Cross-Border Data Transfer

Transfer of personal data to countries outside the EEA, requiring additional safeguards under GDPR.

A

B

C

When your startup processes personal data of EU residents using services hosted outside the European Economic Area (such as US-based AI providers, cloud platforms or analytics tools), you are performing a cross-border data transfer. Under GDPR, this requires additional legal safeguards to ensure the data receives equivalent protection.

What you need to do:

  • Check adequacy: If the destination country has an EU adequacy decision (e.g. the EU-US Data Privacy Framework), transfers are permitted without additional measures. Verify your provider participates in the framework.
  • Standard Contractual Clauses (SCCs): For countries without adequacy, use the European Commission's standard contract templates. Most major cloud and AI providers already include SCCs in their terms. Check their DPA.
  • Transfer Impact Assessment (TIA): Evaluate whether local laws in the destination country could undermine the protection provided by SCCs. Document your assessment and any supplementary measures.
  • Map your data flows: Create an inventory of all services that process personal data and where that data is stored. This is often more complex than expected. Subprocessors may route data through multiple countries.

The Dutch Data Protection Authority provides detailed guidance on international transfers. Tidal Control helps you document data flows, track SCC compliance and maintain your TIA as part of your privacy management system.

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is a cross-border data transfer?
Under the GDPR it is a disclosure of personal data to a different controller or processor outside the EEA, including remote access by an organisation outside the EEA and storage in data centres outside the EEA. Chapter V of the GDPR sets out when this is allowed. Your own employee accessing data while travelling is not a transfer.
What legal mechanisms allow such a transfer?
Most commonly an adequacy decision by the European Commission, or Standard Contractual Clauses. Binding Corporate Rules apply within a group, and the derogations in Article 49 cover narrow exceptions.
Do you still need a transfer impact assessment?
Yes, where you rely on Article 46 safeguards such as SCCs or Binding Corporate Rules. Following the Schrems II ruling you must assess whether the destination country’s laws undermine those safeguards, and add supplementary measures such as strong encryption where they do.