CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A US-based cloud provider will host personal data for a company operating in the European Union, and no EU adequacy decision covers the United States. Which mechanism should the parties include in their contract to legally justify this cross-border transfer of personal data under GDPR?

  1. ABusiness Associate Agreement (BAA)
  2. BNon-Disclosure Agreement (NDA)
  3. CStandard Contractual Clauses (SCCs)
  4. DService Level Agreement (SLA)
Show answer & explanation

Correct answer: C. Standard Contractual Clauses (SCCs)

When transferring personal data from the EU to a country without an adequacy decision, GDPR requires an approved transfer mechanism such as Standard Contractual Clauses (SCCs), which impose contractual data protection obligations on the data importer to ensure GDPR-equivalent protections.

Why the other options are wrong

  • A. A BAA is a HIPAA-specific contract for handling protected health information, not a GDPR transfer mechanism.
  • B. An NDA protects confidential business information but does not satisfy GDPR's requirements for lawful international data transfer.
  • D. An SLA defines service performance metrics but has no legal standing for GDPR cross-border transfer compliance.

Standard Contractual Clauses (SCCs)

EU Commission-approved contractual clauses that organizations use to legally transfer personal data to countries outside the EEA that lack an adequacy decision.

  • Required when no adequacy decision exists for the destination country
  • Impose GDPR-equivalent obligations on the data importer
  • One of several approved GDPR transfer mechanisms (also includes Binding Corporate Rules)
  • Failure to use a valid mechanism can result in GDPR enforcement action

Memory trick: 'No adequacy? Sign the SCCs' to legally ship data across borders.

More Governance, Risk, Compliance and Security questions