> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# When Can Personal Data Leave the EU? A Practical Guide to GDPR International Transfers
- URL: https://www.thedelatorrereview.com/whencanpersonaldataleavetheeu/
- Published: 2026-08-01T00:55:00.000Z
- Updated: 2026-08-16T03:29:44.000Z
- Description: A practical guide to GDPR international data transfers, explaining when personal data may leave the EEA and how adequacy decisions, appropriate safeguards, SCCs, BCRs, Transfer Impact Assessments, and Article 49 derogations enable lawful cross-border transfers.
- Author: Lydia
- Tags: International Data Transfers, Adequacy Decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), GDPR, EU, Data Protection Law, Anonymization, Pseudonymization, Codes of Conduct, Certifications, Consent, Legitimate Interests, Vital Interest, Public Interest, Contractual Necessity, International Association of Privacy Professionals (IAPP)

> **Key Points:** (1) **The GDPR does not prohibit international transfers**, but Chapter V requires organizations to ensure that EU-level protections are not undermined when personal data leaves the EEA.(2) **Article 44 establishes the general rule:** transfers and onward transfers must comply with Chapter V. (3) Organizations should first determine whether the activity actually constitutes an **international transfer** to a separate controller or processor in a third country. (4) There are **three principal routes for lawful transfers:** an **adequacy decision**, **appropriate safeguards**, or—only in specific situations—an **Article 49 derogation**.(5) **Adequacy decisions (Article 45)** allow transfers without additional Chapter V safeguards where the European Commission has determined that the destination provides protection that is essentially equivalent to EU standards. (6) Where adequacy is unavailable, organizations may rely on **appropriate safeguards (Articles 46–47)**, including **SCCs and BCRs**, provided enforceable rights and effective remedies are available. (7) Following ***Schrems II***, organizations relying on SCCs must assess whether the protections will work **in practice**, including through a **Transfer Impact Assessment (TIA)** and supplementary measures where necessary.(8) **Article 49 derogations are exceptions**, generally intended for specific situations rather than routine or systematic international transfers.(9) **Article 48 limits the effect of foreign-government disclosure demands:** a third-country order cannot simply bypass the GDPR's international-transfer framework. (10) A valid Chapter V mechanism is **only one part of GDPR compliance**. The underlying processing must still satisfy the GDPR's other requirements.

---

The GDPR does not prohibit personal data from leaving Europe. Instead, Chapter V of the GDPR establishes a framework designed to ensure that personal data remains protected when it is transferred to third countries or international organizations.

[Article 44 ](https://gdpr-info.eu/art-44-gdpr/?ref=thedelatorrereview.com)sets out the starting point. A controller or processor may transfer personal data to a third country or international organization only if the requirements of Chapter V (Articles 44–50 GDPR) are satisfied. The rule also applies to onward transfers—for example, where data is first transferred from the EU to a recipient in one third country and is subsequently transferred to another third country.

---

> The underlying principle is straightforward: transferring personal data outside the EU should not undermine the level of protection guaranteed by the GDPR.

---

The GDPR’s international transfer rules can be approached as a step-by-step decision process. Before sending personal data outside the EEA, organizations should determine whether a transfer is actually taking place and necessary, and then identify the appropriate Chapter V mechanism. The following decision tree summarizes the key questions to ask—from adequacy and appropriate safeguards to the limited derogations available under [Article 49](https://gdpr-info.eu/art-49-gdpr/?ref=thedelatorrereview.com).

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-07_11_42-PM.png)

**If information has been truly anonymized so that individuals are no longer identifiable, it is no longer personal data for purposes of the GDPR and the international-transfer restrictions do not apply.** Pseudonymized data, however, generally remains personal data and continues to be subject to the GDPR.

Article 48 addresses situations where a **court, law-enforcement agency, intelligence authority, or other public authority outside the EU demands disclosure of personal data**. A third-country judgment or administrative decision requiring disclosure generally may be recognized or enforced only when based on an **international agreement**, such as a mutual legal assistance treaty (MLAT), between that country and the EU or a Member State. Although Article 48 is often discussed in connection with U.S. surveillance laws such as FISA, it applies broadly to foreign-government demands. It also preserves other possible transfer grounds under Chapter V. The key principle is that a foreign authority cannot bypass the GDPR’s international-transfer protections simply by issuing a domestic order requiring disclosure.

## What Counts as an International Data Transfer?

The GDPR does not expressly define the term “transfer.” You may also see these arrangements described as **international transfers**, **cross-border transfers**, or—particularly in UK guidance—**restricted transfers**.

For purposes of Chapter V, the key question is not simply whether data physically crosses a border. Rather, **the analysis focuses on whether personal data is made available by one controller or processor to another controller or processor in a third country or to an international organization.**

As reflected in the European Data Protection Board’s guidance, three elements are particularly important:

1. **The exporter is subject to the GDPR for the processing in question.** The controller or processor making the data available must itself be subject to the GDPR for that processing.
2. **The exporter discloses or otherwise makes personal data available to another controller or processor.** There must be a transfer from one entity—the *data exporter*—to another entity—the *data importer*.
3. **The importer is located in a third country or is an international organization.** This is the case even where the importer may itself be subject to the GDPR under Article 3.

That last point is important. **A recipient's own extraterritorial obligations under the GDPR do not necessarily eliminate the need to consider Chapter V.** A transfer can therefore fall within Chapter V even when the overseas recipient is independently subject to the GDPR.

### The Recipient Must Be a Separate Entity outside of the EEA

A transfer generally requires disclosure to a **different controller or processor**. This can include another company within the same corporate group.

For example, transferring employee information from a German subsidiary to its U.S. parent company can constitute an international transfer. The fact that the two companies belong to the same corporate group does not make them the same controller or processor for Chapter V purposes.

By contrast, an employee who travels outside the EU and remotely accesses data belonging to their EU employer generally does not create a Chapter V transfer merely because the employee happens to be abroad. The employee is acting as part of the same controller rather than as a separate controller or processor.

The EEA consists of the EU countries \[see EU member states [here](https://european-union.europa.eu/principles-countries-history/eu-countries%5Fen?ref=thedelatorrereview.com)\] plus EEA countries \[Iceland, Liechtenstein, and Norway.\] Only transfers outside this area are subject to restrictions. Switzerland, the UK, and other non-EU/EEA countries are considered *third countries*. Some of them have been recognised by the European Commission as providing **adequate protection** (see below).

### Transfer Is Not the Same as Transit

A useful distinction is between **transferring data to a third country** and data merely **passing through a third country in transit**.

Suppose personal data is sent from France to Ireland but, because of the technical architecture of the network, the data is routed through a server located in Australia. If no organization in Australia receives or is given access to the personal data, the mere routing of the information through Australia does not, by itself, turn the transaction into a Chapter V transfer.

The relevant question is therefore not simply “Did the data cross the border?” but rather “Was the personal data made available to a separate controller or processor in a third country?”

### Transfers Are Not Limited to Electronic Data

International transfer rules are not confined to cloud services, databases, or other electronic systems.

For example, an EU organization could send **paper records containing personal data** to a company outside the EU so that the records can be digitized and entered into a database. Making those records available to the overseas service provider can constitute an international transfer even though the information was sent in physical rather than electronic form.

The technology used to move the information is therefore less important than the fact that personal data is being made available to a separate recipient in a third country.

### What About Publishing Personal Data on a Website?

Making personal data available on the internet requires a more nuanced analysis. The Court of Justice addressed this issue in **Lindqvist (Case C-101/01)**. The mere act of uploading information to a website that can be accessed from outside Europe does not automatically mean that the publisher has transferred that information to every third country from which the website can theoretically be viewed.

The Chapter V analysis instead depends on the particular disclosure or availability of the data and whether it amounts to a transfer to an identifiable recipient in a third country.

This distinction has become increasingly important as modern processing involves websites, cloud infrastructure, remote access, software-as-a-service providers, and globally distributed corporate systems.

### Examples of International Transfers

**EU company → U.S. HR provider.** A German company sends employee information to a U.S.-based HR service operated by its parent company. The U.S. parent is a separate entity receiving the personal data. **This is an international transfer.**

**EU travel company → Australian hotel.** A Belgian travel company sends customers' names and booking information to hotels in Australia so that reservations can be fulfilled. **This is an international transfer.**

**France → Ireland, routed through Australia.** Personal data is transmitted between organizations in France and Ireland but technically passes through infrastructure in Australia without being made available to an Australian recipient. **The routing alone does not constitute a transfer to Australia.**

**Paper records → overseas digitization provider.** A French insurance broker sends handwritten records containing personal data to a service provider outside the EU for digitization. **This is an international transfer.**

**EU company → non-EU group company.** An EU company makes customer information available to a separately incorporated affiliate outside the EU. **This can be an international transfer even though both companies belong to the same corporate group.**

## What Rules Apply to International Data Transfers?

There are three principal routes for transferring personal data to a third country or international organization:

1. **Adequacy Decision —** [Article 45](https://gdpr-info.eu/art-45-gdpr/?ref=thedelatorrereview.com). The European Commission has determined that the destination provides an adequate level of protection.
2. **Appropriate Safeguards —** [Article 46](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com) and [Article 47](https://gdpr-info.eu/art-47-gdpr/?ref=thedelatorrereview.com). In the absence of an adequacy decision, the transfer is protected through an approved safeguard, such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).
3. **Derogations —** [Article 49.](https://gdpr-info.eu/art-49-gdpr/?ref=thedelatorrereview.com) In certain limited circumstances, a transfer may proceed under a specific derogation, such as explicit consent or when the transfer is necessary for the performance of certain contracts.

Having a valid transfer mechanism does **not** make the underlying processing automatically GDPR-compliant. Controllers and processors must continue to satisfy the GDPR's other requirements.

Depending on the relationship and transfer, this may include:

- entering into a compliant controller-to-processor or processor-to-processor agreement under[ Article 28](https://gdpr-info.eu/art-28-gdpr/?ref=thedelatorrereview.com);
- establishing an [Article 26](https://gdpr-info.eu/art-26-gdpr/?ref=thedelatorrereview.com) arrangement where two organizations qualify as joint controllers; and
- where appropriate safeguards such as SCCs are used, assessing whether the laws and practices of the destination country could undermine those safeguards and whether supplementary measures are necessary. This assessment is commonly referred to as a Transfer Impact Assessment (TIA).

In practice, the international-transfer analysis therefore involves two related questions: Is there a valid Chapter V mechanism permitting the transfer, and does the transfer and underlying processing comply with the GDPR more broadly?

### First Transfer Mechanism: Adequacy Decisions (Article 45 GDPR)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-08_15_41-PM.png)

The simplest route for transferring personal data outside the EEA is an adequacy decision under [Article 45 GDPR](https://gdpr-info.eu/art-45-gdpr/?ref=thedelatorrereview.com).

An adequacy decision is a formal determination by the European Commission that a third country, a territory or specified sector within a country, or an international organization provides an adequate level of protection for personal data.

Adequacy does not require the destination's privacy laws to be identical to the GDPR. The relevant standard, developed through the case law of the Court of Justice of the European Union (CJEU), is whether the destination provides protection that is **“essentially equivalent”** to that guaranteed within the EU.

As of August 2026, the European Commission recognizes the following countries, territories, sectors, and organizations as providing adequate protection:

- [Andorra](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32010D0625&ref=thedelatorrereview.com),
- [Argentina](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32003D0490&ref=thedelatorrereview.com),
- [Brazil](https://commission.europa.eu/document/download/5e457271-4292-4b47-bb10-b6b6cb6700e1%5Fen?filename=JUST%5Ftemplate%5Fcomingsoon%5Fstandard%5F2.pdf&ref=thedelatorrereview.com),
- [Canada](https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A32002D0002&ref=thedelatorrereview.com) (commercial organisations),
- [Faroe Islands](https://eur-lex.europa.eu/legal-content/en/ALL/?uri=CELEX%3A32010D0146&ref=thedelatorrereview.com),
- [Guernsey](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32003D0821&ref=thedelatorrereview.com),
- [Israel](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32011D0061&ref=thedelatorrereview.com),
- [Isle of Man](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32004D0411&ref=thedelatorrereview.com),
- [Japan](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L%5F.2019.076.01.0001.01.ENG&toc=OJ:L:2019:076:TOC&ref=thedelatorrereview.com),
- [Jersey](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32008D0393&ref=thedelatorrereview.com),
- [New Zealand](https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32013D0065&ref=thedelatorrereview.com),
- [Republic of Korea](https://commission.europa.eu/document/download/e9453177-f192-4416-a147-3c57adc468c4%5Fen?ref=thedelatorrereview.com),
- [Switzerland](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32000D0518&ref=thedelatorrereview.com),
- the United Kingdom under the [GDPR](https://commission.europa.eu/document/download/dabdaf35-ee58-405e-ac3e-924d04b2cfe4%5Fen?ref=thedelatorrereview.com) and the [LED](https://commission.europa.eu/document/download/67dc46ee-1f1a-4f3b-920f-71af138ffcfc%5Fen?ref=thedelatorrereview.com), as amended in December 2025 through [one renewal decision under the GDPR](https://commission.europa.eu/document/download/a7907f8f-6e1c-4782-a193-d16b2cfe7650%5Fen?filename=JUST%5Ftemplate%5Fcomingsoon%5Fstandard%5F26.pdf&ref=thedelatorrereview.com) and [one renewal decision under the LED](https://commission.europa.eu/document/fcb17e2f-40a5-46ed-8435-7a76434d19fb%5Fen?ref=thedelatorrereview.com) ,
- the [United States](https://eur-lex.europa.eu/eli/dec%5Fimpl/2023/1795/oj?ref=thedelatorrereview.com) (commercial organisations participating in the EU-US Data Privacy Framework),
- [Uruguay](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32012D0484&ref=thedelatorrereview.com),
- and the [European Patent Organisation](https://commission.europa.eu/document/download/2687dc39-5217-4165-8db6-b1294dc5b591%5Fen?filename=EPO%20Adequacy%20Decision%20July%202025.pdf&ref=thedelatorrereview.com) as providing adequate protection.

**Important:** Adequacy may be limited in scope. Canada, for example, is covered with respect to certain commercial organizations. Similarly, the United States does not have blanket adequacy status. The U.S. adequacy decision applies to U.S. organizations that participate in the **EU-U.S. Data Privacy Framework (DPF)**. The European Commission adopted the DPF adequacy decision on July 10, 2023.

The list of adequate jurisdictions can also change. For example, Brazil received an adequacy decision in 2026, and the Commission renewed the UK's adequacy status in December 2025\. The Commission periodically reviews adequacy decisions to determine whether the relevant destination continues to provide the required level of protection.

For an updated version of the list see: [European Commission — Adequacy Decisions List](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions%5Fen?utm%5Fsource=chatgpt.com)

### Second Transfer Mechanism: Appropriate Safeguards (Article 46 GDPR)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-08_17_27-PM.png)

When there is no adequacy decision, personal data may still be transferred to a third country or international organization if the controller or processor puts **appropriate safeguards** in place under [Article 46 GDPR](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com). Critically, Article 46 also requires that **data subjects have enforceable rights and effective legal remedies**.

Several mechanisms can provide appropriate safeguards. Some can be used without prior authorization from a supervisory authority, while others require supervisory-authority approval.

[Article 46(2)](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com) identifies six mechanisms:

1. **Legally binding and enforceable instruments between public authorities or bodies**
2. **Binding Corporate Rules (BCRs)**
3. **Standard Contractual Clauses (SCCs) adopted by the European Commission**
4. **Standard data protection clauses adopted by a supervisory authority and approved by the European Commission**
5. **Approved codes of conduct**, together with binding and enforceable commitments by the recipient to apply the safeguards
6. **Approved certification mechanisms**, together with binding and enforceable commitments by the recipient to apply the safeguards

[Article 46(3)](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com) also permits certain safeguards **with authorization from the competent supervisory authority**, including bespoke contractual clauses and certain administrative arrangements between public authorities or bodies.

**(1) Legally Binding Instruments Between Public Authorities**: Public authorities and bodies may use a legally binding and enforceable instrument to govern transfers between them. The instrument must provide appropriate safeguards as well as enforceable rights and effective remedies for the individuals whose personal data is transferred.

This mechanism is specifically designed for transfers between public authorities or bodies and is not the appropriate mechanism for transfers between private organizations.

**(2) Binding Corporate Rules (BCRs):** Binding Corporate Rules, or BCRs, provide a mechanism for transferring personal data within multinational corporate groups or groups of enterprises engaged in a joint economic activity. Rather than entering into separate SCCs for every intra-group transfer, an organization can establish a common set of binding data-protection rules governing transfers among participating group entities.

Unlike SCCs, however, BCRs require **approval by the competent supervisory authority** under Article 47 GDPR. They are therefore generally most useful for organizations with substantial and recurring international intra-group data flows. Once approved, BCRs can provide a comprehensive framework for transfers among the entities covered by them.

**(3) Standard Contractual Clauses (SCCs):** For many organizations, Standard Contractual Clauses (SCCs) are the most important [Article 46](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com) transfer mechanism.

SCCs are standardized contractual terms adopted by the European Commission that are entered into between the entity transferring the personal data—the data exporter—and the recipient—the data importer.

On June 4, 2021, the European Commission adopted the current SCCs for transfers of personal data to third countries. The modern SCCs use a modular structure designed to accommodate four common transfer relationships:

- **Module 1:** Controller → Controller
- **Module 2:** Controller → Processor
- **Module 3:** Processor → Processor
- **Module 4:** Processor → Controller

The parties must select the appropriate module and complete the relevant annexes. The SCCs generally cannot be altered in a manner that contradicts their provisions or undermines data-subject rights, although organizations may incorporate them into a broader commercial agreement by reference and add provisions that do not conflict with the SCCs.

The SCCs impose obligations on both exporters and importers and provide enforceable rights for data subjects whose personal data is transferred.

> **Example:** A French travel company sends a customer's booking information to an independently operated hotel in Australia. If both organizations act as controllers and Australia is not covered by an applicable adequacy decision, the organizations could use **Module 1 of the SCCs (Controller-to-Controller)** as the Article 46 transfer mechanism.

Putting SCCs in place does not necessarily end the transfer analysis. In ***Schrems II***, the CJEU made clear that organizations relying on contractual safeguards must consider whether the laws and practices of the recipient country allow the safeguards to operate effectively in practice.

The Commission's 2021 SCCs incorporate this requirement. Before relying on the SCCs, the parties must assess the circumstances of the transfer and whether the laws and practices of the destination country could prevent the importer from complying with the clauses. This assessment is commonly called a **Transfer Impact Assessment (TIA)**.

A TIA typically considers matters such as:

- the **specific circumstances of the transfer**, including the categories of data, purposes, recipients, and technical arrangements;
- the **laws and practices of the destination country**, particularly government-access and surveillance powers;
- whether those laws could interfere with the protections provided by the SCCs; and
- whether **supplementary contractual, technical, or organizational measures** are necessary to protect the data.

If appropriate safeguards cannot provide the required level of protection—even with supplementary measures—the transfer should not proceed on the basis of the SCCs.

**(4) Standard Clauses Adopted by a Supervisory Authority**: [Article 46](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com) also permits the use of standard data-protection clauses adopted by a supervisory authority and approved by the European Commission.

Like Commission SCCs, these clauses can provide an Article 46 safeguard without requiring individual authorization for each transfer once the clauses themselves have received the required approval.

**(5) Approved Codes of Conduct**: An approved code of conduct under [Article 40](https://gdpr-info.eu/art-40-gdpr/?ref=thedelatorrereview.com) can also serve as an international-transfer safeguard. For this mechanism to work, the recipient in the third country must make binding and enforceable commitments to apply the safeguards contained in the code, including protections relating to data-subject rights.

