International data transfers
International data transfers require that personal data leaving the European Economic Area (EEA) maintains a level of protection essentially equivalent to that guaranteed under the GDPR. Organizations must identify every instance where data leaves the EEA and ensure a valid legal transfer mechanism is in place before the transfer occurs.
What it means
The intent of Chapter 5 is to prevent "forum shopping," where organizations move data to countries with weaker privacy laws to avoid GDPR obligations. It ensures that the protections afforded to EU citizens follow their data regardless of where it is stored or processed globally.
In practice, a "transfer" occurs not only when data is physically moved to a server in a third country but also when someone located outside the EEA accesses data stored within the EEA (remote access). This includes using US-based SaaS providers, outsourcing payroll to a non-EU vendor, or granting remote support access to engineers in Asia.
The scope covers all "third countries" unless the European Commission has issued an Adequacy Decision for that specific country, confirming its laws provide sufficient protection. If no adequacy decision exists, the organization must implement alternative safeguards.
How to meet it
- Map data flows: Create a registry of all personal data transfers, identifying the destination country and the legal entity receiving the data.
- Verify Adequacy Decisions: Check if the destination country is on the EU's approved list (e.g., Canada, Japan, UK) to simplify the transfer process.
- Implement Standard Contractual Clauses (SCCs): For non-adequate countries, execute the European Commission’s latest modular SCCs with data importers.
- Conduct Transfer Impact Assessments (TIAs): Evaluate whether the laws of the destination country—specifically regarding government surveillance—undermine the protections provided by your SCCs.
- Apply Supplementary Measures: Where a TIA reveals risks, implement technical safeguards such as strong end-to-end encryption or pseudonymization where the key remains in the EEA.
- Establish Binding Corporate Rules (BCRs): For large multinational groups, develop BCRs approved by a lead supervisory authority to govern intra-company transfers.
Evidence an auditor asks for
- Data Transfer Map: A document or ROPA entry detailing what data is transferred, where it goes, and the mechanism used for each flow.
- Signed Contracts: Executed SCCs or Data Processing Agreements (DPAs) containing the current EU transfer modules.
- Completed TIAs: Documented risk assessments for each third-country destination proving that the local legal climate was analyzed.
- Technical Configuration Proof: Evidence of encryption standards, key management policies, or access logs showing restricted remote access.
Common pitfalls
- Ignoring Remote Access: Failing to recognize that a support ticket viewed by an employee in India constitutes a data transfer, even if the server is in Germany.
- "Check-box" Compliance: Signing SCCs but failing to perform the required TIA or implement supplementary measures, which is now a mandatory requirement post-Schrems II.
- Over-reliance on Consent: Attempting to use "explicit consent" for systemic, repetitive business transfers; auditors generally view this as invalid for large-scale operational data flows.