L 119/20
EN
Official Journal of the European Union
4.5.2016
protection essentially equivalent to that ensured within the Union, in particular where personal data are
processed in one or several specific sectors. In particular, the third country should ensure effective independent
data protection supervision and should provide for cooperation mechanisms with the Member States' data
protection authorities, and the data subjects should be provided with effective and enforceable rights and effective
administrative and judicial redress.
(105) Apart from the international commitments the third country or international organisation has entered into, the
Commission should take account of obligations arising from the third country's or international organisation's
participation in multilateral or regional systems in particular in relation to the protection of personal data, as
well as the implementation of such obligations. In particular, the third country's accession to the Council of
Europe Convention of 28 January 1981 for the Protection of Individuals with regard to the Automatic Processing
of Personal Data and its Additional Protocol should be taken into account. The Commission should consult the
Board when assessing the level of protection in third countries or international organisations.
(106) The Commission should monitor the functioning of decisions on the level of protection in a third country, a
territory or specified sector within a third country, or an international organisation, and monitor the functioning
of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy
decisions, the Commission should provide for a periodic review mechanism of their functioning. That periodic
review should be conducted in consultation with the third country or international organisation in question and
take into account all relevant developments in the third country or international organisation. For the purposes
of monitoring and of carrying out the periodic reviews, the Commission should take into consideration the views
and findings of the European Parliament and of the Council as well as of other relevant bodies and sources. The
Commission should evaluate, within a reasonable time, the functioning of the latter decisions and report any
relevant findings to the Committee within the meaning of Regulation (EU) No 182/2011 of the European
Parliament and of the Council (1) as established under this Regulation, to the European Parliament and to the
Council.
(107) The Commission may recognise that a third country, a territory or a specified sector within a third country, or an
international organisation no longer ensures an adequate level of data protection. Consequently the transfer of
personal data to that third country or international organisation should be prohibited, unless the requirements in
this Regulation relating to transfers subject to appropriate safeguards, including binding corporate rules, and
derogations for specific situations are fulfilled. In that case, provision should be made for consultations between
the Commission and such third countries or international organisations. The Commission should, in a timely
manner, inform the third country or international organisation of the reasons and enter into consultations with it
in order to remedy the situation.
(108) In the absence of an adequacy decision, the controller or processor should take measures to compensate for the
lack of data protection in a third country by way of appropriate safeguards for the data subject. Such appropriate
safeguards may consist of making use of binding corporate rules, standard data protection clauses adopted by the
Commission, standard data protection clauses adopted by a supervisory authority or contractual clauses
authorised by a supervisory authority. Those safeguards should ensure compliance with data protection
requirements and the rights of the data subjects appropriate to processing within the Union, including the
availability of enforceable data subject rights and of effective legal remedies, including to obtain effective adminis
trative or judicial redress and to claim compensation, in the Union or in a third country. They should relate in
particular to compliance with the general principles relating to personal data processing, the principles of data
protection by design and by default. Transfers may also be carried out by public authorities or bodies with public
authorities or bodies in third countries or with international organisations with corresponding duties or
functions, including on the basis of provisions to be inserted into administrative arrangements, such as a
memorandum of understanding, providing for enforceable and effective rights for data subjects. Authorisation by
the competent supervisory authority should be obtained when the safeguards are provided for in administrative
arrangements that are not legally binding.
(109) The possibility for the controller or processor to use standard data-protection clauses adopted by the
Commission or by a supervisory authority should prevent controllers or processors neither from including the
(1) Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general
principles concerning mechanisms for control by Member States of the Commission's exercise of implementing powers (OJ L 55,
28.2.2011, p. 13).