International data transfers

An international transfer is making personal data available to a recipient outside the European Economic Area. It is permitted, but only where the level of protection under the GDPR is not undermined in practice.

Legal basis

Chapter V GDPR governs transfers. Article 45 permits transfers to countries covered by an adequacy decision of the European Commission; for the United States the EU-US Data Privacy Framework has applied since 10 July 2023, and only for certified organisations. Article 46 lists appropriate safeguards, of which the 2021 standard contractual clauses are the most used, alongside binding corporate rules. Article 49 provides derogations for occasional cases. Following the Schrems II judgment of 16 July 2020 an instrument alone does not suffice: an assessment of the law in the receiving country is required, the transfer impact assessment, with supplementary measures where needed, such as encryption with the key held in Europe.

How it works in practice

The first step is to establish where data actually reside and who has access, including support from outside Europe. That last point is often overlooked: remote access by a support team is also a transfer. The choice of instrument and the assessment then follow, and must be recorded in writing. Contracts should oblige the supplier to notify changes of location or of sub-processors.

Where it goes wrong

Organisations rely on their supplier’s certification without checking that it actually covers the service in question. A second error is signing standard contractual clauses without completing the annexes, so that the description of the processing is missing. Third, the assessment is not documented, even though the accountability principle requires precisely that.

Related terms

Transfers connect to the data processing agreement, the data protection impact assessment and the SaaS agreement.

Do you know where your data sit? Our IT law specialists map the transfers and the safeguards.