Transfers to Third Countries (Data Export)
When personal data are transferred to a third country, which assessment framework applies and which instruments establish an adequate level of protection. Overview of Chapter V of the GDPR (Articles 44 to 49 GDPR) covering derogations, standard contractual clauses, the Data Privacy Framework and Binding Corporate Rules.
Where personal data are transferred to a country outside the EU and the European Economic Area, additional requirements apply (Chapter V of the GDPR, Articles 44 to 49 GDPR). The rationale is that the level of protection afforded by the GDPR must be maintained even where the data leave the immediate scope of EU law. This page explains when a data export actually occurs and guides you through the assessment framework. The individual instruments are dealt with on the subpages.
Key takeaways
- A data export already occurs where a recipient in a third country is able to access the data; the physical storage location is irrelevant (Article 44 GDPR).
- First question: is the transfer directed to an unsafe third country (no adequacy decision of the European Commission)? Within the EU/EEA and to safe third countries, no special requirements apply.
- If no derogation under Article 49 GDPR applies, an adequate level of protection must be established by means of appropriate safeguards: in practice the Data Privacy Framework (US only), the EU standard contractual clauses together with a transfer impact assessment, or Binding Corporate Rules (intra-group only).
- The appropriate safeguards do not replace the legal basis under Article 6 GDPR; both must be in place.
- Every data export must be documented in the records of processing activities (Article 30 GDPR) and disclosed transparently in the privacy notice (Article 13(1)(f) GDPR).
1. When does a data export occur
Three conditions must coincide for the special rules of Chapter V to apply: there must be (3.) a transfer of (1.) personal data (2.) to a recipient in an unsafe third country. If one of these conditions is not met, the transfer is to be treated like a transfer within Germany.
1.1 Transfer: the possibility of access is sufficient
For a transfer to exist, it is sufficient that a recipient in the third country accesses or is able to access the personal data. Actual access is not required. This covers in particular sending data by post or as an email attachment, granting access rights, and operating servers on which the data are stored.
The storage location of the data is not a decisive criterion. In legal terms, a transfer also takes place where the data are physically stored on computers in the EU but a company in the third country is able to access them, or where the contractual partner is a company in the third country.
A transfer also exists where it is not the company itself that passes the data to the third country, but a processor in the EU which in turn engages a sub-processor in the third country. That transfer is attributed to the controller; the controller remains responsible and must ensure that the requirements of Chapter V are met.
Intra-group access likewise constitutes a transfer: where group companies outside the EU/EEA are granted access to personal data (for example to central HR or CRM systems), a transfer to a third country occurs. There is no group privilege.
By contrast, there is no transfer where the access takes place within the same legal person. If other departments of the same company access the data, or if an employee retrieves the data while on a business trip in a third country, there is no disclosure to another recipient. The decisive factor is the boundary of the legal person, not the place where the person happens to be.
1.2 Third country and unsafe third country
A third country is any country outside the EU and the European Economic Area. In addition to the EU Member States, the EEA comprises Iceland, Norway and Liechtenstein; transfers to those countries are to be treated like domestic transfers.
Within the group of third countries, a further distinction must be drawn:
- Safe third country: an adequacy decision of the European Commission under Article 45 GDPR exists for that country. The European Commission has determined that the country ensures an adequate level of protection. The transfer is then to be treated like a domestic transfer; additional safeguards are not required.
- Unsafe third country: no adequacy decision exists for that country. Here the special requirements of Chapter V apply. Unsafe third countries include, for example, China, Russia, India and Mexico.
The following overview shows the countries covered by an adequacy decision. The position may change; what is decisive is the current list published by the European Commission.
| Safe third country | Note |
|---|---|
| United Kingdom | since July 2021 |
| South Korea | since December 2021 |
| Switzerland, Canada, Israel, Japan, New Zealand, Argentina, Uruguay, Andorra, Faroe Islands, Guernsey, Isle of Man, Jersey | adequacy decision |
| United States | only for recipients certified under the Data Privacy Framework |
The United States is therefore a special case: it is not a safe third country across the board. An adequacy decision exists only for recipients that are certified under the EU-US Data Privacy Framework. Transfers to non-certified US recipients remain transfers to an unsafe third country.
1.3 Personal data
This covers all information that can be attributed to a natural person. Even simple details such as name, function, business email address or contact details of employees, customers or business partners fall within this scope, as do access credentials and the content of emails and chats.
Pseudonymized or encrypted data also remain personal data as long as the link to a person can be restored. The special rules of Chapter V therefore apply to them as well. Pseudonymization or encryption may, however, be taken into account as a protective measure within the transfer impact assessment.
2. The assessment framework
Once it is established that personal data are being transferred to an unsafe third country, whether and how the transfer is permissible is assessed in three stages.
