Transfers outside the EU - After Schrems II
Objective: Secure data transfers outside the EU and master the data breach notification process.
Sources
- Art. 44-49 GDPR - Data transfers to third countries
- Art. 33 GDPR - Data breach notification to the authority
- CJEU, 16 July 2020, C-311/18 (Schrems II ruling)
- EU-US Data Privacy Framework (2023)
If your supplier is based outside the EU/EEA or uses sub-processors outside the EU, appropriate safeguards are mandatory:
🚨 Data breach - Notification cascade
D+0
Discovery of the breach by the supplier
↓
+24h
Notification from supplier to buyer (contractually recommended)
↓
+72h
Mandatory notification from buyer to the CNIL (Art. 33 GDPR)
⚖️ CNIL sanctions
Up to €20 million or 4% of global annual turnover (whichever is higher) - A processor's non-compliance directly exposes the buyer as the data controller.