Cork hospital fined €65k after patients’ personal data found in public recycling facility
Cork hospital fined €65k after patients’ personal data found in public recycling facility The Data Protection Commission (DPC) has handed […]
Last reviewed: 24 August 2026.
Signing Standard Contractual Clauses is not the end of an international transfer review. Where an organisation relies on an Article 46 transfer tool, it must assess whether the protection promised by that tool can work in the legal and practical circumstances of the transfer.
That assessment is commonly called a transfer impact assessment (TIA), data transfer impact assessment (DTIA), or, in the United Kingdom, a transfer risk assessment (TRA). The labels vary. The underlying question is the same: can the personal data receive a level of protection that is essentially equivalent to the protection guaranteed in the European Union?
This guide explains when a TIA is needed, how to complete one without turning it into a generic country report, and how to connect the result to your RoPA, vendor records, contracts, DPIAs and security controls.
A transfer impact assessment is a documented, case-specific analysis used to test whether an international transfer safeguard remains effective in practice. The term “TIA” does not appear in the GDPR itself. The obligation comes from the GDPR’s requirement for appropriate safeguards, the Court of Justice judgment in Schrems II, the European Data Protection Board’s recommendations, and, for the 2021 EU Standard Contractual Clauses, Clause 14.
A useful TIA does not attempt to declare an entire country safe or unsafe. It examines the laws and practices that are relevant to a particular importer, sector, data set, purpose and technical architecture. It then records whether the selected transfer tool is effective, whether additional measures are needed, and whether the transfer can proceed.
Important: A TIA is not the same as a DPIA. A DPIA examines risks created by a processing operation. A TIA examines whether Chapter V safeguards remain effective after personal data is transferred or made available to an importer in a third country. The same activity may require both assessments.
Not every use of a non-EEA vendor calls for the same assessment. Identify the transfer route first. The route decides what you have to document.
Examines whether Chapter V safeguards remain effective after personal data is transferred or made available to an importer in a third country.
Examines the risks created by a processing operation itself, regardless of where the data goes.
The same activity may require both assessments. Keep the legal tests separate, but connect the records and reuse verified factual information.
A TIA is only as reliable as the transfer map beneath it. Work through the steps in order so you assess the right activity, with the right evidence.
Use the three cumulative criteria. Record why a transfer does or does not exist, including remote access from outside the EEA.
Document entities, data, purposes, locations, subprocessors and who holds the keys. Do not rely on the vendor’s country of incorporation alone.
Identify the legal route before analysing risk. Adequacy, SCCs, another Article 46 tool or an Article 49 derogation each carry different steps.
Require transfer-specific answers and evidence, not yes-or-no assurances. A vendor’s global memo is input, not your TIA.
Focus on public authority access, oversight and redress, and whether the importer can comply without breaching local law.
Consider the specific circumstances and reliable evidence. An absence of past requests is not decisive against a material legal concern.
Where the tool is not sufficient, add technical, contractual and organisational measures that address the specific gap.
Record a clear outcome, link the supporting records, and set event-based triggers so material changes force a review.
The EDPB uses three cumulative criteria to identify an international transfer:
Remote access can be a transfer. A vendor’s support team, group company or subprocessor may access data from outside the EEA even when the primary server is located in Europe. Direct collection from an individual by a third-country organisation is not automatically a transfer from the individual, although the organisation may still be subject to the GDPR and other safeguards may be necessary.
Record why Chapter V does or does not apply. This threshold decision prevents teams from producing TIAs for the wrong activities while missing transfers hidden inside support, analytics, administration or onward-processing arrangements.
A TIA is only as reliable as the transfer map beneath it. Use the RoPA, vendor register, contract, security review and system architecture together. Do not rely on the vendor’s country of incorporation alone.
For each transfer, document:
Avoid broad descriptions such as “customer information” or “cloud services”. A regulator or internal approver should be able to understand exactly what leaves the EEA, who can access it and why.
Identify the legal transfer route before analysing risk. The route determines which assessment, contract and monitoring steps are required.
Check whether the European Commission decision covers the destination, the type of recipient and the transfer. Some decisions are limited by sector or recipient status. The US decision, for example, covers participating commercial organisations rather than every organisation in the United States.
For the 2021 EU SCCs, the module must match the real relationship between exporter and importer. Complete the annexes so they reflect the actual transfer.
The SCCs do not replace the Article 28 processor agreement where that agreement is also required. Read them with the commercial contract, DPA, security schedule and subprocessor terms.
Binding Corporate Rules, approved codes of conduct, certification mechanisms and ad hoc contractual clauses can also support transfers where their legal conditions are met. The same core question remains: does the tool provide effective protection in the destination context? The documentation and approval route will differ from SCCs.
Derogations such as explicit consent, contractual necessity or important public interest are narrow exceptions. They should not become a convenient substitute for an Article 45 or 46 mechanism in routine vendor transfers. Record the precise condition, why it applies, and any required information provided to the data subject.
The exporter cannot complete a credible assessment without importer input. Build a standard questionnaire, but require evidence and transfer-specific answers rather than yes-or-no assurances.
A vendor’s global TIA or country memo can be useful evidence, but it is not automatically your TIA. The exporter remains responsible for checking that the evidence matches its own data, purposes, systems and contractual configuration.
Focus on laws and practices that could affect the importer’s ability to comply with the selected safeguard. The analysis should be proportionate, current and connected to the transfer.
Use reliable sources, including legislation, case law, official guidance, independent oversight reports and credible sector-specific material. Record the source, publication date, jurisdiction and the part of the assessment it supports. A generic internet summary should not be the only evidence for a material conclusion.
The 2021 SCCs allow the parties to consider the specific circumstances of the transfer and reliable information about how relevant laws are applied in practice. This is not permission to ignore objective legal concerns.
Relevant circumstances include:
Do not treat “the vendor has never received a request” as a pass. Documented practical experience may be considered under strict conditions, but it must be supported by objective evidence. An absence of past requests is not decisive when the law or credible evidence points to a material problem.
The conclusion is not whether the business is comfortable accepting a general commercial risk. The question is whether the transfer tool, together with any supplementary measures, provides the required level of protection.
The EDPB groups supplementary measures into technical, contractual and organisational controls. Match the measure to the specific gap, and record its owner, evidence and effective date.
Encryption in transit and at rest is good practice, but it does not solve every transfer problem. If the importer needs continuous access to plaintext and can be compelled to disclose it, ordinary server-side encryption may not prevent public authority access.
The conclusion should be clear enough for legal, security, procurement and the business owner to act without re-reading the file.
The transfer tool is effective in the circumstances and the evidence supports the conclusion.
Implement specified supplementary measures before transfer, verify evidence and record continuing conditions.
A material issue cannot be resolved from the available evidence. Obtain legal or technical input.
The required level of protection cannot be achieved. Change the architecture, recipient, location or route, or stop.
There is no universal GDPR rule that every TIA must be reviewed exactly once a year. Use a proportionate periodic review cadence and event-based triggers. Higher-risk or fast-changing transfers may need more frequent review.
A stand-alone TIA quickly becomes stale. Connect it to the records that change when the transfer changes.
GDPR Register helps privacy teams keep transfer assessments connected to processing activities, vendors, contracts, risks and review tasks. That connected record is more useful in an audit than a signed PDF stored in a separate folder.
Tick each item as you complete it. Progress is tracked as you go, and saved in your browser so you can return to it.
This article provides general information and is not legal advice. International transfer requirements depend on the parties, jurisdictions, data, purpose, transfer route and current law.
GDPR Register connects transfer assessments with RoPAs, vendor records, risks, documents, owners and review tasks. See how connected compliance records work in practice.