Cross-Border Data Flows
Master cross-border data flows. 50 deep dives across 300 lessons covering foundations (sovereignty, localization vs free flow, treaties), EU mechanisms (GDPR Chapter V, adequacy, EU-US DPF, SCCs, BCRs, Article 49, Schrems II, TIAs), US mechanisms (DPF, UK-US bridge, APEC CBPR, CLOUD Act), APAC (China three-pathway, Japan, India DPDPA, Singapore, Australia, Korea, Indonesia), other regions (UK IDTA, Brazil LGPD, Canada PIPEDA, LATAM), sectoral (financial, healthcare, government, defense ITAR/EAR, cloud, telecom), operations (multi-jurisdiction strategy, vendor management, SCC implementation, BCR approvals, TIAs in practice, breach coordination, DSAR handling), and emerging issues (AI training data, genomic data, children's data, government access, future governance).
All Topics
50 cross-border data flow topics organized into 9 categories. Each has 6 detailed lessons with statutory frameworks, sample clauses, and practical templates.
Foundations
Cross-Border Data Flow Foundations
Master the foundations of cross-border data flows. Learn what counts as a 'transfer', the legal taxonomy of data movements, the mapping framework, and why CBDF matters for global digital trade.
6 LessonsData Sovereignty Doctrine
Master data sovereignty doctrine. Learn the constitutional and political foundations of data sovereignty, government access concerns, and the major regional approaches.
6 LessonsData Localization vs Free Flow Debate
Engage with the data localization debate. Learn the arguments for and against localization, the OECD/WTO position, country-by-country localization map, and economic impact studies.
6 LessonsCross-Border Data Flow Economics
Master CBDF economics. Learn the trade impact of data flows, the McKinsey/IMF studies, the cost of localization mandates, and the WTO digital trade negotiations.
6 LessonsCross-Border Data Flow Treaties
Master CBDF treaties. Learn USMCA Chapter 19, CPTPP digital trade rules, EU bilateral adequacy, ASEAN frameworks, and the Council of Europe Convention 108+.
6 LessonsGlobal Data Flow Mapping
Master global data flow mapping. Learn how to map enterprise data flows, identify transfer triggers, document mechanisms, and maintain transfer registers for audit.
6 LessonsEU Cross-Border Mechanisms
GDPR Chapter V Architecture
Master GDPR Chapter V architecture. Learn the transfer hierarchy (adequacy > safeguards > derogations), Article 44 general principle, accountability requirements, and the no-ride-around rule.
6 LessonsEU Adequacy Decisions Framework
Master EU adequacy decisions. Learn the Article 45 framework, current adequacy decisions, criteria for adequacy, periodic review, and the EDPB's role.
6 LessonsEU-US Data Privacy Framework Deep Dive
Master the EU-US Data Privacy Framework. Learn the principles, certification process, DPRC review, ombudsperson, EDPB opinion, and the pending Schrems III challenge.
6 LessonsStandard Contractual Clauses (2021)
Master the 2021 SCCs. Learn the four modules (C2C, C2P, P2P, P2C), docking clause, supplementary measures, governing law, and the SCC negotiation patterns.
6 LessonsBinding Corporate Rules (BCRs)
Master BCRs. Learn the BCR-Controller and BCR-Processor frameworks, content requirements, approval process via lead DPA, and major BCR adopters.
6 LessonsArticle 49 Derogations
Master Article 49 derogations. Learn the seven derogations (consent, contract, public interest, legal claims, vital interests, register, compelling LI), and EDPB Guidance 2/2018.
6 LessonsSchrems II Compliance Path
Master post-Schrems II compliance. Learn the case in detail, transfer impact assessment requirement, supplementary measures (technical, contractual, organizational), and EDPB Recommendations 01/2020.
6 LessonsTransfer Impact Assessments (TIAs)
Master TIAs. Learn the six-step methodology, third-country law assessment, supplementary measures selection, documentation requirements, and the IAPP/CIPL TIA frameworks.
