Recital 103

Recital 103

General Data Protection Regulation · UE 2016/679

(103)

The Commission may decide with effect for the entire Union that a third country, a territory or specified sector within a third country, or an international organisation, offers an adequate level of data protection, thus providing legal certainty and uniformity throughout the Union as regards the third country or international organisation which is considered to provide such level of protection. In such cases, transfers of personal data to that third country or international organisation may take place without the need to obtain any further authorisation. The Commission may also decide, having given notice and a full statement setting out the reasons to the third country or international organisation, to revoke such a decision.

Luxembourg specificity
loi du 1er août 2018 portant organisation de la Commission nationale pour la protection des données

In Luxembourg, the CNPD (not APDL) is the supervisory authority competent to oversee international transfers. The law of 1 August 2018 organising the CNPD empowers it to audit transfer legal bases and suspend a flow deemed non-compliant, even under an adequacy decision, if it considers that local guarantees are no longer effective. The Luxembourg financial centre is particularly exposed: banking groups make heavy use of US providers (Salesforce, AWS, Microsoft) covered by the DPF.

Luxgap practice: for CSSF and ILR regulated entities, we couple the Adequacy Radar with the mapping of critical providers under CSSF circular 22/806 on IT outsourcing, to produce a single file opposable to both CNPD and CSSF.