Articles

Transfer Impact Assessment: A Step-by-Step GDPR Guide for 2026

Krete Paal
CEO · 24.08.2026
Transfer impact assessment steps for GDPR international transfers

Last reviewed: 24 August 2026.

Signing Standard Contractual Clauses is not the end of an international transfer review. Where an organisation relies on an Article 46 transfer tool, it must assess whether the protection promised by that tool can work in the legal and practical circumstances of the transfer.

That assessment is commonly called a transfer impact assessment (TIA), data transfer impact assessment (DTIA), or, in the United Kingdom, a transfer risk assessment (TRA). The labels vary. The underlying question is the same: can the personal data receive a level of protection that is essentially equivalent to the protection guaranteed in the European Union?
This guide explains when a TIA is needed, how to complete one without turning it into a generic country report, and how to connect the result to your RoPA, vendor records, contracts, DPIAs and security controls.

What is a transfer impact assessment?

A transfer impact assessment is a documented, case-specific analysis used to test whether an international transfer safeguard remains effective in practice. The term “TIA” does not appear in the GDPR itself. The obligation comes from the GDPR’s requirement for appropriate safeguards, the Court of Justice judgment in Schrems II, the European Data Protection Board’s recommendations, and, for the 2021 EU Standard Contractual Clauses, Clause 14.

A useful TIA does not attempt to declare an entire country safe or unsafe. It examines the laws and practices that are relevant to a particular importer, sector, data set, purpose and technical architecture. It then records whether the selected transfer tool is effective, whether additional measures are needed, and whether the transfer can proceed.

Important: A TIA is not the same as a DPIA. A DPIA examines risks created by a processing operation. A TIA examines whether Chapter V safeguards remain effective after personal data is transferred or made available to an importer in a third country. The same activity may require both assessments.

Before you assess

When is a TIA required?

Not every use of a non-EEA vendor calls for the same assessment. Identify the transfer route first. The route decides what you have to document.

Situation
TIA position
No Chapter V transfer
No TIA under Chapter V. GDPR security, transparency, processor and accountability duties still apply.
Adequacy decision covers the destination and recipient
No SCC Clause 14 assessment for that route. Verify the decision’s territorial, sectoral and recipient scope, and monitor its status.
EU-US Data Privacy Framework
Adequacy route only for a US recipient whose active certification covers the relevant entity and data. Otherwise use another valid transfer tool.
SCCs or another Article 46 safeguard
Assess whether the safeguard is effective in the circumstances of the transfer. The 2021 SCCs expressly require an assessment of relevant laws and practices.
Article 49 derogation
A Clause 14 TIA is not the mechanism, but document why the narrow derogation applies. Derogations are exceptional and unsuitable for routine, repetitive transfers.
Do not confuse the two

A TIA is not a DPIA

TIA

Transfer Impact Assessment

Examines whether Chapter V safeguards remain effective after personal data is transferred or made available to an importer in a third country.

DPIA

Data Protection Impact Assessment

Examines the risks created by a processing operation itself, regardless of where the data goes.

The same activity may require both assessments. Keep the legal tests separate, but connect the records and reuse verified factual information.

The method

Eight steps to a defensible TIA

A TIA is only as reliable as the transfer map beneath it. Work through the steps in order so you assess the right activity, with the right evidence.

1

Confirm that Chapter V applies

Use the three cumulative criteria. Record why a transfer does or does not exist, including remote access from outside the EEA.

2

Map the transfer and onward access

Document entities, data, purposes, locations, subprocessors and who holds the keys. Do not rely on the vendor’s country of incorporation alone.

3

Select and verify the transfer tool

Identify the legal route before analysing risk. Adequacy, SCCs, another Article 46 tool or an Article 49 derogation each carry different steps.

4

Gather evidence from the importer

Require transfer-specific answers and evidence, not yes-or-no assurances. A vendor’s global memo is input, not your TIA.

5

Assess relevant laws and practices

Focus on public authority access, oversight and redress, and whether the importer can comply without breaching local law.

6

Assess the transfer in practice

Consider the specific circumstances and reliable evidence. An absence of past requests is not decisive against a material legal concern.

7

Select effective supplementary measures

Where the tool is not sufficient, add technical, contractual and organisational measures that address the specific gap.

8

Conclude, document and review

Record a clear outcome, link the supporting records, and set event-based triggers so material changes force a review.

Step 1: Confirm that Chapter V applies

The EDPB uses three cumulative criteria to identify an international transfer:

  • The exporter is a controller or processor subject to the GDPR for the relevant processing.
  • The exporter discloses or otherwise makes personal data available to another controller, joint controller or processor.
  • The importer is located in a third country or is an international organisation.

