Well, I'm back.
I hope to carry on blogging about the law from the slightly different perspective that I have adopted in the past. In particular, I want to try talking about some difficult questions that I come across while working with clients and which I can't help thinking about in my spare time. Thank you for helping me scratch that itch.
This post is just an introduction. If you are familiar with how the GDPR works, then you should skip to the bit about Brexit.
The export of personal data
I want to start by talking about the General Data Protection Regulation, or GDPR as it is affectionately known, which will have been in force for two years in May. In particular, I want to talk about the regime create by the GDPR for the international transfer of data. From a technical point of view, transferring data around the world is, thanks to the Internet, not only straightforward but often invisible. However, from a legal perspective it is not so simple.The reason why the GDPR tries to control international transfers of data is simple to see. The GDPR's aim is to create a region of really strong protection for personal data in the European Union and the European Economic Area. If someone processing personal data could simply transfer it outside that region and do whatever they liked with it, it would be really easy to get around the GDPR. The protection it gives would be much less useful.
How exports are controlled
The GDPR divides the world into two parts: a "safe" part, which at the moment contains the EU and the EEA; and a potentially wild and dangerous part consisting of what are called "third countries". By the way, there is (as far as I have been able to discover) no formal definition of "third country" as you might expect. It seems to be understood to mean anywhere that isn't a member state of the EU or the EEA, but maybe other countries (eg the UK after Brexit) could escape being "third countries" in the same way as the EEA members have done.By default, moving data from the safe part of the world to a third country is forbidden, unless one of a (long) list of conditions is met. I plan to look through some of these conditions over this blog series, but in a moment, I will give a brief summary of two that are particularly significant.
Adequacy
The European Commission can declare that a country has "adequate" protection. Even though the country is a mere third country, it has done enough to live up to the high standards set by Europeans and data may be exported there.This is a sort of data imperialism, perhaps with the hope that European data protection law will dominate the world. Given the steadily increasing list of countries declared "adequate", this may be working.
But, a word of caution about adequacy. Adequacy decisions can be made that are limited to certain kinds of transfer. In other words, just because a country is in the list, does not mean that you can just export data there without further thought. A few countries, for example the United States and Japan have adequacy decisions that are limited in various ways.
For example, the United States clearly does not think that it has to play along with the EU's data protection rules but has set up a system known as the "Privacy Shield" which allows companies to opt into a lightweight version of the GDPR. The USA only counts as having "adequate" protection for transfer to companies who are members of the Privacy Shield. I will have quite a bit to say about the Privacy Shield in a later blog.