This allows sector-specific or industry-specific compliance frameworks to potentially provide a mechanism for international transfers rather than requiring every participating organization to develop its own contractual framework.

**(6) Approved Certification Mechanisms**: Similarly, an approved certification mechanism under [Article 42 ](https://gdpr-info.eu/art-42-gdpr/?ref=thedelatorrereview.com)may provide appropriate safeguards when combined with binding and enforceable commitments by the third-country recipient to comply with those safeguards.

Certification alone is therefore not enough. The recipient must also undertake legally binding commitments designed to ensure that individuals' rights remain protected.

**Bespoke Contractual Clauses Authorized by a Supervisory Authority**: Organizations may also develop bespoke contractual clauses for a particular transfer under [Article 46(3)](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com).

Unlike the Commission's SCCs, these clauses cannot simply be adopted and used. They require authorization from the competent supervisory authority.

This option provides flexibility for transfers that cannot readily be accommodated by standardized mechanisms, but the additional authorization requirement generally makes it less straightforward than using Commission-approved SCCs.

**Administrative Arrangements Between Public Authorities**: Finally, [Article 46(3) ](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com)permits certain administrative arrangements between public authorities or bodies that include enforceable and effective data-subject rights.

This mechanism can be useful where public authorities cannot enter into a legally binding instrument of the type contemplated by Article 46(2). Because these arrangements are not themselves legally binding in the same manner, they require authorization from the competent supervisory authority.

### Third Transfer Mechanism: Derogations for Specific Situations (Article 49 GDPR)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/ChatGPT-Image-Aug-15--2026-at-08_19_27-PM.png)

When a transfer is not covered by an adequacy decision and appropriate safeguards are unavailable, [Article 49 GDPR](https://gdpr-info.eu/art-49-gdpr/?ref=thedelatorrereview.com) provides a final set of derogations for specific situations.

These derogations are intended to operate as exceptions, rather than substitutes for adequacy or appropriate safeguards. They should therefore generally be interpreted narrowly and used for specific situations rather than as the legal basis for routine international data flows.

Article 49 identifies seven principal derogations:

1. **Explicit consent** of the data subject after being informed of the risks;
2. **Necessity for a contract** between the data subject and controller;
3. **Necessity for a contract concluded in the data subject's interest**;
4. **Important reasons of public interest**;
5. **Establishment, exercise, or defense of legal claims**;
6. **Protection of vital interests** where the individual cannot give consent; and
7. **Transfers from certain public registers**.

Article 49 also contains a narrow **last-resort derogation based on the controller's compelling legitimate interests**, subject to significantly more restrictive 

**(1) Explicit Consent**: A transfer may take place where the data subject has explicitly consented to the proposed transfer after being informed of the possible risks resulting from the absence of an adequacy decision and appropriate safeguards. This is a demanding standard. In addition to satisfying the GDPR's general requirements for valid consent, the individual must understand the particular risks associated with transferring their information to the destination country.

In practice, consent is often unsuitable for regular or structural international transfers, particularly because consent must be freely given and capable of being withdrawn.

**(2) Necessary for a Contract with the Data Subject**: A transfer may be permitted where it is necessary to perform a contract between the data subject and the controller, or to implement pre-contractual measures requested by the data subject.

The key word is **necessary**. It is not enough that an international transfer would be convenient or less expensive. There must be a sufficiently close and substantial connection between the transfer and performance of the contract.

> **Example:** A Spanish travel company arranges a customer's vacation in Peru. Sending the customer's name and necessary reservation information to the Peruvian hotel may be necessary to perform the travel contract.

This derogation is intended for transfers that are **o**ccasional rather than regular or systematic. It also cannot be relied upon by public authorities when exercising their public powers.

**(3) Necessary for a Contract in the Data Subject's Interest**: A related derogation applies when a transfer is necessary for the conclusion or performance of a contract between the controller and another person that is entered into in the interests of the data subject.

> **Example:** A customer purchases a family vacation package from a Spanish travel company. Sending the names of the customer's family members to a hotel in Peru may be necessary to make their reservations, even though those family members did not enter into the contract themselves.

As with the previous contractual derogation, the transfer must be necessary and generally occasional, and public authorities cannot rely on it when exercising their public powers.

**(4) Important Reasons of Public Interest**: Transfers may also take place when necessary for important reasons of public interest. The relevant public interest must be recognized by EU law or the law of the Member State to which the controller is subject. It may arise, for example, in certain forms of international regulatory, law-enforcement, public-health, or governmental cooperation.

This derogation should address specific situations rather than systematic international transfers and can potentially be relied upon by both public and private entities.

Where a foreign authority requests personal data and an applicable international cooperation mechanism exists—such as a Mutual Legal Assistance Treaty (MLAT)—organizations should also consider the requirements of [Article 48 GDPR](https://gdpr-info.eu/art-48-gdpr/?ref=thedelatorrereview.com) governing foreign judgments and administrative demands.

