skip to content

Cross-Border Transfers and Penalties

Moving personal data outside the EEA requires an adequacy decision, standard contractual clauses, binding corporate rules or a narrow derogation, and getting it wrong sits in the higher fine tier. Interviewers raise it whenever the architecture involves a non-EU cloud region or subprocessor.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

questions

6

Under GDPR Chapter V, what routes can make a transfer of personal data to a third country lawful, and in what order?

level: juniorimportance: must knowfreq 62%

answer

  1. a second test on top of lawfulness
  2. country first, then safeguards
  3. SCCs, BCRs and friends
  4. derogations are the last resort

basics

~20 s

Under GDPR Chapter V, a transfer needs an adequacy decision (Art. 45), or appropriate safeguards such as SCCs or BCRs (Art. 46), or, as a narrow exception, an Art. 49 derogation. The rest of the Regulation must be met too.

solid answer

~50 s

**Art. 44** makes Chapter V a second test on top of the rest of the GDPR, and it covers onward transfers too. The routes are tiered. First, an **adequacy decision** under **Art. 45**: the Commission has found the destination adequate, and no specific authorisation is needed. Without one, **appropriate safeguards** under **Art. 46**, with enforceable data subject rights and effective remedies. Art. 46(2) lists safeguards that need no specific authorisation: **standard contractual clauses** adopted by the Commission, **binding corporate rules** (Art. 47), approved codes of conduct or certifications with binding commitments, and instruments between public bodies. Ad hoc contractual clauses under Art. 46(3) need the supervisory authority's authorisation. Only when neither exists do the **Art. 49 derogations** apply, such as explicit consent or necessity for a contract. The Regulation treats them as exceptions, not a routine basis.

go deeper

for a junior

Recall the three tiers in order: adequacy under Art. 45, safeguards under Art. 46 such as SCCs and BCRs, and derogations under Art. 49. Know that Chapter V sits on top of lawfulness.

for a middle

Explain which Art. 46 safeguards need no supervisory authorisation, why ad hoc clauses do, and why Art. 49 routes are exceptions for occasional transfers only.

for a senior

Show how the tier chosen affects resilience: adequacy can be suspended, SCCs need an assessment, derogations cannot carry a recurring flow. Plan a fallback for each transfer.

for a principal

Frame a transfer inventory where every flow names its Chapter V route, so a court ruling or suspended decision triggers a known switch rather than a scramble.

## Two tests, not one The GDPR asks two separate questions about personal data leaving the EU: 1. Is the processing lawful at all: principles, lawful basis, transparency, security? 2. If the data goes to a **third country** (outside the EEA) or an international organisation, is there a Chapter V route for the transfer? **Art. 44** says a transfer may take place only if, *"subject to the other provisions of this Regulation"*, the Chapter V conditions are met. It also covers **onward transfers**, from the first importer to another third country. A lawful basis does not make a transfer lawful, and a transfer mechanism does not supply a lawful basis. ## Tier 1: adequacy (Art. 45) Under **Art. 45(1)** a transfer may take place where the Commission has decided that the third country, a territory, one or more specified sectors, or the international organisation *"ensures an adequate level of protection"*. Such a transfer *"shall not require any specific authorisation."* - The Commission weighs rule of law, public-authority access to data, independent supervision and international commitments (Art. 45(2)). - Each decision has a **periodic review at least every four years** (Art. 45(3)). The Commission can **repeal, amend or suspend** a decision without retroactive effect (Art. 45(5)). If it does, Arts. 46-49 remain available (Art. 45(7)). - An adequacy decision can be partial. The EU-US Data Privacy Framework decision, for instance, covers only US organisations on its list. ## Tier 2: appropriate safeguards (Art. 46) Without adequacy, **Art. 46(1)** allows a transfer only if the controller or processor provides **appropriate safeguards** *and* enforceable data subject rights and effective legal remedies are available. | Safeguard | Provision | Supervisory authorisation needed? | |---|---|---| | Legally binding instrument between public authorities | Art. 46(2)(a) | no | | **Binding corporate rules** | Art. 46(2)(b), Art. 47 | no per transfer, but the BCRs themselves are approved | | **Standard data protection clauses** adopted by the Commission | Art. 46(2)(c) | no | | Standard clauses adopted by an authority and approved by the Commission | Art. 46(2)(d) | no | | Approved code of conduct + binding commitments of the importer | Art. 46(2)(e) | no | | Approved certification + binding commitments of the importer | Art. 46(2)(f) | no | | Ad hoc contractual clauses | Art. 46(3)(a) | **yes** | For a company-to-company transfer the practical choice is usually between the Commission's **standard contractual clauses (SCCs)**, currently those in Implementing Decision (EU) 2021/914, and BCRs within a group. ## Tier 3: derogations (Art. 49) **Art. 49(1)** applies only *"in the absence of"* an adequacy decision or Art. 46 safeguards. A transfer or set of transfers may then take place on one of these conditions: - **(a)** the data subject has **explicitly consented**, after being informed of the risks; - **(b)** necessary to perform a **contract with the data subject**, or pre-contractual steps at their request; - **(c)** necessary for a contract concluded **in the data subject's interest** with another person; - **(d)** necessary for **important reasons of public interest**, recognised in EU or Member State law (Art. 49(4)); - **(e)** necessary for **legal claims**; - **(f)** necessary to protect **vital interests** where the data subject cannot consent; - **(g)** made from a **public register**, within limits (Art. 49(2)). If none fits, a last-resort route remains: a transfer that is **not repetitive**, concerns a **limited number** of data subjects, is necessary for **compelling legitimate interests** not overridden by the data subject's rights, and follows an assessment with suitable safeguards. The controller must **inform the supervisory authority** and the data subject, and document the assessment in its **Art. 30 records** (Art. 49(6)). Public authorities exercising public powers cannot use points (a) to (c) or that fallback (Art. 49(3)). Recital 111 describes the contract and legal-claims derogations as covering transfers that are *occasional*, and Recital 113 says the compelling-legitimate-interests route is for *residual* cases. A daily data feed built on "necessary for a contract" or blanket consent misuses the tier. ## Why the order matters Getting the route wrong falls in the GDPR's higher fine tier. **Art. 83(5)(c)** covers infringements of Arts. 44-49: up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. The supervisory authority can also order the **suspension of data flows** to a third-country recipient under Art. 58(2)(j).

