← back to the act's dossier

GDPR — Article 46

The article's text

Article 46 Transfers subject to appropriate safeguards 1. In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. 2. The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by: (a) a legally binding and enforceable instrument between public authorities or bodies; (b) binding corporate rules in accordance with Article 47; (c) standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2); (d) standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2); (e) an approved code of conduct pursuant to Article 40 toge
full text
ther with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights; or (f) an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights. or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights. 3. Subject to the authorisation from the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided for, in particular, by: (a) contractual clauses between the controller or processor and the controller, processor or the recipient of the personal data in the third country or international organisation; or (b) provisions to be inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights. 4. The supervisory authority shall apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3 of this Article. apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3 of this Article. 5. Authorisations by a Member State or supervisory authority on the basis of Article 26(2) of Directive 95/46/EC shall remain valid until amended, replaced or repealed, if necessary, by that supervisory authority. Decisions adopted by the Commission on the basis of Article 26(4) of Directive 95/46/EC shall remain in force until amended, replaced or repealed, if necessary, by a Commission Decision adopted in accordance with paragraph 2 of this Article.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

17
business association
8
company
3
other
2
NGO
1
EU citizen
WhoCountryWhat they wrote
ANITEC-ASSINFORMITthe EDPB should correct the wording of these recommendations to clarify the standards to be applied under Art. 46 GDPR. 6) Experience with accountability and the risk‐based approach b. What is your experience with the scalability of obligations (e.g.,
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEred to other mechanisms. We would like to encourage the European Commission to emphasise that each appropriate safeguard pursuant Art. 46 GDPR may have its unique approach. For details, also refer to Section 9.3. 12.2. Approval As organizations involved in the
European Centre for Certification and Privacy (ECCP)LUtition, or stifle innovation and technological development.” Unilateral Contractual Commitment Tool Current legislative framework Article 46 GDPR requires “binding enforceable commitments of the controller or processor in the third country to apply appropriate
Bitkom e.V.DEthe EDPB should correct the wording of these recommendations to clarify the standards to be applied under Art. 46 GDPR. Instead, we see efforts to work towards a complete reversal of the burden of proof in civil proceedings, including supporting case law. More
Global Data AllianceBEdering those willing to invest in such programs and thereby impacting public trust. The GDA supports initiatives that make use of Article 46 of the GDPR to create additional tools to help address business needs in a legally and operationally sound manner, in l
The Information Technology Industry Council (ITI)USt the existing code, the EU Cloud Code of Conduct is currently building an additional module designed to act as a safeguard under Article 46 GDPR. As codes of conduct acting as transfer tools require validation via Implementing Acts, we encourage the Commissio
Van Bael & BellisBEsued modernised Standard Contractual Clauses (SCCs) for international personal data transfers20 as an appropriate safeguard under Article 46 GDPR, having considered the CJEU jurisprudence.
BSA | The Software AllianceBEion of codes of conduct that can serve as adequate and independent transfer mechanisms. BSA supports initiatives that make use of Article 46 of the GDPR to create additional tools to help address business needs in a legally and operationally sound manner, in l
German Insurance AssociationDEno increased risk arises from the transfer return of the data back to the “third country”. In these cases, the requirement to use Article 46 safeguards for the transfer back would expand obligations resulting from the GDPR to data processing that does not even
Intrum ABSEtional transfers that extended for years. Despite relying on Standard Contractual Clauses (SCC) as an appropriate safeguard under Article 46 of the GDPR, the legal landscape became even more challenging with the Court of Justice of the European Union (CJEU)’s
Insurance EuropeBEefore, no increased risk arises from the transfer of the data back to the “third country”. In these cases, the requirement to use Article 46 safeguards for the transfer back would expand obligations resulting from the GDPR to data processing that does not even
Hans-Hermann SchildDEef- 16 ABl. 1971 L 124, S. 1. 17 Das richtige Pendant zu Art. 46 Abs. 11 Asylverfahrens-RL 2013 i. V. m. § 81 AsylG. 18 Bezüglich eines in Luxemburg ansässigen internationalen Zahlungs- dienstleisters wegen automatisierter Einzelentscheidung läuft seit 2020
