Nobody Defined What a Data Transfer Is, So the Regulators Did It Themselves
Key Takeaways
- The GDPR contains no legal definition of "transfer"; the EDPB supplies three cumulative criteria, and remote access by the same controller does not meet them
- Article 46 tools are standard contractual clauses, binding corporate rules, codes of conduct, certification mechanisms and ad hoc clauses; Article 49 derogations are exceptional by nature
- The EDPB's transfer impact assessment is a six-step method, ending in re-evaluation at appropriate intervals rather than a one-off sign-off
- The General Court dismissed the challenge to the EU-US Data Privacy Framework on 3 September 2025 in Latombe v Commission, Case T-553/23
- The UK, Brazil, China and India each restrict transfers on entirely different logic — adequacy is not the universal model it can look like from Brussels
A Note on Sourcing
EUR-Lex, the official repository of EU legal texts, was unreachable from this publication's research environment while this guide was written. It was not down: the host returned HTTP 202 with the header x-amzn-waf-action: challenge, an automated bot challenge that a document fetch cannot answer.
Rather than cite provisions that could not be retrieved and read, everything below is sourced to documents that were: European Commission publications, European Data Protection Board guidelines and recommendations, a Court of Justice press release, and the national instruments of the other regimes discussed. Where a GDPR article is described, the description follows the EDPB's or the Commission's own account of it rather than a text this publication could not open. The article numbers are given so a reader with EUR-Lex access can check.
There Is No Statutory Definition of a Transfer
Chapter V of the GDPR restricts transfers of personal data to third countries. It does not say what one is. The EDPB's Guidelines 05/2021 open by conceding the point: "The GDPR does not provide for a legal definition of the notion 'transfer of personal data to a third country or to an international organisation'."
The Board therefore constructed one. Three criteria, all of which must be satisfied:
- A controller or processor — the exporter — is subject to the GDPR for the given processing
- The exporter discloses by transmission, or otherwise makes available, personal data subject to that processing to another controller, joint controller or processor — the importer
- The importer is in a third country, irrespective of whether that importer is itself subject to the GDPR for the given processing under Article 3, or is an international organisation
The second criterion does the surprising work. It requires disclosure to a different controller or processor. On the EDPB's analysis, where the same controller or processor handles data outside the EU without disclosing it to anyone else — an employee of an EU controller travelling abroad and accessing that controller's data, or direct collection from individuals in the EU by a controller caught by Article 3(2) — the processing is not a transfer under Chapter V.
This is not a loophole, and the Board says so. Where the three criteria are not met and Chapter V does not apply, the controller still has to comply with every other provision of the GDPR and remains fully accountable for its processing wherever it takes place. The transfer rules are a specific overlay, not the whole of the extraterritorial analysis.
The Ladder: Adequacy, Then Safeguards, Then Derogations
The EDPB's Recommendations 01/2020, version 2.0 adopted on 18 June 2021, set out the order of resort. If an adequacy decision covers the destination and remains in force, no further step is needed beyond monitoring that it stays valid. Absent adequacy, the exporter relies on one of the transfer tools in Article 46. Only in some cases, and on strict conditions, may it fall back on an Article 49 derogation.
The Board lists the main Article 46 tools as standard data protection clauses, binding corporate rules, codes of conduct, certification mechanisms and ad hoc contractual clauses — adding that whichever is chosen, the exporter must ensure the transferred data benefits overall from an essentially equivalent level of protection. It also notes the structural limitation running through all of them: these instruments are "basically of contractual nature, so the guarantees foreseen and the commitments taken by the parties therein cannot bind third country public authorities." A contract between two companies cannot constrain a government that is not a party to it. That is the whole reason the supplementary-measures analysis exists.
On Article 49 the Board is deliberately restrictive: the derogations have "an exceptional nature" and must be interpreted so as not to contradict their character as exceptions to the rule that data may not go to a third country without adequacy or appropriate safeguards. Before relying on one, an exporter has to check that its transfer meets the strict conditions the provision sets for that specific derogation. The EDPB's Guidelines 2/2018 deal with them in detail.
Who Currently Holds EU Adequacy
Adequacy is decided by the Commission under Article 45(3), on a process it describes as a Commission proposal, an EDPB opinion, approval from member state representatives, and adoption. Its effect, in the Commission's words, is that personal data can flow from the EU and from Norway, Liechtenstein and Iceland to that third country without any further safeguard — transfers "will be assimilated to intra-EU transmissions of data".
The Commission's adequacy decisions page lists the jurisdictions recognised: Andorra, Argentina, Brazil, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States for commercial organisations participating in the Data Privacy Framework, Uruguay, and the European Patent Organisation.
