LinkedInInstagramXTikTok

International Data Transfers: How to Stay GDPR-Compliant Outside the EU

Why international data transfers concern almost every company

Most companies believe they keep their data inside the EU. In practice, they rarely do. The moment you use a cloud service, a support tool, an analytics platform or a CRM system with roots outside the EU, there is a good chance personal data crosses a border – sometimes without anyone in the organisation realising it. This is what the GDPR calls a transfer to a third country, and the rules surrounding such transfers are among the most misunderstood in the entire data protection framework.

The issue is not theoretical. Chapter V of the GDPR sets concrete requirements for how personal data may leave the EU and the EEA, and supervisory authorities have shown in recent years that they take the rules seriously. At the same time, the legal landscape keeps shifting: court rulings, new decisions from the European Commission and updated contractual templates have changed the conditions several times since the GDPR took effect.

This article explains when a transfer actually takes place, which transfer mechanisms exist, what a transfer impact assessment involves, the most common mistakes and the risks you face if the rules are not followed.

What an international data transfer is – and when it happens

An international data transfer in the GDPR sense occurs when personal data is made available to a recipient in a country outside the EU and the EEA, a so-called third country. Chapter V of the GDPR governs these transfers and rests on a simple principle: the level of protection afforded to the data must not be undermined merely because it leaves the union.

Transfers happen more often than you think

A common misunderstanding is that a transfer only occurs when data is physically copied to a server in another country. That is not the case. A transfer can just as easily happen through remote access – a support engineer in a third country logging in to view data stored in the EU counts as a transfer. The same applies when a subcontractor in a third country can access the data to perform operations, troubleshooting or maintenance.

This means the question is not where the data centre sits, but who can access the data and from where. A company that uses a European cloud provider with EU-based servers may still be making third-country transfers if the provider’s parent company or support organisation is located outside the EU.

The transfer mechanisms in Chapter V

The GDPR allows transfers to third countries on three main grounds. The first is an adequacy decision from the European Commission. If the Commission has determined that a particular country offers a level of protection essentially equivalent to that of the EU, data may be transferred there on roughly the same terms as within the union.

The second ground is appropriate safeguards. The most common are Standard Contractual Clauses (SCCs) – ready-made contractual templates produced by the European Commission and entered into between the parties. The Commission adopted modernised Standard Contractual Clauses in June 2021, replacing the older versions. An alternative for corporate groups is Binding Corporate Rules (BCRs), internal frameworks approved by a supervisory authority that permit transfers within a company group.

The third ground is derogations for specific situations. These include, for example, explicit consent from the data subject or transfers necessary to perform a contract. These derogations are intended to be used restrictively and in individual cases, not as a routine basis for ongoing transfers.

The EU-US Data Privacy Framework

For transfers to the United States there is a special arrangement. In July 2023 the European Commission adopted an adequacy decision for the US under the EU-US Data Privacy Framework (DPF). This means personal data can be transferred to US companies that have certified themselves under the framework, much as to a country with an adequacy decision.

The key point is that adequacy is tied to the certification. Transfers to a US recipient that is not DPF-certified are not covered and require Standard Contractual Clauses or another mechanism. Before relying on the framework, you therefore need to verify that the specific recipient is actually certified and that the certification covers the relevant type of data.

A caveat is also in order here. The legal position on transfers to the US has been changeable. In the ruling commonly known as Schrems II, the Court of Justice of the EU invalidated the previous Privacy Shield framework in 2020. We describe the current DPF as the legal landscape applicable during 2025, but it may be tested and may change. It is wise, therefore, to build a solution that can withstand change, for example by keeping Standard Contractual Clauses as a fallback.

Transfer impact assessment – the step that is often forgotten

The Schrems II judgment did not only change the view of the US. The Court held that anyone using Standard Contractual Clauses cannot simply sign the agreement and consider the matter settled. You must also assess whether the law in the recipient country actually allows the protection in the clauses to be upheld in practice.

This assessment is called a transfer impact assessment. In short, it means mapping the level of protection that the recipient country’s legal order offers, particularly regarding government authorities’ ability to access data. If the assessment shows that the protection is insufficient, you need to apply supplementary measures – such as encryption where you control the keys yourself, pseudonymisation or contractual limitations – to raise the protection to an acceptable level.

The point is that a mechanism is never a guarantee in itself. Standard Contractual Clauses only work if they are combined with a realistic assessment of conditions on the ground and, where necessary, with concrete technical and organisational measures.

The role of the processor in the chain

Most transfers do not happen directly between you and a recipient in a third country, but through a chain of suppliers. You engage a processor – a cloud provider, say – which in turn engages sub-processors for parts of the service. It is within this chain that transfers often arise, and it is also here that they are most easily overlooked.

As the controller, you are obliged to maintain oversight of the entire chain. It is not enough that your data processing agreement with the main supplier contains the right clauses if a sub-processor further down the chain exports data to a third country without adequate protection. You therefore need to know which sub-processors are engaged, where they are located and on what basis any transfers take place. A well-considered processing agreement also governs how new sub-processors may be added and how you are informed of changes.

Practical example: the SaaS tool nobody reviewed

Imagine a mid-sized Swedish company introducing a new customer support tool. The tool is popular, affordable, and the provider states that data is stored in an EU data centre. The purchase is quickly approved and the tool is rolled out.

