CIPP/E Study Guide
Ch 12.1 - Limitations on international transfers

The general restriction on transfers outside the EEA

The GDPR lets personal data flow freely between member states, but transfers to any country outside the EEA are restricted. A transfer to a third country (or an international organisation) is only lawful if one of three conditions in Chapter 5 of the GDPR is met: an adequacy decision, appropriate safeguards, or a derogation. The aim is to stop the EU's level of protection being undermined once data leaves Europe.

One objective of the GDPR is the free flow of personal data between member states. But the GDPR treats transfers to countries outside the EEA as needing special care. Transfers to a third country may only take place subject to the conditions of Chapter 5.

  1. The third country ensures an adequacy decision|adequate level of protection as determined by the European Commission; or
  2. In the absence of adequacy, the controller or processor provides appropriate safeguards - on condition that enforceable data subject rights and effective legal remedies are available; or
  3. In the absence of adequacy or safeguards, the transfer fits within one of the derogation|derogations for specific situations.
Same rule for international organisations

The same restriction applies to transfers to an international organisation - a body governed by public international law or set up by agreement between two or more countries.

Recital 101 recognises cross-border flows are necessary for international trade, but says the EU's level of protection must not be undermined. In effect this imposes EU data protection standards on jurisdictions outside Europe, and is seen as a barrier to international commerce.

Key terms - quick answers

What is “Third country”?
Any country outside the European Economic Area (EEA).
What is “International organisation”?
An organisation and its subordinate bodies governed by public international law, or any body set up by or on the basis of an agreement between two or more countries.
What is “Chapter 5 of the GDPR”?
The chapter governing transfers of personal data to third countries and international organisations.
What is “Adequacy decision”?
A Commission decision that a third country ensures an adequate level of protection, allowing transfers without further authorisation.