Three entries on that list carry qualifications a reader should not skip. Canada's covers commercial organisations only, which means data reaching a Canadian entity outside PIPEDA's commercial scope is outside the decision. The United States entry covers only participants in the Data Privacy Framework, not US recipients generally. And the United Kingdom is the sole listed jurisdiction whose adequacy also covers law enforcement exchanges under the Law Enforcement Directive — the Commission states expressly that, with that exception, the decisions do not cover data exchanges in the law enforcement sector governed by Article 36 of Directive (EU) 2016/680.
The list also moves. Technical extensions of the UK decisions were published on 24 June 2025 and renewal decisions on 19 December 2025, one under the GDPR and one under the LED. Brazil was added by a decision adopted on 26 January 2026. The Commission published its first periodic review of the Korean decision on 23 July 2026, its first review of the eleven decisions inherited from Directive 95/46/EC on 15 January 2024, and its first review of the Data Privacy Framework on 9 October 2024. Adequacy is a monitored status, not a permanent one.
Standard Contractual Clauses, and Their Imitators
The Commission issued modernised standard contractual clauses on 4 June 2021, for transfers from controllers or processors in the EU or EEA — or otherwise subject to the GDPR — to controllers or processors established outside the EEA and not subject to the GDPR. They replaced the three sets adopted under Directive 95/46. The Commission has published Q&As on their use, describing them as a dynamic source updated as new questions arise, and says it is developing further sets: one for transfers by EU institutions and bodies, and one for transfers to controllers or processors outside the EU whose processing is directly subject to the GDPR.
That second gap is worth pausing on, because it is the practical consequence of the EDPB's third criterion. An importer in a third country that is itself caught by Article 3(2) is still an importer, so Chapter V applies — but the 2021 clauses were not drafted for a recipient already bound by the GDPR, and the Commission has said the replacement is still in development.
The clauses have also been copied, adapted and paralleled. The Commission records that the United Kingdom and Switzerland have endorsed the EU SCCs with limited formal adaptations to their domestic legal order, and that other bodies have developed model clauses sharing common principles: the Council of Europe's Consultative Committee of Convention 108 under Convention 108+, the Ibero-American Data Protection Network with an accompanying implementation guide, ASEAN's Model Contractual Clauses for Cross Border Data Flows, and national clauses in New Zealand, Argentina and the United Kingdom. The Commission and ASEAN have jointly published a guide mapping the commonalities between the two sets, dated 24 May 2023.
The Transfer Impact Assessment Is a Method, Not a Form
Recommendations 01/2020 sets out a six-step roadmap for deciding whether an Article 46 tool needs supplementing:
| Step | What it asks |
|---|---|
| 1 | Know your transfers |
| 2 | Identify the transfer tools you are relying on |
| 3 | Assess whether that Article 46 tool is effective in light of all circumstances of the transfer |
| 4 | Adopt supplementary measures |
| 5 | Take the procedural steps that follow if you have identified effective supplementary measures |
| 6 | Re-evaluate at appropriate intervals |
Step 3 is where the analysis bites, and the EDPB is specific about its scope. The assessment focuses first on third-country legislation relevant to the particular transfer and the particular tool, and the Board stresses that examining actual practices matters too. It contrasts this with the Commission's work under Article 45: an exporter's assessment is "limited to the legislation and practices relevant to the protection of the specific data you transfer, in contrast with the general and wide encompassing adequacy assessments the European Commission carries out".
The Board lists the circumstances that shape the applicable legal context: the purposes for which data are transferred and processed, giving marketing, HR, storage, IT support and clinical trials as examples; the types of entities involved, public or private, controller or processor; and the sector in which the transfer occurs. Two companies sending the same categories of data to the same country can therefore reach different conclusions.
Step 6 is the one most often dropped. The assessment is not a document produced once at contract signature; the Board frames it as requiring re-evaluation at appropriate intervals, which follows from the accountability principle rather than from any fixed review period.
The Data Privacy Framework Survived Its First Court Challenge
The transatlantic route has been annulled twice. The Court of Justice struck down Safe Harbour in Schrems I, Case C-362/14, on 6 October 2015, and Privacy Shield in Schrems II, Case C-311/18, on 16 July 2020, in each case because the decision did not ensure protection essentially equivalent to that guaranteed by EU law.
The third attempt is Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the EU-US Data Privacy Framework. The Commission records that it followed Executive Order 14086 on Enhancing Safeguards for United States Signals Intelligence Activities, signed on 7 October 2022, and a regulation issued by the US Attorney General at 28 CFR Part 201, which together introduced binding safeguards addressing the points raised in Schrems II — limiting intelligence access to what is necessary and proportionate, and creating an independent redress mechanism.
One consequence is easy to miss and matters to companies not in the Framework at all. On the Commission's account, the national security safeguards including the redress mechanism apply to all data transfers under the GDPR to companies in the US, regardless of the transfer mechanism used — so they also support reliance on standard contractual clauses and binding corporate rules for US transfers.
