Article 44 GDPR — General principle for transfers and the Chapter V framework
Article 44 GDPR establishes the foundational rule for all international data transfers: any transfer of personal data that is undergoing processing or is intended for processing after transfer to a third country (a jurisdiction outside the European Economic Area) or to an international organisation may only take place if the controller and processor comply with the conditions laid down in Chapter V of the GDPR, including for onward transfers from the third country to another third country or international organisation.
The core principle codified in Article 44 is that "the level of protection of natural persons guaranteed by this Regulation is not undermined" when personal data leaves the EEA. This anti-circumvention mandate applies to every transfer mechanism in Chapter V—adequacy decisions (Article 45), appropriate safeguards (Article 46, including standard contractual clauses and binding corporate rules), and derogations for specific situations (Article 49).
What constitutes a "transfer" for Chapter V purposes is not defined in the GDPR text itself. The European Data Protection Board (EDPB) clarified in its Guidelines 05/2021 on the Interplay between Article 3 and Chapter V that three cumulative criteria must be met for a processing operation to qualify as an international transfer:
- An exporter subject to GDPR. A controller or processor is subject to the GDPR for the given processing (under Article 3's territorial scope rules).
- Disclosure to an importer. The exporter discloses by transmission or otherwise makes personal data available to another controller, joint controller, or processor (the "importer"). Direct collection by a third-country entity from an EU data subject is not a transfer because the data subject is not a controller or processor and therefore cannot be an exporter.
- Importer located in a third country or international organisation. The importer is geographically in a third country (outside the EEA) or is an international organisation, irrespective of whether or not the importer itself is subject to the GDPR under Article 3.
When all three criteria are met, Chapter V applies and the transfer can proceed only if the exporter has implemented one of the Chapter V transfer mechanisms. The EDPB has emphasized that even when the data importer is itself subject to GDPR (for instance, a US company offering services to EU residents under Article 3(2)(a)), Chapter V still applies to the physical transfer of data out of the EEA because the importer remains in a third country where EU supervisory authorities cannot directly enforce GDPR obligations and where national security or law-enforcement access laws may conflict with GDPR protections.
Chapter V's three-tier hierarchy structures the available transfer mechanisms:
- Tier 1: Adequacy decisions (Article 45). The European Commission may decide, by implementing act, that a third country, a territory or specified sector within a third country, or an international organisation ensures an adequate level of protection. Transfers on the basis of an adequacy decision require no specific authorisation. As of May 2026, adequacy decisions cover Andorra, Argentina, Canada (commercial organisations subject to PIPEDA), the Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, Uruguay, and the United States (organisations participating in the EU-US Data Privacy Framework under Commission Implementing Decision (EU) 2023/1795 of 10 July 2023).
- Tier 2: Appropriate safeguards (Article 46). In the absence of an adequacy decision, a controller or processor may transfer personal data to a third country if it has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Article 46 lists standard contractual clauses (adopted by the Commission under Implementing Decision (EU) 2021/914 of 4 June 2021), binding corporate rules, and other mechanisms. Following the CJEU's judgment in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II), Case C-311/18, ECLI:EU:C:2020:559, paragraph 133, exporters must verify on a case-by-case basis whether the law or practice of the third country impinges on the effectiveness of the Article 46 safeguards, and if necessary adopt supplementary measures (technical, contractual, or organisational) to ensure essentially equivalent protection.
- Tier 3: Derogations for specific situations (Article 49). In the absence of an adequacy decision or appropriate safeguards, transfers may still occur under narrowly construed derogations: explicit consent, necessity for contract performance, necessity for important reasons of public interest, necessity to establish or defend legal claims, necessity to protect vital interests, or transfers from a public register. Article 49(1) second subparagraph permits occasional, non-repetitive transfers not part of massive or structural processing activities if necessary for compelling legitimate interests and the controller has assessed all circumstances and provided suitable safeguards. The EDPB has stressed that these derogations cannot serve as a basis for systematic or routine data flows.
Compliance obligations for controllers and processors. Article 44 applies the Chapter V conditions to both controllers and processors, and explicitly extends them to onward transfers—subsequent transfers from the initial third-country recipient to another third country or international organisation. A controller in the EEA that engages a processor also located in the EEA, which then sub-contracts processing to a sub-processor in a third country, remains responsible under Article 44 for ensuring the sub-processor transfer complies with Chapter V. Similarly, when an adequacy decision or standard contractual clauses permit the initial transfer to a third country, any onward transfer by that recipient must independently satisfy Chapter V (either through a separate adequacy decision, appropriate safeguards, or a derogation).
Recent EDPB update — Third-country authority access requests (2026): On 9 April 2026, the European Data Protection Board (EDPB) adopted its final Guidelines 05/2024 on Transfers of Personal Data to Third Country Authorities. These guidelines provide detailed, binding practical clarification for how controllers should respond to requests for personal data from public authorities (including law enforcement and national security agencies) located outside the EEA. Key requirements introduced and clarified:
- Controllers must systematically assess the legal basis for any data disclosure, considering EU law, the GDPR's restrictions on international transfers, and the necessity and proportionality of responding to the request.
- Before transferring data in response to a third-country authority request, controllers must evaluate if the request is compatible with Union or Member State law, document their assessment, and apply appropriate safeguards (which may require challenging overbroad or unlawful requests, adopting technical or organizational measures, or, where transfer is unavoidable, applying the narrow derogations in Article 49).
- Guidelines 05/2024 specifically reinforce that all disclosures to non-EEA authorities qualify as Chapter V international transfers, triggering the full set of GDPR restrictions for cross-border transfers—even when requests cite foreign legal requirements.
- Controllers must maintain detailed records of their assessment and any transfer, and must be able to demonstrate compliance to supervisory authorities.
Status and timing: The EDPB Guidelines 05/2024 were finalized on 9 April 2026 and take effect as of 19 December 2025. This is a major clarification and harmonization of GDPR compliance for responding to third-country authority requests, supplementing existing obligations under Chapter V. All advice or practice regarding transfers to non-EEA public authorities must be aligned to these Guidelines from the effective date.
Infringement of the transfer conditions in Articles 44–49 is subject to administrative fines up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, under Article 83(5)(c). Data subjects also have the right to lodge a complaint with a supervisory authority (Article 77) and to an effective judicial remedy against a controller or processor for alleged infringement of Chapter V (Article 79).
Source: Regulation (EU) 2016/679 (GDPR), Articles 44–49, 83(5)(c) Source: EDPB Guidelines 05/2021 on the Interplay between Article 3 and Chapter V Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559 Source: Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses) Source: Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework) Source: EDPB Guidelines 05/2024 on Transfers of Personal Data to Third Country Authorities, adopted 9 April 2026, effective 19 December 2025
Standard Contractual Clauses — Article 46(2)(c) four-module structure and execution requirements
Standard Contractual Clauses (SCCs) are the most widely used transfer mechanism under Article 46(2)(c) GDPR, enabling controllers and processors to provide "appropriate safeguards" for international data transfers in the absence of an adequacy decision. On 4 June 2021, the European Commission adopted Implementing Decision (EU) 2021/914, which modernized the SCC framework to reflect GDPR requirements and the CJEU's Schrems II judgment (Case C-311/18). The 2021 SCCs replaced the legacy 2001 and 2010 versions with effect from 27 September 2021; contracts concluded under the old clauses remained valid until 27 December 2022, provided the processing operations remained unchanged.
The four-module structure. Decision 2021/914 establishes a modular architecture to address the various controller-processor configurations that arise in modern processing chains. Parties must select the module (or combination of modules) that corresponds to their actual relationship:
- Module One: Controller to Controller. Used when an EEA controller transfers personal data to a third-country controller. Both parties act as independent controllers for their respective processing purposes. This module applies, for example, when an EU company shares customer data with a US marketing analytics firm that determines its own analytical purposes, or when a French employer sends employee records to a non-EEA subsidiary that uses the data for local payroll and HR decisions.
- Module Two: Controller to Processor. Used when an EEA controller engages a third-country processor (a service provider that processes personal data on the controller's behalf and under the controller's instructions). This is the most common commercial scenario: an EU company contracts with a US cloud-storage provider, a Japanese software-as-a-service vendor, or a Brazilian call center to process EU-origin personal data solely on the controller's documented instructions. Module Two incorporates the Article 28(3)–(4) GDPR processor obligations (written instructions, confidentiality, security measures, sub-processor authorization, assistance with data-subject requests, deletion or return of data at contract termination, and audit rights).
- Module Three: Processor to Processor. Used when an EEA processor (itself acting on behalf of an EEA controller) engages a sub-processor in a third country. The initial processor remains fully liable to the EEA controller for the sub-processor's performance. For example, if a German controller hires an Italian processor (both in the EEA) and the Italian processor sub-contracts specific database hosting to a server farm in Singapore, Module Three governs that Italy-to-Singapore leg. The EEA controller must authorize the sub-processor engagement under Article 28(2) and (4) GDPR, and the processor must flow down equivalent data-protection obligations.
- Module Four: Processor to Controller. Used when a processor in a third country transfers personal data it holds on behalf of an EEA controller to a separate controller (whether in the EEA or in a third country). This scenario arises when, for instance, a data importer must disclose data to a statutory auditor, a tax authority, or another entity that will process the data for its own purposes. Module Four is the least common; many processors are contractually prohibited from making such disclosures without the EEA controller's explicit authorization.
Multiple modules and complex chains. A single contract may incorporate multiple modules when the parties' roles shift across different processing activities. The SCCs expressly permit "docking" — allowing additional exporters or importers to accede to an existing SCC contract by completing the annexes and signing. When onward transfers occur (the initial importer in a third country subsequently transfers to another third country or back into the EEA), each leg of the chain requires its own Chapter V legal basis: adequacy, appropriate safeguards (including SCCs), or a derogation under Article 49. The 2021 SCCs include specific onward-transfer clauses requiring the initial importer to ensure the next recipient provides the same level of protection and, where the onward recipient is in a non-adequate third country, to use the SCCs or another Article 46 mechanism.