Remote access can be a transfer. A vendor’s support team, group company or subprocessor may access data from outside the EEA even when the primary server is located in Europe. Direct collection from an individual by a third-country organisation is not automatically a transfer from the individual, although the organisation may still be subject to the GDPR and other safeguards may be necessary.

Record why Chapter V does or does not apply. This threshold decision prevents teams from producing TIAs for the wrong activities while missing transfers hidden inside support, analytics, administration or onward-processing arrangements.

Step 2: Map the transfer and onward access

A TIA is only as reliable as the transfer map beneath it. Use the RoPA, vendor register, contract, security review and system architecture together. Do not rely on the vendor’s country of incorporation alone.

For each transfer, document:

  • Exporter and importer legal entities, roles and locations
  • Business purpose and processing purpose
  • Categories of data subjects and personal data, including special category or criminal-offence data
  • Volume, frequency, duration and retention period
  • How the data is transmitted, stored and accessed
  • Hosting, backup, disaster recovery, support and administration locations
  • Subprocessors and onward-transfer destinations
  • Whether the importer needs data in readable form
  • Who controls encryption or pseudonymisation keys
  • Existing contracts, SCC module, DPA, security measures and audit evidence

Avoid broad descriptions such as “customer information” or “cloud services”. A regulator or internal approver should be able to understand exactly what leaves the EEA, who can access it and why.

Step 3: Select and verify the transfer tool

Identify the legal transfer route before analysing risk. The route determines which assessment, contract and monitoring steps are required.

Adequacy decisions

Check whether the European Commission decision covers the destination, the type of recipient and the transfer. Some decisions are limited by sector or recipient status. The US decision, for example, covers participating commercial organisations rather than every organisation in the United States.

Standard Contractual Clauses

Choose the correct SCC module

For the 2021 EU SCCs, the module must match the real relationship between exporter and importer. Complete the annexes so they reflect the actual transfer.

1
Module 1Controller to controller
2
Module 2Controller to processor
3
Module 3Processor to processor
4
Module 4Processor to controller

The SCCs do not replace the Article 28 processor agreement where that agreement is also required. Read them with the commercial contract, DPA, security schedule and subprocessor terms.

Other Article 46 tools

Binding Corporate Rules, approved codes of conduct, certification mechanisms and ad hoc contractual clauses can also support transfers where their legal conditions are met. The same core question remains: does the tool provide effective protection in the destination context? The documentation and approval route will differ from SCCs.

Article 49 derogations

Derogations such as explicit consent, contractual necessity or important public interest are narrow exceptions. They should not become a convenient substitute for an Article 45 or 46 mechanism in routine vendor transfers. Record the precise condition, why it applies, and any required information provided to the data subject.

Step 4: Gather evidence from the importer

The exporter cannot complete a credible assessment without importer input. Build a standard questionnaire, but require evidence and transfer-specific answers rather than yes-or-no assurances.

  • Applicable surveillance, national security, law-enforcement and disclosure laws
  • Whether the importer is subject to those laws in the relevant capacity
  • Government access requests received, including the period, type and outcome where disclosure is legally possible
  • Public transparency reports and independent audit reports
  • Policies for reviewing, narrowing and challenging requests
  • Ability to notify the exporter and affected individuals
  • Data location, remote-access locations and subprocessor chain
  • Encryption design, key ownership, access logging and privileged access controls
  • Data deletion, return and portability arrangements
  • Material changes since the last assessment

A vendor’s global TIA or country memo can be useful evidence, but it is not automatically your TIA. The exporter remains responsible for checking that the evidence matches its own data, purposes, systems and contractual configuration.

Step 5: Assess relevant laws and practices

Focus on laws and practices that could affect the importer’s ability to comply with the selected safeguard. The analysis should be proportionate, current and connected to the transfer.

Public authority access

  • Which authorities can require or obtain access?
  • What legal thresholds, purposes and procedures apply?
  • Are access powers limited to what is necessary and proportionate?
  • Is independent authorisation or oversight available?
  • Can the importer challenge an unlawful or disproportionate request?
  • Can affected individuals obtain effective redress?

Enforceability and importer obligations

  • Can the importer comply with the SCCs or other safeguards without breaching local law?
  • Are contractual audit, notification, deletion and challenge commitments enforceable?
  • Do secrecy rules prevent the importer from giving meaningful information?
  • Are onward recipients subject to equivalent protections?

Use reliable sources, including legislation, case law, official guidance, independent oversight reports and credible sector-specific material. Record the source, publication date, jurisdiction and the part of the assessment it supports. A generic internet summary should not be the only evidence for a material conclusion.

Step 6: Assess the transfer in practice

The 2021 SCCs allow the parties to consider the specific circumstances of the transfer and reliable information about how relevant laws are applied in practice. This is not permission to ignore objective legal concerns.

Relevant circumstances include:

  • Nature and sensitivity of the personal data
  • Purpose, volume, frequency and duration of the transfer
  • Type of importer and sector
  • Storage and processing locations
  • Likelihood that the importer falls within the scope of relevant access powers
  • Whether the data is intelligible to the importer or authorities
  • Documented sector experience and independent evidence
  • Technical, contractual and organisational protections already in place

Do not treat “the vendor has never received a request” as a pass. Documented practical experience may be considered under strict conditions, but it must be supported by objective evidence. An absence of past requests is not decisive when the law or credible evidence points to a material problem.

The conclusion is not whether the business is comfortable accepting a general commercial risk. The question is whether the transfer tool, together with any supplementary measures, provides the required level of protection.

Step 7: Select effective supplementary measures

Where the tool is not enough

Three families of supplementary measures

The EDPB groups supplementary measures into technical, contractual and organisational controls. Match the measure to the specific gap, and record its owner, evidence and effective date.

TechnicalConstrain what the importer can read
  • Strong encryption with keys held in the EEA
  • Robust pseudonymisation, kept separate
  • Data minimisation, tokenisation, split processing
  • Privileged-access management and immutable logging
  • Architectures that avoid intelligible data
ContractualImprove accountability
  • Enhanced transparency and notification duties
  • Commitments to review and challenge access requests
  • Audit and evidence rights
  • Onward-transfer and subprocessor restrictions
  • Termination, suspension and deletion rights
OrganisationalGovern day to day
  • Government-access response procedures
  • Role-based access and segregation of duties
  • Staff training and confidentiality controls
  • Regular transparency reporting
  • Change-management and escalation rules

Encryption in transit and at rest is good practice, but it does not solve every transfer problem. If the importer needs continuous access to plaintext and can be compelled to disclose it, ordinary server-side encryption may not prevent public authority access.

Step 8: Conclude, document and review

The conclusion

Four outcomes procurement can act on

The conclusion should be clear enough for legal, security, procurement and the business owner to act without re-reading the file.

Proceed
Transfer can go ahead

The transfer tool is effective in the circumstances and the evidence supports the conclusion.

Conditions
Proceed with measures

Implement specified supplementary measures before transfer, verify evidence and record continuing conditions.

Escalate
Get specialist advice

A material issue cannot be resolved from the available evidence. Obtain legal or technical input.

Suspend
Do not proceed

The required level of protection cannot be achieved. Change the architecture, recipient, location or route, or stop.

The final record should include:

  • Assessment scope and transfer identifier
  • Exporter, importer, roles and transfer tool
  • Data, purpose, locations and onward transfers
  • Applicable laws and practices
  • Evidence and sources relied on
  • Assessment of the practical circumstances
  • Supplementary measures and implementation evidence
  • Conclusion, approver and approval date
  • Conditions, open actions and owners
  • Review triggers and next scheduled review

There is no universal GDPR rule that every TIA must be reviewed exactly once a year. Use a proportionate periodic review cadence and event-based triggers. Higher-risk or fast-changing transfers may need more frequent review.

Review the TIA when:

  • The importer, subprocessor chain or data location changes
  • The purpose, data categories, volume or affected population changes
  • The SCCs, adequacy status or other transfer tool changes
  • Relevant legislation, case law or official guidance changes
  • The importer receives a government access request or cannot comply with the safeguards
  • A security incident, complaint, audit finding or control failure occurs
  • A supplementary measure is changed, removed or found ineffective

Connect the TIA to your GDPR programme

A stand-alone TIA quickly becomes stale. Connect it to the records that change when the transfer changes.

  • Link the transfer to the relevant RoPA entries.
  • Link the importer to the vendor record, DPA, SCCs, security evidence and subprocessor list.
  • Link any related DPIA or privacy assessment.
  • Assign owners and review tasks with due dates.
  • Store the legal sources and version used for the country analysis.
  • Track open supplementary measures and block deployment until mandatory controls are verified.

GDPR Register helps privacy teams keep transfer assessments connected to processing activities, vendors, contracts, risks and review tasks. That connected record is more useful in an audit than a signed PDF stored in a separate folder.

