A US company that is not self-certified under the EU-US Data Privacy Framework must still receive occasional, one-off personal data from an EU partner for a specific contractual purpose, and no adequacy mechanism or standard contractual clauses are in place. Which lawful basis under EU transfer rules best fits this limited situation?
- AA general legitimate-interests assessment that permits routine transfers without further conditions once documented.
- BAn adequacy decision the company can invoke because the US already holds a country-wide adequacy status.
- CBinding corporate rules covering the EU partner and the US company even though they are unrelated entities.
- DA derogation for transfers necessary for the performance of a contract, available for occasional and not repetitive transfers. Correct
Why A is wrong: Tempting because legitimate interests is a processing ground, but it is not a standalone transfer mechanism for routine cross-border flows and does not substitute for an appropriate safeguard or derogation.
Why B is wrong: Tempting because the framework brings partial adequacy, but the US has no blanket country-wide adequacy; only certified organisations benefit, which this company is not.
Why C is wrong: Tempting because binding corporate rules authorise transfers, but they apply within a single corporate group of related undertakings and cannot cover two unrelated companies.
Why D is correct: Correct: where no adequacy decision or appropriate safeguards apply, the contractual-necessity derogation can cover transfers that are occasional and necessary to perform a contract with or in the interest of the data subject, fitting a genuinely one-off need.