Cross-Border Transfers

Nobody Defined What a Data Transfer Is, So the Regulators Did It Themselves

Key Takeaways

  • The GDPR contains no legal definition of "transfer"; the EDPB supplies three cumulative criteria, and remote access by the same controller does not meet them
  • Article 46 tools are standard contractual clauses, binding corporate rules, codes of conduct, certification mechanisms and ad hoc clauses; Article 49 derogations are exceptional by nature
  • The EDPB's transfer impact assessment is a six-step method, ending in re-evaluation at appropriate intervals rather than a one-off sign-off
  • The General Court dismissed the challenge to the EU-US Data Privacy Framework on 3 September 2025 in Latombe v Commission, Case T-553/23
  • The UK, Brazil, China and India each restrict transfers on entirely different logic — adequacy is not the universal model it can look like from Brussels

A Note on Sourcing

EUR-Lex, the official repository of EU legal texts, was unreachable from this publication's research environment while this guide was written. It was not down: the host returned HTTP 202 with the header x-amzn-waf-action: challenge, an automated bot challenge that a document fetch cannot answer.

Rather than cite provisions that could not be retrieved and read, everything below is sourced to documents that were: European Commission publications, European Data Protection Board guidelines and recommendations, a Court of Justice press release, and the national instruments of the other regimes discussed. Where a GDPR article is described, the description follows the EDPB's or the Commission's own account of it rather than a text this publication could not open. The article numbers are given so a reader with EUR-Lex access can check.

There Is No Statutory Definition of a Transfer

Chapter V of the GDPR restricts transfers of personal data to third countries. It does not say what one is. The EDPB's Guidelines 05/2021 open by conceding the point: "The GDPR does not provide for a legal definition of the notion 'transfer of personal data to a third country or to an international organisation'."

The Board therefore constructed one. Three criteria, all of which must be satisfied:

  • A controller or processor — the exporter — is subject to the GDPR for the given processing
  • The exporter discloses by transmission, or otherwise makes available, personal data subject to that processing to another controller, joint controller or processor — the importer
  • The importer is in a third country, irrespective of whether that importer is itself subject to the GDPR for the given processing under Article 3, or is an international organisation

The second criterion does the surprising work. It requires disclosure to a different controller or processor. On the EDPB's analysis, where the same controller or processor handles data outside the EU without disclosing it to anyone else — an employee of an EU controller travelling abroad and accessing that controller's data, or direct collection from individuals in the EU by a controller caught by Article 3(2) — the processing is not a transfer under Chapter V.

This is not a loophole, and the Board says so. Where the three criteria are not met and Chapter V does not apply, the controller still has to comply with every other provision of the GDPR and remains fully accountable for its processing wherever it takes place. The transfer rules are a specific overlay, not the whole of the extraterritorial analysis.

The Ladder: Adequacy, Then Safeguards, Then Derogations

The EDPB's Recommendations 01/2020, version 2.0 adopted on 18 June 2021, set out the order of resort. If an adequacy decision covers the destination and remains in force, no further step is needed beyond monitoring that it stays valid. Absent adequacy, the exporter relies on one of the transfer tools in Article 46. Only in some cases, and on strict conditions, may it fall back on an Article 49 derogation.

The Board lists the main Article 46 tools as standard data protection clauses, binding corporate rules, codes of conduct, certification mechanisms and ad hoc contractual clauses — adding that whichever is chosen, the exporter must ensure the transferred data benefits overall from an essentially equivalent level of protection. It also notes the structural limitation running through all of them: these instruments are "basically of contractual nature, so the guarantees foreseen and the commitments taken by the parties therein cannot bind third country public authorities." A contract between two companies cannot constrain a government that is not a party to it. That is the whole reason the supplementary-measures analysis exists.

On Article 49 the Board is deliberately restrictive: the derogations have "an exceptional nature" and must be interpreted so as not to contradict their character as exceptions to the rule that data may not go to a third country without adequacy or appropriate safeguards. Before relying on one, an exporter has to check that its transfer meets the strict conditions the provision sets for that specific derogation. The EDPB's Guidelines 2/2018 deal with them in detail.

Who Currently Holds EU Adequacy

Adequacy is decided by the Commission under Article 45(3), on a process it describes as a Commission proposal, an EDPB opinion, approval from member state representatives, and adoption. Its effect, in the Commission's words, is that personal data can flow from the EU and from Norway, Liechtenstein and Iceland to that third country without any further safeguard — transfers "will be assimilated to intra-EU transmissions of data".

The Commission's adequacy decisions page lists the jurisdictions recognised: Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for commercial organisations participating in the Data Privacy Framework, Uruguay, and the European Patent Organisation.

Three entries on that list carry qualifications a reader should not skip. Canada's covers commercial organisations only, which means data reaching a Canadian entity outside PIPEDA's commercial scope is outside the decision. The United States entry covers only participants in the Data Privacy Framework, not US recipients generally. And the United Kingdom is the sole listed jurisdiction whose adequacy also covers law enforcement exchanges under the Law Enforcement Directive — the Commission states expressly that, with that exception, the decisions do not cover data exchanges in the law enforcement sector governed by Article 36 of Directive (EU) 2016/680.