SRIW & SCOPE EuropeDEto Art. 46.2 (e) in conjunction with Art. 40 GDPR can be a crucial, robust but innovation-friendly transfer mechanism. Codes of conduct can be developed by industries themselves, making it possible to in- troduce modern business practices and giving the flexib
Gesamtverband der Deutschen Versicherungswirtschaft e.V.DEavailable for the processing pursuant to Article 28 Page 9 / 20 GDPR and for the transfer of data to third countries pursuant to Article 46(2)(c) and (d) GDPR. 3. Opening the GDPR for digitalisation in the insurance industry Like in almost all industries, an
or both BCRs for controllers and BCRs for processors, whether or not combined. The GDPR foresees alternative transfer mechanisms (Article 46), including certifications mechanisms and codes of conduct. Unfortunately, their uptake and adoption has been limited.
BSA | The Software AllianceBEally important transfer mechanisms which should be upheld, and to prepare revised SCCs to bring them fully in line with the GDPR. Article 46 of the GDPR foresees additional tools to provide the necessary safeguards such as BCRs, codes of conduct and certificat
International Society for Biological and Environmental Repositories (ISBER)USto permit the transfer of genetic data 32 Id. at para. 128. 33 Id. at paras. 134 and 135. 34 GDPR, Article 46(3). 35 See, e.g., United Kingdom, Information Commissioner’s Office (“At present the ICO is not authorizing any such bespoke contracts, until guid
Multi-Regional Clinical Trials Center of Harvard University and Brigham and Women’s HospitalUSto permit the transfer of genetic data 32 Id. at para. 128. 33 Id. at paras. 134 and 135. 34 GDPR, Article 46(3). 35 See, e.g., United Kingdom, Information Commissioner’s Office (“At present the ICO is not authorizing any such bespoke contracts, until guid
Global Data AllianceBEof conduct and certification mechanisms remain largely theoretical. The Commission should encourage initiatives that make use of Article 46 to create additional tools to help address business needs in a legally and operationally sound manner to bridge gaps be
CrowdStrikeUSmaking clear that the power of recognizing an adequate jurisdiction is vested in the European Commission. Therefore, ii. amending Art. 46(1) by noting that it is up to an organization, regardless of whether they are a data controller or a data processor, to ch
EFPIAGB(access) and 20 (portability). xxi Id. Art. 25(2) Directive 95/46/EC and Art. 45 GDPR. xxii Id. Art. 26(2) Directive 95/46/EC and Art. 46 GDPR. xxiii Id. Art. 26(1) Directive 95/46/EC and Art. 49 GDPR. xxiv Id. Art. 25(2) Directive 95/46/EC and Art. 45 GDPR. x
French Association of Large Companies (AFEP)FRts future report. Some of these corrections are related to adequacy decisions (art 45) and standard contractual clauses ( "SCC" - art 46), which are major tools in companies daily- life for both the practical circulation of these data flows and the related leg
Fundamental Rights European Experts Group (FREE-Group)BEor bodies” in the EU and corresponding public authorities and bodies in third countries mentioned in Article 46(2)(a). At the moment, no-one has any idea of the nature, scope and detail of such arrangements – let alone whether they really contain the required
DIGITALEUROPEBEo consideration. We therefore encourage the EDPB to revise its guidance regarding appropriate safeguards for data transfers under Art. 46 GDPR. 6 Art. 46 GDPR 7 For example, ISO 27701, providing a globally recognised tool for international data transfers.
TECH IN FRANCEFRconduites, certifications et autres mécanismes de transfert international de données personnelles Les autres outils prévus par l’article 46 tels que les codes de conduite ou les mécanismes de certification n’ont jamais été utilisés à ce jour pour permettre un
RELXGBhe uninterrupted flows of data across the Channel. In the cases where there is no third country data adequacy agreement in place, Article 46 of the GDPR offers other mechanisms that enable data to flow internationally, such as standard contractual clauses.
Ecommerce EuropeBEthat, in case the European Court of Justice, after the Safe Harbor, also overturns the practice of Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR), there will no longer be an unbureaucratic instrument available for personal data transfers to third
Insurance EuropeBEg gap in the available SCCs for international data transfers and develop SCCs for transfers between processors in accordance with Article 46 (2) (c) GDPR. Comments on the level playing field of GDPR enforcement: Article 52(4) of the GDPR establishes that each
Computer & Communication Industry Association (CCIA)USDecision 206/2297 currently restrict the use of model clauses to ‘data exporters’/controllers established in the EU. Yet, neither Article 46 nor any other provision of the GDPR preclude ‘data exporters’/controllers established outside the Union from using stan
Developers AllianceUSprocessor-to-processor SCCs would allow the appropriate framing of such transfers in accordance with Article 46 GDPR. 5. Other transfer mechanisms are possible, according to Article 46(2) GDPR, which allows data transfers under approved codes of conduct and ce

Source: public consultation submissions and position papers. n = 33 mentions; counted as a literal reference to the article number.

Ask about this article →