GDPR Update: Transfer of Personal Data (outside the EEA)

by Dentons



In this GDPR update, we will address the transfer of personal data outside the European Economic Area (EEA).

Similar as under the current Data Privacy Directive 95/46/EC (the Directive), the transfer of personal data outside the EEA remains restricted under the General Data Protection Regulation (the GDPR). However, the GDPR introduces several changes in this respect, including new derogations for the cross-border data transfers.

Adequate level of protection

As a general rule, the transfer of personal data to a country outside the EEA (generally referred to as a “third country”) may only take place if that country ensures an adequate level of data protection.

The European Commission (the Commission) has the power to determine that a third country, a territory or a specified sector within that third country, or an international organisation ensures an adequate level of protection for data transfers. After the Commission has recognised a third country as providing an adequate level of protection, personal data can be transferred without any further protective measures or authorisation. The GDPR obliges the Commission to review its adequacy decisions at least every four years.

In determining whether a third country, territory or specified sector or an international organisation ensures an adequate level of protection, the Commission will take into account, inter alia:

  1. the rule of law, respect for human rights and relevant legislation e.g. with regard to (the (onward) transfers of) personal data and the effective and enforceable data subject rights;
  2. the existence and effective functioning of one or more independent supervisory authorities, with authority and responsibility for ensuring and enforcing compliance with the data protection rules; and
  3. international commitments by the third country or international organisation, or other obligations arising from legally binding conventions or instruments in relation to the protection of personal data.

The existing adequacy decisions by (including notably the decision on the EU - US Privacy Shield), adopted by the Commission under the Directive, shall remain in force until amended, replaced or repealed by the Commission in accordance with the GDPR.

Transfer of personal data to third countries that do not ensure an adequate level of protection

In the absence of an adequacy decision by the Commission, personal data may only be transferred to a third country if (i) the controller or processor provides appropriate safeguards, and (ii) enforceable data subject rights and effective legal remedies for data subjects are available.

These safeguards may be provided, without requiring any specific authorisation from a supervisory authority, by:

  1. a legally binding and enforceable instrument between public authorities or bodies;
  2. Binding Corporate Rules;
  3. standard contractual clauses adopted by the Commission;
  4. standard contractual clauses adopted by the supervisory authority and approved by the Commission;
  5. approved codes of conduct; and
  6. approved certification mechanisms.

Below, we will address the three safeguards that in practice are likely to be the most relevant.

Binding Corporate Rules

Binding Corporate Rules (BCRs) are internal rules adopted by a multinational group of undertakings which define its global policy with regard to the international transfers of personal data within the same corporate group to entities in countries which do not provide an adequate level of protection.

Under the GDPR, BCRs must:

  1. be approved by the competent (lead) supervisory authority;
  2. be legally binding and apply to and are enforced by every member concerned of the group of undertakings;
  3. confer enforceable rights on data subjects with regard to the processing of their personal data; and
  4. contain specific information on, inter alia: (a) the structure and contact details of the group; (b) the data transfers including the categories of personal data; (c) the type of processing and its purposes; (d) the type of data subjects affected; (e) the identification of the third countries in question; (f) the application of the general data protection principles; (g) the rights of the data subjects; (h) the acceptance of liability by the controller or processor established in the EU for any breaches of the BCRs by a group member not established in the EU; (i) the tasks of the data protection officer; and (j) the complaint procedures.

Standard contractual clauses adopted or approved by the Commission

The transfer of personal data to a third country that does not provide an adequate level of protection is also allowed if standard contractual clauses adopted by the Commission or by a supervisory authority (and approved by the Commission) are used.

The GDPR explicitly states that standard contractual clauses can be included in a wider agreement and parties are allowed to add other clauses or safeguards, provided that they do not contradict the standard contractual clauses or prejudice the data subjects’ fundamental rights or freedoms.

Ad hoc contractual clauses may also be used, but these require supervisory authority approval prior to the cross-border transfer.

The Commission has currently issued three sets of standard contractual clauses: two sets for transfers from data controllers established in the EEA to data controllers established outside the EEA and one set for the transfer from data controllers established in the EEA to processors established outside the EEA. No standard contractual clauses exist for the cross-border transfer from processors established in the EEA to sub-processors established outside the EEA.

The approved sets of standard contractual clauses remain valid, but the GDPR leaves open the possibility for these sets to be repealed (and replaced by a new set of standard contractual clauses).

Approved codes of conduct

Under the GDPR, the use of codes of conduct is encouraged to serve as a tool to demonstrate compliance with the GDPR. Codes of conduct may also serve as appropriate safeguards for the cross-border transfer of personal data.

Codes of conducts may be prepared by associations or other bodies representing controllers or processors and must be submitted to the supervisory authority for prior approval.

Adherence to an approved code of conduct combined with commitments by a controller or processor outside the EEA to apply the appropriate safeguards, can demonstrate that the controller or processor outside the EEA has implemented adequate safeguards.

Derogations for specific situations

The GDPR contains various derogations from the prohibition to transfer personal data outside the EEA without adequate protection. These derogations are largely similar to the derogations under the Directive. The derogations apply when:

  1. the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards (i.e. it is insufficient to just mention that data will be transferred to a third country);
  2. the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject's request;
  3. the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and a third party;
  4. the transfer is necessary for important reasons of public interest;
  5. the transfer is necessary for the establishment, exercise or defence of legal claims;
  6. the transfer is necessary to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent; and
  7. the transfer is made from a register that, according to EU or member state law, is intended to provide information to the public and that is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions set out in Union or Member State law for consultation are fulfilled in the particular case.

Finally, if the transfer cannot be based on standard contractual clauses, BCRs or any of the other derogations set out above, the transfer may take place if:

  1. it is not repetitive;
  2. concerns only a limited number of data subjects;
  3. is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests and freedoms of the data subjects;
  4. the controller has assessed all circumstances and has provided suitable safeguards;
  5. the controller informs the supervisory authority of the transfer.

This final derogation allows for some flexibility but also requires a careful assessment and proper documentation and should only be applied as an exception.

Practical recommendations

Failure to comply with the GDPRs’ provisions on data transfers to third countries are subject to fines up to EUR 20,000,000 or 4% of the total worldwide annual turnover, whichever is higher. Therefore, organisations would do well to review and map (key) cross-border data flows and assess whether the current cross-border mechanisms continue to be appropriate.

In general we do not recommend relying on consent for your onward transfers of personal data. Data subjects can withdraw their consent at any time and if they do, you no longer have a valid basis for the transfer of personal data outside the EEA. As data storage becomes more and more cloud based and may be stored in various data centres across the world (which may not even be the same data centre every time), having to deal with withdrawal of consent may create a complex and time-consuming puzzle. Where possible, it is better to rely on other forms of safeguards, such as BCRs or model clauses, or to store data within the EEA and avoid onwards transfers.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Dentons | Attorney Advertising

Written by:


Dentons on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
Sign up using*

Already signed up? Log in here

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
Privacy Policy (Updated: October 8, 2015):

JD Supra provides users with access to its legal industry publishing services (the "Service") through its website (the "Website") as well as through other sources. Our policies with regard to data collection and use of personal information of users of the Service, regardless of the manner in which users access the Service, and visitors to the Website are set forth in this statement ("Policy"). By using the Service, you signify your acceptance of this Policy.

Information Collection and Use by JD Supra

JD Supra collects users' names, companies, titles, e-mail address and industry. JD Supra also tracks the pages that users visit, logs IP addresses and aggregates non-personally identifiable user data and browser type. This data is gathered using cookies and other technologies.

The information and data collected is used to authenticate users and to send notifications relating to the Service, including email alerts to which users have subscribed; to manage the Service and Website, to improve the Service and to customize the user's experience. This information is also provided to the authors of the content to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

JD Supra does not sell, rent or otherwise provide your details to third parties, other than to the authors of the content on JD Supra.

If you prefer not to enable cookies, you may change your browser settings to disable cookies; however, please note that rejecting cookies while visiting the Website may result in certain parts of the Website not operating correctly or as efficiently as if cookies were allowed.

Email Choice/Opt-out

Users who opt in to receive emails may choose to no longer receive e-mail updates and newsletters by selecting the "opt-out of future email" option in the email they receive from JD Supra or in their JD Supra account management screen.


JD Supra takes reasonable precautions to insure that user information is kept private. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. However, please note that no method of transmitting or storing data is completely secure and we cannot guarantee the security of user information. Unauthorized entry or use, hardware or software failure, and other factors may compromise the security of user information at any time.

If you have reason to believe that your interaction with us is no longer secure, you must immediately notify us of the problem by contacting us at In the unlikely event that we believe that the security of your user information in our possession or control may have been compromised, we may seek to notify you of that development and, if so, will endeavor to do so as promptly as practicable under the circumstances.

Sharing and Disclosure of Information JD Supra Collects

Except as otherwise described in this privacy statement, JD Supra will not disclose personal information to any third party unless we believe that disclosure is necessary to: (1) comply with applicable laws; (2) respond to governmental inquiries or requests; (3) comply with valid legal process; (4) protect the rights, privacy, safety or property of JD Supra, users of the Service, Website visitors or the public; (5) permit us to pursue available remedies or limit the damages that we may sustain; and (6) enforce our Terms & Conditions of Use.

In the event there is a change in the corporate structure of JD Supra such as, but not limited to, merger, consolidation, sale, liquidation or transfer of substantial assets, JD Supra may, in its sole discretion, transfer, sell or assign information collected on and through the Service to one or more affiliated or unaffiliated third parties.

Links to Other Websites

This Website and the Service may contain links to other websites. The operator of such other websites may collect information about you, including through cookies or other technologies. If you are using the Service through the Website and link to another site, you will leave the Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We shall have no responsibility or liability for your visitation to, and the data collection and use practices of, such other sites. This Policy applies solely to the information collected in connection with your use of this Website and does not apply to any practices conducted offline or in connection with any other websites.

Changes in Our Privacy Policy

We reserve the right to change this Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our privacy policy will become effective upon posting of the revised policy on the Website. By continuing to use the Service or Website following such changes, you will be deemed to have agreed to such changes. If you do not agree with the terms of this Policy, as it may be amended from time to time, in whole or part, please do not continue using the Service or the Website.

Contacting JD Supra

If you have any questions about this privacy statement, the practices of this site, your dealings with this Web site, or if you would like to change any of the information you have provided to us, please contact us at:

- hide
*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.