An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?
SCCs are the European Commission's approved contractual template that imposes GDPR-equivalent safeguards on a data importer in a third country lacking an adequacy decision. They provide the lawful transfer mechanism the privacy program requires for such restricted jurisdictions.
Why this answer
Standard Contractual Clauses (SCCs) (A) are a core GDPR transfer mechanism under Article 46, providing pre-approved contractual terms that legally safeguard personal data when it moves to a third country lacking an adequacy finding. An adequacy decision by the European Commission (C) is essential because under Article 45 it declares a third country's data protection regime essentially equivalent to the EU's, allowing transfers without additional safeguards. Binding Corporate Rules (BCRs) (D) are another Article 47 mechanism, essential for multinational groups to legitimize intra-group cross-border transfers through internally binding data protection policies approved by supervisory authorities.
The unmarked options do not belong: a DPIA (B) is a risk assessment tool for high-risk processing, not a transfer mechanism, and encryption at rest (E) is a security control that may supplement but does not by itself legalize a cross-border transfer.
Exam trap
The trap is selecting security measures like encryption or risk assessments as legal transfer mechanisms. Candidates might think encryption alone suffices, but GDPR requires a legal basis for transfer. The exam tests knowledge of the specific legal instruments (SCCs, adequacy, BCRs) that are explicitly recognized.