# Transfers subject to appropriate safeguards 46(2) — GDPR — provision context

> Focused context for a single provision (46(2)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-46#par-2
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Transfers subject to appropriate safeguards** (GDPR, full article: https://overview.legal/laws/gdpr/art-46).

## Provision text

### 46(2)

The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by:

a) a legally binding and enforceable instrument between public authorities or bodies;
b) binding corporate rules in accordance with Article 47;
c) standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2);
d) standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);
e) an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights; or
f) an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights.

## Topics on this provision

- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

## Cited by (exact-provision citations)

- **Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta** (case-law) — https://overview.legal/posts/132346
- **Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta** ¶17 (case-law, Court of Justice of the European Union) — https://overview.legal/posts/132346
- **Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH** (guidance) — https://overview.legal/posts/51079
- **Opinion 16/2025 regarding the draft decision of the German North Rhine Westphalia Supervisory Authority regarding Trusted Site Data Privacy (TÜV IT) certification criteria** (guidance) — https://overview.legal/posts/51080
- **Opinion 3/2025 on the draft decision of the French Supervisory Authority (FR SA) regarding the “Lexing GDPR certification criteria”** (guidance) — https://overview.legal/posts/50756
- **EDPB Document Setting Forth a Co-Operation procedure for the approval of Binding Corporate Rules for controllers and processors** (guidance) — https://overview.legal/posts/50655
- **Opinion 27/2024 on the Brand Compliance criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)** (guidance) — https://overview.legal/posts/125702
- **Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented** (guidance) — https://overview.legal/posts/125701
- **Opinion 18/2024 on the draft decision of the Austrian Supervisory Authority regarding DSGVO-zt GmbH certification criteria** (guidance) — https://overview.legal/posts/125721
- **Opinion 19/2024 on the EuroPrise criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)** (guidance) — https://overview.legal/posts/125722
- **Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria** (guidance) — https://overview.legal/posts/125759
- **Opinion 15/2023 on the draft decision of the Dutch Supervisory Authority regarding the Brand Compliance certification criteria** (guidance) — https://overview.legal/posts/125831

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-46#par-2 · 2026-08-22
