

If you follow our blog posts, you may have noticed a theme emerging over the past months: increasing cyber security requirements. We recently published an article outlining the potential for Australia to introduce more robust cyber security regulation and we highlighted Australia’s first cyber security case. In this post, we’ll take a deeper look at the technical requirements outlined in the new SCCs. Then, we’ll outline how these can be used to develop stronger technical cyber security measures at your organisation.
Read this article first if you need a refresher on the significance of the new SCCs.
The GDPR requires any data transferred out of the EU to be protected by measures that are essentially equivalent to the EU standard. The supplementary measures, including the technical measures outlined in Annex II of the new SCCs, have been developed to help organisations meet that requirement.
The European Data Protection Board (EDPB) released their updated recommendations in the days following the publication of the new SCCs. These recommendations provided specific examples of ‘effective’ measures.
For businesses that are required to comply with the SCCs, these serve as a useful cynosure. Organisations that aren’t required to comply with the SCCs may still draw best practices from these examples. As we outlined above, there is a global trend emerging in privacy regulation requiring greater technical cyber security measures. Consumer sentiment reflects the growing demand for better cyber security too.
Under the new SCCs, data exporters are likely to be able to transfer encrypted data to third countries for storage where the data importer is verified and there are effective encryption measures in place.
The EDPB’s guidance refers to the following encryption measures specifically:
We wrote previously about an innovative encryption tool we helped develop. You can find the white paper on Cryptoloc here.
Pseudonymisation can be an effective measure for protecting personal data when the data being transferred is intended to be used by the data importer. This covers situations like, for instance, when the information will be used for research purposes.
The EDPB’s guidance goes on to specify the following conditions for pseudonymisation to be considered an effective measure:
It is important to consider, however, that pseudonymisation doesn’t always protect the data subject. In some cases, the data importer (or third parties who intercept or otherwise receive the data) can use techniques like brute attack, guesswork, or dictionary search to essentially reverse the pseudonymisation.
For more information about robust pseudonymisation measures, read this guidance from the European Union Agency for Cybersecurity (ENISA): https://www.enisa.europa.eu/publications/pseudonymisation-techniques-and-best-practices/at_download/fullReport
Whether or not your organisation is required to consider the SCCs for cross-border data transfers from the EU, you should be starting to reflect on the cyber security measures you have in place to protect the personal data you hold. The technical measures from Annex II (referred to above) are a good starting point. But organisations must first identify the personal data they collect, store, use and transfer, and the must understand organisational data flows.
If you need assistance mapping data flows within your organisation or developing more robust cyber security measures to protect personal information and to comply with the EU’s SCCs, get in touch. Privacy 108 has extensive experience in identifying, managing and streamlining organisational data flows and in developing resilient technical protections.
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.