logo-small.png
- BLOG -

Headquarters

501 Boylston Street, 10th Floor

Boston, MA 02116

(617)-737-5000

info@outsidegc.com

ON-DEMAND INSIGHTS

Important Compliance Deadline for U.S. Companies Handling EU Data

Posted by Stephan Grynwajc on December 6, 2022 at 1:16 PM

GDPR compliance standard contractual clauses eu data transferThe clock is ticking! The deadline for switching to the new EU Standard Contractual Clauses (SCC) for data transfers between the EU and non-EU countries is December 27, 2022. As of that date, data controllers and processors around the world that process the personal data of EU residents will no longer be able to rely on the old SCCs without violating the General Data Protection Regulation (GDPR). In other words, companies are legally obligated to replace all previously used SCCs with the new ones, and should be able to demonstrate having done so in case of an audit.  

As a reminder, SCCs are standardized and pre-approved model data protection clauses that allow data controllers and data processors to comply with their obligations under EU data protection law. They ensure that appropriate data protection safeguards are in place for international data transfers. SCCs must be properly completed and signed by the parties. Simply including a reference to the SCCs in a data processing agreement is not sufficient and does not comply with EU law.

Violating the GDPR may result in heavy penalties for big and small organizations alike. In this case, failure to adopt the new SCCs may lead to a penalty of up to 10M euros ($10,500,000) or up to 2% of the company’s total worldwide annual revenue for the preceding financial year, whichever is higher.

If you have questions about complying with this important deadline, please contact Stephan Grynwajc at stephan@outsidegc.com or 347-543-3035.

 

Stephan Grynwajc is admitted to the practice of law in the U.S., Canada, U.K. and in France/the European Union. He has served as a senior in-house attorney for several blue-chip technology corporations (e.g., Intel and Symantec) in France, the U.K. and the U.S., and today, focuses his practice on advising U.S.-based clients on navigating the EU, UK and Canadian legal and regulatory landscape. 

Topics: GDPR, SCCs, EU personal data, international data transfer, GDPR compliance

Subscribe to our Blog

Popular Posts

   
This publication should not be construed as legal advice or a legal opinion on any specific facts or circumstances nor an offer to represent you. It is not intended to create, and receipt does not constitute, an attorney-client relationship. The contents are intended for general informational purposes only, and you are urged to consult your attorney concerning any particular situation and any specific legal questions you may have. Pursuant to applicable rules of professional conduct, portions of this publication may constitute Attorney Advertising.

Outside GC is an innovative approach to legal services for growing and mature businesses. Companies who engage Outside GC fall into two main categories: (1) those without in-house counsel who need regular, on-going legal support but do not wish to hire a full-time in-house lawyer, and (2) those with in-house counsel who do not wish to add more full-time resources to their existing in-house staff. Contact us to speak to one of our on-demand attorneys.