6 LessonsUS Cross-Border Mechanisms
EU-US DPF (US Side)
Master the US side of EU-US DPF. Learn DOC certification process, FTC enforcement, principles compliance, and how US companies operationalize the framework.
6 LessonsUK-US Data Bridge
Master the UK-US Data Bridge. Learn the UK Extension to the DPF, ICO oversight, UK-only obligations, and how UK transfers integrate with EU transfers.
6 LessonsAPEC CBPR for US Companies
Master APEC CBPR for US companies. Learn the US accountability agent (TrustArc, Schellman), certification process, scope of CBPR, and value vs DPF.
6 LessonsCLOUD Act & Lawful Access
Master the CLOUD Act. Learn the law's scope, MLAT vs CLOUD Act access, executive agreements (UK, Australia), and the conflict with foreign blocking laws.
6 LessonsUS Government Access to Foreign Data
Master US government access to foreign data. Learn FISA Section 702, EO 12333, the Schrems II court's analysis, FISA reform debates, and PRESIDENTIAL access controls.
6 LessonsAPAC Cross-Border
APEC Cross-Border Privacy Rules
Master APEC CBPR system. Learn the participating economies, accountability agents, certification standards, and the Global CBPR Forum (post-2022).
6 LessonsChina Cross-Border Data Transfer Rules
Master China cross-border transfer rules. Learn the three pathways (CAC Security Assessment, China SCC + filing, certification), thresholds, important data, and recent CAC enforcement.
6 LessonsJapan Cross-Border Transfer Framework
Master Japan APPI cross-border framework. Learn equivalent country list (EU adequate, etc.), sufficient measures requirement, consent, and the EU-Japan Mutual Adequacy.
6 LessonsIndia DPDPA Cross-Border Rules
Master India DPDPA cross-border rules. Learn the negative list approach (vs whitelist), notification requirements, sectoral rules (finance, telecom), and pending Rules.
6 LessonsSingapore PDPA Cross-Border
Master Singapore PDPA cross-border. Learn the comparable protection requirement, contracts, BCRs, and Singapore's role as APEC and ASEAN data hub.
6 LessonsAustralia Cross-Border Disclosure
Master Australia Privacy Act cross-border (APP 8). Learn the accountability principle, reasonable steps requirement, exceptions, and the 2024 reforms.
6 LessonsSouth Korea PIPA Cross-Border
Master South Korea PIPA cross-border. Learn the consent requirement (separate consent for transfers), notification, certification, and 2023 amendments easing transfers.
6 LessonsIndonesia PDP Law Cross-Border
Master Indonesia PDP Law (UU PDP 2022) cross-border. Learn adequate-country recognition, contractual safeguards, consent, and sectoral localization (banking, e-commerce).
6 LessonsOther Regional Mechanisms
UK International Data Transfer Agreement (IDTA)
Master the UK IDTA. Learn IDTA structure, UK Addendum to EU SCCs, ICO transfer risk assessment guidance, and the practical multi-mechanism strategy for UK + EU + global.
6 LessonsBrazil LGPD Cross-Border
Master Brazil LGPD cross-border. Learn ANPD-issued adequate countries, Standard Contractual Clauses (Brazil), specific consent, and the Brazil-EU adequacy negotiations.
6 LessonsCanada PIPEDA International Transfers
Master Canada PIPEDA international transfers. Learn the accountability principle, transfer for processing vs disclosure, contractual measures, and consent considerations.
6 LessonsLatin America Cross-Border Patterns
Master Latin America CBDF patterns. Learn Mexico LFPDPPP, Argentina (EU adequate), Chile, Colombia, the Ibero-American Data Protection Network, and regional convergence.
6 LessonsSectoral Cross-Border
Financial Services Data Localization
Master financial services data localization. Learn RBI India localization, China financial data rules, EU DORA cross-border ICT services, MAS Singapore, and FFIEC US guidance.
