The rules for cross-border transfers of personal data are regulated under Article 44 and following of the GDPR which provides different rules for transferring data within the EEA and transferring data to jurisdictions outside the EEA. These rules indicate that the transfer of personal data from Poland to a processor or controller in another EEA member state must comply with the same requirements as if the transfer was made within Poland, whereas the transfer of personal data from Poland to countries or territories outside the EEA cannot be made unless that third country or territory in that third country provides an adequate level of protection for personal data. At the same time, the GDPR sets forth a number of exceptions to this rule, i.e., situations where data can be transferred outside the EEA without seeking confirmation about an adequate level of protection. Whereas in the case of third countries as to which the European authorities have made no ruling that there are adequate safeguards, personal data may still be transferred to those countries under certain specific circumstances.
In practice, it means that transfers from Poland outside EEA may be made where the European Commission has decided that a given third country, a territory in that third country, or an international organization, ensures adequate safeguards for the protection of data. Currently, these countries are Andorra, Argentina, Canada (commercial organisations), the Faeroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, United Kingdom, Uruguay, and South Korea. Alternatively, the controller as transferor could ensure an adequate level of protection through either entering into standard contractual clauses approved by the European Commission for both controller-to-processor and controller-to-controller transfers, or, for transfers within the same group, adopting binding corporate rules. On 4 June 2021, the European Commission issued modernised standard contractual clauses under the GDPR for data transfers from controllers or processors in the EU/EEA to controllers or processors established outside the EU/EEA (the Commission Implementing Decision (EU) 2021/914). These modernized standard contractual clauses have replaced the previous standard contractual clauses adopted under the Data Protection Directive 95/46.
Data can otherwise be transferred if one of the exceptions mentioned above applies. These include the following situations:
- the data subject has consented to the transfer (as noted above, this consent should be explicit as well as freely given, specific, informed, and unambiguous);
- the transfer is necessary for the performance of a contract between the data subject and controller, or the implementation of pre-contractual measures taken at the data subject’s request;
- the transfer is necessary for the conclusion of a contract between the controller and a person other than the data subject, which is entered into in the data subject’s interests;
- the transfer is necessary for important reasons of public interest;
- the transfer is necessary for the establishment, exercise or defence of legal claims; or
- the transfer is necessary to protect the vital interests of the data subject.
Where none of the above situations is the case, a transfer to a third country or an international organisation may still take place if the transfer is not repetitive, concerns only a limited number of data subjects, and is necessary for the purposes of compelling legitimate interests of the controller (which are not overridden by the interests or rights and freedoms of the data subject), and the controller has assessed all the circumstances surrounding the transfer and has, based on that assessment, provided suitable safeguards concerning the protection of personal data.