The list also moves. Technical extensions of the UK decisions were published on 24 June 2025 and renewal decisions on 19 December 2025, one under the GDPR and one under the LED. Brazil was added by a decision adopted on 26 January 2026. The Commission published its first periodic review of the Korean decision on 23 July 2026, its first review of the eleven decisions inherited from Directive 95/46/EC on 15 January 2024, and its first review of the Data Privacy Framework on 9 October 2024. Adequacy is a monitored status, not a permanent one.

Standard Contractual Clauses, and Their Imitators

The Commission issued modernised standard contractual clauses on 4 June 2021, for transfers from controllers or processors in the EU or EEA — or otherwise subject to the GDPR — to controllers or processors established outside the EEA and not subject to the GDPR. They replaced the three sets adopted under Directive 95/46. The Commission has published Q&As on their use, describing them as a dynamic source updated as new questions arise, and says it is developing further sets: one for transfers by EU institutions and bodies, and one for transfers to controllers or processors outside the EU whose processing is directly subject to the GDPR.

That second gap is worth pausing on, because it is the practical consequence of the EDPB's third criterion. An importer in a third country that is itself caught by Article 3(2) is still an importer, so Chapter V applies — but the 2021 clauses were not drafted for a recipient already bound by the GDPR, and the Commission has said the replacement is still in development.

The clauses have also been copied, adapted and paralleled. The Commission records that the United Kingdom and Switzerland have endorsed the EU SCCs with limited formal adaptations to their domestic legal order, and that other bodies have developed model clauses sharing common principles: the Council of Europe's Consultative Committee of Convention 108 under Convention 108+, the Ibero-American Data Protection Network with an accompanying implementation guide, ASEAN's Model Contractual Clauses for Cross Border Data Flows, and national clauses in New Zealand, Argentina and the United Kingdom. The Commission and ASEAN have jointly published a guide mapping the commonalities between the two sets, dated 24 May 2023.

The Transfer Impact Assessment Is a Method, Not a Form

Recommendations 01/2020 sets out a six-step roadmap for deciding whether an Article 46 tool needs supplementing:

StepWhat it asks
1Know your transfers
2Identify the transfer tools you are relying on
3Assess whether that Article 46 tool is effective in light of all circumstances of the transfer
4Adopt supplementary measures
5Take the procedural steps that follow if you have identified effective supplementary measures
6Re-evaluate at appropriate intervals

Step 3 is where the analysis bites, and the EDPB is specific about its scope. The assessment focuses first on third-country legislation relevant to the particular transfer and the particular tool, and the Board stresses that examining actual practices matters too. It contrasts this with the Commission's work under Article 45: an exporter's assessment is "limited to the legislation and practices relevant to the protection of the specific data you transfer, in contrast with the general and wide encompassing adequacy assessments the European Commission carries out".

The Board lists the circumstances that shape the applicable legal context: the purposes for which data are transferred and processed, giving marketing, HR, storage, IT support and clinical trials as examples; the types of entities involved, public or private, controller or processor; and the sector in which the transfer occurs. Two companies sending the same categories of data to the same country can therefore reach different conclusions.

Step 6 is the one most often dropped. The assessment is not a document produced once at contract signature; the Board frames it as requiring re-evaluation at appropriate intervals, which follows from the accountability principle rather than from any fixed review period.

The Data Privacy Framework Survived Its First Court Challenge

The transatlantic route has been annulled twice. The Court of Justice struck down Safe Harbour in Schrems I, Case C-362/14, on 6 October 2015, and Privacy Shield in Schrems II, Case C-311/18, on 16 July 2020, in each case because the decision did not ensure protection essentially equivalent to that guaranteed by EU law.

The third attempt is Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the EU-US Data Privacy Framework. The Commission records that it followed Executive Order 14086 on Enhancing Safeguards for United States Signals Intelligence Activities, signed on 7 October 2022, and a regulation issued by the US Attorney General at 28 CFR Part 201, which together introduced binding safeguards addressing the points raised in Schrems II — limiting intelligence access to what is necessary and proportionate, and creating an independent redress mechanism.

One consequence is easy to miss and matters to companies not in the Framework at all. On the Commission's account, the national security safeguards including the redress mechanism apply to all data transfers under the GDPR to companies in the US, regardless of the transfer mechanism used — so they also support reliance on standard contractual clauses and binding corporate rules for US transfers.

The challenge came from Philippe Latombe, a French citizen and user of platforms transferring his data to the US, who argued that the Data Protection Review Court was neither impartial nor independent but dependent on the executive, and that bulk collection of data in transit from the EU without prior judicial authorisation was not circumscribed with sufficient clarity and precision. On 3 September 2025 the General Court dismissed the action in Case T-553/23, Latombe v Commission.

