Monday, July 15, 2013
On 25th of June 2013, the Belgian Privacy Commission and the Ministry of Justice entered into a protocol agreement which forms the framework for the transfer of personal data outside the EU. Following this, contracts governing the exchange of personal data between companies outside the EU will be handled more smoothly from now on.
The immense volume of personal data transferred between countries has rightly demanded the need for the protection of such personal data. Where the data is transferred within Belgium and the EU, personal data may be transferred subject to the Belgian Data Protection Law. EU member states are accorded the same level of protection for the processing of personal data by virtue of the European Directive 95/46/EC.
Where the data is transferred outside the EU, personal data can only be transferred to countries which provide an adequate level of protection of the data - similar to the protection accorded within the EU. The European Commission has recognised a number of countries which are regarded as providing an adequate level of protection of personal data. This can be viewed on the
European Commission's website.
Where a country is not recognised as offering an adequate level of protection, personal data may still be transferred through:
- European Commission's model contracts or contractual clauses drawn up by organizations themselves offering an adequate level of protection of the personal data to be transferred
- Binding Corporate Rules
- Exceptions provided by law.
In Belgium, where the European Commission's model contracts are used, these contracts are sent to the Belgian Privacy Commission to be checked to ensure conformity with the European Commission's standard contractual clauses. There is however, no need for a Royal Decree to validate such contracts and this has been clearly stated in the recent protocol agreement between the Belgian Privacy Commission and the Ministry of Justice. The date on which conformity with the standard contractual clauses is confirmed in writing by the Privacy Commission is also the date on which the data transfer is allowed.
In the second instance where organizations themselves draw up their own contractual clauses binding themselves and the receivers of the personal data, the existing situation is such that a Royal Decree is necessary. However, owing to the shared jurisdiction of the Belgian Privacy Commission and the Ministry of Justice, the process became long and cumbersome and meant that very few organizations took up this method of providing an adequate level of protection.
The protocol agreement has changed that - the Privacy Commission will now play the leading role in this procedure and quicken the process. Organizations can send the contracts to the Privacy Commission for review. If the necessary guarantees for the protection of personal data are in place, the Privacy Commission will forward these contracts to the Ministry of Justice along with a positive assessment and a proposed wording for a Royal Decree for the King's signature and publication in the Belgian Official Gazette. If not, the Privacy Commission will contact the applicant and refer to the principles which are required to be addressed properly in the contractual clauses.
The new procedure will significantly shorten the period of approval of such contracts and is said to be a win-win situation for the government, organizations and citizens. It will also prevent the possible consequences of violation and provide more legal certainty for the data subjects whos personal data is transferred as well as the organizations involved. The protocol agreement takes effect immediately.
Category: