cascade

D+0
Discovery of the breach by the supplier
+24h
Notification from supplier to buyer (contractually recommended)
+72h
Mandatory notification from buyer to the CNIL (Art. 33 GDPR)

⚖️ CNIL sanctions

Up to €20 million or 4% of global annual turnover (whichever is higher) - A processor's non-compliance directly exposes the buyer as the data controller.

Open in the appSaved progress, quizzes and certificate