Data protection

Data transfers outside the EEA. Current rules and recommendations for technology companies

2026-09-10

This text is for general information only. It does not constitute legal advice or a recommendation for any specific factual situation.

Transfers begin with mapping

Before assessing the legality of a transfer, it is necessary to determine whether personal data actually leaves the European Economic Area, who acts as data importer, what the purpose of the transfer is and which tools the supplier uses.

Core elements of the process

  • mapping data flows,
  • establishing the roles of the parties,
  • selecting the transfer mechanism,
  • assessing risks related to the third country,
  • implementing supplementary measures where needed,
  • documenting the decision.

Standard contractual clauses are an important tool, but they do not replace assessment of the specific transfer. Technology companies should treat transfers as part of supplier and data architecture management.

Sources

GDPR: EUR-Lex. EDPB Recommendations 01/2020: EDPB.