CIPP-US - Introduction to the U.S. Privacy Environment - Section 1.4

Explain mechanisms for transferring personal data between the US and other jurisdictions, including adequacy decisions and standard contractual clauses.

Explain how adequacy decisions, standard contractual clauses, and binding corporate rules each serve as a legal basis for cross-border transfers of personal data to or from the US. Distinguish the conditions under which each mechanism is appropriate and recognise that an adequacy decision may be revoked, requiring a fallback transfer tool.

Adequacy decisionStandard contractual clausesCross-border transferEU-US data flows

Practice question for this objective

Free sampleIntroduction to the U.S. Privacy Environmenthard

A US company that is not self-certified under the EU-US Data Privacy Framework must still receive occasional, one-off personal data from an EU partner for a specific contractual purpose, and no adequacy mechanism or standard contractual clauses are in place. Which lawful basis under EU transfer rules best fits this limited situation?

  • AA general legitimate-interests assessment that permits routine transfers without further conditions once documented.
  • BAn adequacy decision the company can invoke because the US already holds a country-wide adequacy status.
  • CBinding corporate rules covering the EU partner and the US company even though they are unrelated entities.
  • DA derogation for transfers necessary for the performance of a contract, available for occasional and not repetitive transfers. Correct
For occasional, non-repetitive transfers without adequacy or safeguards, the contractual-necessity derogation can provide a lawful basis under EU transfer rules. Derogations are narrow exceptions used only when no adequacy decision or appropriate safeguard is available, and the contract-performance derogation is expressly limited to occasional transfers, which is why it fits a one-off contractual need rather than routine flows.

Why A is wrong: Tempting because legitimate interests is a processing ground, but it is not a standalone transfer mechanism for routine cross-border flows and does not substitute for an appropriate safeguard or derogation.

Why B is wrong: Tempting because the framework brings partial adequacy, but the US has no blanket country-wide adequacy; only certified organisations benefit, which this company is not.

Why C is wrong: Tempting because binding corporate rules authorise transfers, but they apply within a single corporate group of related undertakings and cannot cover two unrelated companies.

Why D is correct: Correct: where no adequacy decision or appropriate safeguards apply, the contractual-necessity derogation can cover transfers that are occasional and necessary to perform a contract with or in the interest of the data subject, fitting a genuinely one-off need.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Introduction to the U.S. Privacy Environment objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.