**(5) Establishment, Exercise, or Defense of Legal Claims**: A transfer may be permitted where it is necessary for the establishment, exercise, or defense of legal claims. The concept of a legal claim is broader than an existing lawsuit. Depending on the circumstances, it may encompass judicial proceedings, formal pre-litigation procedures, regulatory investigations, administrative proceedings, and other legally defined processes.

However, there must be a real and sufficiently close connection between the transfer and the legal claim. A speculative possibility that litigation or regulatory proceedings might arise in the future is not enough.

This derogation is generally intended for occasional transfers, not ongoing transfers conducted in anticipation of possible litigation.

**(6) Protection of Vital Interests**: Article 49 permits a transfer where it is necessary to protect the vital interests of the data subject or another person and the data subject is physically or legally incapable of giving consent.

The clearest example is an emergency involving an individual's life or physical safety.

> **Example:** A traveler becomes unconscious while abroad and urgently requires medical treatment. Transferring relevant medical information from an EU healthcare provider may be necessary to protect the individual's vital interests.

This derogation is narrow. It is not designed to support routine medical-data transfers, general medical research, or situations in which the individual is capable of providing valid consent.

**(7) Transfers from Public Registers**: Personal data may also be transferred from certain official registers established under EU or Member State law that are intended to provide information to the public or to persons who can demonstrate a legitimate interest.

Examples may include certain company, land, association, or other official public registers, depending on the applicable national law.

There are important limitations. The derogation does not permit the transfer of an entire register or entire categories of personal data contained within it. Any conditions imposed by EU or Member State law governing access to the register must also be respected.

Where access is available only to persons demonstrating a legitimate interest, the transfer must be made at the request of those persons or where they are themselves the recipients.

The derogation does not extend simply because information happens to be contained in a privately operated database.

**A Last Resort: Compelling Legitimate Interests**: [Article 49](https://gdpr-info.eu/art-49-gdpr/?ref=thedelatorrereview.com) contains one additional, exceptionally narrow mechanism for situations where none of the other Chapter V mechanisms is available. A controller may make a transfer based on its compelling legitimate interests, but only when numerous conditions are satisfied. Among other things:

- the transfer must **not be repetitive**;
- it must concern only a **limited number of data subjects**;
- it must be **necessary for compelling legitimate interests** of the controller;
- those interests must not be overridden by the rights and freedoms of the affected individuals;
- the controller must conduct and document a detailed **assessment of the circumstances of the transfer**;
- **suitable safeguards** must be implemented;
- the controller must **inform the competent supervisory authority**; and
- affected data subjects must be informed of the transfer and the compelling legitimate interests pursued.

Suitable safeguards might include measures such as encryption, pseudonymization, strict access restrictions, confidentiality requirements, or short retention periods, depending on the risks associated with the transfer.

**This mechanism should be viewed as a true last resort**, not as a convenient alternative when SCCs, BCRs, or another Chapter V mechanism would require additional work.

## Additional Resources

### GDPR Provisions

The GDPR provisions most relevant to international data transfers include:

- [**Article 44** ](https://gdpr-info.eu/art-44-gdpr/?ref=thedelatorrereview.com)— General principles governing international transfers.
- [**Article 45**](https://gdpr-info.eu/art-45-gdpr/?ref=thedelatorrereview.com)— Adequacy decisions.
- [**Article 46**](https://gdpr-info.eu/art-46-gdpr/?ref=thedelatorrereview.com)— Appropriate safeguards.
- [**Article 47** ](https://gdpr-info.eu/art-47-gdpr/?ref=thedelatorrereview.com)— Binding Corporate Rules (BCRs).
- [**Article 48** ](https://gdpr-info.eu/art-48-gdpr/?ref=thedelatorrereview.com)— Transfers or disclosures required by third-country courts or administrative authorities.
- [**Article 49**](https://gdpr-info.eu/art-49-gdpr/?ref=thedelatorrereview.com)— Derogations for specific situations.
- [**Article 50**](https://gdpr-info.eu/art-50-gdpr/?ref=thedelatorrereview.com) \- International cooperation for the protection of personal data
- [Recital 101](https://gdpr-info.eu/recitals/no-101/?ref=thedelatorrereview.com) \- General Principles for International Data Transfers\*
- [Recital 102](https://gdpr-info.eu/recitals/no-102/?ref=thedelatorrereview.com) \- International Agreements for an Appropriate Level of Data Protection\*
- [Recital 103](https://gdpr-info.eu/recitals/no-103/?ref=thedelatorrereview.com) \- Appropriate Level of Data Protection Based on an Adequacy Decision\*
- [Recital 104](https://gdpr-info.eu/recitals/no-104/?ref=thedelatorrereview.com) \- Criteria for an Adequacy Decision\*
- [Recital 105 ](https://gdpr-info.eu/recitals/no-105/?ref=thedelatorrereview.com)\- Consideration of International Agreements for an Adequacy Decision\*
- [Recital 106 ](https://gdpr-info.eu/recitals/no-106/?ref=thedelatorrereview.com)\- Monitoring and Periodic Review of the Level of Data Protection\*
- [Recital 107 ](https://gdpr-info.eu/recitals/no-107/?ref=thedelatorrereview.com)\- Amendment, Revocation and Suspension of Adequacy Decisions\*
- [Recital 108](https://gdpr-info.eu/recitals/no-108/?ref=thedelatorrereview.com) \- Appropriate Safeguards\*
- [Recital 109](https://gdpr-info.eu/recitals/no-109/?ref=thedelatorrereview.com) \- Standard Data Protection Clauses\*
- [Recital 110](https://gdpr-info.eu/recitals/no-110/?ref=thedelatorrereview.com) \- Binding Corporate Rules\*
- [Recital 111](https://gdpr-info.eu/recitals/no-111/?ref=thedelatorrereview.com) \- Exceptions for Certain Cases of International Transfers\*
- [Recital 112](https://gdpr-info.eu/recitals/no-112/?ref=thedelatorrereview.com) \- Data Transfers due to Important Reasons of Public Interest\*
- [Recital 113](https://gdpr-info.eu/recitals/no-113/?ref=thedelatorrereview.com) \- Transfers Qualified as Not Repetitive and that Only Concern a Limited Number of Data Subjects\*
- [Recital 114 ](https://gdpr-info.eu/recitals/no-114/?ref=thedelatorrereview.com)\- Safeguarding of Enforceability of Rights and Obligations in the Absence of an Adequacy Decision\*
- [Recital 115](https://gdpr-info.eu/recitals/no-115/?ref=thedelatorrereview.com) \- Rules in Third Countries Contrary to the Regulation\*

