Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 46 (Transfer safeguards)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Article 46 GDPR : Appropriate Safeguards for International Transfers

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

In the absence of an adequacy decision, Article 46 GDPR enables regular transfer safeguards — public instruments, BCRs, SCCs, codes of conduct, or certification — provided enforceable data subject rights, effective legal remedies, and where necessary a third-country transfer impact assessment (TIA) with supplementary measures are established.

1. Position of Article 46 in Chapter V

In the absence of an adequacy decision under Article 45, a controller or processor may transfer personal data to a third country or an international organisation under Article 46 only if appropriate safeguards are provided, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Article 46 governs structural, ongoing transfer mechanisms; statutory derogations under Article 49 remain strictly exceptional.

2. Available Appropriate Safeguards

The choice of mechanism depends on the contracting parties, the processing supply chain, and the legal status of the data importer. Without requiring any specific authorisation from a supervisory authority, Article 46(2) provides for:

  • A legally binding and enforceable instrument between public authorities or bodies;
  • Binding corporate rules (BCRs) approved in accordance with Article 47 for intra-group transfers;
  • Standard data protection contractual clauses adopted by the Commission or by a supervisory authority and approved by the Commission (SCCs);
  • An approved code of conduct pursuant to Article 40, together with binding and enforceable commitments of the importer to apply appropriate safeguards;
  • An approved certification mechanism pursuant to Article 42, together with binding and enforceable commitments of the importer.

Subject to the explicit authorisation from the competent supervisory authority, Article 46(3) also allows contractual clauses agreed between exporter and importer, and provisions to be inserted into administrative arrangements between public authorities providing enforceable rights.

3. Article 46(2)(f) Certification: The Europrivacy v82 Benchmark

Opinion 15/2026, adopted on 15 April 2026, approved the criteria of the Europrivacy extension designed for data importers established outside the EEA not directly subject to the GDPR under Article 3(2). On 6 August 2026, this extension v2.0 (also designated v82) was published in the EDPB register as an approved European Data Protection Seal usable as a transfer mechanism under Article 46(2)(f).

  • Certification is voluntary and applies to a defined processing perimeter; organisations must verify the certificate, its scope, validity, and accredited certification body;
  • The importer must enter into binding and enforceable commitments covering appropriate safeguards, data subject rights, and effective legal remedies;
  • Certification does not replace other Chapter V obligations, the controller's accountability, or the ongoing oversight of the processor chain.

A distinction must be drawn between the Article 46 Europrivacy extension for third-country importers and the general Article 42 Europrivacy seal: the latter demonstrates GDPR compliance within the Union, but does not in itself constitute an international transfer tool.

4. Third-Country Legal Assessment and Supplementary Measures (TIA)

Regardless of the transfer tool selected, the data exporter must assess whether the legislation or practices of the third country may impinge on the effectiveness of the appropriate safeguards. Where such risks exist, a documented Transfer Impact Assessment (TIA) is required and supplementary technical, contractual, or organisational measures must ensure an essentially equivalent level of protection.

  • Map all data flows, remote accesses, sub-processors, categories of data, and processing purposes;
  • Assess the legal order and surveillance practices of the destination third country in relation to the specific transfer;
  • Verify the technical effectiveness of supplementary safeguards, notably encryption key custody and data minimisation;
  • Suspend the transfer or terminate the processing agreement if safeguards cannot be effectively respected in practice.

5. Documentary Action Plan for International Transfers

  • First qualify the existence of an international transfer and ascertain whether an adequacy decision applies;
  • Select an appropriate Article 46 safeguard without defaulting systematically to SCCs alone;
  • Document the scope of the instrument, importer commitments, enforceable rights, and legal remedies;
  • Perform and regularly update the third-country assessment and supplementary technical measures where required;
  • Record the transfer in the Article 30 register, update privacy notices, and establish periodic compliance audits.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
⚖️ Binding Source
Schrems II (16 juil. 2020) · ECLI: ECLI:EU:C:2020:559

Invalidation du Privacy Shield, exigence d'évaluation d'impact des transferts (TIA) et mesures supplémentaires pour les CCT

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V

Transferts internationaux (Chapitre V), champ d'application Art. 3, critères d'exportation

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Recommendations 01/2020 on measures that supplement transfer tools · 2021-06-18

Évaluation du droit du pays tiers et mesures supplémentaires pour maintenir un niveau de protection essentiellement équivalent

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Standard Contractual Clauses for international transfers · 2021-06-04

Clauses contractuelles types de 2021 et garanties appropriées pour les transferts vers les pays tiers

Consult official source →
💡 EDPB Art. 64 Opinion
Opinion 15/2026 on the Europrivacy certification criteria as a tool for transfers · 2026-04-15

Approbation des critères Europrivacy comme label européen de protection des données utilisable pour les transferts au titre des articles 42 et 46(2)(f) RGPD

Consult official source →
⚖️ Official Reference
Europrivacy Certification Scheme Extension for Certifying Data Importers under Article 46 · 2026-08-06

Critères v82 du label européen de protection des données pour les responsables ou sous-traitants hors EEE agissant comme importateurs de données — outil de transfert Art. 46(2)(f)

Consult official source →

See Also in the Legal Framework

CJEU Schrems II CJEU Case Law

CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU

CJEU judgment of 16 July 2020 (Schrems II): invalidation of Privacy Shield, conditional validity of SCCs and mandatory T...

View document
Article 32 GDPR Official Text

Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures

Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...

View document
Article 35 GDPR Official Text

Article 35 GDPR : Criteria and Methodology of the DPIA

Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-30 Last modified: 2026-08-30

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice