Skip to content
Call, 0511 – 47 55 58 11

Transferring data to third countries

A transfer to a third country needs two things: a legal basis for the processing and, on top of that, a transfer instrument under Chapter V GDPR. Neither replaces the other.

The most common mistake lies not in choosing the instrument but before that. A transfer is not recognised as one at all, because the servers sit in Europe and access from the third country is only a side clause in the contract.

Two levels, both to be settled

Legal basis

  • Follows Art. 6 and, where relevant, Art. 9 GDPR
  • Answers whether the processing is permitted at all
  • Applies regardless of where processing happens
  • Without it, even the best transfer instrument does not help

Transfer instrument

  • Adequacy decision, standard contractual clauses or binding corporate rules
  • Answers whether the data takes the level of protection with it
  • With standard clauses, an assessment of the destination country is added
  • Where the assessment reveals gaps, supplementary measures are needed

How we proceed

  1. Step 1: Find the transfers

    We work through the chain of service providers, including support, remote maintenance and sub-processors. Server location alone says little.

  2. Step 2: Choose the instrument

    An adequacy decision where one applies, otherwise standard contractual clauses or binding corporate rules within a group.

  3. Step 3: Assess the destination country

    Does the law there permit the level of protection promised? That assessment has to be documented even where it produces an unproblematic result.

  4. Step 4: Supplementary measures

    Where gaps remain, technical and organisational measures are added, such as encryption with the keys held in Europe or pseudonymisation before transfer.

How we support you

We map the transfers, choose the instrument, carry out the assessment of the destination country and negotiate the contractual commitments with the provider. Where an adequacy decision carries the transfer, we also set out what would have to happen if it fell away.

A provider with access from abroad?

We check whether the transfer has been recognised and secured.

Get in touch

Frequently asked questions

When is there a transfer at all?

Not only when data physically leaves the country. It is enough that access is possible from a third country, for instance in support or remote maintenance. That possibility of access is frequently overlooked in contracts because the servers sit in Europe.

Are standard contractual clauses enough?

They are the instrument, not the answer. Under the case law of the Court of Justice you also have to assess whether the law of the destination country actually permits the level of protection the clauses promise. Where the assessment reveals gaps, supplementary measures are needed, such as encryption with the keys held in Europe.

What about providers from the United States?

For providers certified under an adequacy decision in force, no separate instrument is required. What remains to be checked is whether the certification covers the specific service and still stands. Adequacy decisions have repeatedly been annulled in the past, so a fallback scenario belongs in the planning.

Related