Description

National Commission on Informatics and Liberty adopted final guide on transfer impact assessments

On 31 January 2025, the National Commission on Informatics and Liberty (CNIL) adopted the final version of its guide on Transfer Impact Assessments (TIA) for cross-border data transfers. This guide aims to assist organisations in ensuring that personal data transferred outside the European Economic Area (EEA) maintains a level of protection equivalent to that provided by the General Data Protection Regulation (GDPR). The guide delineates a methodology for conducting TIAs, in accordance with the European Data Protection Board's recommendations, and comprises a 6-step manual, encompassing the identification of transfer tools, the evaluation of third-country legislation, and the implementation of supplementary measures where necessary.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-01-08
processing consultation

On 8 January 2024, the Commission nationale de l'informatique et des libertés (CNIL) opened a consu…

2024-02-12
in consultation

On 12 February 2024, the public consultation on the Commission nationale de l'informatique et des l…

2025-01-31
adopted

On 31 January 2025, the National Commission on Informatics and Liberty (CNIL) adopted the final ver…