Back to blog
Ai News

Cross Border Data Transfer

6 min read

Moving personal data across borders is one of the more legally fraught operations a company can perform if it touches EU residents' data, and getting it wrong carries real financial consequences — GDPR fines for unlawful transfers can reach 20 million euros or 4% of global annual revenue, whichever is higher. In 2026, the mechanisms for doing this legally are reasonably well established, but they still require deliberate compliance work rather than an assumption that things are fine by default.

The four mechanisms, in order of preference

GDPR cross-border data transfers require one of four legal mechanisms, and they're generally understood in a rough order of preference from simplest to most burdensome:

  1. Adequacy decisions — the EU has formally determined that roughly 15 countries (as of 2026) provide data protection equivalent to EU standards, allowing data to flow to those jurisdictions without additional safeguards. Countries covered include the UK, Japan, South Korea, and others.
  2. Appropriate safeguards — primarily Standard Contractual Clauses (SCCs), pre-approved contractual terms that impose GDPR-equivalent obligations on the receiving party even in a jurisdiction without an adequacy decision.
  3. Binding Corporate Rules (BCRs) — internal, regulator-approved policies for transfers within a corporate group, useful for large multinational organizations moving data between their own entities across borders.
  4. Narrow derogations — specific, limited exceptions (explicit consent, necessity for contract performance) that apply to particular transfer scenarios rather than serving as a general-purpose mechanism.

Most organizations end up relying on a combination — SCCs paired with a Transfer Impact Assessment — as the practical default for transfers to jurisdictions without an adequacy decision, since adequacy only covers a limited list of countries and BCRs are primarily useful for intra-group transfers at large organizations.

The EU-US Data Privacy Framework's uncertain footing

The EU-US Data Privacy Framework, adopted in July 2023, provides a valid adequacy basis for transfers to certified US organizations and remains valid in 2026 — but its legal standing is not entirely settled. It survived a legal challenge at the EU General Court in September 2025, but that ruling has been appealed to the Court of Justice of the European Union. This matters practically: organizations relying heavily on the Framework for US transfers should treat it as currently valid but not permanently guaranteed, given the pattern of previous EU-US transfer mechanisms (Safe Harbor, then Privacy Shield) both being struck down after legal challenges. A reasonable compliance posture keeps SCCs as a backup mechanism in place even where currently relying primarily on the Framework's adequacy basis.

Transfer Impact Assessments are now a mandatory step

Following the Schrems II ruling, a Transfer Impact Assessment (TIA) is now a mandatory companion to SCCs, not optional supporting documentation. A TIA requires the organization to evaluate whether the destination country's laws (particularly around government surveillance and data access) could undermine the protections the SCCs are supposed to provide, and to document additional technical or organizational safeguards where risks are identified. Organizations that rely on SCCs without a documented TIA are running a real compliance gap, even if the underlying contractual terms are otherwise sound.

Beyond the legal transfer mechanism itself, current guidance emphasizes combining SCCs and TIAs with genuine technical safeguards — encryption, pseudonymization, and access controls that maintain EU-level data protection standards in practice, not just on paper. Regulators and courts have increasingly scrutinized whether the technical reality of a transfer arrangement actually matches its legal documentation, meaning a well-drafted SCC paired with weak technical controls is a real compliance risk, not just a theoretical one.

Localization as an alternative strategy

For some organizations, particularly those handling especially sensitive data or operating in jurisdictions with strict data residency requirements, the practical response to this compliance complexity has been data localization — keeping data within the originating region entirely rather than managing the ongoing compliance burden of cross-border transfer. This is a genuine tradeoff between compliance complexity and operational flexibility (localized infrastructure costs more and limits centralized processing), and the right answer depends heavily on the specific data sensitivity and business model involved.

Beyond GDPR: China's PIPL and India's DPDP add separate compliance tracks

For organizations moving data beyond the EU-US corridor, two other major regimes now require their own, largely independent compliance tracks rather than being solvable with the same GDPR mechanisms described above. China's Personal Information Protection Law (PIPL) imposes genuinely strict data localization: personal information collected within China must generally stay on servers located in mainland China, particularly for critical information infrastructure operators and processors handling data above defined volume thresholds. The regulatory picture there kept evolving into 2026 — the Cyberspace Administration of China and the State Administration for Market Regulation jointly issued Measures for Certification of Cross-Border Personal Information Transfer, effective January 1, 2026, completing a three-pathway framework for cross-border transfers, with a further technical standard (GB/T 46068-2025) taking effect March 1, 2026, and Shanghai launching a dedicated cross-border data transfer pilot in April 2026 offering streamlined filing for qualifying transfers. None of the GDPR mechanisms above — SCCs, adequacy decisions, BCRs — satisfy PIPL's requirements on their own; a company operating in both the EU and China needs to run two separate, non-interchangeable compliance tracks.

India's Digital Personal Data Protection (DPDP) Act takes a meaningfully different, more permissive approach worth knowing if you're comparing regimes: its finalized rules (November 2025) establish a negative-list model under which cross-border transfers are permitted to all destinations by default, unless the Indian government specifically restricts a particular country by notification — the inverse structure from GDPR's default-restrictive approach requiring an affirmative legal mechanism for every transfer. Full DPDP cross-border compliance obligations come into force by May 2027, giving organizations still a real transition window, but the structural difference is worth planning around now: a compliance program built entirely around GDPR's transfer-mechanism logic won't map cleanly onto India's default-permissive model, and treating all three regimes as variations on the same underlying framework is a common and costly mistake.

Practical compliance checklist

  • Identify which transfer mechanism applies to each cross-border data flow — don't assume a blanket approach covers every destination country.
  • Keep SCCs in place as a backup even when relying on an adequacy decision like the EU-US Data Privacy Framework, given its unsettled legal status.
  • Complete and document a Transfer Impact Assessment for every transfer relying on SCCs — this is a mandatory step post-Schrems II, not optional.
  • Verify technical safeguards (encryption, access controls) actually match what's documented in your legal transfer mechanism.
  • Reassess your transfer mechanisms periodically — this area of law has changed significantly multiple times over the past decade, and a mechanism valid today isn't guaranteed to remain so indefinitely.

Sources: Duality Tech — Cross-Border Data Transfers Under GDPR, Secrails — Cross Border Data Transfer: GDPR Rules 2026, Legiscope — GDPR Data Transfer Rules 2026, China Briefing — China Releases Cross-Border Data Transfer Certification Measures, Securiti — Cross Borders Data Transfers Under GDPR and PIPL

Keep reading

Get new posts as they publish

No spam — just the next post, straight to your inbox.

Discussion