  • Under GDPR Art. 46(3), when do contractual clauses need a supervisory authority's approval?
    When they are ad hoc clauses the parties drafted themselves rather than the Commission's standard clauses. Art. 46(3)(a) makes those clauses subject to authorisation by the competent supervisory authority, applying the Art. 63 consistency mechanism (Art. 46(4)). Commission-adopted SCCs under Art. 46(2)(c) need no specific authorisation.
  • Under the GDPR, what happens to transfers if the Commission suspends an adequacy decision?
    Art. 45(5) repeals, amends or suspends a decision without retroactive effect, and Art. 45(7) says that is without prejudice to transfers under Arts. 46-49. Past transfers are not made unlawful, but new transfers need another route, usually SCCs with their Clause 14 assessment, or BCRs.

saying these in an interview costs you the question

  • If processing has a lawful basis, the transfer abroad needs nothing more.
  • Chapter V only governs the first hop out of the EU, not onward transfers.
  • Art. 49 explicit consent is an equal alternative to SCCs for routine transfers.
  • Any contract clause the parties write themselves counts as an Art. 46(2) safeguard.
  • An adequacy decision, once adopted, can never be reviewed or withdrawn.
open as a page

Under GDPR Art. 83, what is the maximum fine for an unlawful transfer, and how does 'whichever is higher' apply to a corporate group?

level: middleimportance: must knowfreq 56%

basics

~20 s

Under GDPR Art. 83(5)(c), infringing the transfer rules (Arts. 44-49) risks up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher. For a group, turnover is that of the whole undertaking under Arts. 101-102 TFEU.

open as a page

Under the GDPR, a contracted support desk in India views EU customer records hosted in the EU; is that a transfer, and what is needed?

level: middleimportance: must knowfreq 55%

basics

~20 s

Under the GDPR, making EU-hosted data viewable by a contractor in India is a transfer. Absent an adequacy decision, it needs Art. 46 safeguards, typically SCC Module Two with a Clause 14 assessment, plus notice to customers.

open as a page

Under the GDPR, when can an EU startup rely on the EU-US Data Privacy Framework to send personal data to a US-headquartered cloud provider?

level: middleimportance: should knowfreq 52%

basics

~20 s

Under Decision (EU) 2023/1795, only US organisations on the Data Privacy Framework List are adequate. The startup checks that the recipient is listed, current and covers the data type; otherwise it needs SCCs or another Art. 46 route.

open as a page

Under the GDPR, an EU subsidiary sends employee HR data to its US parent; which transfer mechanisms fit, and when are binding corporate rules worth it?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Under the GDPR an intra-group flow is still a transfer. It can rely on an HR-covering DPF listing, on SCCs chosen by role, or on Art. 47 BCRs, which pay off for groups with many entities and flows.

open as a page

Under the GDPR after Schrems II (case C-311/18), why may signing the 2021 standard contractual clauses not be enough to make a transfer lawful?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Under the GDPR, SCCs bind only exporter and importer, not the destination's authorities. After Schrems II, Clause 14 of the 2021 SCCs requires assessing local law, adding supplementary measures where needed, and suspending the transfer if protection cannot be ensured.

open as a page