The Approach to Defining Countries With Adequate Data Protection Has Changed

Rate this post

New rules governing the cross-border transfer of personal data have come into force, affecting companies that work with foreign services, contractors and overseas group entities. A country’s status as offering an adequate level of data protection will no longer be determined by a formal criterion alone, but by the actual measures the state takes to safeguard citizens’ rights.

What has changed in the approach

Previously, a country’s formal participation in the relevant international convention on the protection of individuals in the automated processing of personal data was enough for it to be included on the list of states recognised as providing adequate protection. This is no longer sufficient – the regulator will now assess how a country applies its own legislation in practice and what real protective mechanisms operate within its territory.

The revision was prompted by observations that certain foreign authorities do not always ensure the restoration of citizens’ violated rights, even where their legislation formally complies with international standards. The new approach is intended to close this gap between a country’s formal status and the actual level of data protection it provides.

How the system currently works

The current list of countries with adequate data protection was drawn up several years ago and includes around ninety states – among them CIS countries, a large share of European states, and several jurisdictions that are not party to the relevant convention but apply comparable standards. Alongside the change in approach, the regulator has put forward a draft of an updated list, proposing to remove one previously included jurisdiction.

  • countries on the approved list are subject to a notification regime – a company notifies the regulator and may begin transferring data as soon as the notification is filed;
  • for countries not on the list, a stricter procedure applies – the operator must additionally disclose information about data protection regulation in the recipient country and wait for the review of the notification to be completed;
  • the regulator reviews each notification within a set period and may restrict or prohibit the data transfer.

Expert assessments and practical risks

Lawyers see a mixed effect from the changes. On one hand, the new approach genuinely allows the actual level of data protection in a given country to be taken into account, rather than relying solely on formal participation in an international agreement. On the other, it increases regulatory unpredictability: a country’s status now depends on the regulator’s discretion, and the assessment criteria are not exhaustively defined in the law. In practice, the authority looks at whether a country has a dedicated data protection body, national legislation on personal data, and a system of sanctions for violations – though even these criteria leave room for discretion when the final list is drawn up.

Experts generally agree that the mechanism of cross-border data transfer itself remains unchanged, and that notifications already filed will not be reviewed retroactively, since the new rules do not apply retrospectively. At the same time, further revisions to the list are expected to target jurisdictions currently regarded as less friendly.

What this means for business

Companies that transfer personal data abroad should review their cross-border data flows in advance and identify which of them rely solely on a country’s formal status on the list. Particular attention should be paid to the use of foreign CRM systems, cloud storage, analytics services, and situations where foreign group entities or contractors gain access to data located in Russia – formally, this also falls within the concept of cross-border transfer.

A potential revision of the list is likely to affect e-commerce and the financial sector most heavily, as well as any business heavily reliant on foreign IT infrastructure. A sensible strategy would be to identify alternative service providers in advance in case a particular jurisdiction is removed from the approved list, and to regularly monitor updates to the list and regulatory clarifications – since the final criteria for assessing countries are still being shaped in practice rather than exhaustively fixed in the text of the law.

Share: