The Practical Guide to CrossBorder Data Transfers Under GDPR

africa, growth, development, plant, light, boom, business, stock exchange, globe, map of the world, world map, world, continent, earth, geography, map, europe, nature, world market

International data transfers remain one of the most operationally demanding areas of EU data protection compliance. Chapter V of the GDPR (Articles 44–50) governs any transfer of personal data to a recipient located outside the European Economic Area. It does so through a layered system of legal mechanisms rather than a single test. For organisations operating across borders, understanding how these mechanisms interact, and how they have evolved since 2020, is essential to building a defensible transfer strategy.

Understanding the Hierarchy Behind GDPR International Transfers

The GDPR’s transfer regime is built around a simple hierarchy. A transfer to a third country is lawful if the European Commission has recognised that country as offering an adequate level of protection under Article 45. Where no adequacy decision exists, the exporter must instead rely on one of the appropriate safeguards listed in Article 46, or, exceptionally, on one of the narrow derogations in Article 49.

Adequacy decisions are the simplest route: once granted, they allow personal data to flow to the third country without any additional authorisation or contractual mechanism, as if the transfer were taking place within the EEA. The Commission currently recognises a limited number of jurisdictions as adequate, and each decision is subject to periodic review and, in several cases, a sunset clause.

Standard Contractual Clauses

In the absence of an adequacy decision, Standard Contractual Clauses (SCCs) remain the most widely used appropriate safeguard in practice. As the name suggests, SCCs are pre-approved contractual templates issued by the European Commission, incorporating a fixed set of data protection obligations that the parties cannot unilaterally alter in substance. The 2021 modernised SCCs replaced the earlier 2001/2010 clauses and introduced a modular structure covering controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller scenarios. This structure lets a single instrument capture multi-party and complex processing chains.

While SCCs offer a comparatively fast and low-cost route to compliance, they are not a standalone fix. Since the Court of Justice’s ruling in Schrems II, signing the clauses is only the starting point, the exporter must also verify, in practice, that the clauses can actually be honoured in the destination country.

Binding Corporate Rules

For multinational groups with recurring intra-group transfers, Binding Corporate Rules (BCRs) can offer a more tailored and durable safeguard. BCRs are internal codes of conduct. A lead supervisory authority approves them under the Article 4(1)(f) cooperation mechanism. They bind every entity within the corporate group to a common set of data protection standards. Their principal advantage is that, once approved, they cover the full range of intra-group transfers without the need to execute and manage separate contracts for each data flow or entity pair. The trade-off is procedural: securing lead authority approval is a substantial undertaking, typically requiring detailed internal governance documentation, mapping of data flows, and an approval timeline that can extend well beyond that of SCCs.

Certification Mechanisms

Article 42 and 46(2)(f) GDPR also provide for approved certification mechanisms, issued by accredited certification bodies, as a further category of appropriate safeguard. These remain less commonly used in practice than SCCs or BCRs, but they are gaining relevance as more certification schemes and bodies receive formal accreditation, offering organisations an alternative, particularly useful in sector-specific or cloud-service contexts.

Schrems II and the Essential Equivalence Standard

The Court of Justice’s judgment in Case C-311/18 (Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, “Schrems II”) fundamentally raised the compliance bar for transfers relying on Article 46 safeguards. The Court confirmed that a transfer mechanism such as SCCs is not, by itself, sufficient: exporters must ensure that data subjects are afforded a level of protection “essentially equivalent” to that guaranteed within the EU, taking into account the law and practices of the destination country, including government access to data for national security or law enforcement purposes.In practice, this means every transfer relying on Article 46 safeguards must be preceded by a Transfer Impact Assessment (TIA), basically an evaluation of the legal regime and surveillance practices in the destination jurisdiction, the nature of the data and processing involved, and the practical accessibility of the data to public authorities. Where the assessment identifies a gap between the protection guaranteed by the SCCs or BCRs and the actual regime in the destination country, the exporter must implement supplementary measures, meaning technical (such as strong encryption or pseudonymisation with keys retained in the EEA), contractual, or organisational measures sufficient to close that gap, as set out in the EDPB’s Recommendations 01/2020. If no combination of supplementary measures can bridge the gap, the transfer should not proceed.

The UK: A Case Apart

The UK’s position illustrates how quickly this area can shift. Following Brexit, the European Commission adopted adequacy decisions for the UK under both the GDPR and the Law Enforcement Directive in 2021, subject to a sunset clause requiring periodic review. That review process proved eventful: the original decisions were due to expire in June 2025, were extended on a technical basis to December 2025 to allow the Commission time to assess the impact of the UK’s Data (Use and Access) Act 2025, and were ultimately renewed on 19 December 2025 for a further six years, now running until 27 December 2031. As a result, transfers of personal data from the EEA to the UK continue to benefit from adequacy status and require no additional transfer mechanism, though the Commission has committed to a further functional review after four years.

The position reverses for transfers originating in the UK. Because the UK operates its own, parallel data protection framework post-Brexit, UK exporters sending personal data to third countries cannot rely on the EU adequacy finding in the other direction. Instead, they must use UK-specific instruments: either the UK International Data Transfer Agreement (IDTA) issued by the Information Commissioner’s Office, or the UK Addendum to the EU SCCs, which adapts the EU clauses for use under the UK GDPR. As with the EU regime post-Schrems II, UK exporters are also expected to carry out a Transfer Risk Assessment (TRA), the ICO’s equivalent of the TIA, before relying on either instrument, assessing whether the destination country’s laws and practices undermine the protection the IDTA or Addendum is intended to provide.

Practical Takeaways

For organisations managing cross-border data flows, three points are worth keeping in mind. First, the choice of transfer mechanism should reflect the structure of the data flows involved: SCCs for one-off or limited relationships, BCRs where the scale and recurrence of intra-group transfers justify the upfront investment. Second, no mechanism operates in isolation from the Schrems II standard, a signed contract without a documented transfer impact assessment leaves an exposed compliance gap. Third, the EU and UK regimes, though historically aligned, must now be tracked as two distinct frameworks, each with its own instruments, its own risk assessment methodology, and its own review timeline.

Given how frequently the underlying adequacy landscape and supervisory guidance shift, transfer compliance is best treated as a living process,  mapped, documented, and revisited, rather than a box ticked once at contract signature.

 

Send us a Message

If you have any questions about our services