The Risk-Based Approach in the GDPR and personal data transfers

29 May 2024


Graça Canto Moniz,

Board Member of the South EU Google Data Governance Chair.


About the Author:  Graça Canto Moniz is a member of the South EU Google Data Governance Chair.


About the South EU Google Data Governance:  

Last June 24th, 2021  the launch and the beginning of the activities of the South EU Google Data Governance Chair took place. 

The Board is headed by Professor José Luis Piñar (CEU-San Pablo University, Madrid) and counts with Professors Maria da Graça Canto Moniz (Nova University Lisbon), Georgios Yannopoulos (University of Athens) and Vincenzo Zeno-Zencovich (University of RomaTre).

The Chair will focus on scientific reflection and research in the academic field on data governance, in the context of the European countries.

In addition, it will serve as a framework to analyze the challenges for Law and Data Governance in the European sphere, in areas such as Big Data, Data Driven Innovation, Artificial Intelligence or International Personal Data flows.


Abstract: This text is an overview of the article “The risk-based approach in the GDPR and the ‘two-step test’ within Article 44” published by the Author in the International Data Privacy Law.  The article provides an in-depth analysis of the integration and implications of the risk-based approach (RBA) in the General Data Protection Regulation (GDPR), focusing on Article 44’s ‘two-step test’ for personal data transfers.

Keywords: GDPR, Data transfers, risk-based approach, article 44.


1. SUMMARY

The article “The Risk-Based Approach (RBA) in the GDPR and the ‘Two-Step Test’ within Article 44”, published in the International Data Privacy Law, examines the integration of the risk-based approach within the General Data Protection Regulation (GDPR)1, focusing on the ‘two-step test’ prescribed in Article 44 for personal data transfers2. It explores how the RBA has been partially adopted in the GDPR, necessitating that data controllers implement risk-based measures to safeguard fundamental rights and freedoms. It discusses the renewed importance of the RBA following the Schrems II decision3, which heightened scrutiny on data transfers outside the European Union (EU). The article delves into the necessity of conducting Data Protection Impact Assessments (DPIAs) for high-risk processing activities, particularly in the context of data transfers.

            Through a detailed analysis, the article outlines the requirements of the ‘two-step test’, emphasizing compliance with both the general provisions of the GDPR and the specific rules for data transfers in Chapter V. Ultimately, the article provides guidance on ensuring GDPR compliance in data transfers, addressing the complexities introduced by the Schrems II ruling.

2. KEY TAKEAWAYS

Article 44 of the GDPR mandates that personal data transfers must comply with both the general provisions of the GDPR (first step) and the specific requirements of Chapter V (second step). This double protection aims to ensure that personal data transfers do not undermine the level of protection guaranteed by the GDPR.

            In particular, the article explores the connection between both steps of the test and the RBA. The first step entails compliance with the general obligation to manage risks under Article 24 and the duty to perform a Data Protection Impact Assessment (DPIA) under Article 35 of the GDPR. However, a DPIA is only required for processing operations likely to result in high risk to data subjects such as large-scale processing of special categories of data. Therefore, the article examines the conditions that necessitate DPIAs for data transfer and concludes that not all data transfers require such a procedure. Differently, the general obligation to manage risks under Article 24 means that controllers must conduct risk assessments of all data transfers regardless of the level or risk they pose to data subjects.            

The second step of the test has become more stringent following the Schrems II decision4. The CJEU emphasized the need for additional safeguards and thorough transfer assessments of ensure ‘essential equivalence’. Controllers are thus tasked with evaluating

the effectiveness of the transfer mechanisms and the legal and practical landscape in the destination country. However, the article concludes that the Court’s assessment in Schrems II and the risk assessment process outlined in Articles 24 and 35 are different for three main reasons.

            Firstly, a risk assessment occurs in the first phase of the test, while the CJEU’s assessment applies to the second. Accordingly, the necessity for a DPIA is influenced by the processing’s risk level, independent of the chosen transfer mechanism, marking the second distinction. The third difference highlights that the CJEU’s recommended assessment departs from the risk analysis or quantification foundational to Articles 24 and 35 GDPR. The Court emphasized that controllers are to consider the same factors as the EU Commission, as specified in Article 45 (2) GDPR, which includes the rule of law in a third country, the presence of comprehensive data protection laws, or an independent data protection authority.


1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),

2 It states that “Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.”

3 Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited, Maximilian Schrems [2020] ECLI:EU:C:2020:559.

4 Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited, Maximilian Schrems [2020] ECLI:EU:C:2020:559.

The South EU Google Data Governance Chair focuses on scientific reflection and research in the academic field on Data Governance in the context of European countries. The Chair analyzes the challenges of Law and Data Governance in areas such as Big Data, Data Driven Innovation, Artificial Intelligence and International Flows of Personal Data.

South EU Google Chair
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.