What nobody reviewed was that the provider is a US company whose support organisation sits in the US and India, and which engages a couple of subcontractors for operations and analytics. When a support case is escalated, staff outside the EU can log in and view customer data – remote access that, in the GDPR sense, is a transfer to a third country. The provider is not DPF-certified, and no data processing agreement with correct Standard Contractual Clauses has been concluded for the entire chain.

The company therefore has ongoing third-country transfers without a valid mechanism, without a transfer impact assessment and without an overview of its sub-processors. The problem arose not from bad faith but because nobody asked from where the data can actually be accessed. With a mapping exercise before purchase, a proper processing agreement and an assessment of the recipient countries, the situation would have been manageable from the start.

Common mistakes companies make

The first mistake is assuming that an EU data centre settles the matter. Where the data is stored says nothing about who can access it. Remote access from a third country is a transfer even if the server stands in Stockholm.

The second mistake is never mapping the sub-processors. Many companies know their direct suppliers but have no picture of their suppliers’ suppliers. Transfers often occur further down the chain, and without mapping they are impossible to manage.

The third mistake is relying on outdated mechanisms. Companies that signed agreements using older Standard Contractual Clauses, or that still refer to frameworks invalidated long ago, formally have no valid basis for their transfers. Mechanisms need to be updated as the legal position changes.

A fourth mistake is leaning on the derogations, such as explicit consent, for ongoing and large-scale transfers. The derogations are intended for individual situations and rarely hold up as a permanent basis for a business-critical flow of information.

Legal risks

International data transfers are governed by the same sanction regime as the rest of the GDPR. Infringements can lead to administrative fines of up to 20 million euros or four percent of the group’s global annual turnover, whichever is higher. The transfer requirements in Chapter V belong to the more serious category of infringements.

Beyond the financial penalties there are other consequences. A supervisory authority can order you to cease a transfer, which in practice may force you to replace a business-critical tool at short notice. Data subjects can claim damages, and a high-profile incident can damage the trust of customers and partners. For companies selling to the public sector or to larger enterprises, documented compliance is moreover often a requirement in tenders and contracts.

Recommended actions

Start by mapping your information flows. Go through the services and suppliers you use, the personal data being processed and where it can actually be accessed from – including remote access and sub-processors. Without this map it is impossible to know which transfers you are making.

For each transfer to a third country, establish a valid mechanism. Check whether the recipient country is covered by an adequacy decision, whether a US recipient is DPF-certified, or whether you need Standard Contractual Clauses or Binding Corporate Rules. Carry out a transfer impact assessment where the mechanism requires it and introduce supplementary measures where protection needs to be raised.

Review your data processing agreements so that they reflect reality and the entire chain of sub-processors. Build solutions that can withstand change, for example by keeping Standard Contractual Clauses as a fallback even when you rely on the DPF. Document your assessments – the ability to show how you reasoned is central both in supervisory matters and in business relationships. Finally, make the review recurring, since both supply chains and the legal position change over time.

Frequently asked questions about international data transfers

Is it enough that the supplier’s servers are within the EU?

No. Where the data is stored is only part of the picture. If staff or subcontractors in a third country can access the data, for example through remote support access, a transfer takes place even if the server stands within the EU. What matters is who can reach the data and from where.

Can we always rely on the EU-US Data Privacy Framework for US suppliers?

Only if the specific recipient is certified under the framework and the certification covers the processing in question. Transfers to non-certified US recipients require Standard Contractual Clauses or another mechanism. Since the legal position on the US has been changeable, it is wise to keep Standard Contractual Clauses as a fallback.

What is a transfer impact assessment?

It is an assessment of whether the recipient country’s law actually allows the protection in, for example, Standard Contractual Clauses to be upheld in practice. If the assessment shows that the protection is insufficient, you need to apply supplementary measures, such as encryption or pseudonymisation, before the transfer may take place.

Do we need to keep track of the supplier’s subcontractors?

Yes. As the controller you are responsible for the entire processing chain. Transfers often occur at sub-processors further down the chain, and without knowing who they are and where they sit you can neither assess nor document your transfers correctly.

Can we use consent as the basis for our data transfers?

Explicit consent is one of the GDPR derogations and can be used in specific situations. It is not intended, however, as a routine basis for ongoing, large-scale transfers and rarely holds up for a business-critical flow of information. For such flows a stable mechanism such as Standard Contractual Clauses is normally more suitable.

How often do we need to review our transfers?

There is no fixed deadline, but the review should be recurring and always carried out when things change – new suppliers, new sub-processors, new tools or a changed legal position. Because both supply chains and regulations evolve, a one-off review quickly becomes outdated.

Conclusion

International data transfers are not a niche problem for large corporate groups, but an issue that concerns virtually every company using modern cloud services. The challenge rarely lies in bad intentions and most often in the fact that nobody has asked the basic questions: what data is being processed, who can reach it and on what basis does it leave the EU. Those who map their flows, choose the right mechanism and document their assessments have come a long way – and avoid the unpleasant surprises when a supplier, a customer or a supervisory authority starts asking questions.

Lawgent helps companies map their data flows, choose the right transfer mechanism and build a data protection structure that holds even when the legal position changes. We combine experienced business-law advice with AI-driven efficiency, so that you achieve secure and documented compliance – faster and more cost-effectively than at a traditional firm. Want to know where your personal data actually goes and whether you comply with the GDPR? Contact Lawgent for a review of your international data transfers.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop