Articles

Cross-Border Data Transfer Under GDPR: Rules and Mechanisms

Cross-border data transfer under GDPR: adequacy, SCCs and derogations

Cross-border data transfer under GDPR is one of the most complex parts of compliance and a common source of unexpected exposure. If personal data leaves the European Economic Area, to a US cloud provider, a subsidiary in Singapore or a support team in India, you need a lawful transfer mechanism before it moves.

Quick answer

The two main routes: adequacy or appropriate safeguards

Article 45

Adequacy decision

  • Commission finds the country’s protection essentially equivalent
  • No extra mechanism needed
  • Monitor status: decisions can be withdrawn
Article 46

Appropriate safeguards

  • SCCs, BCRs, codes of conduct or certification
  • Transfer Impact Assessment where local law may conflict
  • Supplementary measures if the TIA finds gaps
Last resort.Article 49 derogations cover occasional, non-repetitive transfers only. They are not a routine mechanism.

What Counts as a Cross-Border Data Transfer Under GDPR

Not every flow of personal data across a border triggers Chapter V. The European Data Protection Board sets three cumulative criteria, and all three must be met:

  1. The exporter is a controller or processor subject to the GDPR.
  2. The exporter transmits or makes personal data available to an importer.
  3. The importer is in a third country outside the EEA, or is an international organisation.

If any one is missing, for example because the recipient is inside the EEA, Chapter V does not apply.

Example: your HR platform is hosted by a US vendor that processes employee data on your behalf. The data leaves the EEA and reaches a processor in a third country. All three criteria are met, so you need a transfer mechanism.

When Chapter V of the GDPR Applies

Chapter V applies whenever personal data moves from the EEA to a country, territory or sector without an adequacy decision from the European Commission.

Transfers within the EEA, including EU member states, Iceland, Liechtenstein and Norway, fall outside Chapter V. Transfers to the UK are covered by its adequacy decision, but that decision has a review cycle, so monitor its status.

Transfers to most other countries need an active transfer mechanism. This includes the United States outside the EU-US Data Privacy Framework, India and China.

The Two Main Routes: Adequacy or Appropriate Safeguards

The EDPB describes two main ways to transfer personal data outside the EEA lawfully: rely on an adequacy decision, or put appropriate safeguards in place.

Adequacy Decisions

Under Article 45, the European Commission can find that a third country protects personal data to a standard essentially equivalent to the GDPR. Where such a decision exists, no additional mechanism is needed.

Countries with current adequacy decisions include Andorra, Argentina, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, Uruguay and the United Kingdom. US organisations certified under the EU-US Data Privacy Framework are also covered. The Framework replaced Privacy Shield, which the Schrems II ruling invalidated.

Adequacy is not permanent. The Commission reviews decisions periodically and can suspend or withdraw them. When Privacy Shield fell in 2020, organisations relying on it without supplementary measures were exposed overnight. Adequacy is convenient, but keep an eye on its status.

A 2026 Cullen International benchmark of 14 jurisdictions found only five with operational adequacy regimes. Most organisations will need more than adequacy for at least some data flows.

Appropriate Safeguards

When no adequacy decision covers the destination, Article 46 requires appropriate safeguards. The main options:

  • Standard Contractual Clauses (SCCs): The most widely used mechanism. The Commission’s modular SCCs cover controller to controller, controller to processor, processor to controller and processor to processor transfers. You add the relevant module to your contract with the recipient. SCCs are free and need no prior approval from a supervisory authority.
  • Binding Corporate Rules (BCRs): For intra-group transfers within a multinational. A lead supervisory authority must approve them, and they bind every group entity. They are thorough and auditable, but approval often takes 18 months or more. They suit large groups with stable, high-volume internal flows. For most SMBs, they are disproportionate.
  • Codes of conduct and certification: Allowed where the importer makes binding, enforceable commitments. Still rare in practice.
  • International agreements: Public authorities may rely on legally binding agreements or administrative arrangements.

How Schrems II Changed the Use of SCCs in Practice

Schrems II did not invalidate SCCs. It changed how they must be used. The Court of Justice held that SCCs alone may not be enough if local law lets public authorities access personal data in ways incompatible with the GDPR.

The practical result is the Transfer Impact Assessment (TIA). Before relying on SCCs for a country with unclear surveillance or access laws, assess whether the SCCs can actually be honoured there. If not, add supplementary measures, such as encryption with exporter-held keys, or do not make the transfer.

EDPB guidance groups supplementary measures into three types:

  • Technical: encryption, pseudonymisation, split processing.
  • Contractual: transparency obligations, audit rights.
  • Organisational: data minimisation, access controls.

For teams managing dozens of vendors, this creates a real documentation burden. You need to record which transfers rely on SCCs, which TIAs are complete, their outcomes and the measures in place. A spreadsheet makes this fragile and hard to audit.

Derogations: When Neither Adequacy Nor Safeguards Are Available

Article 49 lists derogations for specific situations where neither adequacy nor appropriate safeguards exist. They are a last resort for occasional, non-repetitive transfers, not a routine mechanism.

