Include the data transfers in the Binding Corporate Rules.
CONTROL ID 12590
CONTROL TYPE Establish/Maintain Documentation
CLASSIFICATION Preventive
SUPPORTING AND SUPPORTED CONTROLS
This Control directly supports the implied Control(s):
Establish, implement, and maintain Binding Corporate Rules for the international transfers of restricted data., CC ID: 12584
This Control has the following implementation support Control(s):
Include specifying the mechanisms for verifying compliance of the binding corporate rules in the Binding Corporate Rules., CC ID: 12662
Include the identification of the countries in question for the data transfers in the Binding Corporate Rules., CC ID: 12601
Include the type of data subjects affected by the data transfers in the Binding Corporate Rules., CC ID: 12600
Include all pertinent data processing information for data transfers in the Binding Corporate Rules., CC ID: 12599
Include the categories of personal data for data transfers in the Binding Corporate Rules., CC ID: 12598
SELECTED AUTHORITY DOCUMENTS COMPLIED WITH
The competent authorities of the People's Republic of China shall handle foreign judicial or law enforcement authorities' requests for personal information stored within China in accordance with relevant laws and the international treaties and agreements concluded or acceded to by the People's Repub… (Article 41, Personal Information Protection Law of the People's Republic of China)
the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of the third country or countries in question; (Art. 47.2.(b), Regulation (EU) 2016/679 of The European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation))
binding corporate rules in accordance with Article 47; (Art. 46.2.(b), Regulation (EU) 2016/679 of The European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation))