Auditen
Home / Frameworks / GDPR / International data transfers
GDPR · Ch. 5

International data transfers

International data transfers require that personal data leaving the European Economic Area (EEA) maintains a level of protection essentially equivalent to that guaranteed under the GDPR. Organizations must identify every instance where data leaves the EEA and ensure a valid legal transfer mechanism is in place before the transfer occurs.

What it means

The intent of Chapter 5 is to prevent "forum shopping," where organizations move data to countries with weaker privacy laws to avoid GDPR obligations. It ensures that the protections afforded to EU citizens follow their data regardless of where it is stored or processed globally.

In practice, a "transfer" occurs not only when data is physically moved to a server in a third country but also when someone located outside the EEA accesses data stored within the EEA (remote access). This includes using US-based SaaS providers, outsourcing payroll to a non-EU vendor, or granting remote support access to engineers in Asia.

The scope covers all "third countries" unless the European Commission has issued an Adequacy Decision for that specific country, confirming its laws provide sufficient protection. If no adequacy decision exists, the organization must implement alternative safeguards.

How to meet it

Evidence an auditor asks for

  • Data Transfer Map: A document or ROPA entry detailing what data is transferred, where it goes, and the mechanism used for each flow.
  • Signed Contracts: Executed SCCs or Data Processing Agreements (DPAs) containing the current EU transfer modules.
  • Completed TIAs: Documented risk assessments for each third-country destination proving that the local legal climate was analyzed.
  • Technical Configuration Proof: Evidence of encryption standards, key management policies, or access logs showing restricted remote access.

Common pitfalls

  • Ignoring Remote Access: Failing to recognize that a support ticket viewed by an employee in India constitutes a data transfer, even if the server is in Germany.
  • "Check-box" Compliance: Signing SCCs but failing to perform the required TIA or implement supplementary measures, which is now a mandatory requirement post-Schrems II.
  • Over-reliance on Consent: Attempting to use "explicit consent" for systemic, repetitive business transfers; auditors generally view this as invalid for large-scale operational data flows.