The main derogations:

  • Explicit consent: the data subject consents explicitly after being told the risks.
  • Contract performance: the transfer is necessary to perform a contract with the data subject, or to take pre-contractual steps at their request.
  • Public interest: the transfer is necessary for important reasons of public interest.
  • Legal claims: the transfer is necessary to establish, exercise or defend legal claims.
  • Vital interests: the transfer protects the vital interests of the data subject or others, where the data subject cannot give consent.

Supervisory authorities consistently hold that derogations cannot fill a gap left by a withdrawn adequacy decision or replace SCCs. The EDPB’s Article 49 guidance is clear: derogations are narrow and should not become standard practice for commercial transfers.

Decision path

Choosing the right mechanism: a practical decision path

1
Adequacy?

Check the destination

  1. If covered, no further mechanism
  2. Document the reliance and monitor status
2
Intra-group?

Weigh BCRs against SCCs

  1. BCRs give long-term certainty
  2. SCCs are faster and work for most groups
3
Third party?

Default to SCCs

  1. Pick the correct module
  2. Add it to the contract
  3. Run a TIA if local access laws may conflict
4
One-off?

Consider a derogation

  1. Check Article 49 fits the case
  2. If relying on consent, make it explicit, granular and risk-informed
  3. Document the justification case by case

The Documentation Obligation

Whatever mechanism you use, document it. Article 30 requires your Records of Processing Activities to include transfers to third countries and the mechanism relied on. Supervisory authorities reviewing your RoPA will check for this.

This is not a formality. When a regulator investigates a breach or complaint, it first asks for your RoPA and the contracts behind your third-country transfers. You should be able to produce:

  • a signed SCC for each transfer that relies on one
  • a completed TIA where local access laws may conflict
  • evidence of any adequacy decision you relied on

Most mid-market teams manage many vendors, so they need a systematic way to link each transfer to its mechanism, TIA status and contract. GDPR Register connects vendor management, DPA tracking and RoPA documentation in one workflow. You see at a glance which transfers are covered, which need TIAs and which contracts are due for renewal.

The Broader Regulatory Picture

Transfer rules are not unique to the GDPR, but its framework is among the most structured. ITIF research found that 62 countries have imposed data localisation restrictions, and the number of such measures keeps rising. That makes compliance harder for any organisation operating globally.

A 2026 Cullen International benchmark of 14 jurisdictions found adequacy regimes are the exception, not the rule. Most jurisdictions rely on contractual mechanisms or sector rules, and standards vary widely.

If you are also subject to UK GDPR, the Swiss FADP, Brazil’s LGPD or Canada’s PIPEDA, the transfer rules interact and need careful mapping. The UK uses its own International Data Transfer Agreement (IDTA) or an addendum to the EU SCCs. Switzerland has its own standard data protection clauses. EU SCCs alone may not satisfy every framework that applies to you.

Questions we hear

Frequently asked questions

What is a cross-border data transfer under GDPR?+
It occurs when a controller or processor subject to the GDPR transmits or makes personal data available to a recipient outside the EEA. Chapter V applies only when all three EDPB criteria are met: the exporter is subject to the GDPR, data is made available to an importer, and the importer is in a third country or is an international organisation.
Which countries have adequacy decisions?+
Andorra, Argentina, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, Uruguay and the United Kingdom. US organisations certified under the EU-US Data Privacy Framework are also covered. Decisions are reviewed periodically and can be withdrawn.
What are Standard Contractual Clauses and when do I need them?+
SCCs are Commission-approved contract terms that bind the exporter and the importer. You need them when transferring to a country without adequacy and no other Article 46 safeguard is in place. They come in four modules. After Schrems II, they must be backed by a TIA where local surveillance laws may conflict.
What is a Transfer Impact Assessment?+
A documented analysis of whether the law and practice of the destination country lets your SCC obligations be honoured. If the TIA finds a conflict, you need supplementary measures or you cannot make the transfer.
Can I use Article 49 derogations as a routine transfer mechanism?+
No. The EDPB is clear that derogations are for occasional, non-repetitive transfers. Using consent for routine commercial transfers is not considered compliant practice.
Do I need to document cross-border transfers in my RoPA?+
Yes. Article 30 requires your RoPA to include third-country transfers and the mechanism relied on. Supervisory authorities check this during audits and investigations.
How do BCRs differ from SCCs for intra-group transfers?+
BCRs are approved by a lead supervisory authority and bind every group entity. They take much longer to obtain but give long-term certainty for large groups. SCCs also work for intra-group transfers and are faster, so they are the practical default for most organisations.
Official sources

Sources

  1. European Parliament and Council, Regulation (EU) 2016/679 (GDPR), Chapter V and Article 30
  2. European Commission, Adequacy decisions
  3. European Commission, Standard Contractual Clauses
  4. EDPB, Recommendations 01/2020 on supplementary measures
  5. EDPB, Guidelines 2/2018 on Article 49 derogations
  6. CJEU, Case C-311/18 (Schrems II)

This article provides general information and is not legal advice.

Get your transfer documentation in order

Link every transfer to its mechanism, TIA status and contract in one place, before a regulator asks.

See GDPR Register
Tags:
case study
data privacy framework
gdpr
gutenberg
interesting
international transfers
scc
schrems ii
PREVIOUS
GDPR Certification: What Schemes Exist and Do They Help