Mandatory annexes and transparency. The 2021 SCCs require parties to complete and attach detailed annexes specifying the scope and nature of the transfer:
- Annex I.A: List of parties (names, addresses, contact persons, roles as controller/processor).
- Annex I.B: Description of the transfer (categories of data subjects, categories of personal data, sensitive data if any, frequency of transfer, nature and purpose of processing, retention period, and, for onward transfers, identification of sub-processors or other recipients).
- Annex I.C: Competent supervisory authority (the lead supervisory authority of the EEA data exporter under Article 56 GDPR, or the authority of the Member State where the exporter is established if Article 56 does not apply).
- Annex II: Technical and organizational measures (TOMs), including measures to ensure data security under Article 32 GDPR and, critically post-Schrems II, any supplementary measures adopted to bring the level of protection up to EU standards in light of the laws and practices of the destination country.
Incomplete or generic annexes render the SCCs unenforceable. Supervisory authorities have emphasized in enforcement guidance that annexes must be specific, granular, and kept up to date as processing evolves.
Clause 14: the Schrems II assessment obligation. The 2021 SCCs embed the Schrems II case-by-case assessment directly into the contractual text. Clause 14 ("Local laws and practices affecting compliance with the Clauses") requires both the data exporter and data importer, before and throughout the term of the contract, to assess whether the laws or practices of the third country of destination prevent the importer from fulfilling its obligations under the SCCs. This assessment must address in particular whether the third country's laws permit public authorities (intelligence services, law enforcement, regulatory agencies) to access the transferred data in a manner that impinges on the Article 46 safeguards — for instance, through broad surveillance powers that lack necessity, proportionality, judicial oversight, or effective remedies as required by Articles 47 and 52 of the EU Charter of Fundamental Rights.
Where the assessment reveals that such laws exist and are likely to be applied to the specific transfer, the parties must document the assessment and notify the competent EEA supervisory authority if they cannot identify effective supplementary measures to fill the protection gap. The SCCs explicitly state that they cannot bind the public authorities of third countries; therefore, contractual commitments alone will not suffice where governmental access is the risk. Technical, organizational, or contractual supplementary measures may be necessary to ensure essentially equivalent protection. The European Data Protection Board's Recommendations 01/2020 (adopted 10 November 2020, final version 18 June 2021) provide a six-step roadmap and a non-exhaustive catalogue of supplementary measures (encryption with EEA-held keys, pseudonymization, data minimization, split processing, contractual obligations for the importer to challenge unlawful access requests and notify the exporter).
Enforcement and liability. The 2021 SCCs grant data subjects express third-party beneficiary rights: individuals whose data is transferred may invoke Clauses 3–17 directly against either the exporter or the importer and seek compensation for material or non-material damage resulting from a breach (Clause 12). Data subjects may lodge complaints with the competent EEA supervisory authority or bring judicial proceedings in the courts of the Member State where the exporter is established (Clauses 11 and 18). The importer agrees to submit to the jurisdiction of those courts even though it is located outside the EEA.
Liability is joint and several when both exporter and importer are at fault; when only one party is liable, that party bears full liability (Clause 12(1)–(2)). The exporter remains liable even where the breach was caused solely by the importer unless the exporter proves it is not responsible for the event giving rise to the damage. Processors are liable for breaches of processor-specific obligations; controllers are liable for breaches of controller obligations; where a processor acts outside or contrary to lawful controller instructions, the processor is treated as a controller for that processing and bears corresponding liability (Clause 12(3)).
Interaction with adequacy decisions and derogations. SCCs are not required when the third country (or a sector or territory within it) benefits from a Commission adequacy decision under Article 45 GDPR; in such cases the transfer may proceed without additional safeguards. Conversely, SCCs do not cure a transfer that lacks one of the foundational elements of lawful processing (a lawful basis under Article 6, a special-category condition under Article 9 where applicable, and compliance with the transparency, purpose-limitation, data-minimization, and security obligations in Articles 5 and 32). The Article 49 derogations (explicit consent, contract necessity, vital interests, legal claims, public interest, or public registers) are available as a fallback only when SCCs are unavailable or ineffective and the transfer meets the narrow conditions for the derogation (occasional, non-repetitive, not part of massive processing activities, and—for the compelling-legitimate-interests derogation in Article 49(1) second subparagraph—accompanied by a documented assessment and suitable safeguards).
Practical adoption timeline. Decision 2021/914 entered into force 27 June 2021. Organizations had until 27 September 2021 to replace or supplement legacy 2001/2010 SCCs for new transfers. Contracts already in force on 27 September 2021 under the old clauses were grandfathered until 27 December 2022, creating a fifteen-month transition window; after that date, all transfers relying on SCCs must use the 2021 modules and complete the Clause 14 assessment. Supervisory authorities across the EEA have prioritized SCC compliance in post-Schrems II enforcement sweeps, particularly scrutinizing transfers to the United States (until the EU-US Data Privacy Framework adequacy decision of 10 July 2023 provided an alternative for DPF-certified organizations), China (in light of the PRC's National Intelligence Law and Data Security Law), Russia, and other jurisdictions whose surveillance or data-localization laws may conflict with GDPR protections.
Source: Commission Implementing Decision (EU) 2021/914 of 4 June 2021 Source: EDPB Recommendations 01/2020 on supplementary measures (final version, 18 June 2021) Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559
Article 45 GDPR — Adequacy decision assessment criteria, adoption procedure, and mandatory periodic review
Article 45 GDPR establishes the legal framework for adequacy decisions, the highest-tier and most streamlined mechanism for international data transfers under Chapter V. When the European Commission determines by implementing act under Article 45(3) that a third country, a territory or specified sector within a third country, or an international organisation ensures an adequate level of protection, personal data may flow from the EEA to that jurisdiction without any additional safeguard, specific authorisation, or data-exporter action beyond compliance with general GDPR obligations. Transfers to an adequate third country are assimilated to intra-EEA data flows.
The "essential equivalence" standard. Article 45(1) GDPR provides that the Commission "shall take account of" enumerated factors when assessing adequacy, but the overarching legal threshold—developed through CJEU case law—is essential equivalence to the level of protection guaranteed within the European Union. In Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II), Case C-311/18, paragraph 92, the Court held that adequacy "does not require a third country to ensure a level of protection 'identical' to that guaranteed in the EU legal order" but rather that the third country's regime, "assessed in the light of international commitments, must ensure a level of protection 'essentially equivalent' to that guaranteed within the European Union" by the GDPR, the Charter of Fundamental Rights (in particular Articles 7, 8, and 47), and general principles of EU law. This is a strict and holistic standard: the Commission must examine both the substantive data-protection rules applicable to data importers and the legal framework governing access to transferred data by third-country public authorities (national security agencies, law enforcement, regulatory bodies).
Assessment criteria under Article 45(2). Article 45(2) GDPR specifies that the Commission "shall take account of" the following elements when assessing adequacy:
- Rule of law, respect for human rights and fundamental freedoms (Article 45(2)(a)). The third country's general legal order, including relevant legislation concerning public security, defence, national security, and criminal law, and the access of public authorities to personal data.
- The existence and effective functioning of one or more independent data protection supervisory authorities (Article 45(2)(b)). The third-country authority must be competent to monitor and enforce compliance with data-protection rules, including adequate enforcement powers, and to assist and advise data subjects in the exercise of their rights. It must have genuine independence from government interference.
- International commitments entered into by the third country or international organisation (Article 45(2)(c)). Adherence to international or regional data-protection instruments, human-rights treaties, and other relevant international agreements (for instance, the Council of Europe Convention 108+ or the International Covenant on Civil and Political Rights).
Recital 104 GDPR clarifies that the assessment of adequacy "should be based on all relevant circumstances" and "should be of a general nature," meaning it evaluates the third country's legal framework as a whole rather than individual entities or sectors unless the adequacy decision is expressly limited to a sector or territory. The CJEU emphasised in Schrems II, paragraphs 104–105, that the assessment must include whether the third country ensures effective and enforceable data-subject rights and whether data subjects have access to effective administrative and judicial redress, including the right to bring legal action before an independent and impartial court (Article 47 of the Charter). The absence of effective judicial redress against governmental access to personal data is fatal to a finding of adequacy (Schrems II, paragraphs 186–195).
Sectoral and territorial scope. Article 45(3) third sentence GDPR permits the Commission to adopt adequacy decisions that are geographically or sectorally limited. The implementing act must "specify its territorial and sectoral application" and, where applicable, identify the competent supervisory authority or authorities in the third country. For example:
- Canada (commercial organisations subject to PIPEDA): The adequacy decision (Decision 2002/2/EC of 20 December 2001, reaffirmed under GDPR review in January 2024) covers only organisations governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) in the commercial sector, not public authorities or provincially regulated sectors outside PIPEDA's scope.
- United States (EU-US Data Privacy Framework): The adequacy decision adopted by Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 covers only U.S. organisations that have self-certified participation in the Data Privacy Framework and are listed on the publicly available DPF List maintained by the U.S. Department of Commerce (Article 1 of Decision 2023/1795). Transfers to non-participating U.S. entities require Article 46 safeguards or Article 49 derogations.
- Japan (business operators under APPI): Commission Implementing Decision (EU) 2019/419 of 23 January 2019, Article 1, covers "personal information handling business operators" in Japan subject to the Act on the Protection of Personal Information (APPI) as complemented by Supplementary Rules adopted by the Personal Information Protection Commission.
A sectoral adequacy decision does not lift the Chapter V requirement for transfers falling outside its scope; exporters must verify that each transfer falls within the decision's defined boundaries.
Adoption procedure — Article 93(2) examination and EDPB opinion. Article 45(3) second sentence provides that the implementing act is adopted "in accordance with the examination procedure referred to in Article 93(2)," meaning the Commission must submit the draft decision to a committee composed of representatives of the Member States. Before adoption, the Commission must consult the European Data Protection Board (EDPB) under Article 70(1)(s) GDPR; the EDPB opinion is public and, while not legally binding on the Commission, carries significant political and interpretive weight. The European Parliament and Council may, under Article 93(3), indicate to the Commission that a draft exceeds the implementing powers provided for in the GDPR.
