Data Protection HubIndividual TopicsTransfers to Third Countries (Data Export)

Derogations under Article 49 GDPR

When personal data may be transferred to an unsafe third country without appropriate safeguards: consent, performance of a contract, legal claims, public interest, vital interests and registers under Article 49 GDPR, as well as the catch-all ground of compelling legitimate interests. Strict interpretation, limitation to occasional transfers, documentation and transparency obligations.

Where neither an adequacy decision nor an appropriate safeguard under Article 46 GDPR is available for an unsafe third country, a transfer may nevertheless be permissible by way of exception if one of the derogations in Article 49 GDPR applies. In those cases, no adequate level of protection in the third country is required.

Key takeaways

  • The derogations must be interpreted strictly. In case of doubt, no derogation applies; appropriate safeguards (standard contractual clauses, Data Privacy Framework, binding corporate rules) are then required.
  • Most derogations justify only occasional transfers, not systematic and repetitive ones.
  • It is not sufficient that the transfer is merely useful; it must be necessary for the particular purpose.
  • Article 49 is subsidiary to an adequacy decision and to appropriate safeguards: a derogation only comes into consideration once those are ruled out.
  • Where a derogation applies, it must be documented in the records of processing activities, stating the relevant category and a brief justification. The obligation to inform data subjects remains in place.

1. Function and common limits of the derogations

Article 49 GDPR forms the third and final stage of the assessment scheme: it permits a transfer to an unsafe third country even though no adequate level of protection exists there and no appropriate safeguards under Article 46 GDPR have been agreed. The derogations rest on the consideration that the need for protection of the data subjects is comparatively low in the situations covered, for example because they consent on a self-determined basis or because a recognized public interest prevails.

Because the derogations depart from the protective scheme of the GDPR, three common limits apply to all of them:

  • Strict interpretation. As exceptions, the derogations must be applied restrictively so that the exception does not become the rule. Anyone seeking to rely on them bears the risk of a misjudgment. In case of doubt, appropriate safeguards should be used instead.
  • Necessity, not mere usefulness. The transfer must be necessary for the particular purpose. It is not sufficient that it is merely convenient or efficient, for example in order to involve a US service provider so that cooperation runs more efficiently.
  • Limitation to occasional transfers. Most derogations apply only where the transfer takes place occasionally, that is, not systematically and repetitively. A permanent transfer embedded in ordinary business operations can as a rule not be based on Article 49 GDPR.

Like the appropriate safeguards, a derogation under Article 49 GDPR concerns only the question of the level of protection in the third country. It does not replace the legal basis under Article 6 GDPR; that legal basis must additionally be present at the first stage of the assessment. Before personal data are transferred, it must also be examined whether anonymous or pseudonymous data would suffice. Only where that is not sufficient and no appropriate safeguard comes into consideration can a derogation carry the transfer.

2. The derogations under Article 49(1), first sentence

Article 49(1), first sentence, GDPR contains an exhaustive catalog of seven derogations. The following overview arranges them by their practical importance.

DerogationProvisionTypical applicationPractical relevance
ConsentArticle 49(1)(a) GDPRData subject gives informed consent to the specific transferhigh
Contract with the data subjectArticle 49(1)(b) GDPRTransfer necessary for the performance of a contract with the data subjecthigh
Legal claimsArticle 49(1)(e) GDPRTransfer to lawyers, courts or public authorities for the pursuit of legal claimshigh
Public interestArticle 49(1)(d) GDPRExchange of data with financial, supervisory or government authoritiesmedium
Contract in the interest of the data subjectArticle 49(1)(c) GDPRContract between the controller and a third party for the benefit of the data subjectlow
Vital interestsArticle 49(1)(f) GDPRMedical emergencies, disasters, where consent is not possiblelow
Public registerArticle 49(1)(g) GDPRTransfer from commercial registers, registers of associations or comparable registerslow

The data subject may explicitly consent to the transfer to a specific unsafe third country (Article 49(1)(a) GDPR). This consent must be distinguished from consent as a general legal basis under Article 6(1)(a) GDPR; it relates specifically to the transfer.