On the DPRC, the Court noted safeguards around appointment and functioning, that judges may be dismissed only by the Attorney General and only for cause, and that the Attorney General and intelligence agencies may not hinder or improperly influence their work. It also relied on the Commission's continuing monitoring obligation and its power to suspend, amend or repeal the decision if US law changes. On bulk collection, the Court held that nothing in Schrems II requires prior authorisation by an independent authority; what that judgment requires is that the authorising decision be subject, at minimum, to ex post judicial review, which US signals intelligence activities receive from the DPRC.

The Court's own note records that an appeal limited to points of law may be brought before the Court of Justice within two months and ten days of notification. The judgment also confirms adequacy "on the date of adoption of the contested decision" — a formulation that decides the case in front of it and not the durability of the framework.

The Same Vocabulary, Different Machinery, Elsewhere

"International data transfer mechanisms" reads like one concept. It is not. Four regimes covered elsewhere on this site restrict cross-border flows on logic that shares the European vocabulary while asking different questions.

RegimeWhat the rule turns on
EU / EEAWhether the destination is adequate; failing that, whether an Article 46 tool plus supplementary measures achieves essential equivalence
United KingdomWhether protection after transfer is "not materially lower" than under UK law — a test the Data (Use and Access) Act 2025 wrote into the legislation, carried by the ICO's IDTA or its Addendum to the EU SCCs
BrazilOne of nine Article 33 grounds, with the contractual routes only usable since ANPD Resolution 19/2024 supplied the standard clauses Article 35 reserved to the authority
ChinaHow many individuals' data is leaving, whether any of it is sensitive, and whether the exporter is a critical information infrastructure operator — thresholds set in CAC Order No. 16
IndiaNothing, unless the Central Government notifies a restriction on the destination under section 16 of the DPDP Act — a negative list rather than a positive finding

Two of those invert the European default outright. India's section 16 permits transfer everywhere until a country is named, so the burden is on the state to restrict rather than on the exporter to justify. China's Order No. 16 makes the destination almost irrelevant and the headcount decisive: below 100,000 individuals' non-sensitive personal information in a calendar year, a non-CIIO processor needs no mechanism at all; above a million, it needs a state security assessment regardless of where the data is going.

The UK case is the subtler one, because it looks like continuity and is not. The ICO's position is that the EU standard contractual clauses "are not valid on their own for restricted transfers under the UK GDPR" — the UK Addendum is what lets an exporter rely on them. A multinational running one set of European paperwork is running two.

What none of these regimes has is a mutual-recognition mechanism that removes the analysis. Even the EU-Brazil mutual adequacy of January 2026 was two unilateral instruments adopted in coordination, each reassessable after four years on its own timetable. A company transferring data among several of these jurisdictions is running parallel assessments under parallel rules, and the answers do not transfer between them any more readily than the data does.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

What counts as a transfer under Chapter V of the GDPR?
The GDPR does not define it. The EDPB's Guidelines 05/2021 apply three cumulative criteria: the exporter is subject to the GDPR for the processing; the exporter discloses or makes the data available to another controller, joint controller or processor; and that importer is in a third country or is an international organisation. All three must be met.
Is remote access from outside the EU a transfer?
Not where the same controller or processor is handling the data without disclosing it to a different one. The EDPB gives the example of an employee of an EU controller travelling abroad and accessing that controller's data, and states that this should not be regarded as a transfer under Chapter V. The controller still has to comply with the rest of the GDPR and remains accountable for the processing wherever it happens.
What are the Article 46 transfer tools?
The EDPB lists the main ones as standard data protection clauses, binding corporate rules, codes of conduct, certification mechanisms and ad hoc contractual clauses. Whichever is used, the exporter must ensure the data benefits overall from an essentially equivalent level of protection, which is what the supplementary-measures analysis addresses.
How often does a transfer impact assessment need redoing?
The EDPB's six-step roadmap ends with re-evaluating at appropriate intervals, without fixing a period. The interval follows from the accountability principle and from whether anything relevant to the assessment has changed — the law or practice in the destination country, the tool relied on, or the circumstances of the transfer itself.
Is the EU-US Data Privacy Framework still valid?
The General Court dismissed the action for annulment in Latombe v Commission, Case T-553/23, on 3 September 2025, confirming that on the date the decision was adopted the United States ensured an adequate level of protection. The Court's note records that an appeal on points of law may be brought before the Court of Justice within two months and ten days of notification, and the Commission retains power to suspend, amend or repeal the decision.
Do EU standard contractual clauses work for transfers out of the UK or Brazil?
Not on their own. The ICO states the EU SCCs are not valid alone for UK restricted transfers, and that its International Data Transfer Addendum is what allows reliance on them, alongside a transfer risk assessment. Brazil's Article 33 route requires the standard contractual clauses the ANPD approved in Resolution 19/2024, which processing agents using contractual clauses were to incorporate within twelve months of its publication.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.