Work through it

Transfer impact assessment checklist

Tick each item as you complete it. Progress is tracked as you go, and saved in your browser so you can return to it.

TIA checklist

0 of 21 complete
Watch for these

Common TIA mistakes

  • Starting with a generic country report. Map the actual transfer first, then assess the laws relevant to that importer, data and purpose.
  • Treating signed SCCs as sufficient. Clause 14 requires an assessment of local laws and practices, and the annexes must reflect reality.
  • Assuming every non-EEA vendor needs the same TIA. Check whether there is a Chapter V transfer and whether an adequacy route covers the recipient.
  • Relying only on the importer's lack of government requests. Past experience is one input. It must be documented, credible and evidenced.
  • Calling ordinary encryption a complete solution. Assess who holds the keys and whether compelled access remains possible.
  • Ignoring support access and subprocessors. European hosting does not remove transfer risk when administrators access data from third countries.
  • Setting an annual review and forgetting the transfer. Use event-based triggers so material changes prompt a review immediately.
Primary sources

Official sources

  1. European Data Protection Board, Guidelines 05/2021 on the interplay between Article 3 and Chapter V
  2. European Data Protection Board, Recommendations 01/2020 on measures that supplement transfer tools
  3. European Commission, Implementing Decision (EU) 2021/914 and the 2021 Standard Contractual Clauses
  4. European Commission, Adequacy decisions
  5. European Data Protection Board, Guidelines 2/2018 on derogations of Article 49
  6. Court of Justice of the European Union, Case C-311/18, Schrems II

This article provides general information and is not legal advice. International transfer requirements depend on the parties, jurisdictions, data, purpose, transfer route and current law.

Turn the TIA into a working process

GDPR Register connects transfer assessments with RoPAs, vendor records, risks, documents, owners and review tasks. See how connected compliance records work in practice.

Book a demo
Questions we hear

Frequently asked questions

Is a transfer impact assessment legally required under GDPR?+
The term TIA is not used in the GDPR. However, Schrems II requires exporters and importers to verify whether an Article 46 safeguard is effective in practice. The 2021 SCCs make this assessment explicit in Clause 14, and the EDPB provides a structured roadmap for completing it.
What is the difference between a TIA, DTIA and TRA?+
TIA and DTIA are commonly used for EU GDPR transfer assessments. The UK ICO uses the term transfer risk assessment for UK restricted transfers. The terminology and legal tools differ, so an EU SCC assessment should not be replaced with a UK-only process.
Do we need a TIA for a US vendor certified under the EU-US Data Privacy Framework?+
Not for the transfer route covered by the adequacy decision, provided the correct US legal entity is actively certified and the certification covers the relevant data. Verify the certification before transfer and monitor it. Use another mechanism for entities or data outside the certification.
Can we rely on a TIA supplied by the vendor?+
Use it as evidence, not as a substitute for your own analysis. Check whether it covers the correct legal entity, service, data, locations, SCC module, technical architecture and onward transfers.
Can a TIA conclude that no supplementary measures are needed?+
Yes, where the evidence supports that the selected transfer tool is effective in the circumstances. Document the reasoning. Do not use a vague low-risk label without addressing the legal test.
How often should a TIA be reviewed?+
There is no single statutory annual interval. Set a proportionate review schedule and review sooner when the transfer, importer, laws, adequacy status, safeguards or risk evidence changes.
What happens if supplementary measures cannot solve the problem?+
The transfer should not begin or should be suspended. Consider a different provider, an EEA-based architecture, an adequacy-covered recipient, stronger technical measures or another lawful transfer route.
Do processors also need to be involved?+
Yes. Processors may act as exporters or importers and hold evidence needed for the assessment. Controllers should define responsibilities contractually and ensure that processors provide information about subprocessors, locations and safeguards.

Tags:
case study
data privacy framework
gdpr
gutenberg
interesting
international transfers
scc
schrems ii
Krete Paal
Krete Paal is the CEO of GDPR Register and an IAPP Fellow of Information Privacy (FIP, CIPP/E, CIPM) with advanced degrees in Information Technology Law. She has led privacy and compliance work across the public and private sector, from the Estonian Police and Border Guard Board to Veriff, and now builds software that turns data protection requirements into practical, structured workflows.
PREVIOUS
EU Chat Control Vote: What Message Scanning Means for Privacy
EU AI Act compliance checklist and application timeline for DPOs
NEXT
EU AI Act Compliance Checklist for DPOs in 2026