“If you do not meet the adequacy decision of the GDPR,” said Ipac, “the controller or processor to whom you are sharing personal information must have provided appropriate safeguards, such as the EU’s standard contractual clauses.”
He added that within the ASEAN region, businesses should instead look to the ASEAN Model Contractual Clauses (MCCs) to regulate inter-country data transfers — though they don’t override the requirements of the GDPR if it applies directly.
Beyond legal frameworks, Ipac urged attendees to prioritize due diligence. “The key takeaway from international cases is this: It’s not enough to draft a good privacy policy. You need to ensure that it’s backed by actual practices that meet both legal and factual scrutiny,” he said.
Ipac is a member of the International Association of Privacy Professionals and a key member of DivinaLaw’s Data Privacy team.