GDPR International Data Transfers: SCCs & Adequacy (2026)

By Recording Law Editorial TeamReviewed June 9, 202635 min read
GDPR International Data Transfers: SCCs & Adequacy (2026)

Frequently Asked Questions

Can I transfer personal data outside the EU under GDPR?

Yes, but only if a valid Chapter V transfer mechanism is in place before the data leaves the EEA. The three tiers are: (1) transfer to a country with an EU adequacy decision (no contract needed); (2) use appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, combined with a Transfer Impact Assessment; or (3) rely on a narrow Article 49 derogation for occasional, non-repetitive transfers. Ongoing, systematic transfers must use Tier 1 or Tier 2, Article 49 derogations are not available as a routine mechanism.

What are Standard Contractual Clauses under GDPR?

Standard Contractual Clauses are pre-approved contractual templates issued by the European Commission under GDPR Article 46(2)(c) that create binding data protection obligations between an EEA data exporter and a non-EEA importer. The 2021 modernised SCCs (Commission Implementing Decision (EU) 2021/914) have four modules covering every transfer scenario: controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. They also include Clause 14, which requires the parties to complete a Transfer Impact Assessment confirming that destination-country law will not prevent compliance. The old SCCs were phased out on December 27, 2022.

What was Schrems II and why does it matter?

Schrems II is the CJEU judgment in Case C-311/18 (Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems), delivered on July 16, 2020. The Court invalidated the EU-US Privacy Shield adequacy decision, finding that US surveillance law did not provide EU data subjects with essentially equivalent protection or effective judicial redress. More broadly, the ruling confirmed that SCCs are valid but conditional: before relying on SCCs, the data exporter must verify that the destination country's laws will not prevent compliance in practice. If they will, supplementary measures are required, or the transfer cannot proceed. Schrems II made Transfer Impact Assessments a mandatory step for every SCC-based transfer.

Is the US adequate under GDPR?

Partially. On July 10, 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, covering transfers to US organisations that have self-certified to the DPF Principles and fall within the jurisdiction of the FTC or Department of Transportation. Approximately 2,700 US organisations are certified as of mid-2026. US organisations that are not DPF-certified, and those outside FTC/DoT jurisdiction, must rely on SCCs or another Article 46 mechanism. The DPF has been challenged by civil-liberties organisations and may face future CJEU scrutiny; maintaining SCC fallbacks is prudent.

What is a Transfer Impact Assessment and when is it required?

A Transfer Impact Assessment is a structured legal analysis that data exporters must complete before relying on SCCs, BCRs, or other Article 46 safeguards. It assesses whether the destination country's legal framework, particularly its surveillance and law-enforcement laws, would prevent the importer from honouring the transfer mechanism's obligations in practice. The TIA requirement was established by the CJEU in Schrems II and operationalised by the EDPB in Recommendations 01/2020 v2.0. The 2021 SCCs build the TIA into Clause 14 as a contractual obligation. TIAs must be documented, retained as evidence of compliance, and updated whenever relevant legal developments occur in the destination country.

What are Binding Corporate Rules and how do they differ from SCCs?

Binding Corporate Rules are internally adopted, legally binding data protection policies that a multinational group uses to govern intra-group transfers of personal data outside the EEA. They must be approved by a lead EU supervisory authority under Article 47 following an EDPB consistency review, which typically takes 12 to 18 months. BCRs cover only transfers within the same corporate group; SCCs are needed for transfers to unrelated third parties. BCRs provide a cleaner governance structure for ongoing intra-group flows and avoid the need to re-execute SCC sets each time a new group entity is added. Both require a Transfer Impact Assessment.

Can I use explicit consent as my routine basis for international data transfers?

No. GDPR supervisory authorities and the EDPB consistently interpret Article 49 derogations, including explicit consent, as narrow exceptions for occasional, non-repetitive transfers, not as alternatives to Article 46 safeguards. Routine or systematic transfers require a Tier 1 adequacy decision or Tier 2 appropriate safeguard. Even where consent is validly relied on for a specific transfer, it must be specific to the international transfer and its risks: it cannot be bundled into general terms of service, and data subjects must be able to withdraw it without detriment.

What supplementary measures can make an SCC transfer lawful after Schrems II?

The EDPB's Recommendations 01/2020 v2.0 identify three categories. Technical measures include end-to-end encryption where the importer holds no plaintext key, pseudonymisation with the key retained in the EEA, and split-processing architectures. Contractual measures include mandatory notification clauses when government access is received, challenge requirements, and audit rights. Organisational measures include data minimisation at export and internal escalation policies. The EDPB stresses that technical measures must be genuinely effective, encryption is valid only if the processing purpose can be achieved without the importer accessing the cleartext. Where no combination of measures can eliminate the gap, the transfer must not proceed.

What is the maximum penalty for an unlawful international data transfer?

Violations of GDPR Chapter V fall under Article 83(5), the highest fine tier: up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher. Supervisory authorities also have authority under Article 58(2) to impose temporary or permanent transfer bans, which can suspend cross-border data flows entirely and may be more operationally disruptive than any financial penalty. The EUR 1.2 billion fine issued to Meta Platforms by the Irish DPC in May 2023, combined with a transfer ban, illustrates the combined enforcement risk.

Do the Chapter V transfer rules apply to processors as well as controllers?

Yes. Article 44 states that the Chapter V conditions must be complied with by both the controller and the processor, including for onward transfers. A processor established in the EEA that sub-contracts to a non-EEA sub-processor must ensure that a Chapter V mechanism covers the onward transfer. Module 3 of the 2021 SCCs (processor-to-processor) is designed for this scenario and requires prior authorisation from the original controller before the sub-processing arrangement is established.

Sources and References

  1. GDPR Regulation (EU) 2016/679, Articles 44-50 and Recitals 101-115(eur-lex.europa.eu)
  2. Commission Implementing Decision (EU) 2021/914 on Standard Contractual Clauses(eur-lex.europa.eu)
  3. Commission Implementing Decision (EU) 2023/1795, EU-US Data Privacy Framework adequacy decision(eur-lex.europa.eu)
  4. CJEU Case C-311/18 (Schrems II) - Data Protection Commissioner v Facebook Ireland and Maximillian Schrems(curia.europa.eu)
  5. CJEU Case C-362/14 (Schrems I) - Maximillian Schrems v Data Protection Commissioner(curia.europa.eu)
  6. EDPB Recommendations 01/2020 v2.0 on Measures to Supplement Transfer Tools(edpb.europa.eu)
  7. EDPB Guidelines 2/2018 on Derogations of Article 49 under Regulation 2016/679(edpb.europa.eu)
  8. EDPB Recommendations 1/2022 on the Application for Approval and on the Elements and Principles to be Found in Controller Binding Corporate Rules(edpb.europa.eu)
  9. European Commission Adequacy Decisions - current list(commission.europa.eu)
  10. European Commission - Binding Corporate Rules(commission.europa.eu)
  11. European Commission - EU-US Data Transfers History (Safe Harbor, Privacy Shield, DPF)(commission.europa.eu)
Share: