{"id":17928,"date":"2025-03-24T08:00:48","date_gmt":"2025-03-24T08:00:48","guid":{"rendered":"https:\/\/letslaw.es\/?p=17928"},"modified":"2025-03-06T09:22:17","modified_gmt":"2025-03-06T09:22:17","slug":"edpb-data-protection-seal-certification","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/edpb-data-protection-seal-certification\/","title":{"rendered":"The EDPB clarifies rules for data exchange with authorities in third countries and approves the EU Data Protection Seal Certification"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">In an effort to strengthen personal data protection in the context of international transfers, the European Data Protection Board (EDPB) has issued <\/span><b>new guidelines on data exchange with authorities in third countries<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, it has approved the certification of the European Union (EU) Data Protection Seal, providing a clearer framework to ensure the security and legality of these practices.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">EDPB Legislation for International Data Transfers<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">International data transfers have been a critical issue in privacy regulation, especially after the invalidation of the Privacy Shield between the EU and the U.S. in 2020. The EDPB has reinforced requirements to ensure that any data transfer to authorities in third countries complies with the General Data Protection Regulation (GDPR).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The guidelines establish that:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Principle of necessity and proportionality<\/b><span style=\"font-weight: 400;\">: transfers of data to authorities in third countries must be strictly necessary and proportionate to the intended objective.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Adequate safeguard mechanisms<\/b><span style=\"font-weight: 400;\">: tools such as <\/span><a title=\"Standard Contractual Clauses\" href=\"https:\/\/letslaw.es\/en\/standard-contractual-clauses\/\"><span style=\"font-weight: 400;\">Standard Contractual Clauses<\/span><\/a><span style=\"font-weight: 400;\"> (SCCs) or Binding Corporate Rules (BCRs) must be used to ensure an adequate level of protection.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Prior risk assessment<\/b><span style=\"font-weight: 400;\">: before transferring data, companies and entities must assess whether the recipient country offers a level of protection equivalent to that of the GDPR.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Transparency and additional safeguards<\/b><span style=\"font-weight: 400;\">: in cases where there are potential risks of foreign authorities accessing data, notification mechanisms and additional security measures must be established.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">These measures aim to balance international cooperation with the need to protect the fundamental rights of European citizens.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Explanation of the Data Protection Seal Certification<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Along with transfer regulations, the EDPB has approved a certification scheme that allows organizations to demonstrate compliance with the GDPR through the EU Data Protection Seal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Features of the seal:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Voluntary<\/b><span style=\"font-weight: 400;\">: it is not mandatory but provides a competitive advantage to certified companies.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Strict evaluation criteria<\/b><span style=\"font-weight: 400;\">: it is based on requirements such as data minimization, security, data subjects\u2019 rights, and proactive accountability.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Supervision by accredited bodies<\/b><span style=\"font-weight: 400;\">: only certification entities recognized by data protection authorities can grant it.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Recognition across the EU<\/b><span style=\"font-weight: 400;\">: it facilitates business operations within the European Economic Area (EEA) and fosters trust among customers and partners.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">This seal not only improves transparency and regulatory compliance but also strengthens consumer trust in digital services.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Consequences and implementations for global companies<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The new EDPB guidelines impose challenges and opportunities for companies handling data of EU citizens. Some key implications include:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Review of transfer agreements<\/b><span style=\"font-weight: 400;\">: companies must assess their contracts and adapt their clauses to comply with the additional safeguards required.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Greater investment in data security<\/b><span style=\"font-weight: 400;\">: the use of advanced encryption, EU-based storage, and privacy-by-design strategies will be key to compliance.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Mandatory audits and documentation<\/b><span style=\"font-weight: 400;\">: continuous monitoring is required to demonstrate the adequacy of transfers and implemented protection measures.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Impact on international trade<\/b><span style=\"font-weight: 400;\">: companies operating in the U.S., China, or other countries must assess local legal frameworks and their potential conflicts with European regulations.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Leveraging the Data Protection Seal<\/b><span style=\"font-weight: 400;\">: obtaining certification can provide a competitive advantage by assuring customers and business partners of a strong commitment to data protection.<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">In conclusion, the EDPB strengthens <\/span><a title=\"data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\"><span style=\"font-weight: 400;\">personal data protection<\/span><\/a><span style=\"font-weight: 400;\"> in the international sphere by clarifying transfer rules and establishing a certification system. Companies must quickly adapt to these guidelines to avoid penalties and take advantage of the trust and security opportunities these regulatory changes bring.<\/span><\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/17928#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>The European Data Protection Board (EDPC) has issued new guidelines on the exchange of data with authorities in third countries. <\/p>\n","protected":false},"author":44,"featured_media":17930,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-17928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=17928"}],"version-history":[{"count":3,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17928\/revisions"}],"predecessor-version":[{"id":17929,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/17928\/revisions\/17929"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/17930"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=17928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=17928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=17928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}