International Transfer
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Transfer of personal data outside the EU/EEA
Overview
24 sources · Jul 23, 2026Legal Framework
International transfers of personal data outside the EU/EEA are governed by Chapter V of the GDPR (Articles 44–50). Article 44 sets the general principle: any transfer—and any onward transfer from a third country to another—must comply with Chapter V so that the GDPR's level of protection is not undermined. Three transfer mechanisms dominate practice. First, under Article 45, the European Commission may adopt an adequacy decision finding that a third country ensures a comparable level of protection, permitting transfers without further safeguards. Second, absent such a decision, Article 46 requires the controller or processor to provide "appropriate safeguards" and ensure data subjects have enforceable rights and effective legal remedies—typically through Standard Contractual Clauses, Binding Corporate Rules, or approved certification mechanisms. Third, Article 49 provides derogations for specific situations, including explicit consent, though only as a last resort.
Transparency obligations reinforce these mechanisms. When collecting data directly, Article 13(1)(f) requires controllers to inform data subjects of intended transfers and the existence or absence of an adequacy decision:
"where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission"
— GDPR Art. 13(1)(f)
A parallel duty applies under Article 14(1)(f) for data not obtained from the data subject. Upon request, the right of access under Article 15 extends to transfer-related information:
"Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer."
— GDPR Art. 15(2)
Key Developments
The landmark ruling in Schrems II (C-311/18, 16 July 2020) invalidated the EU-US Privacy Shield adequacy decision and reshaped the transfer landscape. The Court of Justice emphasised that Chapter V must operate as a coherent protective regime:
"Alle bepalingen van dit hoofdstuk worden toegepast opdat het door deze verordening voor natuurlijke personen gewaarborgde beschermingsniveau niet wordt ondermijnd."
— Schrems II ¶12
The Court confirmed that Standard Contractual Clauses remain valid but placed a duty on data exporters to assess, on a case-by-case basis, whether the law of the destination country undermines the contractual safeguards—particularly regarding government access for surveillance. Where the destination country's legal framework does not ensure essentially equivalent protection, the exporter must adopt supplementary measures or suspend the transfer.
Enforcement reflects this heightened scrutiny. The Italian DPA fined Character.AI €158,000 in connection with transfers to a US-based controller, and Sweden's IMY investigated the national police authority's border-control data transfers—both illustrating that supervisory authorities are actively examining whether transfers meet Article 46 standards.
Status of the Debate
This topic is actively litigated and enforcement-led. Schrems II settled the legal architecture—adequacy decisions, Article 46 safeguards, and derogations remain the three-tier framework—but the operational question of when supplementary measures suffice remains contested. Courts and DPAs diverge on how to assess "essential equivalence" in practice, particularly for US transfers post-Schrems II and in the context of government access. The EDPB has issued guidance on contractual clauses and certification as transfer tools, but no court has definitively resolved what specific supplementary measures are sufficient across all scenarios. A future CJEU ruling on the EU-US Data Privacy Framework or on a specific supplementary-measures case would likely crystallise the boundaries.
Practical Guidance
- Map all transfers: Identify every data flow to third countries or international organisations, including onward transfers by importers, and classify each under Article 45 (adequacy), Article 46 (safeguards), or Article 49 (derogations).
- Conduct Transfer Impact Assessments: For each non-adequacy transfer, assess the destination country's legal framework—especially government access powers—and determine whether supplementary measures (encryption, pseudonymisation, contractual overrides) are needed to achieve essential equivalence.
- Implement SCCs and update them: Use the European Commission's 2021 Standard Contractual Clauses and ensure they are correctly incorporated into processor and sub-processor agreements; verify that importers can honour them in practice.
- Fulfil transparency duties: Update privacy notices under Articles 13(1)(f) and 14(1)(f) to identify third-country recipients, the transfer mechanism, and how to obtain copies of safeguards.
- Reserve Article 49 derogations for exceptional cases: Explicit consent under Article 49 should be a last resort, not a routine basis. The EDPB treats explicit consent as appropriate only where "a high level of individual control over personal data is deemed appropriate"—a threshold that demands genuine, informed, and freely given consent.