CIPP/E Study Guide
IAPP Training · Module 7 - BoK III.D

Module 7 · The landscape: three options in order

When personal data leaves the EEA (the EU plus Iceland, Liechtenstein and Norway) it must stay protected to an EU-equivalent standard, and this applies to onward transfers too. First confirm there is an Article 6 legal basis to process at all. Then work through the transfer mechanisms strictly in order: (1) adequacy decisions, (2) appropriate safeguards, (3) derogations. The controller must also inform data subjects about the transfer - whether or not an adequacy decision exists, and which safeguards are used.

A transfer of personal data out of the EEA is only allowed if protection travels with the data. The GDPR sets up a clear hierarchy. You do not get to pick freely - you consider the mechanisms in order.

  1. First, check there is an Article 6 legal basis - a transfer mechanism is not a substitute for a lawful basis to process.
  2. (1) Is there an adequacy decision for the destination country? If yes, no extra safeguards needed.
  3. (2) If not, can you use appropriate safeguards (SCCs, BCRs, codes/certification, ad hoc clauses, international agreements)?
  4. (3) Only if neither applies, can a derogation under Article 49 justify the transfer?
Burn this in

The order is fixed: adequacy → appropriate safeguards → derogations. Derogations are a last resort, not an alternative you reach for first. And the controller must always inform data subjects about the transfer and the safeguard used.

The duty to protect follows the data even after it arrives - onward transfers from the first recipient to a further party must also meet the adequate-protection standard.

Key terms - quick answers

What is “EEA”?
European Economic Area - the EU plus Iceland, Liechtenstein and Norway. GDPR transfer rules apply to data leaving this zone.
What is “Onward transfer”?
A further transfer of the data by the original recipient to yet another country or party. It must also be protected to an adequate standard.
What is “Article 6 legal basis”?
A lawful ground to process the data in the first place (e.g. consent, contract, legitimate interests). Needed before any transfer mechanism is even considered.
What is “Adequacy decision”?
A European Commission ruling that a third country offers essentially equivalent protection, so no extra safeguards are needed.