The consent must be freely given, specific, informed and unambiguous (Article 4(11), Article 7 GDPR). The data subject must be informed in advance of the risks of the transfer, in particular of the possible absence of an adequate level of protection and of the absence of supervision and enforceable rights in the third country. The information should state which data and which processing operations the agreement covers, who the recipient is and to which country the data are transferred. The requirement that consent be explicit rules out consent by mere silence or by presumed agreement. Blanket consent to any and all transfers to third countries is not sufficient; where the specific circumstances only become apparent after the data have been collected, specific consent must be obtained before the transfer.

In the online environment, for example in the case of cookie consent, the supervisory authorities take a critical view of this derogation because of its exceptional character. In the employment context, whether consent is freely given must be examined with particular care; it should only be used where the employee has a genuine choice and can withdraw consent without suffering any detriment. For repetitive or routine transfers, such as a centralized human resources database in a third country, consent is as a rule not a suitable basis.

2.2 Performance of a contract with the data subject (point (b))

A transfer may be permissible where it is necessary for the performance of a contract with the data subject or for the implementation of pre-contractual measures taken at the data subject's request (Article 49(1)(b) GDPR). This requires a direct contractual or pre-contractual relationship between the data subject and the controller, as well as a close and substantial connection between the transfer and the purpose of the contract. Typical examples are the booking of a hotel or a rental car in a third country through a travel agency, transfers in international payment transactions, or the handling of a mail-order purchase.

In the case of employee data, the derogation may come into consideration where the performance of the obligations under the employment contract necessarily entails the transfer, for instance in the case of isolated email correspondence between employees and business partners in an unsafe third country, provided that no data on third parties are sent. The position of a managing director may necessarily entail that his or her data have to be transferred to bodies in third countries from time to time.

The derogation applies only to occasional transfers. It does not carry a transfer that would merely be useful, for example where a US service provider is to be involved solely in order to make cooperation more efficient. The centralization of payroll and human resources management functions with a service provider in a third country is not covered, as it is not necessary.

A transfer may be permissible where it is necessary for the establishment, exercise or defense of legal claims (Article 49(1)(e) GDPR). This may cover transfers to lawyers, courts or regulatory authorities, both in judicial and in out-of-court proceedings, including administrative and supervisory proceedings, for example in criminal or regulatory investigations in a third country (such as antitrust law, anti-corruption enforcement or insider dealing). Transfers for the purposes of a formal pre-trial procedure (pretrial discovery) or in order to initiate proceedings, such as an application for merger clearance, may also be covered.

The mere possibility of future litigation is not sufficient. What is required is a close and substantial connection between the data and the pursuit of the legal claim in the individual case. Before personal data are transferred, it must be examined in stages whether anonymized or pseudonymized data would suffice and whether the data are relevant to the matter (data minimization). Where courts or authorities of a third country issue a request, the special provision in Article 48 GDPR must be observed. This derogation, too, justifies only occasional transfers.

2.4 Important reasons of public interest (point (d))

A transfer may be permissible for important reasons of public interest (Article 49(1)(d) GDPR). Only public interests that are recognized in Union law or in German law are relevant (Article 49(4) GDPR); the interest of an authority in the third country alone is not sufficient. The recitals of the GDPR cite as examples the international exchange of data between competition authorities, tax or customs administrations, between financial supervisory authorities or between services competent for social security or public health matters, for instance in combating contagious diseases or doping in sport.

The derogation is addressed primarily to public authorities, but it can also be relied on by companies, for example for transfers to financial, supervisory and government authorities outside the EU where recognized interests are pursued. An international agreement signed by the EU or by a Member State can be an indication of such a public interest.

2.5 Contract in the interest of the data subject (point (c))

This derogation covers occasional transfers that are necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and a third party (Article 49(1)(c) GDPR). Unlike point (b), the data subject is not a party to the contract here. Examples include contracts for the benefit of third parties under § 328 of the German Civil Code (BGB), the transfer of booking data by a travel agency to an airline, or taking out employee insurance with a company in a third country. Here, too, a close and substantial connection between the transfer and the contract is required; engaging a service provider in a third country to manage payroll or stock options is not covered, as it is not necessary.