### Key CJEU Cases

- **C-101/01, *Lindqvist* (2003)** — An early CJEU decision addressing when publication of personal data on the internet constitutes a transfer to a third country. The Court concluded that placing information on a website did not, in the circumstances before it, constitute a transfer to third countries merely because the website could be accessed from abroad.
- **C-362/14, *Schrems I* (2015)** — The CJEU invalidated the European Commission's **EU-U.S. Safe Harbor**adequacy decision.
- **C-311/18, *Schrems II* (2020)** — The CJEU invalidated the **EU-U.S. Privacy Shield** adequacy decision. The Court upheld the validity of SCCs as a transfer mechanism but emphasized the need to determine whether transferred data receives the required protection in practice. The decision is foundational to today's approach to **Transfer Impact Assessments (TIAs) and supplementary measures**.

### European Data Protection Board (EDPB)

The EDPB has published several important resources interpreting Chapter V, including:

- [**Guidelines 05/2021 on the Interplay between Article 3 and Chapter V of the GDPR** ](https://www.edpb.europa.eu/documents/guideline/guidelines-052021-on-the-interplay-between-the-application-of-article-3-and-the%5Fen?ref=thedelatorrereview.com)— Particularly useful for determining **what constitutes a transfer** and when Chapter V applies.
- [**Recommendations 01/2020 on Measures that Supplement Transfer Tools** ](https://www.edpb.europa.eu/documents/recommendation/recommendations-012020-on-measures-that-supplement-transfer-tools-to%5Fen?ref=thedelatorrereview.com)— Guidance for assessing third-country protections and identifying supplementary measures where necessary.
- [**Recommendations 02/2020 on the European Essential Guarantees for Surveillance Measure**](https://www.edpb.europa.eu/documents/recommendation/recommendations-022020-on-the-european-essential-guarantees-for%5Fen?ref=thedelatorrereview.com)**s** — Relevant when evaluating government access to personal data in third countries.
- [**Guidelines 2/2018 on Article 49 Derogations**](https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679%5Fen?ref=thedelatorrereview.com) — Detailed guidance on the narrow circumstances in which the Article 49 derogations may be used.

### Adequacy Decisions

- Because adequacy decisions can be adopted, amended, reviewed, or repealed, organizations should consult the [**Commission's current list** ](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions%5Fen?ref=thedelatorrereview.com)rather than relying on an older list of adequate jurisdictions.
- For U.S. transfers, see also the European Commission's materials concerning the [**EU-U.S. Data Privacy Framework (DPF)**](https://eur-lex.europa.eu/eli/dec%5Fimpl/2023/1795/oj?ref=thedelatorrereview.com) and its July 10, 2023 adequacy decision.

### Standard Contractual Clauses (SCCs)

The European Commission adopted the current [**Standard Contractual Clauses for international transfers** on **June 4, 2021**.](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc%5Fen?ref=thedelatorrereview.com) The SCCs use a modular structure covering:

The Commission's older 2001, 2004, and 2010 transfer clauses have been replaced and **should no longer be used for new or existing transfers**.

### Binding Corporate Rules (BCRs)

Organizations considering BCRs should consult the EDPB's current guidance and application materials for **Controller BCRs (BCR-C)** and **Processor BCRs (BCR-P)**.

