Skip to main content
Category: Data Transfers

Cross-Border Data Flow

Also known as: Cross-Border Data Transfer, International Data Transfer, Cross-Border Data Transfers
Simply put

A cross-border data flow is the movement or transfer of digital information, including personal data, between servers or organizations located in different countries. Because such transfers can involve people's personal data leaving one country's legal framework for another, they are typically subject to legal and regulatory requirements intended to protect that data. The specific rules that apply depend on the jurisdictions involved and can vary considerably from one country to another.

Formal definition

Cross-border data flow refers to the transmission or transfer of digital information between servers or entities situated in different countries. In a data protection context, the term is most significant where the data transferred constitutes personal data, since jurisdictions such as the EU (and, in parallel, jurisdictions like China under its personal information protection regime) impose conditions on transferring such data outside their territory. Regulatory approaches vary by jurisdiction and range from broadly permissive frameworks tied to trade arrangements to restriction-based models that limit transfers on personal information protection grounds while permitting them subject to specified conditions. The applicable transfer mechanisms, safeguards, and permitted conditions differ across legal systems and continue to evolve; practitioners should verify the current requirements of each relevant jurisdiction and the specific transfer instruments recognized there. This entry describes the concept generally and does not itself set out the particular Article-based transfer rules of any single regime.

Why it matters

Cross-border data flows sit at the intersection of commerce and data protection. International trade involving consumers generally cannot take place without collecting and sending personal data across borders, so restricting these flows can have direct economic consequences while permitting them without safeguards can undermine the legal protections individuals enjoy in their home jurisdiction. When personal data leaves the territory whose legal framework produced it, it may enter a jurisdiction with materially different protections, which is why many regimes attach conditions to such transfers.

The stakes are heightened by the divergence between regulatory approaches. Some jurisdictions favor broadly permissive frameworks tied to trade arrangements, while others adopt restriction-based models that limit transfers on personal information protection grounds but permit them subject to specified conditions. For example, under China's personal information protection regime, cross-border data flow is restricted for personal information protection reasons, though data processors may still transfer data across borders where the applicable conditions are met. Organizations operating across multiple countries must therefore reconcile several sets of rules at once.

Because the applicable transfer mechanisms, recognized safeguards, and permitted conditions differ across legal systems and continue to evolve, the compliance position is not static. What is lawful under one instrument or arrangement today may be affected by later guidance, negotiation, or reform. Practitioners should treat any snapshot of the rules as provisional and verify the current requirements of each relevant jurisdiction.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams must map where personal data moves across borders and identify which jurisdictions' transfer conditions apply. Because regulatory approaches range from permissive to restriction-based and continue to evolve, they should periodically re-verify the current requirements and recognized transfer instruments for each relevant jurisdiction rather than relying on a fixed assessment.
Privacy and Technology Lawyers
Legal advisers structuring international operations need to distinguish the transfer requirements of each regime involved, since the safeguards and permitted conditions differ across legal systems. They should flag where the position is uncertain or subject to change and avoid presenting one jurisdiction's framework as representative of all.
Engineers and Data Architects
Because a transfer can arise simply from data moving between servers located in different countries, those designing systems and infrastructure need to understand where data physically resides and routes. Architectural decisions about server location and data flows can determine whether jurisdiction-specific transfer conditions are engaged.
Organizations Engaged in International Trade
Businesses whose activities depend on collecting and sending personal data across borders should recognize that such flows are generally subject to legal and regulatory requirements that vary by country. This is particularly relevant for entities operating in or transferring data to jurisdictions with restriction-based models, such as China's personal information protection regime, where transfers are permitted only subject to specified conditions.

Inside Cross-Border Data Flow

Restricted Transfer
A movement of personal data from an organisation subject to the GDPR (or UK GDPR) to a recipient in a third country or international organisation outside that framework. Whether a given data flow qualifies as a restricted transfer subject to Chapter V requirements depends on assessment of the parties and their location; the boundary of what counts as a 'transfer' has itself been the subject of regulatory guidance and should be verified against the current position.
Adequacy Decision
A determination by the European Commission (or, separately, by the UK authorities under the UK regime) that a third country, territory, or sector ensures a level of data protection considered essentially equivalent to that within the EU. Where such a decision applies, transfers may generally proceed without an additional transfer tool. Adequacy decisions can be adopted, amended, suspended, or repealed over time, so their status should be checked against current official sources rather than assumed permanent.
Appropriate Safeguards (Transfer Tools)
Mechanisms relied upon where no adequacy decision covers the destination. These include Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs), among other instruments recognised in Chapter V. SCCs are contractual terms adopted for use between parties, whereas BCRs are internal rules approved for intra-group transfers within a corporate group; the two are distinct tools with different approval and application processes and should not be conflated.
Supplementary Measures
Additional technical, contractual, or organisational measures that may be required alongside a transfer tool where an assessment indicates the tool alone does not ensure an essentially equivalent level of protection in the destination. The need for and adequacy of such measures is context-dependent and informed by evolving case law and regulatory guidance.
Transfer Impact / Risk Assessment
An assessment, typically undertaken by the data exporter, of the laws and practices of the destination and the risks to the transferred data, to determine whether a chosen transfer tool provides adequate protection and whether supplementary measures are needed. Terminology and expected scope may vary between regulators.
Derogations for Specific Situations
Limited grounds on which a transfer may occur in the absence of an adequacy decision or appropriate safeguards, such as explicit consent to the proposed transfer or necessity for the performance of a contract. These are generally interpreted narrowly and are typically intended for occasional or non-repetitive transfers rather than as a routine transfer basis; their precise conditions should be checked against the current text and guidance.

