Back to the hub

How does the GDPR restrict international data transfers?

Chapter V of the GDPR lets you transfer personal data outside the EEA only under a lawful mechanism: an adequacy decision under Article 45, such as the EU-US Data Privacy Framework; appropriate safeguards under Article 46, like standard contractual clauses or binding corporate rules; or a specific derogation under Article 49.

Applies to: Controllers and processors subject to the GDPR that send personal data to a third country outside the EEA, including US SaaS vendors and cloud providers receiving EU personal data.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

For a US SaaS company, this is often the part of the GDPR that actually blocks a deal. Your EU customers' data lands on servers you run, and the GDPR treats moving that data outside the European Economic Area as a restricted act you need a specific legal mechanism to perform. Chapter V sets out those mechanisms, and picking the right one is a procurement question as much as a legal one.

What Chapter V requires

Article 44 states the general principle: a transfer of personal data to a third country or international organisation may take place only where the conditions in Chapter V are met, and the level of protection the GDPR guarantees must not be undermined. The rule follows the data, so it also catches onward transfers, where your processor in a third country passes the data on again. In practice you need one of three things before EU personal data leaves the EEA: an adequacy decision, appropriate safeguards, or a derogation.

Adequacy decisions and the EU-US Data Privacy Framework

The cleanest route is Article 45. Where the European Commission has decided that a third country ensures an adequate level of protection, data can flow there with no specific authorisation, as if it stayed inside the EEA. For the United States, that decision is the EU-US Data Privacy Framework, adopted on 10 July 2023 as Commission Implementing Decision (EU) 2023/1795. A US organisation that self-certifies to the DPF can receive EU personal data under it. The DPF is a live adequacy decision, though its future is contested: the EU General Court dismissed a challenge to it in September 2025 (Latombe, T-553/23), and an appeal is now pending before the Court of Justice, so many companies keep a fallback safeguard in place.

Safeguards when there is no adequacy decision

If the destination has no adequacy decision, Article 46 lets you transfer on the basis of appropriate safeguards that give data subjects enforceable rights and effective remedies. The common tools are the Commission's standard contractual clauses, which you sign with the importer, and binding corporate rules for transfers within a corporate group. After the Schrems II judgment, safeguards are not enough on their own: you must assess whether the importing country's surveillance laws would undermine them and add supplementary measures, such as encryption, where the assessment shows a gap.

Derogations are the narrow exception

Article 49 allows a transfer with neither adequacy nor safeguards, but only in specific situations, such as the data subject's explicit consent to the proposed transfer, necessity for a contract with the data subject, important reasons of public interest, or the establishment or defence of legal claims. These derogations are meant for occasional, non-repetitive transfers. Building your product's routine data flows on a derogation is the mistake regulators flag most often.

Next step

If you serve EU users from US infrastructure, the free 2-minute Obligation Scan checks whether the GDPR reaches you and flags the transfer mechanisms you need to document. See GDPR for SaaS and GDPR for US companies for how the rest of the obligations apply, and the GDPR compliance hub for the full picture.

Compliance checklist

  • Map every flow of personal data from the EEA to a third country, including onward transfers by your processors and sub-processors, since Article 44 covers those too.
  • Check whether the destination has a European Commission adequacy decision under Article 45; for the United States, confirm the recipient is certified under the EU-US Data Privacy Framework.
  • Where there is no adequacy decision, put an Article 46 safeguard in place, most often the Commission's standard contractual clauses, or binding corporate rules for intra-group transfers.
  • Run a transfer risk assessment after Schrems II to check the destination's laws do not undermine your safeguards, and document any supplementary measures.
  • Use an Article 49 derogation, such as explicit consent or contract necessity, only for occasional transfers, not as a routine transfer mechanism.

Sources

Last verified: 2026-08-10

Informational, not legal advice.