EDPB Clarifications on transfers to importers subject to GDPR

来源:广悦律师事务所

文章摘要
On 18 November 2021, the European Data Protection Board (EDPB) released the Guidelines on the Interp

On 18 November 2021, the European Data Protection Board (EDPB) released the Guidelines on the Interplay between the application of Article 3 and the provisions on international transfer as per Chapter V of the GDPR (The Guidelines) for public consultation until 31 January 2022.
2021年11月18日,欧洲数据保护委员会(EDPB)通过了《关于GDPR第3条及第五章关于跨国数据转移之间的相互作用的指南》以供公众征询意见,截止日期为2022年1月31日。
Following Art. 3(2) of the European General Data Protection Regulation (GDPR), the law still applies to a company outside the territory of the European Union (for instance located in China) if it offers goods or services or monitors the behavior of data subject (e.g., customers) in Europe. In addition, by virtue of Art. 44, the transfer of personal information to a third country (including China) for the activity of processing (qualified as a “transfer”) must comply with Chapter V.
根据欧盟《一般数据保护条例》(GDPR)第3(2)条,若在欧盟境外的公司(如中国公司)如果向欧盟境内的数据个体(如客户)提供商品、服务或监管数据个体的行为,则该公司仍需要遵守GDPR的规定。另外,根据GDPR第44条,在将个人信息自欧洲传输至第三国(包括中国)境内时,数据接收方需要遵守GDPR第五章的规定。
In the first three years of GDPR, it was unclear what rules should be followed by controllers or processors outside the EU but subject to the GDPR by Art. 3(2), which process data from controllers or processors inside the EU. In other words, it is unclear whether such a process will constitute transfer and require the application of Chapter V even though the recipient should be already GDPR compliant.
在GDPR开始实施的过去三年里,这种情况构成一些混淆,即位于欧盟境外、根据第3(2)条应当遵守GDPR的数据控制者和处理者且同时处理由欧盟境内控制者和处理者提供的数据。亦即,前述处理行为是否构成“转移”因此应当符合GDPR第五章的要求,即使该数据接收方已经受GDPR的约束。
In this regard, the Guidelines specifies three cumulative criteria that qualify processing as transfers:



  • a controller or a processor (“exporter”) is subject to the GDPR for the given processing;

  • this controller or processor transmits or makes personal data available to (a joint) controller, or processor (“importer”);

  • the importer is in a third country or is an international organization.
    就此,该指南确定了以下三个累积性标准,使一项处理构成“向第三国或国际组织转移个人数据”:

  • 控制者或处理者在特定的处理过程中需要遵守GDPR;

  • 该控制者或处理者(“数据出口者“)通过传输或其他方式将受此处理的个人数据提供给另一控制者、共同控制者或处理者(“数据进口者”);

  • 数据进口者在第三国,或者是一个国际组织,同时不管这个数据进口者是否按照第3条的规定在特定的处理方面受到GDPR的约束。
    Example: An Italian company provides personal data of its customers to a cloud service provider established in China who is already subject to the GDPR by virtue of the Art. 3(2) due to its offering of hosting services to data subjects in the EU. The processing of such data will be considered as a transfer to a processor in a third country and therefore, subject to Chapter V of the GDPR although the processor in China is already subject to the GDPR via Art. 3(2).
    例:一家意大利公司将其客户的数据提供给一家在中国成立的提供云服务的公司;根据GDPR第3(2)条,中国公司因向欧盟境内主体提供服务而应当遵守GDPR的规则。同时,处理数据的行为将被视为向第三国处理者转移数据的行为,因而应当符合GDPR第五章的要求,尽管该中国公司已根据第3(2)条受GDPR约束。
    As a consequence, the controller or processor in an “international transfer” situation needs to comply with the conditions of Chapter V of the GDPR to protect personal information that would be transferred to a third country or an international organization.
    因此,在 “国际转移 ”的情况下,控制者或处理者需要遵守GDPR第五章的规定,以保护将被转移到第三国或国际组织的个人信息。
    So far, since China has not been recognized by the European Commission as a country providing adequate protection (Art. 45 of the GDPR), controllers and/or processors transferring data to China shall implement appropriate safeguards provided for in Article 46 before the transfer, including:

