CIPP/E Domain 3: How the GDPR Regulates Cross-Border Data Transfers
Quick Insights:
Personal data may be transferred outside the EEA under the GDPR only when adequate protection remains in place. Organizations may rely on adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or limited Article 49 derogations. Where required, they must also assess destination-country risks through a Transfer Impact Assessment and apply supplementary safeguards.

Why Are International Data Transfers Restricted?
EU law recognizes the protection of personal data as a fundamental right. The GDPR’s international-transfer rules are intended to ensure that this protection is not undermined when personal data moves outside the European Economic Area.
Personal data may generally circulate within the EEA, which consists of the EU Member States, Norway, Liechtenstein, and Iceland. When personal data is transferred to a third country or international organization, the requirements of Chapter V of the GDPR must be considered.
The GDPR provides a hierarchy of transfer mechanisms:
- An adequacy decision under Article 45
- Appropriate safeguards under Article 46, including SCCs and BCRs
- Limited derogations under Article 49
A transfer mechanism does not replace the controller’s wider GDPR responsibilities, including lawful processing, transparency, security and data minimization.
What Constitutes an International Data Transfer?
 An international transfer may occur where:
- The relevant processing activity must fall within the scope of the GDPR and involve a controller or processor subject to its requirements.
- It discloses or otherwise makes personal data available to another controller or processor.
- The recipient is located in a third country or is an international organization.
The exporter and importer must be separate entities. Therefore, sharing personal data between legally distinct companies in the same corporate group can constitute an international transfer. The transfer rules can apply even where the third-country recipient is independently subject to the GDPR under Article 3.
Adequacy Decisions
An adequacy decision is a formal determination by the European Commission that a country, territory, specified sector or international organization provides an adequate level of personal-data protection.
The assessment considers matters such as:
- The rule of law and respect for fundamental rights
- Data-protection legislation
- Public-authority and surveillance access
- Independent supervisory authorities
- Enforceable individual rights
- Effective administrative and judicial remedies
- Restrictions on onward transfers
- International data-protection commitments
Where an adequacy decision applies, personal data may generally be transferred without implementing an additional Article 46 safeguard.
Current adequate jurisdictions include Japan, the Republic of Korea, Switzerland, the United Kingdom, Brazil and others.
The Evolution of EU-US Data Transfer Frameworks
- Safe Harbor
The EU and the U.S. launched Safe Harbor, a self-certification system allowing U.S. companies to receive EU personal data if they agreed to follow certain privacy principles. It was meant to provide “adequate protection” under EU law.
In 2015, the CJEU invalidated Safe Harbor in the Schrems I judgment after finding that the framework did not provide adequate protection against access by U.S. public authorities or sufficiently effective remedies for individuals.
- Privacy Shield
The EU-US Privacy Shield replaced Safe Harbor and introduced stronger oversight mechanisms, including:
- A complaint resolution system
- A State Department ombudsperson
However, in 2020, the CJEU invalidated Privacy Shield in the Schrems II ruling, concluding that U.S. surveillance laws still lacked proportionality and effective judicial remedies for EU individuals.
- EU-US Data Privacy Framework
After two failed frameworks, the EU and the U.S. proposed a new framework. In March 2022, the Biden administration and the European Commission announced a new Trans-Atlantic Data Privacy Framework.
The goal? To address past legal flaws and create a durable solution for EU-U.S. data flows.
Key promises include:
- New limitations on U.S. intelligence access to EU data
- The establishment of an independent Data Protection Review Court
- Stronger oversight of certified U.S. companies
- Enhanced transparency and compliance monitoring
Organizations in the United States can self-certify under the DPF, allowing them to receive EU personal data without additional transfer safeguards.
However, companies must still monitor regulatory developments, as legal challenges to the framework are ongoing.
Standard Contractual Clauses (SCCs)
When transferring personal data outside the EU to countries without an adequacy decision, SCCs have long been the go-to legal tool. These are pre-approved legal contracts that bind both data exporters and importers to EU-level data protection standards.
In June 2021, the EU introduced modular SCCs to reflect GDPR and Schrems II:
- Module 1: Controller to Controller
- Module 2: Controller to Processor
- Module 3: Processor to Processor
- Module 4: Processor to Controller
Parties can select the relevant module(s) and must conduct a Transfer Impact Assessment (TIA) to ensure data remains protected, even if government access is a risk in the destination country.
Transfer Impact Assessment (TIA)
A Transfer Impact Assessment is a documented assessment used to determine whether a transfer mechanism such as the SCCs can provide effective protection in the circumstances of a particular transfer.
