Service

CROSS-BORDER DATA TRANSFER PERMIT

According to the Personal Data Protection Act, Chapter 44, the Personal Data Protection Commission (PDPC) is mandated to regulate and oversee the transfer of Personal Data outside the country to ensure that such data is accorded an adequate level of protection.

According to the Personal Data Protection Act, Chapter 44, the Personal Data Protection Commission (PDPC) is mandated to regulate and oversee the transfer of Personal Data outside the country to ensure that such data is accorded an adequate level of protection.

In discharging this mandate, the Commission:
  1. Issues permits to entities intending to transfer personal data outside the country;
  2. Assesses the level of Personal Data protection in the destination country to ensure adequacy and comparability with domestic standards;
  3. Ensures that appropriate legal, technical, and organizational safeguards are in place prior to any Personal Data transfer;
  4. Establishes conditions and compliance requirements for cross-border data transfers;
  5. Monitors and audits adherence to the set conditions to prevent misuse, unauthorized access or data breaches.

Furthermore, the Commission seeks to ensure that cross-border data transfers do not compromise the rights and privacy of data subjects and that personal data remains protected against risks such as loss, unauthorized disclosure or unlawful processing.

Through this permit-based framework, the Commission enhances accountability among data controllers and processors, and ensures that all international data transfer activities are conducted in compliance with the law, transparency and best practices in data protection.

Application Procedure for Cross-Border Data Transfer Permits
Any entity intending to transfer personal data outside the country is required to submit a formal application to the Personal Data Protection Commission (PDPC) in accordance with the following procedure:
  1. Submission of Formal Application
The applicant shall submit a written application detailing:
*The type of personal data to be transferred;
*The purpose of the transfer;
*The destination country and recipient entity;
*The duration and method of transfer.

2. Provision of Compliance Information
The applicant must demonstrate that:
*They comply with applicable data protection laws;
*Adequate security measures are in place;
*There are legally binding agreements between parties involved.

3. Assessment by the Commission
The Commission shall assess the application based on:
*The level of data protection in the destination country;
*Potential risks to personal data;
*Availability of adequate safeguards.

4. Decision Making
Upon assessment, the Commission may:
*Approve the application and issue a permit;
*Request additional information; or
*Reject the application if requirements are not met.

5. Monitoring and Compliance
The applicant shall comply with the conditions of the permit, and the Commission will conduct periodic monitoring to ensure continued compliance.

Compliance Checklist for Cross-Border Data Transfers
Before submitting an application, entities are advised to ensure the following:
  1. The purpose of the data transfer is clearly defined and lawful;
  2. Only necessary data is transferred (data minimization principle);
  3. Consent from the data subject has been obtained where required;
  4. Adequate technical and organizational security measures are in place;
  5. A legally binding agreement exists between the parties;
  6. The destination country ensures an adequate level of data protection;
  7. Risks associated with the transfer have been assessed and mitigated;
  8. Data breach response mechanisms are established;
  9. Measures are in place to uphold data subject rights.