- Stage 1: is there a transfer to an unsafe third country? If the transfer goes to the EU, the EEA or a safe third country, no special requirements apply (see section 1).
- Stage 2: does a derogation under Article 49 GDPR apply? The derogations are to be interpreted narrowly and generally justify only occasional transfers. For details, see the subpage Derogations under Article 49 GDPR.
- Stage 3: how is an adequate level of protection established? If no derogation applies, appropriate safeguards under Article 46 GDPR are required. In practice, three instruments come into consideration: the Data Privacy Framework (only for certified US recipients), the EU standard contractual clauses together with a transfer impact assessment or, exclusively for intra-group transfers, Binding Corporate Rules.
3. Overview of the appropriate safeguards under Article 46
Where neither an adequacy decision nor a derogation applies, the adequate level of protection must be established by way of an appropriate safeguard under Article 46 GDPR. The GDPR provides several instruments for this purpose. They fall into safeguards that require no authorization and safeguards that are subject to authorization.
Not subject to authorization (Article 46(2) GDPR), that is, usable without a separate authorization from the supervisory authority:
- a legally binding and enforceable instrument between public authorities or bodies (point (a)),
- Binding Corporate Rules under Article 47 GDPR (point (b)),
- standard contractual clauses adopted by the European Commission (point (c)),
- standard data protection clauses adopted by a supervisory authority and approved by the Commission (point (d)),
- an approved code of conduct under Article 40 GDPR together with binding commitments of the recipient (point (e)),
- an approved certification mechanism under Article 42 GDPR together with binding commitments of the recipient (point (f)).
Subject to authorization (Article 46(3) GDPR), that is, usable only with the prior authorization of the supervisory authority: individually negotiated contractual clauses between the exporter and the importer, as well as provisions in administrative arrangements between public authorities. Because of the considerable review effort involved, these play hardly any role in practice.
In corporate practice, three instruments carry the load: the Data Privacy Framework (certified US recipients only), the EU standard contractual clauses and, exclusively for intra-group purposes, Binding Corporate Rules. These are dealt with on the subpages.
An adequacy decision and appropriate safeguards are not mutually exclusive. Even a party transferring data to a safe third country or to a certified US recipient may base the transfer on appropriate safeguards instead or in addition, for example in order to remain independent of an adequacy decision that is open to challenge.
4. Accompanying obligations
A permissible data export is not exhausted by the choice of the right instrument. Three obligations are added to it:
- A separate legal basis is required (two-stage assessment). The supervisory authorities understand the lawfulness of a data export as a two-stage assessment. At the first stage, the transfer must, like any processing operation, be covered by a legal basis under Article 6 GDPR. At the second stage, an adequate level of protection in the third country must additionally be ensured. The appropriate safeguards under Article 46 GDPR and a certification under the Data Privacy Framework concern only the second stage; they do not replace the legal basis required at the first stage.
- Documentation in the records of processing activities. Transfers to third countries must be documented in the records of processing activities (Article 30 GDPR), including the destination country and the basis of the transfer (adequacy decision, derogation or appropriate safeguard).
- Transparency towards data subjects. The privacy notice must state that data are transferred to a third country, to which country, and whether an adequacy decision exists or how an adequate level of protection is otherwise established (Article 13(1)(f) GDPR). This information obligation is unaffected by the derogations in Article 49 GDPR.
5. Structure of this chapter
Derogations Under Article 49 GDPR
When a transfer is permissible without appropriate safeguards: consent, performance of a contract, legal claims, public interest; narrow interpretation, occasional transfers only.
Standard Contractual Clauses and Transfer Impact Assessment
The four modules of the EU standard contractual clauses, their conclusion and the relevant constellations, as well as the three-step case-by-case assessment (TIA).
EU-US Data Privacy Framework
Adequacy decision for certified US recipients: verifying the certification, its scope and contractual safeguards.
Binding Corporate Rules
Binding internal data protection rules for intra-group transfers (controller and processor BCR).
Intra-Group Transfers
A framework agreement (Data Transfer Agreement) with an allocation clause and a Data Transfer Directory for all internal transfers within a group of undertakings.
Article 44 GDPR
General principles for transfers of personal data to third countries.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Opening Clause for Member State Law (Article 9(4) GDPR)
Scope of the national opening clause for genetic data, biometric data and data concerning health; implementation in the German Federal Data Protection Act (BDSG) and in sector-specific law.
Derogations under Article 49 GDPR
When personal data may be transferred to an unsafe third country without appropriate safeguards: consent, performance of a contract, legal claims, public interest, vital interests and registers under Article 49 GDPR, as well as the catch-all ground of compelling legitimate interests. Strict interpretation, limitation to occasional transfers, documentation and transparency obligations.