  • Standard Contractual Clauses (SCCs);

  • Binding Corporate Rules (BCRs);

  • Code of conduct;

  • Certification Mechanisms;

  • Ad hoc contractual clauses ;

  • International agreements/administrative arrangements.
    由于到目前为止,中国并未被欧盟委员会承认为能够“提供充分保护的国家”(GDPR第45条),在缺失该充分保护决议的情况下,向中国转移数据的控制者和/或处理者可以采取第46条规定的适当保障措施,包括:

  • 标准合同条款(SCC)

  • 有约束力的公司规则(BCRs)

  • 行为准则

  • 认证机制

  • 特设合同条款

  • 国际协议/行政安排
    In the absence of an adequacy decision under Art. 45 or appropriate safeguards pursuant to Art. 46, a transfer of personal data may take place if:

  • the data subject gives explicit consent after being informed of risks of transfer;

  • the transfer is necessary for the performance of a contract between data subjects and controllers or processors or implementation of pre-contractual measures;

  • the transfer is necessary for the conclusion or performance of a contract between the controller or the processor and a third party but the contract is made in the interest of the data subject;

  • the transfer is necessary for the important reason of public interests;

  • the transfer is necessary for legal claims;

  • the transfer is necessary to protect the vital interests of data subjects or other persons, where the data subject is physically or legally incapable of giving consent;

  • the transfer is made from a register which, according to Union or Member State law, is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest.
    在缺失第45条规定的充分保护决议且无法提供第46条所规定的保护措施时,个人数据的转移在下列情况下仍可发生:

  • 数据主体被告知传输的风险并表示明确同意转移

  • 转移是为实现数据主体与控制者之间的合同或先合同措施所必需

  • 订立或履行控制者与第三方之间的合同所必需,但该合同是为数据主体的利益所订立

  • 转移为法律诉讼所必需

  • 因生理原因或法律原因无法给予同意的数据主体,为保护该主体的或其他人的重大利益,有必要进行转移

  • 转移通过登记册进行,根据欧盟或其成员国法律该登记册旨在向公众或能够证明正当权益的主体提供
    In addition, the EDPB also clarified that the collection of personal information directly abroad shall not constitute international transfer but shall follow in any case Art. 3(2) of the GDPR if there is an offering of goods, services, or monitor of behavior. However, in case such foreigner receiver transfers the personal information to a processor established in the same country, this will constitute transfer and follow Chapter V rules.
    另外,EDPB明晰了直接在欧盟境外收集个人信息并不构成数据“转移”,但符合GDPR第3(2)条的情况下依然需要遵守GDPR的规定。然而,若该境外接受方将个人信息再次提供给位于其他国家的数据处理者,这种提供行为构成数据“转移“因为需要适用第五章的规定。
    Example: A Chinese e-commerce company receives personal data from its customers directly on its server in China and transfers the same data to its processor in China (e.g., for storage purposes). The collection of data will be subject to Art. 3(2) if there is an offering of goods, services, or monitor of the behavior of data subject in the EU, whereas the transfer to the Chinese processor shall follow Chapter V of the GDPR although the processor and controller are both in the same country.
    例:在中国境内从事电子商务的公司直接从其在中国的服务器上接收其客户的个人数据,并将相同的数据传输到其在中国的处理者(例如,用于存储目的)。若电子商务公司向欧盟的数据主体提供商品、服务或监控数据主体的行为,则电子商务公司将受第3(2)条的约束,而向中国处理者的数据转移应遵循GDPR第五章,尽管处理者和控制者都在同一国家/地区。
    If these Guidelines will be formally adopted by the EDPB as they are, they will have a huge impact on Chinese companies processing or collecting data from Europe. At Wang Jing & GH Law Firm we are always ready to assist our clients regarding new trends and rules that may have a major impact on your business in China and abroad. If you believe you could be subject to the above rules, please don’t hesitate to reach us to the below contact information for a consultation.
    如果本指南全然被EDPB正式采纳,这将对处理或接受来自于欧洲境内个人数据的中国公司产生巨大影响。

技术驱动法律,专业成就未来