Prepare for Data Breaches to Happen
Timehop, a smartphone app that helps you celebrate the best moments of the past with your friends, recently admitted to more […]
Cross-border data transfer under GDPR is one of the most complex parts of compliance and a common source of unexpected exposure. If personal data leaves the European Economic Area, to a US cloud provider, a subsidiary in Singapore or a support team in India, you need a lawful transfer mechanism before it moves.
Quick answerNot every flow of personal data across a border triggers Chapter V. The European Data Protection Board sets three cumulative criteria, and all three must be met:
If any one is missing, for example because the recipient is inside the EEA, Chapter V does not apply.
Example: your HR platform is hosted by a US vendor that processes employee data on your behalf. The data leaves the EEA and reaches a processor in a third country. All three criteria are met, so you need a transfer mechanism.
Chapter V applies whenever personal data moves from the EEA to a country, territory or sector without an adequacy decision from the European Commission.
Transfers within the EEA, including EU member states, Iceland, Liechtenstein and Norway, fall outside Chapter V. Transfers to the UK are covered by its adequacy decision, but that decision has a review cycle, so monitor its status.
Transfers to most other countries need an active transfer mechanism. This includes the United States outside the EU-US Data Privacy Framework, India and China.
The EDPB describes two main ways to transfer personal data outside the EEA lawfully: rely on an adequacy decision, or put appropriate safeguards in place.
Under Article 45, the European Commission can find that a third country protects personal data to a standard essentially equivalent to the GDPR. Where such a decision exists, no additional mechanism is needed.
Countries with current adequacy decisions include Andorra, Argentina, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, Uruguay and the United Kingdom. US organisations certified under the EU-US Data Privacy Framework are also covered. The Framework replaced Privacy Shield, which the Schrems II ruling invalidated.
Adequacy is not permanent. The Commission reviews decisions periodically and can suspend or withdraw them. When Privacy Shield fell in 2020, organisations relying on it without supplementary measures were exposed overnight. Adequacy is convenient, but keep an eye on its status.
A 2026 Cullen International benchmark of 14 jurisdictions found only five with operational adequacy regimes. Most organisations will need more than adequacy for at least some data flows.
When no adequacy decision covers the destination, Article 46 requires appropriate safeguards. The main options:
Schrems II did not invalidate SCCs. It changed how they must be used. The Court of Justice held that SCCs alone may not be enough if local law lets public authorities access personal data in ways incompatible with the GDPR.
The practical result is the Transfer Impact Assessment (TIA). Before relying on SCCs for a country with unclear surveillance or access laws, assess whether the SCCs can actually be honoured there. If not, add supplementary measures, such as encryption with exporter-held keys, or do not make the transfer.
EDPB guidance groups supplementary measures into three types:
For teams managing dozens of vendors, this creates a real documentation burden. You need to record which transfers rely on SCCs, which TIAs are complete, their outcomes and the measures in place. A spreadsheet makes this fragile and hard to audit.
Article 49 lists derogations for specific situations where neither adequacy nor appropriate safeguards exist. They are a last resort for occasional, non-repetitive transfers, not a routine mechanism.
The main derogations:
Supervisory authorities consistently hold that derogations cannot fill a gap left by a withdrawn adequacy decision or replace SCCs. The EDPB’s Article 49 guidance is clear: derogations are narrow and should not become standard practice for commercial transfers.
Whatever mechanism you use, document it. Article 30 requires your Records of Processing Activities to include transfers to third countries and the mechanism relied on. Supervisory authorities reviewing your RoPA will check for this.
This is not a formality. When a regulator investigates a breach or complaint, it first asks for your RoPA and the contracts behind your third-country transfers. You should be able to produce:
Most mid-market teams manage many vendors, so they need a systematic way to link each transfer to its mechanism, TIA status and contract. GDPR Register connects vendor management, DPA tracking and RoPA documentation in one workflow. You see at a glance which transfers are covered, which need TIAs and which contracts are due for renewal.
Transfer rules are not unique to the GDPR, but its framework is among the most structured. ITIF research found that 62 countries have imposed data localisation restrictions, and the number of such measures keeps rising. That makes compliance harder for any organisation operating globally.
A 2026 Cullen International benchmark of 14 jurisdictions found adequacy regimes are the exception, not the rule. Most jurisdictions rely on contractual mechanisms or sector rules, and standards vary widely.
If you are also subject to UK GDPR, the Swiss FADP, Brazil’s LGPD or Canada’s PIPEDA, the transfer rules interact and need careful mapping. The UK uses its own International Data Transfer Agreement (IDTA) or an addendum to the EU SCCs. Switzerland has its own standard data protection clauses. EU SCCs alone may not satisfy every framework that applies to you.
This article provides general information and is not legal advice.
Link every transfer to its mechanism, TIA status and contract in one place, before a regulator asks.