A TIA ordinarily considers:
- The nature and purpose of the transfer
- The categories and sensitivity of the data
- The transfer mechanism
- Laws and relevant practices in the destination country
- The likelihood and impact of public-authority access
- The effectiveness of technical, contractual or organizational supplementary measures
- The need for periodic reassessment
Binding Corporate Rules (BCRs)
BCRs are internal data protection policies approved by EU regulators that allow multinational companies to legally transfer personal data within their corporate group across borders.
Why do BCRs Matter?
Without BCRs, every international data transfer between branches or subsidiaries could require a separate legal contract, which is an inefficient and costly process. For global companies where data sharing across jurisdictions is essential, BCRs provide scalable, long-term compliance.
BCRs Requirements
To get Binding Corporate Rules (BCRs) approved under the GDPR, companies must:
- Define group structure and list all entities involved
- Detail data flows—what’s shared, why, and where
- Make BCRs legally binding, with enforceable rights for individuals
- Ensure GDPR principles: data minimization, security, purpose limitation
- Guarantee individual rights (e.g., complaints, no profiling)
- Accept liability for non-EU members
- Ensure transparency to data subjects
- Appoint a DPO or equivalent for oversight
- Detail training, audits, and cooperation with regulators
- Identify conflicting laws and mitigation plans
Codes of Conduct and Certifications
The GDPR introduced two underused tools for legitimizing international data transfers: Codes of Conduct and Certification Mechanisms. Though still untested in practice, they offer a promising alternative to complex contracts or legal uncertainty.
A Code of Conduct is a set of data protection rules created by a sector or group of businesses tailored to their industry or data practices.
A Certification Mechanism is a formal seal of approval that shows an organization meets GDPR standards, similar to a quality assurance badge.
If approved by EU regulators, both can legitimize international transfers without standard contracts.
GDPR Article 49 Derogations
Where no adequacy decision or appropriate safeguard is available, Article 49 permits certain transfers in specific circumstances.
These may include:
- Explicit and informed consent to the proposed transfer
- Necessity for performing a contract with the individual
- Necessity for a contract concluded in the individual’s interest
- Important reasons of public interest recognized by law
- Establishment, exercise or defense of legal claims
- Protection of vital interests where the person cannot consent
- Limited transfers from qualifying public registers
Conclusion
The GDPR does not prohibit international data flows. It requires organizations to ensure that personal data continues to receive effective protection after leaving the EEA. Adequacy decisions offer the most straightforward route. Where no adequacy decision applies, organizations may rely on mechanisms such as SCCs or BCRs, supported where necessary by TIAs and supplementary measures. Article 49 derogations should remain limited to specific and exceptional situations.
Because adequacy decisions, destination-country laws and transfer risks can change, organizations should maintain an accurate transfer inventory, document their assessments and regularly review the safeguards supporting their international data flows.
CIPP/E Certification Training with InfosecTrain
Build a stronger understanding of GDPR transfer rules, adequacy decisions, SCCs, BCRs, TIAs, Schrems II, and the latest EDPB guidance with InfosecTrain’s CIPP/E European Privacy Training. The course helps privacy professionals connect legal principles with real-world transfer scenarios, including modern vendor ecosystems, cloud services, and AI-driven processing environments.
TRAINING CALENDAR of Upcoming Batches For CIPP/E Training
| Start Date | End Date | Start - End Time | Batch Type | Training Mode | Batch Status | |
|---|---|---|---|---|---|---|
| 07-Sep-2026 | 22-Sep-2026 | 20:00 - 22:00 IST | Weekday | Online | [ Close ] | |
| 10-Oct-2026 | 25-Oct-2026 | 09:00 - 13:00 IST | Weekend | Online | [ Open ] | |
| 16-Nov-2026 | 01-Dec-2026 | 20:00 - 22:00 IST | Weekday | Online | [ Open ] | |
| 05-Dec-2026 | 20-Dec-2026 | 09:00 - 13:00 IST | Weekend | Online | [ Open ] | |
| 04-Jan-2027 | 19-Jan-2027 | 20:00 - 22:00 IST | Weekday | Online | [ Open ] | |
| 06-Feb-2027 | 21-Feb-2027 | 19:00 - 23:00 IST | Weekend | Online | [ Open ] | |
| 01-Mar-2027 | 16-Mar-2027 | 20:00 - 22:00 IST | Weekday | Online | [ Open ] |
Frequently Asked Questions
What is an adequacy decision?
It is a European Commission decision confirming that a country or specified organization provides adequate data protection.
What are Standard Contractual Clauses?
SCCs are European Commission-approved contractual safeguards used for transfers to countries without an adequacy decision.
What is a Transfer Impact Assessment?
A TIA evaluates whether foreign laws or practices could weaken the protection provided by a transfer mechanism.
When can Article 49 derogations be used?
They may be used in limited and exceptional situations when no adequacy decision or appropriate safeguard is available.
What is a GDPR international data transfer?
It occurs when personal data is made available to a separate organization located outside the EEA.
