Before transferring or disclosing personal data outside the state, the organization must perform and document a risk assessment to ensure lawful and secure processing, especially when the transfer involves sensitive or large-scale data or occurs under legal provisions.
The assessment must:
- Define the purpose and legal basis of the transfer.
- Describe its scope and the safeguards applied.
- Evaluate potential risks or harm to data subjects.
- Ensure that only the minimum necessary data is transferred.
- Confirm that safeguards maintain the required level of privacy and protection.
The organization must also ensure that transfers do not undermine:
- The rights of data subjects, including consent withdrawal.
- Its ability to report data breaches, destroy data, or enforce security measures.
Transfers must be suspended immediately if they present high privacy risks, compromise national security or vital interests, or if safeguards become invalid. Suspended transfers must be re-assessed before any continuation or future transfer.