Recital 108

Recital 108

General Data Protection Regulation · UE 2016/679

(108)

In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses authorised by a supervisory authority. Those safeguards should ensure compliance with data protection requirements and the rights of the data subjects appropriate to processing within the Union, including the availability of enforceable data subject rights and of effective legal remedies, including to obtain effective administrative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in particular to compliance with the general principles relating to personal data processing, the principles of data protection by design and by default. Transfers may also be carried out by public authorities or bodies with public authorities or bodies in third countries or with international organisations with corresponding duties or functions, including on the basis of provisions to be inserted into administrative arrangements, such as a memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by the competent supervisory authority should be obtained when the safeguards are provided for in administrative arrangements that are not legally binding.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2018 portant organisation de la Commission nationale pour la protection des donnees

In Luxembourg, the CNPD (never the APDL) is the competent authority to authorise non-legally-binding administrative arrangements under Recital 108, pursuant to Article 46(3)(b) GDPR. The law of 1 August 2018 organising the CNPD sets out the prior authorisation procedure, particularly relevant for Luxembourg public administrations exchanging with non-EU counterparts (tax, customs, judicial cooperation).

Luxgap practice: for Luxembourg public bodies and CSSF-regulated fintechs transferring to non-EU group entities, we assemble the full CNPD authorisation file (TIA + draft arrangement + supplementary measures) and shepherd it through to decision, typically obtained within 3 to 6 months.