6 LessonsHealthcare Data Cross-Border
Master healthcare data cross-border. Learn HIPAA + cross-border, EU EHDS, GDPR Article 9 health data rules, clinical trial data flows, and genomic data transfer issues.
6 LessonsGovernment / Public Sector Data Sovereignty
Master government data sovereignty. Learn FedRAMP and US government data, EU public sector localization, classified data restrictions, and sovereign cloud offerings.
6 LessonsDefense Data ITAR/EAR Controls
Master ITAR/EAR controls on defense data. Learn USML categories, deemed exports, encryption controls, AI/ML export controls, and recent BIS rule changes.
6 LessonsCloud Service Provider Data Flows
Master cloud service provider cross-border flows. Learn AWS, Azure, GCP region/data residency offerings, EU sovereign cloud (Bleu, S3NS), and customer-controlled keys.
6 LessonsTelecom Data Cross-Border
Master telecom data cross-border. Learn CPNI cross-border restrictions, EU electronic communications privacy, ITU principles, and international roaming data flows.
6 LessonsCompliance Operations
Multi-Jurisdiction Transfer Strategy
Master multi-jurisdiction transfer strategy. Learn the strictest-jurisdiction baseline, mechanism stacking, transfer registers, supplier flow-down, and regional transfer hubs.
6 LessonsVendor Cross-Border Management
Master vendor cross-border management. Learn vendor due diligence for transfers, contractual provisions, ongoing monitoring, sub-processor management, and vendor exit planning.
6 LessonsSCC Implementation in Practice
Master SCC implementation. Learn SCC negotiation patterns, Annex completion (1, 2, 3), supplementary measure documentation, signing process, and version management.
6 LessonsBCR Approval Process
Master the BCR approval process. Learn lead DPA selection, application submission, EDPB review, approval timelines, and post-approval maintenance.
6 LessonsTIA Methodology in Practice
Master TIA methodology in practice. Learn the data-flow-by-data-flow analysis, third-country assessment, supplementary measure evaluation, documentation, and reassessment triggers.
6 LessonsData Flow Mapping for Compliance
Master data flow mapping for compliance. Learn the discovery process, taxonomy of flows, automated tools (OneTrust, Securiti), maintenance cadence, and audit-readiness.
6 LessonsCross-Border Breach Coordination
Master cross-border breach coordination. Learn lead DPA notification, multi-DPA notification orchestration, conflicting timelines, attorney-client privilege, and regulatory cooperation.
6 LessonsCross-Border DSAR Handling
Master cross-border DSAR handling. Learn jurisdictional DSR variations, central intake design, identity verification across regimes, exemption mapping, and response document standards.
6 LessonsEmerging & Specialized
AI Training Data Cross-Border Issues
Master AI training data cross-border issues. Learn jurisdictional issues with global training datasets, GDPR Art 22 cross-border implications, the EU AI Act cross-border, and inference cross-border.
6 LessonsGenomic Data Cross-Border Regulation
Master genomic data cross-border regulation. Learn special category status, biobank cross-border rules, China human genetic resource rules, and US genomic privacy issues.
6 LessonsChildren's Data Cross-Border Rules
Master children's data cross-border. Learn COPPA cross-border, EU GDPR child data rules (Article 8), age assurance across jurisdictions, and EdTech cross-border challenges.
6 LessonsCross-Border Government Access
Master cross-border government access. Learn MLATs (Mutual Legal Assistance Treaties), CLOUD Act process, EU e-evidence regulation, and multi-jurisdictional law enforcement requests.
6 LessonsFuture of Global Data Governance
Engage with the future of global data governance. Learn the Data Free Flow with Trust (DFFT) initiative, OECD AI/data work, UN Global Digital Compact, and the digital trade agenda.
6 Lessons
Lilly Tech Systems