Common questions

Answers to the questions practitioners most commonly ask about Cross-Border Data Flow.

Does the GDPR ban all transfers of personal data outside the EU or EEA?
No. The GDPR does not prohibit cross-border data flows outright. It restricts transfers to third countries or international organisations unless an appropriate legal basis and a valid transfer mechanism apply. Chapter V of the GDPR sets out routes such as adequacy decisions, appropriate safeguards (including Standard Contractual Clauses and Binding Corporate Rules), and specific derogations. The aim is to ensure that the level of protection afforded to individuals is not undermined when data leaves the EEA, not to stop transfers entirely. You should assess each transfer against the current framework and verify the available mechanisms against the official text and current guidance.
Is a transfer mechanism such as Standard Contractual Clauses on its own always enough to make a transfer lawful?
Not necessarily. Relying on a transfer tool like Standard Contractual Clauses or Binding Corporate Rules does not, by itself, guarantee lawfulness in every case. Following case law and regulatory guidance, a transfer typically requires a case-by-case assessment of whether the law and practice in the destination country may undermine the safeguards, and whether supplementary measures are needed. The position on adequacy, transfer tools, and supplementary measures continues to evolve, so a mechanism that is sufficient in one context or at one point in time should not be assumed to be permanently or universally sufficient.
How do we decide which transfer mechanism to use for a given data flow?
In most cases the analysis starts by checking whether the destination is covered by an adequacy decision, which can simplify the transfer without an additional tool. Where there is no adequacy decision, organisations typically consider appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, and only rely on the specific derogations in narrower situations. The appropriate choice depends on factors including the relationship between the parties (for example controller-to-processor or intra-group arrangements), the nature and sensitivity of the data, and the outcome of a transfer risk assessment. Because adequacy decisions and transfer tools change over time, confirm the current status against official sources before finalising your approach.
What is a transfer risk assessment and when is it needed?
A transfer risk assessment is generally the process of evaluating whether the protection guaranteed by a chosen transfer mechanism is actually effective in the destination country, taking account of local laws and practice and the circumstances of the transfer. It is typically associated with reliance on appropriate safeguards rather than adequacy, and its outcome may indicate that supplementary technical, contractual, or organisational measures are required. The precise scope, documentation expectations, and methodology can vary between regulators, so treat this as a context-dependent exercise and consult current guidance for the specifics that apply to your situation.
What are supplementary measures and when might they be required?
Supplementary measures are additional safeguards that may be layered on top of a transfer tool where a risk assessment indicates that the tool alone may not ensure an adequate level of protection in the destination country. They are commonly grouped as technical, contractual, or organisational in nature. Whether they are needed, and which ones are appropriate, depends on the outcome of the case-by-case assessment. This is an area of recognised evolution and some regulatory divergence, so the boundary of what is expected can shift, and you should verify against current guidance.
How should we document and keep our cross-border transfer arrangements up to date?
As a matter of practice, organisations typically maintain records that identify their transfers, the mechanism relied upon, and any assessment and supplementary measures applied. Because adequacy decisions, transfer tools, and supplementary measures evolve, arrangements should generally be reviewed periodically and when relevant circumstances change, rather than treated as fixed. A snapshot that was sufficient at one time may need updating. Confirm the current status of any adequacy decision or transfer tool against the official text and applicable regulatory guidance, and be aware that national implementing law and member state derogations can affect the detailed position.

Common misconceptions

If personal data physically stays on servers within the EU, no cross-border transfer rules apply.
Whether transfer rules apply generally turns on who can access the data and from where, not solely on the physical location of the servers. Remote access by a recipient in a third country can, subject to assessment, engage Chapter V requirements. The precise boundary of what constitutes a transfer has been addressed in regulatory guidance and should be verified.
Signing Standard Contractual Clauses is by itself sufficient to make any international transfer compliant.
SCCs are one recognised transfer tool, but reliance on them typically requires an assessment of the destination's laws and practices and, in some cases, supplementary measures. Their sufficiency is context-dependent and cannot be treated as automatic or permanent.
An adequacy decision permanently guarantees free data flows to that country.
Adequacy decisions can be reviewed, amended, suspended, or repealed, and the EU and UK regimes may reach different conclusions. Practitioners should treat any adequacy status as current-at-time and confirm it against official sources before relying on it.

Best practices

Map data flows to identify each destination and, importantly, who can access the data and from where, so that potential restricted transfers are recognised even where servers remain within the EU.
Confirm the current status of any relevant adequacy decision against official sources before relying on it, and note whether it applies under the EU GDPR, the UK regime, or both, since these can diverge.
Select the correct transfer tool for the situation, keeping Standard Contractual Clauses and Binding Corporate Rules distinct, and document why the chosen mechanism fits the transfer.
Where no adequacy decision applies, conduct and document a transfer risk assessment of the destination's laws and practices, and implement supplementary measures where the assessment indicates the transfer tool alone is insufficient.
Treat derogations as narrow and generally suited to occasional transfers rather than routine reliance, and verify the applicable conditions against the current text and guidance before using them.
Review transfer arrangements periodically to account for evolving adequacy decisions, case law, and regulator guidance, and record the basis and date of each assessment for accountability.