CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A US-based cloud provider will host personal data for a company operating in the European Union, and no EU adequacy decision covers the United States. Which mechanism should the parties include in their contract to legally justify this cross-border transfer of personal data under GDPR?
- ABusiness Associate Agreement (BAA)
- BNon-Disclosure Agreement (NDA)
- CStandard Contractual Clauses (SCCs)
- DService Level Agreement (SLA)
Show answer & explanationAnswer & explanation
Correct answer: C. Standard Contractual Clauses (SCCs)
When transferring personal data from the EU to a country without an adequacy decision, GDPR requires an approved transfer mechanism such as Standard Contractual Clauses (SCCs), which impose contractual data protection obligations on the data importer to ensure GDPR-equivalent protections.
Why the other options are wrong
- A. A BAA is a HIPAA-specific contract for handling protected health information, not a GDPR transfer mechanism.
- B. An NDA protects confidential business information but does not satisfy GDPR's requirements for lawful international data transfer.
- D. An SLA defines service performance metrics but has no legal standing for GDPR cross-border transfer compliance.
Standard Contractual Clauses (SCCs)
EU Commission-approved contractual clauses that organizations use to legally transfer personal data to countries outside the EEA that lack an adequacy decision.
- Required when no adequacy decision exists for the destination country
- Impose GDPR-equivalent obligations on the data importer
- One of several approved GDPR transfer mechanisms (also includes Binding Corporate Rules)
- Failure to use a valid mechanism can result in GDPR enforcement action
Memory trick: 'No adequacy? Sign the SCCs' to legally ship data across borders.