2.6 Protection of vital interests (point (f))

A transfer is permissible where it is necessary in order to protect the vital interests of the data subject or of another person and the data subject is physically or legally incapable of giving consent (Article 49(1)(f) GDPR). Typical cases are medical emergencies and medical care abroad; within the limits of necessity, the transfer of data concerning health is also covered. Transfers following natural disasters may likewise be justified, for example in order to locate victims and to inform relatives and emergency services. Not covered is the transfer of medical data that serves not the treatment of the data subject but general research.

2.7 Transfer from a public register (point (g))

A transfer is permissible where it is made from a register which, under Union or Member State law, is intended to provide information to the public and which is open to consultation either by the public in general or by persons who can demonstrate a legitimate interest (Article 49(1)(g) GDPR). In Germany, this applies above all to the commercial register and the register of associations and, for persons with a legitimate interest, to the land register. The transfer is permissible only to the extent that the statutory conditions for consultation are met in the individual case; in the case of registers open only to persons with a legitimate interest, the transfer may be made only at their request and only to them (Article 49(2) GDPR). The register may not be transferred in its entirety, nor may entire categories of data be transferred. Purely private registers, such as those used to assess creditworthiness, are not covered.

3. Catch-all ground: compelling legitimate interests (paragraph 1, second sentence)

Where a transfer can be based neither on an adequacy decision nor on appropriate safeguards nor on one of the derogations in paragraph 1, first sentence, the catch-all ground in Article 49(1), second sentence, GDPR comes into consideration as a last resort. It is subject to narrow conditions that must be met cumulatively:

No other basis. Neither Article 45 or 46 GDPR nor a derogation under paragraph 1, first sentence, is applicable. The controller must be able to demonstrate that no other basis was available (accountability under Article 5(2) GDPR).
No repetitive transfer. The transfer is not repetitive; routine or systematic transfers are excluded.
Limited number of data subjects. Only a limited number of data subjects is concerned.
Compelling legitimate interests. The transfer is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests, rights and freedoms of the data subject. The interests must carry particular weight, such as averting serious damage; the interests of third parties are not sufficient.
Providing suitable safeguards. The controller assesses all the circumstances surrounding the transfer and, on that basis, provides suitable safeguards for the protection of the data (for example short erasure periods, strict purpose limitation, pseudonymization or encryption).

Specific additional obligations also apply: the controller informs the supervisory authority of the transfer and informs the data subjects of the transfer and of the compelling legitimate interests it pursues; this information comes in addition to the general transparency obligations under Articles 13 and 14 GDPR. The catch-all ground is intended as a last-resort exception and is viable in practice only in rare, special cases.

4. Restriction for public authorities (paragraph 3)

The derogations for consent (point (a)), for the performance of a contract with the data subject (point (b)) and for a contract in the interest of the data subject (point (c)), as well as the catch-all ground in paragraph 1, second sentence, do not apply to activities carried out by public authorities in the exercise of their public powers (Article 49(3) GDPR). For acts of public authority, public authorities therefore cannot rely, in particular, on consent or on the catch-all ground.

5. National restrictions (paragraph 5)

In the absence of an adequacy decision, Union law or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of personal data to third countries (Article 49(5) GDPR). Where a Member State makes use of this option, it must notify the European Commission.

Where a derogation applies, this must be documented in the records of processing activities, stating the relevant category and a brief justification (Article 30 GDPR). In the case of the catch-all ground in paragraph 1, second sentence, the assessment carried out and the suitable safeguards provided must additionally be recorded (Article 49(6) GDPR).

The obligation to inform data subjects about the transfer to a third country is not affected by the derogations (Article 13(1)(f) GDPR). The privacy notice must state that data are transferred to a third country and on what basis this takes place.

Where data are transferred to an unsafe third country without a derogation and without any other basis, the transfer is unlawful. Infringements of the requirements of Chapter V are subject to administrative fines (Article 83(5)(c) GDPR); in addition, the remedies and liability rules of the GDPR apply.

Further guidance from the supervisory authorities is set out in Guidelines 2/2018 on derogations under Article 49 GDPR.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn