Article 46 GDPR : Appropriate Safeguards for International Transfers
In the absence of an adequacy decision, Article 46 GDPR enables regular transfer safeguards — public instruments, BCRs, SCCs, codes of conduct, or certification — provided enforceable data subject rights, effective legal remedies, and where necessary a third-country transfer impact assessment (TIA) with supplementary measures are established.
1. Position of Article 46 in Chapter V
In the absence of an adequacy decision under Article 45, a controller or processor may transfer personal data to a third country or an international organisation under Article 46 only if appropriate safeguards are provided, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Article 46 governs structural, ongoing transfer mechanisms; statutory derogations under Article 49 remain strictly exceptional.
2. Available Appropriate Safeguards
The choice of mechanism depends on the contracting parties, the processing supply chain, and the legal status of the data importer. Without requiring any specific authorisation from a supervisory authority, Article 46(2) provides for:
- A legally binding and enforceable instrument between public authorities or bodies;
- Binding corporate rules (BCRs) approved in accordance with Article 47 for intra-group transfers;
- Standard data protection contractual clauses adopted by the Commission or by a supervisory authority and approved by the Commission (SCCs);
- An approved code of conduct pursuant to Article 40, together with binding and enforceable commitments of the importer to apply appropriate safeguards;
- An approved certification mechanism pursuant to Article 42, together with binding and enforceable commitments of the importer.
Subject to the explicit authorisation from the competent supervisory authority, Article 46(3) also allows contractual clauses agreed between exporter and importer, and provisions to be inserted into administrative arrangements between public authorities providing enforceable rights.
3. Article 46(2)(f) Certification: The Europrivacy v82 Benchmark
Opinion 15/2026, adopted on 15 April 2026, approved the criteria of the Europrivacy extension designed for data importers established outside the EEA not directly subject to the GDPR under Article 3(2). On 6 August 2026, this extension v2.0 (also designated v82) was published in the EDPB register as an approved European Data Protection Seal usable as a transfer mechanism under Article 46(2)(f).
- Certification is voluntary and applies to a defined processing perimeter; organisations must verify the certificate, its scope, validity, and accredited certification body;
- The importer must enter into binding and enforceable commitments covering appropriate safeguards, data subject rights, and effective legal remedies;
- Certification does not replace other Chapter V obligations, the controller's accountability, or the ongoing oversight of the processor chain.
A distinction must be drawn between the Article 46 Europrivacy extension for third-country importers and the general Article 42 Europrivacy seal: the latter demonstrates GDPR compliance within the Union, but does not in itself constitute an international transfer tool.
4. Third-Country Legal Assessment and Supplementary Measures (TIA)
Regardless of the transfer tool selected, the data exporter must assess whether the legislation or practices of the third country may impinge on the effectiveness of the appropriate safeguards. Where such risks exist, a documented Transfer Impact Assessment (TIA) is required and supplementary technical, contractual, or organisational measures must ensure an essentially equivalent level of protection.
- Map all data flows, remote accesses, sub-processors, categories of data, and processing purposes;
- Assess the legal order and surveillance practices of the destination third country in relation to the specific transfer;
- Verify the technical effectiveness of supplementary safeguards, notably encryption key custody and data minimisation;
- Suspend the transfer or terminate the processing agreement if safeguards cannot be effectively respected in practice.
5. Documentary Action Plan for International Transfers
- First qualify the existence of an international transfer and ascertain whether an adequacy decision applies;
- Select an appropriate Article 46 safeguard without defaulting systematically to SCCs alone;
- Document the scope of the instrument, importer commitments, enforceable rights, and legal remedies;
- Perform and regularly update the third-country assessment and supplementary technical measures where required;
- Record the transfer in the Article 30 register, update privacy notices, and establish periodic compliance audits.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Invalidation du Privacy Shield, exigence d'évaluation d'impact des transferts (TIA) et mesures supplémentaires pour les CCT
Consult official source →Transferts internationaux (Chapitre V), champ d'application Art. 3, critères d'exportation
Consult official source →Évaluation du droit du pays tiers et mesures supplémentaires pour maintenir un niveau de protection essentiellement équivalent
Consult official source →Clauses contractuelles types de 2021 et garanties appropriées pour les transferts vers les pays tiers
Consult official source →Approbation des critères Europrivacy comme label européen de protection des données utilisable pour les transferts au titre des articles 42 et 46(2)(f) RGPD
Consult official source →Critères v82 du label européen de protection des données pour les responsables ou sous-traitants hors EEE agissant comme importateurs de données — outil de transfert Art. 46(2)(f)
Consult official source →See Also in the Legal Framework
CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU
CJEU judgment of 16 July 2020 (Schrems II): invalidation of Privacy Shield, conditional validity of SCCs and mandatory T...
Article 32 GDPR : Security of Processing Through Risk-Appropriate Measures
Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restor...
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...