Current list of adequacy decisions as of January 2024. The European Commission publishes the official list of adequacy decisions on its website. As of the Commission's January 2024 review report, adequacy decisions under the GDPR (or reaffirmed from Directive 95/46/EC) cover: Andorra, Argentina, Canada (commercial organisations subject to PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea (South Korea), Switzerland, United Kingdom (both GDPR and Law Enforcement Directive), United States (organisations participating in the EU-US Data Privacy Framework), and Uruguay. With the exception of the United Kingdom, these adequacy decisions do not cover data exchanges in the law-enforcement sector, which are governed separately by the Law Enforcement Directive (Article 36 of Directive (EU) 2016/680).
Mandatory periodic review — Article 45(3) fourth sentence. Adequacy decisions are not permanent. Article 45(3) provides that "[t]he implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation." The Commission must monitor the continued adequacy of the third country's legal framework, including new legislation, judicial developments, enforcement practice, and—critically—surveillance or governmental-access laws that may impinge on the protection of transferred data. The first review of the eleven "legacy" adequacy decisions adopted under Directive 95/46/EC was completed in January 2024; the Commission concluded that all eleven continue to provide an adequate level of protection under GDPR standards. The EU-US Data Privacy Framework decision (Decision (EU) 2023/1795, Article 3(4)) provides for a first review one year after entry into force, followed by reviews at least every four years. The Japan adequacy decision underwent its first review in April 2023 (Staff Working Document SWD(2023) 75 final of 4 April 2023), with the Commission concluding that Japan continues to ensure an adequate level of protection.
Suspension, amendment, or repeal — Article 45(5). Where the Commission finds—whether through periodic review, supervisory-authority notification under Article 45(4), or its own monitoring—that a third country "no longer ensures an adequate level of protection within the meaning of paragraph 2," Article 45(5) requires the Commission "to the extent necessary" to repeal, amend, or suspend the adequacy decision "without retro-active effect." The implementing act effecting the repeal, amendment, or suspension is adopted under the same Article 93(2) examination procedure. The Commission must inform the European Parliament and the Council "on the grounds on which the third country in question no longer ensures an adequate level of protection."
The effect of repeal or suspension is immediate for future transfers: data exporters must cease relying on the adequacy decision and instead implement Article 46 appropriate safeguards (standard contractual clauses, binding corporate rules, or ad hoc contractual clauses authorised by a supervisory authority) or, where available and applicable, invoke an Article 49 derogation for specific situations.
Historical example: Safe Harbour and Privacy Shield invalidations. The Commission's adequacy decision for the United States under the Safe Harbour framework (Decision 2000/520/EC of 26 July 2000) was invalidated by the CJEU in Maximillian Schrems v Data Protection Commissioner (Schrems I), Case C-362/14, ECLI:EU:C:2015:650, paragraph 106, on 6 October 2015, on the grounds that U.S. mass-surveillance programs and the absence of effective judicial redress for EU data subjects rendered the level of protection not essentially equivalent to that guaranteed in the EU. The Commission subsequently negotiated a replacement framework, the EU-US Privacy Shield (Decision (EU) 2016/1250 of 12 July 2016), which was in turn invalidated by the CJEU in Schrems II, paragraph 201, on 16 July 2020 for substantially similar reasons (limitations and safeguards applicable to U.S. surveillance programs under Section 702 FISA and E.O. 12333 did not satisfy EU standards of necessity and proportionality, and the Ombudsperson mechanism did not provide effective judicial protection). The current EU-US Data Privacy Framework (Decision (EU) 2023/1795 of 10 July 2023) was adopted following U.S. Executive Order 14086 of 7 October 2022, which introduced binding safeguards limiting U.S. signals-intelligence activities to what is necessary and proportionate and established a Data Protection Review Court to provide independent redress for Europeans.
Interaction with supervisory-authority powers. Under the CJEU's holdings in Schrems I (paragraph 52) and Schrems II (paragraphs 118–120), supervisory authorities are bound by a valid adequacy decision: a supervisory authority may not, on the sole ground that it considers the third country inadequate, suspend or prohibit a transfer to a jurisdiction covered by a Commission adequacy decision. A supervisory authority that doubts the validity of an adequacy decision must bring the matter before its national courts, which may make a reference for a preliminary ruling to the CJEU under Article 267 TFEU; only the CJEU may declare a Commission adequacy decision invalid (Schrems I, paragraph 62). Supervisory authorities retain full powers under Article 58 GDPR to investigate and sanction transfers on other grounds: lack of a lawful basis under Article 6, insufficient technical and organisational measures under Article 32, non-compliance with transparency or purpose-limitation obligations, or violations of conditions within the adequacy decision's sectoral or territorial scope.
Practical implications for data exporters. An adequacy decision under Article 45(3) removes the need for specific Article 46 safeguards or Article 49 derogations, but does not dispense with the exporter's obligation to comply with all other GDPR provisions. The exporter must still:
- Have a lawful basis for the processing under Article 6(1) GDPR (and Article 9(2) for special categories of data).
- Comply with transparency obligations under Articles 13(1)(f) and 14(1)(f) (informing data subjects of the transfer to a third country).
- Ensure the transfer is compatible with the original purpose under Article 5(1)(b) or obtain consent for a new purpose.
- Implement appropriate technical and organisational measures under Article 32 regardless of where the data resides.
- Maintain a record of the transfer in the Article 30 records of processing activities.
- Verify that the specific transfer falls within the adequacy decision's scope (sectoral, territorial, or entity-based limitations as specified in the implementing act).
Data subjects retain the right to lodge complaints with EEA supervisory authorities under Article 77 and to seek judicial remedy under Articles 78–79 even when data is transferred to an adequate third country. Adequacy decisions do not immunise controllers from liability for unlawful processing; they simply remove the need for additional Chapter V transfer mechanisms.
Source: Regulation (EU) 2016/679 (GDPR), Article 45 Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559 Source: CJEU Case C-362/14, Schrems I, ECLI:EU:C:2015:650 Source: Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework) Source: Commission Implementing Decision (EU) 2019/419 (Japan adequacy decision) Source: European Commission adequacy decisions page
Binding Corporate Rules — Article 47 approval procedure, mandatory elements, and intra-group transfer framework
Binding Corporate Rules (BCRs) under Article 47 GDPR are internal data-protection policies that enable multinational corporate groups to transfer personal data from the European Economic Area to third-country affiliates within the same group, serving as an alternative to Standard Contractual Clauses for intra-group transfers. Unlike SCCs, which govern transfers between individual legal entities on a contract-by-contract basis, BCRs create a unified compliance framework binding on every member of a corporate group or group of enterprises engaged in a joint economic activity, including their employees. BCRs provide "appropriate safeguards" under Article 46(2)(b) GDPR and, once approved by the competent supervisory authority through the Article 63 consistency mechanism, permit transfers to any third country covered by the BCR without additional authorization for each individual transfer.
Article 4(20) GDPR defines BCRs as "personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity." The definition encompasses both controller BCRs (BCR-C, governing transfers where group entities act as independent controllers or where an EEA controller engages a third-country affiliate as a processor) and processor BCRs (BCR-P, governing transfers where the entire group acts as a processor on behalf of external EEA clients and must subcontract processing to third-country affiliates).
Approval procedure: the BCR Lead and the consistency mechanism. Article 47(1) GDPR provides that "the competent supervisory authority shall approve binding corporate rules in accordance with the consistency mechanism set out in Article 63." The approval process is cross-border by design: the applicant group proposes a "BCR Lead" supervisory authority, which acts as a single point of contact throughout the approval process, coordinates with all other concerned EEA supervisory authorities, and submits a draft approval decision to the European Data Protection Board (EDPB) for an opinion under Article 64(1)(f) GDPR. Article 64(1)(f) requires the EDPB to issue an opinion on any supervisory authority's draft decision "to approve binding corporate rules pursuant to Article 47." The EDPB's opinion, while not legally binding on the BCR Lead supervisory authority, is public and carries substantial weight in ensuring consistent application of Article 47 across the EEA.
Three foundational conditions under Article 47(1). BCRs must meet three threshold requirements before the supervisory authority may approve them:
- Legally binding and enforced across the group (Article 47(1)(a)). The BCRs must be "legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees." Groups typically achieve internal bindingness through an intra-group agreement signed at board level by all participating entities, unilateral declarations by the parent company recognized as binding under the applicable corporate law, or incorporation into employment contracts with disciplinary sanctions for non-compliance.
- Enforceable data-subject rights (Article 47(1)(b)). The BCRs must "expressly confer enforceable rights on data subjects with regard to the processing of their personal data." Data subjects must be able to invoke the BCRs as third-party beneficiaries and bring claims for compensation directly against any group member that breaches the rules, regardless of whether that member is in the EEA or in a third country.
- Fulfillment of Article 47(2) requirements (Article 47(1)(c)). The BCRs must specify at least the fourteen elements detailed in Article 47(2)(a)–(n).
Fourteen mandatory elements under Article 47(2). Article 47(2) provides that BCRs "shall specify at least" the following:
(a) Structure and contact details of the group of undertakings or group of enterprises engaged in a joint economic activity and of each of its members.
(b) Data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected, and the identification of the third country or countries in question.
(c) Legally binding nature, both internally and externally. The BCRs must explain how they bind group members vis-à-vis each other and how data subjects can enforce their rights externally.
(d) Application of the general data protection principles, in particular purpose limitation, data minimization, limited storage periods, data quality, data protection by design and by default, legal basis for processing, processing of special categories of personal data, measures to ensure data security, and "the requirements in respect of onward transfers to bodies not bound by the binding corporate rules." This last requirement means that when a group member subject to the BCRs transfers personal data to an external third party (a non-group entity in a third country), the transfer must comply independently with Chapter V—typically through SCCs, an adequacy decision, or an Article 49 derogation.
(e) Rights of data subjects in regard to processing and the means to exercise those rights, including the right not to be subject to decisions based solely on automated processing, including profiling in accordance with Article 22, the right to lodge a complaint with the competent supervisory authority and before the competent courts of the Member States in accordance with Article 79, and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules.
(f) Acceptance of liability by the controller or processor established on the territory of a Member State for "any breaches of the binding corporate rules by any member concerned not established in the Union." This EEA-based "liability entity" must commit to accepting liability for breaches by third-country affiliates, enabling data subjects to sue an EEA entity even when the breach occurred outside the EEA. The EEA controller or processor must make "appropriate arrangements" to ensure it can pay compensation for any damages resulting from the breach by any part of the group.
(g) Data subjects' ability to lodge complaints with a data protection supervisory authority, in particular in the Member State in which the controller or processor has an establishment, and to bring proceedings before the courts of the Member States in accordance with Article 79.
(h) Identification of the competent supervisory authority or authorities "in accordance with Article 56" (the lead supervisory authority) or "the Member State in which the controller or processor is established" if Article 56 does not apply.
(i) Cooperation with the supervisory authority or authorities.
(j) Mechanisms within the group for ensuring the verification of compliance with the binding corporate rules. Article 47(2)(j) second sentence specifies: "Such mechanisms shall include data protection audits and methods for ensuring corrective actions to protect the rights of the data subject."
(k) Mechanisms for reporting and recording changes to the rules and for communicating those changes to the supervisory authority.
(l) Cooperation mechanisms with the supervisory authority to ensure compliance by any member of the group of undertakings, or group of enterprises engaged in a joint economic activity, including in third countries.
(m) Mechanisms for reporting to the competent supervisory authority any legal requirements to which a member of the group in a third country is subject and which are likely to have a substantial adverse effect on the guarantees provided by the binding corporate rules. This obligation requires groups to assess and report governmental access laws (surveillance, law-enforcement access, national-security orders, data-localization mandates) in each third country where a BCR member is located and to report those that conflict with the BCRs.
(n) Appropriate data protection training to personnel having permanent or regular access to personal data.
**Post-Schrems II assessment of third-country laws and supplementary measures.** Although Article 47(2)(m) has required reporting of adverse legal requirements since the GDPR's entry into force, the CJEU's judgment in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Schrems II), Case C-311/18, ECLI:EU:C:2020:559, 16 July 2020, clarified that all Article 46 appropriate safeguards—including BCRs—must ensure a level of protection "essentially equivalent" to that guaranteed within the EU. Paragraph 133 of Schrems II held that exporters relying on Article 46 safeguards must verify "on a case-by-case basis" whether the law or practice of the third country impinges on the effectiveness of the safeguards and, if necessary, adopt supplementary measures (technical, contractual, or organizational) to ensure essentially equivalent protection. The EDPB's Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data (adopted 10 November 2020, final version 18 June 2021) provide a six-step roadmap for this assessment and a non-exhaustive catalogue of supplementary measures, including encryption with EEA-held keys, pseudonymization, data minimization, split processing, and contractual obligations for the importer to challenge unlawful access requests and notify the exporter.
The EDPB's Recommendations 1/2022 on the Application for Approval and on the Elements and Principles to be Found in Controller Binding Corporate Rules (adopted 20 June 2023) update the legacy Article 29 Working Party BCR-C referential (WP256 rev.01 and WP264) and integrate the Schrems II assessment obligation into the BCR approval process. Recommendations 1/2022 require BCR applicants and holders to document their assessment of third-country laws under Article 47(2)(m), identify supplementary measures where necessary, and report material legal requirements in the annual update to the BCR Lead supervisory authority. All existing BCR-C holders were required to bring their BCRs into line with Recommendations 1/2022 as part of their 2024 annual update.
Controller BCRs versus processor BCRs. The EDPB Recommendations 1/2022 apply to controller BCRs (BCR-C). The Article 29 Working Party previously published separate guidance for processor BCRs (WP257 rev.01 and WP265, endorsed by the EDPB on 25 May 2018). A single corporate group may hold both a BCR-C (for internal administrative processing such as HR, finance, IT, and legal) and a BCR-P (for client data processing when the group acts as a service provider), although this requires separate applications and supervisory-authority approvals.
Enforcement, liability, and data-subject remedies. BCRs create direct third-party beneficiary rights for data subjects under Article 47(1)(b) and (2)(e). An individual whose personal data is transferred under BCRs may:
- Lodge a complaint with any competent supervisory authority under Article 77 GDPR.
- Bring judicial proceedings before the courts of the Member State where the EEA controller or processor is established, or where the data subject has habitual residence (Article 79 GDPR), directly against any group member (including third-country affiliates) for breach of the BCRs.
- Claim compensation for material or non-material damage resulting from the breach under Article 82 GDPR. The EEA liability entity identified in the BCRs under Article 47(2)(f) is liable for breaches by third-country affiliates.
Supervisory authorities retain full investigative and corrective powers under Article 58 GDPR. Infringement of the Article 46 and 47 transfer conditions is subject to administrative fines up to €20 million or 4% of total worldwide annual turnover, whichever is higher, under Article 83(5)(c) GDPR.
Annual update and ongoing compliance. Article 47(2)(k) requires BCR holders to maintain "mechanisms for reporting and recording changes to the rules and for communicating those changes to the supervisory authority." The EDPB Recommendations 1/2022 operationalize this as a mandatory annual update submitted to the BCR Lead supervisory authority, which must include at minimum: (i) changes to the group structure (members added or removed), (ii) changes to third countries of transfer, (iii) summary of data-protection audits conducted and corrective actions taken, (iv) summary of data-subject complaints and supervisory-authority inquiries, (v) confirmation that the EEA liability entity maintains sufficient assets to satisfy potential claims, and (vi) any legislative or regulatory developments in third countries that may have a substantial adverse effect on the BCRs under Article 47(2)(m).
Commission implementing powers. Article 47(3) provides that "the Commission may specify the format and procedures for the exchange of information between controllers, processors and supervisory authorities for binding corporate rules within the meaning of this Article. Those implementing acts shall be adopted in accordance with the examination procedure set out in Article 93(2)." As of June 2026, the Commission has not adopted such implementing acts; the EDPB Recommendations 1/2022 and the EDPB's procedural cooperation document serve as the operative guidance.
Approved BCRs register. The EDPB maintains a public register of approved BCRs on its website (edpb.europa.eu/our-work-tools/accountability-tools/bcr_en). The register lists BCRs approved under the GDPR (post-25 May 2018) separately from pre-GDPR BCRs approved under Directive 95/46/EC. Each entry includes the company name, the type of BCR (controller or processor), the BCR Lead supervisory authority, the date of the EDPB opinion, and the scope of transfers.
Source: Regulation (EU) 2016/679 (GDPR), Articles 4(20), 46, 47, 63, 64, 77, 79, 82, 83(5)(c) Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559 Source: EDPB Recommendations 1/2022 on the Application for Approval and on the Elements and Principles to be Found in Controller Binding Corporate Rules, adopted 20 June 2023 Source: EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, final version 18 June 2021
Article 49 GDPR — Derogations for specific situations and the restrictive-interpretation requirement
Article 49 GDPR establishes narrow derogations permitting international data transfers in the absence of an adequacy decision under Article 45 or appropriate safeguards under Article 46, but only in tightly defined specific situations and subject to strict conditions. These derogations function as the third and final tier of the Chapter V transfer framework—a safety valve for exceptional circumstances, not a routine compliance mechanism. The EDPB has emphasized that Article 49 derogations "cannot become 'the rule' in practice, but need to be restricted to specific situations" and must be interpreted restrictively, primarily for processing activities that are occasional and non-repetitive.
The layered hierarchy and Article 49's subsidiary role. Recital 111 GDPR confirms that transfers based on Article 49 derogations "should be possible in certain specific situations" but only "where no other legal grounds for transfer ... is available." Article 44 requires all Chapter V provisions to ensure that the level of protection guaranteed by the GDPR is not undermined; the EDPB has clarified that recourse to Article 49 derogations "should never lead to a situation where fundamental rights might be breached." Data exporters must first assess whether an adequacy decision covers the transfer (Article 45), then whether appropriate safeguards can be implemented (Article 46 SCCs, BCRs, ad hoc clauses, codes of conduct, or certification mechanisms), and only when neither is available or effective may they turn to Article 49. The derogations are a last resort, not a first choice.
Article 49(1) first subparagraph: six core derogations. Article 49(1) provides that in the absence of an adequacy decision or appropriate safeguards, a transfer or a set of transfers may take place only if one of the following conditions is met:
(a) Explicit consent after being informed of possible risks. The data subject has explicitly consented to the proposed transfer "after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards." This consent must meet all the Article 7 and Recital 32 conditions for valid GDPR consent: freely given, specific, informed, and unambiguous. The EDPB's Guidelines 2/2018 emphasize that consent in this context requires heightened information because the data subject must understand the concrete implications of transferring data to a jurisdiction that does not provide an adequate level of protection. Consent obtained before the transfer occurred but without disclosure of the specific risks at the time is invalid. Article 49(3) prohibits public authorities from relying on the consent derogation when they are "engaged in the performance of their tasks."
(b) Necessity for contract performance or pre-contractual measures. The transfer is "necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject's request." Necessity means the transfer is objectively essential to fulfill the contractual obligation; it is not sufficient that the transfer is merely convenient, customary, or specified in the contract. The EDPB has clarified that a controller cannot artificially create necessity by inserting a clause in the contract requiring transfer to a third country when alternative means exist within the EEA. The necessity must be assessed case-by-case, taking into account whether the same contractual purpose could reasonably be achieved by other means (for instance, processing within the EEA or in an adequate third country). This derogation does not cover routine commercial transfers that are ancillary to the main contract—for example, outsourcing customer-support services to a third-country call center is not "necessary" for the sale contract between the data subject and the controller.
(c) Necessity for a contract in the interest of the data subject. The transfer is "necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another natural or legal person." This covers, for instance, a bank in the EEA arranging a mortgage with a property seller in a third country on behalf of an EEA customer. The contract must be in the interest of the data subject, not solely for the controller's commercial benefit.
