A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.
For exporting EU branch employees’ data to Asian Countries for processing, which of the following instruments could be used for legal data transfer?
A . Customized contracts mandating ISO 27001 certification by the data processor
B . Standard Contractual Clauses
C . Binding Corporate Rules
D . Privacy Shield Framework
Answer: D
Leave a Reply