WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

General Data Protection Regulation — transfers of personal data to third countries

GDPR Chapter V

European Union · May 25, 2018

Chapter V's governing principle (Art. 44) is that the level of protection the GDPR guarantees must not be undermined by moving data out of the EEA. Transfers are lawful where the destination has a European Commission adequacy decision (Art. 45); failing that, on an appropriate safeguard (Art. 46) — most commonly the 2021 Standard Contractual Clauses, or binding corporate rules under Art. 47; failing that, on one of the narrow Art. 49 derogations, which the EDPB reads as exceptional and unsuitable for repeated or systematic transfers. The Art. 46 route is not a paperwork exercise: after Schrems II (C-311/18), the exporter must also assess whether the destination's law and practice actually deliver essentially equivalent protection, and add supplementary measures where they do not — the transfer impact assessment. Onward transfers by your processor count, and so does remote ACCESS from a third country, which is where most businesses under-scope the analysis.

Regulation (EU) 2016/679, Arts. 44-49Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.