The challenge came from Philippe Latombe, a French citizen and user of platforms transferring his data to the US, who argued that the Data Protection Review Court was neither impartial nor independent but dependent on the executive, and that bulk collection of data in transit from the EU without prior judicial authorisation was not circumscribed with sufficient clarity and precision. On 3 September 2025 the General Court dismissed the action in Case T-553/23, Latombe v Commission.
On the DPRC, the Court noted safeguards around appointment and functioning, that judges may be dismissed only by the Attorney General and only for cause, and that the Attorney General and intelligence agencies may not hinder or improperly influence their work. It also relied on the Commission's continuing monitoring obligation and its power to suspend, amend or repeal the decision if US law changes. On bulk collection, the Court held that nothing in Schrems II requires prior authorisation by an independent authority; what that judgment requires is that the authorising decision be subject, at minimum, to ex post judicial review, which US signals intelligence activities receive from the DPRC.
The Court's own note records that an appeal limited to points of law may be brought before the Court of Justice within two months and ten days of notification. The judgment also confirms adequacy "on the date of adoption of the contested decision" — a formulation that decides the case in front of it and not the durability of the framework.
The Same Vocabulary, Different Machinery, Elsewhere
"International data transfer mechanisms" reads like one concept. It is not. Four regimes covered elsewhere on this site restrict cross-border flows on logic that shares the European vocabulary while asking different questions.
| Regime | What the rule turns on |
|---|---|
| EU / EEA | Whether the destination is adequate; failing that, whether an Article 46 tool plus supplementary measures achieves essential equivalence |
| United Kingdom | Whether protection after transfer is "not materially lower" than under UK law — a test the Data (Use and Access) Act 2025 wrote into the legislation, carried by the ICO's IDTA or its Addendum to the EU SCCs |
| Brazil | One of nine Article 33 grounds, with the contractual routes only usable since ANPD Resolution 19/2024 supplied the standard clauses Article 35 reserved to the authority |
| China | How many individuals' data is leaving, whether any of it is sensitive, and whether the exporter is a critical information infrastructure operator — thresholds set in CAC Order No. 16 |
| India | Nothing, unless the Central Government notifies a restriction on the destination under section 16 of the DPDP Act — a negative list rather than a positive finding |
Two of those invert the European default outright. India's section 16 permits transfer everywhere until a country is named, so the burden is on the state to restrict rather than on the exporter to justify. China's Order No. 16 makes the destination almost irrelevant and the headcount decisive: below 100,000 individuals' non-sensitive personal information in a calendar year, a non-CIIO processor needs no mechanism at all; above a million, it needs a state security assessment regardless of where the data is going.
The UK case is the subtler one, because it looks like continuity and is not. The ICO's position is that the EU standard contractual clauses "are not valid on their own for restricted transfers under the UK GDPR" — the UK Addendum is what lets an exporter rely on them. A multinational running one set of European paperwork is running two.
What none of these regimes has is a mutual-recognition mechanism that removes the analysis. Even the EU-Brazil mutual adequacy of January 2026 was two unilateral instruments adopted in coordination, each reassessable after four years on its own timetable. A company transferring data among several of these jurisdictions is running parallel assessments under parallel rules, and the answers do not transfer between them any more readily than the data does.
Background
For the underlying law rather than this development: Technology & SaaS privacy law.
Frequently Asked Questions
What counts as a transfer under Chapter V of the GDPR?
Is remote access from outside the EU a transfer?
What are the Article 46 transfer tools?
How often does a transfer impact assessment need redoing?
Is the EU-US Data Privacy Framework still valid?
Do EU standard contractual clauses work for transfers out of the UK or Brazil?
Sources
Everything above is reported from these documents. Follow them to verify.
- EDPB Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR, version 2.0 (February 14, 2023) agency guidance
- EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, version 2.0 (June 18, 2021) agency guidance
- European Commission, Adequacy decisions (August 24, 2026) agency release
- European Commission, Standard Contractual Clauses (SCC) (August 24, 2026) agency release
- European Commission, EU-US data transfers (August 24, 2026) agency release
- Court of Justice of the European Union, Press Release No 106/25 — Judgment in Case T-553/23, Latombe v Commission (September 3, 2025) court opinion
- ICO, What are standard data protection clauses (the UK IDTA and the Addendum)? (August 24, 2026) agency guidance
- 促进和规范数据跨境流动规定 (Provisions on Promoting and Regulating Cross-Border Data Flows), CAC Order No. 16 (March 22, 2024) regulation
- The Digital Personal Data Protection Act, 2023, section 16 (India Code consolidated text) (November 19, 2025) statute
- Resolução CD/ANPD nº 19, de 23 de agosto de 2024 — Regulamento de Transferência Internacional de Dados (August 23, 2024) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.