Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. International Data Transfers Outside the EU (Chapter V)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 27/54 Part 3 — Lawfulness & Key Actors Advanced Reviewed 2026-08-23

International Data Transfers Outside the EU (Chapter V)

Transferring personal data outside the European Economic Area (EEA) is prohibited by default, unless a valid transfer mechanism is in place: an adequacy decision, Standard Contractual Clauses (SCCs),

Open in interactive reader
⚖️ Two-Tier Protection 🏛️ CJEU C-311/18 Schrems II

International Data Transfers Outside the EU (Chapter V)

⚡ In 30 seconds

Under Chapter V (Articles 44 to 50), personal data transferred outside the European Economic Area (EEA) must continue to enjoy a level of protection essentially equivalent to that guaranteed within the EU. Transfers are prohibited unless grounded on: 1. Adequacy decisions (Art. 45), 2. Appropriate safeguards (Art. 46, SCCs/BCRs), or 3. Strict statutory derogations (Art. 49).

Transfer Instrument Legal Mechanism Compliance Burden
Adequacy Decision (Art. 45) Formal Commission decision recognizing a third country's equivalent legal system. Direct data flow without prior authorization or additional safeguards (e.g. UK, Japan, DPF).
Standard Contractual Clauses (Art. 46) Commission-approved template clauses (Decision 2021/914) binding exporter and importer. Mandatory Transfer Impact Assessment (TIA); implementation of supplemental technical measures.
Binding Corporate Rules (Art. 47) Legally binding internal codes approved by competent DPAs for multinational groups. Substantial multi-year drafting and supervisory review process for intra-group data flows.
Derogations (Art. 49) Explicit consent, contract performance, legal claims, vital interests. Strictly confined to occasional, non-systematic transfers; cannot justify regular business ops.
⚡ Key Takeaways
  • Two-tier compliance test: lawful basis under Article 6 PLUS valid Chapter V transfer instrument.
  • Post-Schrems II: contractual clauses alone are insufficient if third-country intelligence agencies can intercept data.
  • Cloud hosting in the EU with administrative console access from the US or India legally constitutes a transfer.
⚠️ Common Pitfall

Relying on Article 49 consent for permanent, routine daily cloud storage transfers to foreign SaaS vendors.

🛠️ In Practice

Perform a documented Transfer Impact Assessment (TIA) for every third-country SaaS vendor, ensuring end-to-end encryption with keys retained in the EU.

⚖️ Official Sources: Articles 44 to 50 GDPR · CJEU C-311/18 Schrems II · EDPB Recommendations 01/2020 on Supplementary Measures ✓ Legal review: 23 August 2026

✓ Key takeaways

  • An adequacy decision by the European Commission permits transfers without additional authorizations (e.g. UK, Switzerland, EU-US DPF).
  • SCC transfers mandate a Transfer Impact Assessment (TIA) evaluating destination state surveillance laws (Schrems II).
  • Derogations under Article 49 (e.g. explicit consent) are strictly limited to occasional, non-repetitive transfers.

⚠ Common pitfall: Assuming that intra-group transfers between parent and overseas subsidiaries are exempt from Chapter V transfer tools.

→ Actionable practice: Audit server infrastructure and remote IT support access: remote viewing of EU data from a third country legally constitutes a transfer.

← Subcontracting & Data Processing Agreements (Art. 28) Legitimate Interests & The Balancing Test (LIA) (Art. 6.1.f) →