(d) Important reasons of public interest. The transfer is "necessary for important reasons of public interest." Recital 112 specifies that such public-interest grounds must be "recognised in Union law or in the law of the Member State to which the controller is subject." Article 49(4) confirms that public-interest transfers may take place on the basis of a provision in Union or Member State law "which provides for suitable safeguards with regard to the protection of personal data" and requires the Member State to notify the Commission of such provisions. Examples recognized by the EDPB and Recital 112 include international data exchanges between competition authorities, tax and customs authorities, financial supervisory authorities, and social-security institutions, where grounded in specific legal instruments. A controller's subjective assessment of public importance is not sufficient; the importance must be recognized by law.
(e) Necessity to establish, exercise, or defend legal claims. The transfer is "necessary for the establishment, exercise or defence of legal claims." This derogation is strictly limited to transfers that are essential for litigation, arbitration, administrative proceedings, or pre-litigation dispute resolution. The EDPB Guidelines 2/2018 clarify that the transfer must be directly necessary for the legal claim—for example, transmitting evidence to a third-country tribunal or providing data to a lawyer in a third country representing the controller in a lawsuit. Routine disclosures to a third-country legal department for general compliance monitoring do not qualify. The necessity criterion is strict: the claim must be concrete and the transfer must be an unavoidable element of its establishment, exercise, or defense.
(f) Necessity to protect vital interests when consent cannot be obtained. The transfer is "necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent." Vital interests are understood narrowly as life-or-death situations—medical emergencies requiring immediate treatment in a third country, evacuation in a natural disaster, humanitarian assistance. Recital 46 GDPR notes that vital interests "should not apply where the data subject is capable of giving consent." This derogation is invoked rarely and requires documentation that obtaining consent was genuinely impossible in the time available.
(g) Transfers from a public register. The transfer is made from a register established by Union or Member State law "which is intended to provide information to the public" and is open to consultation either by the public in general or by any person demonstrating a legitimate interest, "but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case." This permits, for instance, transfers from company registries, land registries, or professional registers when accessed in accordance with the applicable legal framework. The transfer must respect the purpose and access conditions of the register.
Article 49(1) second subparagraph: the compelling-legitimate-interests exception. When none of the six derogations above applies, Article 49(1) second subparagraph provides a residual exception for transfers that meet three cumulative conditions:
- Not based on adequacy or appropriate safeguards. No adequacy decision or Article 46 safeguards apply.
- Necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject.
- Occasional, non-repetitive, concerns only a limited number of data subjects, and suitable safeguards provided. Recital 111 elaborates: the transfer must not be part of "massive, disproportionate and repetitive transfers" or "massive and structural activities." The controller must assess all the circumstances surrounding the transfer and provide suitable safeguards (which the controller must document and, on request, provide to the supervisory authority and the data subject). The data subject must be informed of the transfer and of the compelling legitimate interests pursued.
The EDPB Guidelines 2/2018 interpret "occasional" and "not repetitive" as permitting transfers that may happen more than once but occur outside the regular course of business, under random or unknown circumstances, and within arbitrary timeframes—not as part of systematic or routine data flows. "Limited number of data subjects" is context-specific but implies that the transfer cannot involve thousands or tens of thousands of individuals; the scale must be genuinely constrained. The controller's assessment under this exception must be documented in writing, including the nature of the legitimate interests, the assessment of necessity and proportionality, the description of suitable safeguards, and the conclusion that the data subjects' rights are not overridden. Suitable safeguards may include encryption, pseudonymization, strict access controls, contractual commitments by the recipient (even though they do not constitute Article 46 appropriate safeguards), and data minimization. Importantly, the second subparagraph does not require explicit consent, but does require the controller to inform the data subject of the transfer and the compelling legitimate interests.
Article 49(2): one-off urgent contract transfers. Article 49(2) addresses an edge case: where a transfer is necessary for a contract between the controller and a person other than the data subject, the derogation under Article 49(1)(b) (contract necessity with the data subject) does not apply, so the controller may instead rely on the derogation under Article 49(1) second subparagraph (compelling legitimate interests) only if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests which are not overridden by the data subject's interests, and the controller has assessed all circumstances and provided suitable safeguards. This duplicates much of the second-subparagraph framework but clarifies that it may be invoked for urgent one-off B2B contract situations involving data subjects who are not contractual parties.
Article 49(3): public authorities cannot rely on consent. Article 49(3) prohibits a public authority or body "in the exercise of its public powers" from invoking the explicit-consent derogation (Article 49(1)(a)) or the compelling-legitimate-interests exception (Article 49(1) second subparagraph). Public authorities engaged in their official tasks must rely on adequacy decisions, Article 46 safeguards (including Article 46(2)(a) or (3)(b) international agreements), or one of the other Article 49(1) first-subparagraph derogations (contract, public interest, legal claims, vital interests, or public register). The EDPB explains that public authorities exercise inherent power over individuals, so consent cannot be freely given in that context, and reliance on the flexible compelling-legitimate-interests exception would risk undermining Chapter V's protective framework.
Article 49(4): notification of Member State public-interest provisions. Article 49(4) requires Member States to notify the Commission of the provisions of their law that authorize public-interest transfers under Article 49(1)(d), including the categories of personal data, the type of transfer, and the purpose. The Commission must make this information accessible in a publicly available register and transmit it to the EDPB.
Article 49(5): Member State restrictions. Article 49(5) permits Union or Member State law to impose additional limits on transfers for "important reasons of public interest." For example, national law may prohibit or require prior authorization for transfers of health data, tax data, or national-security-related data even when an Article 49 derogation would otherwise apply. Such restrictions must themselves meet proportionality and necessity standards under EU law.
Interaction with other Chapter V obligations and the Schrems II assessment. Article 49 derogations do not exempt controllers from the Article 44 requirement that the level of protection guaranteed by the GDPR "is not undermined." Even when a derogation applies, the transfer must not lead to a situation where fundamental rights are breached. The EDPB has noted that in exceptional cases, relying on a derogation may be unlawful if the data subject's interests or fundamental rights override the controller's interest—for instance, transferring sensitive data of vulnerable individuals to a jurisdiction with a documented record of mass surveillance or where the data subject faces a concrete risk of harm. Article 49 derogations also do not relieve controllers of the obligation to have a lawful basis under Article 6 (or Article 9 for special categories), to comply with transparency obligations (Articles 13(1)(f) and 14(1)(f) require informing data subjects of transfers to third countries, including the derogation invoked), to implement appropriate security measures under Article 32, and to document the transfer in the Article 30 records of processing.
Enforcement and practical guidance. Infringement of the Chapter V transfer conditions, including misuse of Article 49 derogations, is subject to administrative fines up to €20 million or 4% of total worldwide annual turnover, whichever is higher, under Article 83(5)(c) GDPR. Supervisory authorities have issued enforcement decisions penalizing reliance on Article 49 derogations for transfers that were in fact repetitive, massive, or not genuinely necessary. The EDPB's Guidelines 2/2018 on derogations of Article 49, adopted 25 May 2018, provide detailed case-by-case examples, including permissible and impermissible uses of the consent, contract-necessity, legal-claims, and compelling-legitimate-interests derogations. Controllers should document the factual and legal basis for each reliance on Article 49, including the assessment of necessity, the measures taken to inform data subjects, and any suitable safeguards implemented.
Source: Regulation (EU) 2016/679 (GDPR), Article 49 Source: EDPB Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679, adopted 25 May 2018
Transfer Impact Assessment (TIA) — Six-step roadmap and supplementary measures under Schrems II and EDPB Recommendations 01/2020
The transfer impact assessment (TIA) is the mandatory, case-by-case evaluation required whenever a data exporter relies on Article 46 GDPR appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules, or ad hoc contractual clauses) to determine whether the law or practice of the importing third country undermines those safeguards—and, if so, whether effective supplementary measures can bring the level of protection up to the EU's “essential equivalence” standard.
This obligation is codified in Schrems II (CJEU, C-311/18, para. 133), reinforced by Clause 14 of the 2021 Standard Contractual Clauses, and operationalized by the European Data Protection Board (EDPB) in its Recommendations 01/2020 (final version, 18 June 2021). The six-step TIA methodology, use cases, and catalogue of supplementary measures are described in detail throughout Recommendations 01/2020.
General six-step TIA roadmap (per Recommendations 01/2020, paras. 8–96):
- Map all transfers (including data types, importers, purposes, and onward flows).
- Identify the relevant transfer tool (e.g., SCCs/BCRs).
- Assess the destination country's law and practices—particularly those affecting government and public authority access to personal data—with specific attention to factors that could imperil essential equivalence. This must use objective, context-specific analysis, not probabilistic assurances.
- Adopt supplementary measures if the standard transfer tool alone is insufficient–these may be technical (such as strong encryption, pseudonymization, or split processing), organizational (such as internal policies or routine audits), or contractual (such as obligations for the importer to notify and challenge unlawful requests).
- Complete any required notifications or procedures with the competent supervisory authority, including seeking guidance or authorization for problematic transfer scenarios.
- Reassess and monitor regularly—trigger events (new laws, breaches, or new categories of data within the transfer) require prompt re-evaluation of the risk and adequacy of existing safeguards.
TIAs must be documented and are subject to supervisory authority review. The burden of demonstration is on the exporter/controller. Supervisory authorities across the EEA regularly request TIA documentation during investigations, especially for transfers to jurisdictions with known risks (notably the United States, China, Russia, etc.). Failure to conduct a TIA or to implement effective supplementary measures as required may invalidate the transfer mechanism and could expose both the data exporter and importer to fines under GDPR Article 83(5)(c).
Note on special categories of data (including biometric data): GDPR and EDPB Recommendations 01/2020 flag special categories of personal data (such as biometric, health, or genetic data) as carrying heightened risks in international transfers. Where such data is involved, the EDPB expects especially granular risk analysis and typically more robust supplementary measures; however, as of June 2026, no EDPB guidelines creating new or stricter legal requirements for biometric data transfer beyond Recommendations 01/2020 have been issued. All transfer-related obligations for special categories of data derive from the GDPR, Schrems II, and the framework of Recommendations 01/2020. Practitioners should closely monitor EDPB outputs for future developments.
In sum: The six-step TIA and supplementary measure requirements as set out in Schrems II, the 2021 SCCs, and EDPB Recommendations 01/2020 remain legally operative for all transfers as of June 2026. No new guidance or legal authority imposing additional requirements on biometric data transfers has been issued since the adoption of Recommendations 01/2020.
Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559 Source: EDPB Recommendations 01/2020 (final 18 June 2021): Measures Supplementing Transfer Tools Source: Commission Implementing Decision (EU) 2021/914 (SCCs), Clause 14 Source: Regulation (EU) 2016/679 (GDPR), Articles 44, 46, 83(5)(c)
Adequacy Decisions under Article 45 GDPR — Country List, Territorial and Sectoral Scope (As of June 2026)
Current list of European Commission adequacy decisions (June 2026 reference):
A transfer of personal data from the European Economic Area (EEA) to a third country, territory, or specific sector can be made without additional safeguards under Chapter V GDPR only when the European Commission adopts a formal adequacy decision in accordance with Article 45(3) GDPR. As of June 2026, the following jurisdictions reflect their status on the official Commission register and most recent updates. Entries based only on official announcements (not yet in force) are flagged as pending.
| Jurisdiction | Commission Decision / Reference | Scope and Limitations | Date of Most Recent Review | Next Scheduled Review | |---------------------|--------------------------------------------------|-------------------------------------------------------------|---------------------------|----------------------| | Andorra | 2003/490/EC (reaffirmed GDPR era, 2024 review) | All sectors | 2024 | 2028 | | Argentina | 2003/490/EC (reaffirmed, 2024 review) | All sectors | 2024 | 2028 | | Brazil | Announced Jan 2026 (Press Release IP_26_229), pending final decision text | All sectors (pending; not operational on Commission register as of 2026-06-15) | n/a | n/a | | Canada | 2002/2/EC & SWD(2023) 474 (review, Jan 2024) | Only PIPEDA-covered commercial orgs; excludes federal/provincial government institutions & Quebec’s Law 25-only entities | 2024 | 2028 | | Faroe Islands | 2010/146/EU | All sectors | 2024 | 2028 | | Guernsey | 2003/821/EC | All sectors | 2024 | 2028 | | Israel | 2011/61/EU | All sectors | 2024 | 2028 | | Isle of Man | 2004/411/EC | All sectors | 2024 | 2028 | | Japan | 2019/419, update SWD(2023) 75 final | Only APPI-covered business operators; excludes certain public sector data | 2023 | 2027 | | Jersey | 2008/393/EC | All sectors | 2024 | 2028 | | New Zealand | 2012/484/EU | All sectors | 2024 | 2028 | | Republic of Korea | 2021/2217 (December 2021) | All sectors | 2022 | 2026 | | Switzerland | 2000/518/EC | All sectors | 2024 | 2028 | | United Kingdom | 2021/1773 (extended 2025) | Both GDPR and Law Enforcement Directive for respective data; not all sectors | 2025 review | 2029 | | United States | 2023/1795 (EU-US Data Privacy Framework) | Only self-certified orgs on U.S. DPF List; commercial sector | 2023 | 2024 (DPF), periodic | | Uruguay | 2012/484/EU | All sectors | 2024 | 2028 |
Notes:
- Scope/territorial limitations: Decisions for Canada, the US, and Japan do not confer blanket adequacy; check the underlying decision text for precise entity and sector definitions.
- Brazil: As of June 2026, adequacy for Brazil is announced (per European Commission Press Release IP_26_229), but not yet implemented in formally published decision text nor in effect on the Commission register — practitioners should treat transfers as not adequacy-covered until the decision is finalized and listed.
- Law Enforcement Directive: UK (2021/1773) covers both GDPR and Directive (EU) 2016/680 for law enforcement data; other adequacy partners are mostly GDPR-only.
- Periodic review: Standard review cycle is at least every four years (Article 45(3)); some (like the DPF) have annual initial reviews.
- Register and all implementing acts: The European Commission official register remains the authoritative, up-to-date listing: ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
For adequacy decision substance and evaluation criteria, see /guides/european-union/international-data-transfers#article-45-adequacy-assessment-criteria.
Transfers not coverage under adequacy must use Standard Contractual Clauses (#standard-contractual-clauses-2021-modules) or Article 49 derogations (#article-49-derogations-specific-situations).
Source: European Commission adequacy decisions — official register Source: Commission Implementing Decision (EU) 2023/1795 (EU-US DPF) Source: European Commission Press Release IP_26_229 (Brazil)
Article 46(3)(a) GDPR — Ad Hoc Contractual Clauses and Supervisory Authority Authorization Process
Article 46(3)(a) GDPR allows personal data to be transferred to a third country on the basis of ad hoc contractual clauses negotiated specifically between the exporter and the importer, provided these clauses have received prior authorization from the competent supervisory authority. This mechanism exists as an alternative to the European Commission’s standard contractual clauses (SCCs), enabling organizations to address transfer scenarios that are too bespoke or complex for “off-the-shelf” SCCs, such as highly specialized industrial collaborations, sector-specific data flows, or unique commercial arrangements involving multiple parties and nuanced contractual obligations.
Conditions for use:
- No adequacy or other appropriate safeguard: Ad hoc clauses are a fallback when neither an adequacy decision (Article 45) nor a pre-approved Article 46(2) safeguard (SCCs, BCRs, codes) is available, or when the transfer’s circumstances cannot be adequately covered by those existing mechanisms.
- Prior supervisory authority authorization and new 2026 EDPB procedural guidance: Article 46(3)(a) requires that the data exporter obtain authorization from the competent data protection authority (DPA) before the transfer occurs. This is a case-by-case review: the DPA evaluates whether the proposed clauses provide “appropriate safeguards” for data subject rights, effective remedies, enforceability, and essential equivalence to GDPR standards (see Recital 109 and Article 46(3)).
- Procedural update: In January 2026, the European Data Protection Board (EDPB) adopted a cooperation procedure for supervisory authorities when authorizing ad hoc contractual clauses and SCCs under Article 46(3)(a) and (2)(d), respectively. This procedural document aims to streamline and harmonize the review process, especially when transfers impact multiple Member States. The principal changes are: (1) more structured cross-border cooperation; (2) defined consultation timelines with the EDPB consistency mechanism; and (3) clarity on documentation and notification requirements for complex/multi-jurisdictional transfers.
- Consistency mechanism: If the contract involves transfers from multiple Member States, or if the transfer is likely to affect data subjects across several jurisdictions, the DPA must consult the European Data Protection Board (EDPB) per Article 64(2) (“consistency mechanism”), which may take up to 8 weeks (extendable). The new 2026 procedure adds predictability to these deadlines.
- Transparency and documentation: The exporter must inform data subjects (Articles 13(1)(f) and 14(1)(f)), document the contract approval in its Article 30 records of processing, and implement ongoing monitoring for legal changes (recurring reporting to the DPA may be required for high-risk transfers).
Schrems II and the “essential equivalence” requirement: Even with DPA approval, exporters must assess whether the third country’s laws compromise the effectiveness of the contractual safeguards—mirroring the obligations from CJEU Schrems II (Case C-311/18, para. 133) and the EDPB’s guidance on supplementary measures (EDPB Recommendations 01/2020). If effective supplementary measures (e.g., encryption, minimization) cannot fill the gap, the DPA may refuse authorization or require additional obligations.
Differences from SCCs and BCRs:
- Ad hoc clauses allow greater flexibility, but lack the pre-approval of SCCs and are not universally recognized across the EEA (requiring authority-by-authority approval).
- They are suitable for complex, one-off, or highly niche transfers where ‘boilerplate’ SCCs are a poor fit.
- Transfer on the basis of Article 46(3)(a) is rare in practice, given the procedural burden and unpredictability of supervisory authority assessment.
Enforcement and consequences: Should an exporter use unauthorized clauses, or continue transfers after a DPA refuses approval, this constitutes a breach of Article 44 transfer requirements and risks GDPR’s top-tier administrative fines (Article 83(5)(c)). The 2026 EDPB guidance increases the likelihood of consistent enforcement for cross-border or multi-DPA transfers.
Source: Regulation (EU) 2016/679 (GDPR), Article 46(3)(a), Recital 109 Source: EDPB Recommendations 01/2020 on measures that supplement transfer tools Source: CJEU Case C-311/18, Schrems II Source: EDPB Procedural Document on Authorisation of Ad Hoc Clauses and SCCs (adopted January 2026)
Codes of Conduct and Certification Mechanisms — Article 46(2)(e)-(f) GDPR transfer tools and EDPB approval process
Article 46(2)(e) and (f) GDPR permit data exporters to rely on approved Codes of Conduct and Certification Mechanisms as appropriate safeguards for transfers to third countries in the absence of an adequacy decision. These mechanisms are distinct from Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs) and have their own procedural and substantive requirements.
Codes of Conduct (Article 46(2)(e), 40): To be used as a transfer safeguard, a code of conduct must be approved under Article 40(5) GDPR by a competent national supervisory authority and the European Data Protection Board (EDPB), and must provide for binding and enforceable commitments for the third-country data importer. The code must set forth clear obligations for both exporters and importers, and ensure that data subjects have effective enforceable rights (Article 40(3) GDPR). Monitoring of compliance with the code must be carried out by a body accredited under Article 41. The EDPB Guidelines 04/2021 clarify that only codes explicitly approved for transfer purposes—incorporating Chapter V requirements—can be relied on for international transfers. As of June 2026, no cross-sector EU-wide code of conduct has received full approval as a transfer tool for Chapter V; exporters must monitor for future developments but cannot currently rely on this mechanism alone for cross-border transfers.
Certification Mechanisms (Article 46(2)(f), 42): Certifications eligible as transfer safeguards must be approved under Article 42(5) GDPR and are subject to additional criteria as detailed by the EDPB in Guidelines 07/2022 (rev. 2023).
Material update (April 2026): On 16 April 2026, the EDPB, in Opinion 15/2026, approved the Europrivacy certification mechanism as an internationally valid tool for cross-border personal data transfers under GDPR Article 46(2)(f). This marks the first practical use case of certification as a Chapter V transfer tool. Data exporters may now rely on Europrivacy certificates (issued with the transfer addendum) for international transfers to both EEA and non-EEA entities, provided all other Article 46 and Chapter V conditions are met. Certification bodies must be accredited under Article 43, and certified compliance must be verifiable and provide effective remedies for data subjects. The EDPB's approval does not extend to other sectoral or national certifications unless they are also approved through this process.
Approval process: Both codes of conduct and certifications for transfer require a two-stage approval: national supervisory authority approval with a mandatory EDPB opinion (Articles 40(7), 42(5)). Certification mechanisms do not require European Commission approval for use as Chapter V transfer tools, but must meet EDPB criteria for international transfers and be robustly monitored. Certificates must be made publicly available (Article 42(7)). The detailed approval and operational criteria for certification as a transfer tool are elaborated in Guidelines 07/2022 and reinforced by EDPB Opinion 15/2026.
Practical compliance: Controllers and processors must document the use of a code or certification in their Article 30 records and provide the relevant mechanism text or certificate on request. Improper reliance on an unapproved code or certification may trigger enforcement, including administrative fines up to €20 million or 4% of global turnover (Article 83(5)(c)). Any transfer mechanism must also be compatible with the Schrems II ruling and EDPB Recommendations 01/2020 on supplementary measures, particularly for transfers to jurisdictions with problematic surveillance or redress frameworks.
Summary (as of June 2026): Europrivacy is now an officially recognized certification for cross-border transfers under Article 46(2)(f) GDPR. For codes of conduct, no EU-wide transfer code is approved; monitor the EDPB and its register for future developments.
Source: Regulation (EU) 2016/679 (GDPR), Articles 40–42, 46(2)(e)-(f), 83(5)(c) Source: EDPB Guidelines 04/2021 on Codes of Conduct as tools for transfers Source: EDPB Guidelines 07/2022 on certification as a tool for transfers Source: EDPB Opinion 15/2026 on Europrivacy certification as a transfer tool
Onward Transfers under GDPR Chapter V — Conditions, Safeguards, and EDPB Guidance
Onward transfers occur when personal data, initially transferred out of the EEA under a valid GDPR Chapter V mechanism (adequacy decision, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), derogation, or Article 46-approved certification), is further transferred by the non-EEA recipient to a different third country or organization. The core rule—grounded in Article 44 GDPR and reiterated by both the CJEU and EDPB—is that each onward transfer is a new transfer and must independently comply with Chapter V, ensuring the level of data protection is not undermined through any stage of the chain.
Core Rule and 2026 Update: Every onward transfer from the first third-country recipient must have its own lawful basis under Chapter V. As of April 2026, the EDPB's approval of the Europrivacy certification as a transfer tool (Article 46(2)(f)) means onward transfers may now also occur via certified importers, provided they meet all EDPB and Europrivacy requirements. The 2026 EDPB update to Recommendations on Processor Binding Corporate Rules (BCR-P) further clarifies that onward transfers from BCR-processors to non-BCR-bound entities must also rest on an independent Chapter V mechanism—mirroring SCC logic for non-controller pathways, and strengthening audit/reporting obligations for processor-initiated onward transfers.
SCC Onward Transfer Clauses: The 2021 SCCs (EU Implementing Decision 2021/914, Clause 8.7 and 15) require that initial importers inform the exporter and secure authorization before any onward transfer, unless the new recipient accedes to the SCCs or is covered by an adequacy decision or certified mechanism (now including Europrivacy). Any compelled disclosure to third-country public authorities triggers strict notification and documentation safeguards.
BCRs (Controller and Processor) and EDPB Recommendations: Article 47(2)(d) GDPR and the EDPB’s 2026 recommendations (BCR-P and BCR-C) require onward transfers outside a BCR-bound group to rely on a separate Chapter V transfer tool—SCCs, adequacy, certification, or derogation. The 2026 guidance increases requirements for documentation, re-assessment, and supplementary measures for high-risk onward transfers initiated by processors. See EDPB Recommendations 1/2022 (controller BCRs) and Recommendations 1/2026 (processor BCRs). Source: EDPB Recommendations 1/2022 on Controller BCRs Source: EDPB Recommendations 1/2026 on Processor BCRs
Certification as a Transfer Mechanism: From April 2026, certifications like Europrivacy (with EDPB approval) serve as stand-alone Article 46(2)(f) transfer tools. For onward transfers, a certified importer may further transfer data lawfully if the next recipient is likewise certified or is covered by another Chapter V mechanism; such onward transfer must be documented and auditable under certification conditions. See EDPB Opinion 15/2026. Source: EDPB Opinion 15/2026 on Europrivacy certification as a transfer tool
Supplementary Measures and Schrems II Impact: CJEU and EDPB guidance (notably Schrems II, EDPB Recommendations 01/2020, Recommendations 1/2022 (BCR-C), and the new BCR-P Recommendations) all confirm that supplementary technical, organizational, or contractual measures may be required for any onward transfer to ensure essential equivalence with EU standards. Onward transfers to additional sub-processors or higher-risk jurisdictions often trigger a new Transfer Impact Assessment (TIA) and specific additional safeguards.
Consequences and Accountability: Every onward transfer that fails to independently meet Chapter V conditions exposes both exporters and importers to top-tier GDPR fines (up to €20 million or 4% of worldwide annual turnover, Article 83(5)(c)). Supervisory authorities routinely investigate chains of onward transfers, particularly where complex processor/sub-processor arrangements or newly certified mechanisms (such as Europrivacy) are involved.
Summary: Each onward transfer from a third-country recipient must independently satisfy the requirements of Chapter V: adequacy, SCCs/BCRs, certification (now including Europrivacy), or derogation. All new 2026 guidance reinforces—rather than relaxes—GDPR’s demand for continuity of protection throughout the transfer chain.
Source: Regulation (EU) 2016/679 (GDPR), Articles 44–47 Source: Commission Implementing Decision (EU) 2021/914 (SCCs), Clause 8.7, 15 Source: EDPB Recommendations 01/2020 on supplementary measures Source: EDPB Recommendations 1/2022 on Controller BCRs Source: EDPB Recommendations 1/2026 on Processor BCRs Source: EDPB Opinion 15/2026 on Europrivacy certification as a transfer tool Source: CJEU Case C-311/18, Schrems II, ECLI:EU:C:2020:559
Article 49(4)–(5) GDPR — Public Interest Transfers, Member State Notification Obligations, and National Restrictions
Article 49(4)–(5) GDPR governs the specific scenario in which a data transfer to a third country is justified by "important reasons of public interest" under Member State or Union law, and sets procedural requirements for notification and transparency at both the Member State and EU level. While Article 49(1)(d) GDPR permits such transfers without an adequacy decision or Article 46 safeguards, Article 49(4) mandates that any national provision authorizing the transfer must be notified to the European Commission, including the categories of personal data, types of transfers, purposes, and relevant safeguards. The Commission must maintain a publicly available register with this information and also transmit it to the European Data Protection Board (EDPB).
The function of Article 49(4) is to ensure both legal certainty for exporters and transparency for data subjects and regulators across the EEA about when and how Member States justify public-interest transfers outside the automatic protection of Chapter V. This mechanism is particularly relevant where Member States implement special regimes for transfers in sectors such as tax, financial supervision, competition law, public health, or social security. Without notification and registration, controllers cannot rely on such national provisions as a lawful basis for a public-interest transfer under Article 49(1)(d) GDPR.
National restrictions remain possible under Article 49(5). Even when a derogation for public interest applies, Article 49(5) GDPR allows Union or Member State law to impose "limitations with regard to transfers of specific categories of personal data for important reasons of public interest," effectively allowing for statutory bans or conditions on certain export scenarios (e.g., health, genetic, or biometric data transfers; financial at-risk groups). Any such national restriction must itself comply with EU law, particularly proportionality and necessity (see also Article 23 GDPR on restrictions of data-subject rights).
Impact on practical compliance:
- Controllers must check the Commission’s formal public register to determine whether a putative national law enabling a public-interest transfer has been duly notified (see the Commission's registry: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en#public-interest-derogations).
- A transfer based on a non-notified national public-interest law may be invalid. The Commission and EDPB have stressed the importance of correct notification (cf. EDPB Guidelines 2/2018, para. 86–87).
- Member States and the Commission periodically update the register, but gaps remain. National authorities must keep the Commission apprised of new or amended provisions and their effective scope.
- The Commission’s register, while public, is not always immediately up-to-date and practitioners must check both the EU site and relevant national texts.
Enforcement: Reliance on a non-registered or unlawful Member State public-interest basis may be sanctioned as a breach of Articles 44–49 GDPR, subject to top-tier administrative fines (up to €20 million or 4% of annual global turnover).
Source: Regulation (EU) 2016/679 (GDPR), Article 49(4)-(5) Source: European Commission public register of Member State notifications — Public Interest Derogations Source: EDPB Guidelines 2/2018 on derogations of Article 49
Article 30 GDPR Record of Processing Activities (ROPA) — Documenting Transfer Mechanisms and TIA Outcomes for International Data Transfers
Controllers and processors subject to the GDPR must reflect all international data transfers in their Record of Processing Activities (ROPA) as required by Article 30 GDPR. Article 30(1) (for controllers) and 30(2) (for processors) specify that the ROPA must include the categories of recipients in third countries or international organisations, and—where applicable—document the mechanism relied upon for the transfer.
Article 30(1)(e) and (f) GDPR requires controllers to record “the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations” and, where applicable, to note "transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards.”
For international transfers, the ROPA must expressly identify:
- Which Chapter V mechanism is used for each transfer (adequacy, SCCs, BCRs, ad hoc clauses, or a specific Article 49 derogation),
- The name or details of the third country or international organisation,
- When relying on Article 49(1) second subparagraph (compelling legitimate interests), documentation of the assessment and suitable safeguards, as required by Article 30(1)(f).
