International data transfers remain among the most operationally complex areas of GDPR compliance. The invalidation of the Privacy Shield in Schrems II, the subsequent adoption of new Standard Contractual Clauses, and the introduction of the EU-US Data Privacy Framework have each reshaped the landscape. Organisations transferring data outside the EEA must understand which mechanisms are currently available and what each requires.

What mechanisms are available for transferring personal data outside the EEA?

Article 46 GDPR permits transfers where appropriate safeguards are in place. The primary mechanisms are Standard Contractual Clauses, Binding Corporate Rules, and approved codes of conduct or certification mechanisms. Article 45 permits transfers to countries the European Commission has found adequate. Article 49 provides derogations for specific situations – explicit consent, contractual necessity, vital interests, public interest, and legal claims – but these are narrow exceptions, not general transfer mechanisms.

What are Standard Contractual Clauses and how do they work?

Standard Contractual Clauses (SCCs) are pre-approved contractual terms adopted by the European Commission that provide the required safeguards for international transfers. The 2021 SCCs replaced the previous generation and introduced a modular structure covering controller-to-controller, controller-to-processor, processor-to-controller, and processor-to-processor transfer scenarios.

Before relying on SCCs, organisations must conduct a Transfer Impact Assessment (TIA) – an analysis of the law and practice of the destination country to determine whether the SCCs can be effective in practice. Where the legal framework of the destination country would undermine the protection the SCCs provide – for example, through surveillance laws requiring disclosure to public authorities – supplementary measures are required, or the transfer should not proceed.

What is the EU-US Data Privacy Framework?

The EU-US Data Privacy Framework (DPF) was adopted by the European Commission in July 2023, establishing the United States as adequate for the purposes of Article 45 GDPR in respect of certified US organisations. Transfers to DPF-certified organisations do not require SCCs or TIAs. Certification is self-administered through the US Department of Commerce and must be renewed annually.

The DPF remains subject to political risk. A legal challenge before the Court of Justice of the European Union was brought in 2023 and remains ongoing. Organisations relying solely on the DPF should consider whether a parallel SCC mechanism provides additional resilience.

What is the UK IDTA?

The UK International Data Transfer Agreement (IDTA) is the UK equivalent of SCCs, covering transfers from the UK to third countries. It applies following the UK's departure from the EU, which ended the direct applicability of EU SCCs for UK-to-third-country transfers. The UK has also issued adequacy decisions for a number of countries, including the EU, meaning transfers from UK organisations to EEA recipients do not require a transfer mechanism.

What are the most common compliance failures in transfer management?

Supervisory authorities have identified several recurring failures: reliance on outdated pre-2021 SCCs after their retirement date; failing to conduct Transfer Impact Assessments; using SCCs for transfers to countries where the legal framework renders them ineffective without supplementary measures; and failing to document the legal basis for each third-country transfer in the Record of Processing Activities.

What this means for your organisation

  • Every transfer of personal data outside the EEA requires a documented legal basis. Relying on SCCs without a completed Transfer Impact Assessment is not compliant and has been the subject of enforcement action.
  • The EU-US Data Privacy Framework remains subject to legal challenge. Organisations relying solely on DPF certification should consider whether a parallel SCC mechanism provides additional resilience.
  • UK organisations face separate transfer rules under the UK GDPR and must use the IDTA or rely on UK adequacy decisions – EU SCCs do not apply to UK-to-third-country transfers.
  • Transfer compliance is an active enforcement priority. Several of the largest GDPR fines have involved inadequate transfer mechanisms.

What you should do now

  1. Map every third-country transfer in your Record of Processing Activities and confirm the applicable Article 45 or 46 basis for each.
  2. Where SCCs are the mechanism, complete a Transfer Impact Assessment for each destination country and document the outcome.
  3. For DPF-reliant transfers to the US, verify the receiving organisation's current certification status and assess whether a parallel SCC provides additional protection.
  4. UK organisations should confirm that all transfers use the IDTA or rely on a current UK adequacy decision.
  5. Schedule a review of transfer documentation whenever a new third-country processing relationship is established.

How Priventia helps

Priventia's Controls Library maps each international transfer to the applicable legal mechanism and flags Transfer Impact Assessment gaps. The Regulatory Intelligence module monitors adequacy decisions and DPF developments to alert organisations when the basis for an existing transfer requires review.