Subject to the provisions of the PDPA, if personal data is transferred overseas, the destination country or international organization which receives the personal data must have “adequate data protection standards”, the adequacy of which is based on the following factors:
- the presence of PDPA-compliant legal measures or mechanisms, especially those regulating the duties of the data controller, providing appropriate security measures and personal data protection measures which can be enforced in accordance with the rights of the data subject and effective legal remedies; and
- the agencies or organizations that have the duty and authority to enforce such laws.
If any doubt arises regarding the adequacy of the data protection standards of the destination country or international organization, the PDPC shall be empowered to make the decision.