New Standard Clauses For Data Transfers To Data Controllers In Non-EU Countries
Client Alert | 1 min read | 01.24.05
The Data Protection Directive permits the transfer of personal data outside of the EU in certain circumstances, including where a data exporter (based in the EU) and a data importer (based elsewhere) enter into a written agreement guaranteeing that the data importer will adequately protect all personal data received from the data exporter.
In 2001 the European Commission approved standard contract clauses for use in such a situation. However, the clauses were widely regarded as being too onerous on data exporters. In response to a demand from businesses, the European Commission adopted new alternative standard contract clauses in December 2004 for use in contracts between data controllers.
The key differences between the 2001 and 2004 standard contract clauses relate to the liability of the data exporter for the activities of the data importer: The new standard clauses now impose liability for damage suffered by a data subject directly on the data importer, and the data exporter is now only liable where it has failed to use reasonable efforts to determine that the data importer is able to satisfy its legal obligations under the standard contract clauses.
Contacts
Insights
Client Alert | 10 min read | 12.24.25
Since the signing of Executive Order 14187 (“Protecting Children from Chemical & Surgical Mutilation”) in late January 2025, the Trump Administration has made its skeptical stance on gender-affirming care—especially regarding services provided to minors—clear.
Client Alert | 3 min read | 12.24.25
Keeping it Real: FTC Targets Fake Reviews in First Consumer Review Rule
Client Alert | 5 min read | 12.23.25
An ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.
Client Alert | 2 min read | 12.23.25
Record-Setting False Claims Act Settlement Highlights DOJ Commitment to Customs Enforcement