Best practice, per EDPB Recommendations 01/2020, is to also document:
- The outcome of any Transfer Impact Assessment (TIA) conducted when using SCCs, BCRs, or ad hoc contractual clauses, and
- A reference or cross-link to any supplementary technical, organisational, or contractual measures implemented as a result (see Recommendations 01/2020, para. 78 and 95). While GDPR Article 30 does not explicitly require inclusion of TIA detail within the ROPA itself, the EDPB encourages keeping these records as part of the overall accountability framework, with auditability by the supervisory authority.
Failure to maintain up-to-date and complete ROPA entries for international transfers may be considered non-compliance with Article 30 and undermines a controller’s ability to demonstrate accountability under Article 5(2) GDPR if challenged by data protection authorities. The ROPA is routinely reviewed in enforcement investigations as baseline evidence of a controller or processor’s compliance efforts for cross-border data flows.
Practical tip: While the ROPA need not attach every contract, TIA, or technical measure, it should indicate the transfer mechanism for each processing activity and describe, or reference, where supporting records (like the TIA or safeguards documentation) are held for compliance review.
Source: Regulation (EU) 2016/679 (GDPR), Article 30 Source: EDPB Recommendations 01/2020 on supplementary measures, para. 78, 95
Controller–Processor Transfers to Third Countries — Article 28 Data Processing Agreements and Chapter V Interplay
Transfers to processors in third countries trigger compliance obligations under both Article 28 GDPR (data processing agreements) and Chapter V transfer mechanisms (Articles 44–49). When a controller in the European Economic Area (EEA) engages a processor located outside the EEA (a “third country” under GDPR, i.e., any country not covered by EU/EEA law or an adequacy decision), or when an EEA processor subcontracts to a non-EEA sub-processor, both the data processing agreement (DPA) rules and international transfer rules apply.
Article 28(3)–(4) GDPR requires a written DPA binding the processor to the controller with specific minimum clauses: confidentiality, data security, data-subject rights support, and deletion/return of data after processing ends. This DPA obligation applies regardless of whether the processor is inside or outside the EEA. However, if the processor is located in a third country, the exporter must also implement a valid Chapter V transfer mechanism (usually Standard Contractual Clauses [SCCs], see Decision (EU) 2021/914, Module Two for controller-to-processor transfers). The DPA and SCCs must be compatible; often, Module Two is incorporated directly into the DPA itself, ensuring single-step compliance.
Key interplay points:
- The 2021 SCCs (Module Two) directly incorporate the mandatory Article 28 obligations by reference—if used, this satisfies Article 28(3) requirements for third-country processors (see SCCs, Annex, and Recitals).
- If using ad hoc or custom contracts (Article 46(3)(a) GDPR), the DPA must independently satisfy all Article 28(3) conditions; this is closely scrutinized by supervisory authorities.
- Onward transfers (e.g., processing by sub-processors outside the EEA) require both the processor’s DPA and their own transfer mechanism to be in place—sub-processors may only be engaged with the controller’s prior consent, and the main processor must flow down all contractual and Chapter V safeguards.
- The EDPB (Guidelines 07/2020 and 05/2021) clarifies that controllers remain responsible for ensuring processors (and sub-processors) observe all Chapter V requirements, including supplementary measures post-Schrems II and ongoing TIA obligations.
- Where adequacy decisions only cover certain sectors or organizations (e.g., the US Data Privacy Framework, Canada PIPEDA), controllers must document that the third-country processor qualifies for adequacy coverage for each transfer.
Practical implications:
- Controllers must keep the DPA and transfer mechanism documentation in their ROPA (Article 30 GDPR), and reference or link to any TIA or supplementary safeguards.
- Non-compliance exposes the controller, not just the processor, to GDPR’s top-tier fines (up to €20 million or 4% of global turnover: Article 83(5)).
Summary: To lawfully transfer EEA personal data to a processor outside the EEA, a controller must ensure an Article 28-compliant DPA and a valid Chapter V transfer mechanism. The 2021 SCCs Module Two provide a unified basis when properly executed with completed annexes and Schrems II assessment. Neglecting this legal linkage remains one of the most common—and most costly—enforcement gaps in cross-border data flows.
Source: Regulation (EU) 2016/679 (GDPR), Articles 28, 44–46, 83(5) Source: Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses) Source: EDPB Guidelines 07/2020 on Article 28 Source: EDPB Guidelines 05/2021 on Chapter V transfers
Intra-EEA Data Flows — Are Transfers Between EEA Members Subject to Chapter V GDPR?
Transfers of personal data between controllers or processors located within the European Economic Area (EEA) are not subject to the international transfer restrictions in Chapter V of the GDPR. Article 44 GDPR (the foundational rule for Chapter V) applies only to transfers to a “third country or to an international organisation.” Recital 101 of the GDPR confirms that Chapter V mechanisms are needed only for “transfers of personal data to third countries or international organisations” and not for flows between EEA Member States, all of which are presumed to guarantee the GDPR standard of protection by virtue of direct applicability.
What is the “EEA” for transfer purposes? The EEA, for GDPR Chapter V, means all EU Member States plus Iceland, Liechtenstein, and Norway (see EEA Agreement, OJ L1, 1994). Separate adequacy decisions extend to some non-EU jurisdictions aligned by treaty (e.g., Switzerland, Guernsey, Jersey, Isle of Man), but these remain "third countries" under the GDPR and are only covered to the extent of the actual Commission adequacy decision (see Article 45 and the official EC adequacy page).
Edge cases and micro-jurisdictions:
- EU Overseas Countries and Territories (OCTs): Data flows from the EEA to EU OCTs (e.g., Aruba, French Polynesia, Greenland) are considered transfers to a third country unless EU law applies in full and directly. Many OCTs do not apply GDPR by default; assess each territory by its legal status and any adequacy decision.
- Diplomatic Missions/Embassies inside the EEA: Data transfers from an EEA entity to a foreign embassy located within the EEA are generally regarded as transfers to a third country for Chapter V because embassies are treated as extraterritorial for legal purposes (see EDPB Guidelines 05/2021, para. 10, and FAQs published by several DPAs).
EFTA Surveillance Authority and consistency mechanism: Supervisory authorities in the EEA/EFTA states (Iceland, Liechtenstein, Norway) participate as full members of the EDPB and apply GDPR rules for intra-EEA flows.
Restriction by Member State national law: Article 1(3) and Article 23 GDPR allow Member States to restrict processing operations in specific sectors (public interest, national security, law enforcement), but such restrictions do not convert an intra-EEA transfer into a third-country transfer for Chapter V purposes—they operate as direct limits on processing, not as transfer restrictions.
Summary: Routine data flows between EEA-based controllers/processors, including cross-border corporate, HR, and services transfers, require no Chapter V transfer mechanism; only compliance with general GDPR requirements and any national law sectoral constraints. Cross-border flows within the EEA are "internal" for GDPR. Transfers to embassies, EU overseas territories, and microstates may be treated as third-country transfers depending on legal status.
Source: Regulation (EU) 2016/679 (GDPR), Article 44, Recital 101 Source: EDPB Guidelines 05/2021 on Interplay between Article 3 and Chapter V Source: European Commission adequacy decisions page — for definition of third countries and micro-jurisdictions
Transfers from the EEA to the United Kingdom — EU Adequacy Decision, Sunset Clause, and Contingency Planning
Transfers of personal data from the European Economic Area (EEA) to the United Kingdom rely on the European Commission’s adequacy decisions under Article 45 GDPR, adopted following the end of the Brexit transition period (1 January 2021). These are Commission Implementing Decisions (EU) 2021/1772 (GDPR) and 2021/1773 (Law Enforcement Directive), both of 28 June 2021, finding the UK’s data-protection regime “essentially equivalent” to the EU’s and permitting personal data to flow freely to UK-based controllers and processors.
Scope and conditions: The EU adequacy decision for the UK covers all transfers from EEA-based controllers/processors to UK-established recipients, in both public and private sectors. However, it does not extend to UK overseas territories or Crown Dependencies (such as Jersey, Guernsey, Isle of Man, or Gibraltar), which remain subject to their own distinct adequacy assessments (see Recital 7, Decision (EU) 2021/1773). The decision also applies to law enforcement transfers under the parallel Law Enforcement Directive adequacy. Any substantial change to UK law—including the adoption of data-sharing arrangements with third countries or amendments that reduce the level of protection—triggers monitoring and review by the Commission (Arts. 4, 5, and 7).
Sunset clause and review mechanism:
- Article 10 of Decision (EU) 2021/1773 imposes a unique “sunset clause”: the adequacy finding expires four years after entry into force (i.e., 27 June 2025), unless renewed by the Commission. The Commission must monitor UK law and practices and can suspend, amend, or repeal the decision at any point if the adequacy standard is not maintained (Arts. 4–5, 7).
- As of 2026-06-16, the adequacy decision for the UK remains in force. Renewal or expiration beyond June 2025 is unable to confirm as of 2026-06-16; practitioners must verify the latest status directly from the Commission’s official register before relying on adequacy for ongoing or planned transfers.
What if the adequacy is withdrawn or expires?
- If the adequacy decision lapses or is repealed, EEA–UK transfers become subject to the Chapter V fallback mechanisms: Standard Contractual Clauses (SCCs, Decision (EU) 2021/914), Binding Corporate Rules, or one of the narrow derogations under Article 49 GDPR. Any organization transferring personal data to the UK must be ready to pivot quickly if adequacy is lost.
- The Commission and EDPB both recommend that exporters include a “switch” or fallback clause in relevant contracts with UK recipients, enabling a seamless move to SCCs or other safeguards should adequacy end.
Ongoing monitoring and practical tips:
- The UK continues to reform its data-protection regime (notably through legislative proposals like the Data Protection and Digital Information Bill), and the adequacy status is contingent on the UK maintaining a high level of protection.
- The Commission’s public register (see link below) provides the authoritative record of current adequacy decisions, review timetables, and notices about extension or suspension. Always consult the register before structuring significant EEA–UK data flows.
Official sources: Source: Commission Implementing Decision (EU) 2021/1773 (UK adequacy) Source: European Commission adequacy decisions register