The Future of International Data Transfers: Managing Legal Risk with a User-Held Data Model

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jurcys, Paulius, Compagnucci, Marcelo Corrales, Fenwick, Mark
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910546118311936
author Jurcys, Paulius
Compagnucci, Marcelo Corrales
Fenwick, Mark
author_facet Jurcys, Paulius
Compagnucci, Marcelo Corrales
Fenwick, Mark
contents The General Data Protection Regulation contains a blanket prohibition on the transfer of personal data outside of the European Economic Area unless strict requirements are met. The rationale for this provision is to protect personal data and data subject rights by restricting data transfers to countries that may not have the same level of protection as the EEA. However, the ubiquitous and permeable character of new technologies such as cloud computing, and the increased inter connectivity between societies, has made international data transfers the norm and not the exception. The Schrems II case and subsequent regulatory developments have further raised the bar for companies to comply with complex and, often, opaque rules. Many firms are, therefore, pursuing technology-based solutions in order to mitigate this new legal risk. These emerging technological alternatives reduce the need for open-ended cross-border transfers and the practical challenges and legal risk that such transfers create after Schrems. This article examines one such alternative, namely a user-held data model. This approach takes advantage of personal data clouds that allows data subjects to store their data locally and in a more decentralised manner, thus decreasing the need for cross-border transfers and offering end-users the possibility of greater control over their data.
format Preprint
id arxiv_https___arxiv_org_abs_2407_20514
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle The Future of International Data Transfers: Managing Legal Risk with a User-Held Data Model
Jurcys, Paulius
Compagnucci, Marcelo Corrales
Fenwick, Mark
Computers and Society
The General Data Protection Regulation contains a blanket prohibition on the transfer of personal data outside of the European Economic Area unless strict requirements are met. The rationale for this provision is to protect personal data and data subject rights by restricting data transfers to countries that may not have the same level of protection as the EEA. However, the ubiquitous and permeable character of new technologies such as cloud computing, and the increased inter connectivity between societies, has made international data transfers the norm and not the exception. The Schrems II case and subsequent regulatory developments have further raised the bar for companies to comply with complex and, often, opaque rules. Many firms are, therefore, pursuing technology-based solutions in order to mitigate this new legal risk. These emerging technological alternatives reduce the need for open-ended cross-border transfers and the practical challenges and legal risk that such transfers create after Schrems. This article examines one such alternative, namely a user-held data model. This approach takes advantage of personal data clouds that allows data subjects to store their data locally and in a more decentralised manner, thus decreasing the need for cross-border transfers and offering end-users the possibility of greater control over their data.
title The Future of International Data Transfers: Managing Legal Risk with a User-Held Data Model
topic Computers and Society
url https://arxiv.org/abs/2407.20514