On July 28, 2020, German supervisory authorities (Datenschutzkonferenz, the “DSK”) issued a statement emphasizing that organizations that rely on Standard Contractual Clauses (“SCCs”) or Binding Corporate Rules (BCRs”) must implement additional safeguards to lawfully transfer personal data to third countries.  In keeping with the Court of Justice of the European Union  CJEU’s judgment of 7/16, and the European Data Protection Board EDPB FAQ Memo of 7/20, the German DSK statement affirmed it’s intent of enforcing GDPR under the framework of the Court’s ruling, and with no grace period to comply.  The highlights of the German DSK statement are: Organizations receiving transfers of EU Personal Data outside of the European Economic Area (EEA) are required to review the mechanisms and provide additional protections to safeguard the privacy rights…