BCR guidance originated with the former Article 29 Working Party, but organizations should use the [EDPB's current materials because the BCR framework](https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/binding-corporate-rules%5Fen?ref=thedelatorrereview.com) and approval process have continued to develop under the GDPR.

### Transfer Impact Assessments and Supplementary Measures

- Organizations relying on SCCs or other Article 46 safeguards should consider the implications of ***Schrems II*** and the EDPB's [**Recommendations 01/2020 on supplementary measures**.](https://www.edpb.europa.eu/documents/recommendation/recommendations-012020-on-measures-that-supplement-transfer-tools-to%5Fen?ref=thedelatorrereview.com)

For practical implementation, the **International Association of Privacy Professionals (IAPP)** maintains resources and templates relating to [**Transfer Impact Assessments (TIAs)**.](https://iapp.org/resources/article/transfer-impact-assessment-templates?ref=thedelatorrereview.com)

### Foreign Government Access and the U.S. CLOUD Act

For questions concerning government demands for data and Article 48, useful resources include:

- the [**EDPB-EDPS Joint Response on the U.S. CLOUD Act** ](https://www.edpb.europa.eu/documents/edpb-correspondence/edpb-edps-joint-response-to-the-libe-committee-on-the-impact-of-the%5Fen?ref=thedelatorrereview.com)and its assessment of the CLOUD Act's interaction with the EU data-protection framework; and
- [**EDPS Opinion 2/2019** ](https://www.edps.europa.eu/sites/default/files/publication/19-04-02%5Fedps%5Fopinion%5Fon%5Feu%5Fus%5Fagreement%5Fon%5Fe-evidence%5Fen.pdf?ref=thedelatorrereview.com)concerning negotiations for an EU-U.S. agreement on cross-border access to electronic evidence.

These materials are particularly useful when considering the relationship between Chapter V, Article 48, foreign disclosure orders, and government access to personal data.

### Article 49 Derogations

- For detailed interpretation of the exceptions discussed in this article, see the [**EDPB Guidelines 2/2018 on derogations of Article 49 GDPR**.](https://www.edpb.europa.eu/documents/guideline/guidelines-22018-on-derogations-of-article-49-under-regulation-2016679%5Fen?ref=thedelatorrereview.com) The Guidelines emphasize the exceptional nature of Article 49 and are particularly useful for understanding the requirements applicable to explicit consent, contractual necessity, important public interests, legal claims, vital interests, public registers, and the compelling-legitimate-interests derogation.

### Historical Resources: Safe Harbor and Privacy Shield

- The [**EU-U.S. Safe Harbor** ](https://www.ftc.gov/business-guidance/privacy-security/us-eu-safe-harbor-framework?ref=thedelatorrereview.com)and [**EU-U.S. Privacy Shield** ](https://www.privacyshield.gov/ps/eu-us-framework?ref=thedelatorrereview.com)are historically important but **no longer valid transfer mechanisms**. Safe Harbor was invalidated in ***Schrems I*** and Privacy Shield in ***Schrems II***. They have since been succeeded by the **EU-U.S. Data Privacy Framework**, which currently operates pursuant to the European Commission's 2023 adequacy decision.

Older Safe Harbor and Privacy Shield materials may therefore be useful for understanding the development of EU-U.S. data-transfer law, but they should **not be relied upon as current transfer mechanisms**.

### United Kingdom and Switzerland

Since Brexit, transfers involving the **United Kingdom** must be considered in light of the UK's separate data-protection regime and the European Commission's adequacy decision for the UK.

- For transfers governed by **Swiss data-protection law**, organizations should consult guidance from the [**Swiss Federal Data Protection and Information Commissioner (FDPIC)** ](https://www.edoeb.admin.ch/en/cross-border-transfer-of-personal-data?ref=thedelatorrereview.com)concerning international data transfers and the use of SCCs under Swiss law.

### Official Sources to Bookmark

For the most current information, organizations should consult:

- [**European Commission**](https://commission.europa.eu/index%5Fen?ref=thedelatorrereview.com) — International data transfers, adequacy decisions, SCCs, and the EU-U.S. Data Privacy Framework.
- [**European Data Protection Board (EDPB)** ](https://www.edpb.europa.eu/home%5Fen?ref=thedelatorrereview.com)— Guidelines, recommendations, BCR materials, and Chapter V interpretations.
- [**EUR-Lex**](https://eur-lex.europa.eu/homepage.html?ref=thedelatorrereview.com) — Official text of the GDPR, Commission decisions, and CJEU materials.
- [**CURIA**](https://curia.europa.eu/site/?ref=thedelatorrereview.com) — CJEU judgments, including *Lindqvist*, *Schrems I*, and *Schrems II*.
- [**European Data Protection Supervisor (EDPS)** ](https://www.edps.europa.eu/%5Fen?ref=thedelatorrereview.com)— Opinions and materials concerning international transfers and government access.
- [**IAPP** ](https://iapp.org/?ref=thedelatorrereview.com)— Practical resources, including Transfer Impact Assessment materials and templates.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Screenshot-2026-07-04-at-4.45.19---PM-4.jpeg)

### 

### 

##