Moving personal data across borders remains legally fragile, and each transfer mechanism has eventually faced challenge. This hub covers the Data Privacy Framework, contractual clauses, and the localization mandates spreading outside Europe.
Cross-Border Transfers
September 21, 2026
Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.
Read more →
Cross-Border Transfers
September 1, 2026
The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.
Read more →
Cross-Border Transfers
August 24, 2026
Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.
Read more →
GDPR
August 12, 2026
The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.
Read more →