Suspension of Data Flows
Suspension of data flows is a corrective measure a data protection regulator can use to stop personal data from being sent to a recipient in a country outside the EU or to an international organisation. It is typically applied when the regulator finds that a transfer does not meet the legal conditions for protecting that data. In practice, it can require an organisation to halt an ongoing transfer arrangement until issues are resolved.
Suspension of data flows refers to a corrective power exercisable by a supervisory authority to order that the transfer of personal data to a recipient in a third country or to an international organisation be halted. Under the GDPR, Article 58 lists the powers of supervisory authorities, and includes the power to order the suspension of data flows to a recipient in a third country or to an international organisation. This measure is generally directed at cross-border transfers that the authority assesses as failing to satisfy the applicable conditions or safeguards for such transfers, and it is one among several corrective tools available to regulators rather than an automatic or standalone sanction. The precise triggering circumstances, procedural requirements, and interaction with transfer mechanisms and any applicable adequacy considerations are context-dependent; readers should verify the current position, as transfer tools and supervisory practice evolve and may differ between the EU GDPR, the UK GDPR, and national implementing law. The scope described here is confined to personal data transfers under data protection law and should not be confused with the general-purpose IT sense of a 'data flow' (the movement of data between systems).
Why it matters
Suspension of data flows is one of the most consequential corrective measures a supervisory authority can deploy, because it can interrupt an organisation's ability to move personal data to recipients outside the EU. For businesses that rely on cross-border transfers to run cloud services, shared infrastructure, or intra-group operations, an order to halt a transfer arrangement can have significant operational impact until the underlying compliance issues are addressed. Unlike a monetary penalty, which is backward-looking, a suspension directly constrains ongoing processing activity, making it a forward-looking control on how and where data can be sent.
The evidence digest reflects that this power has been exercised in practice in the context of EU-US data transfers. Reporting in May 2023 described a sanction against Meta relating to breaches of the conditions governing transfers of personal data to third countries under the pan-EU regulation. This illustrates that suspension-related enforcement typically arises where a regulator concludes that the safeguards or conditions applicable to a transfer are not being met, rather than as an automatic consequence of any transfer.
Because transfer tools, adequacy considerations, and supervisory practice evolve over time and may differ between the EU GDPR, the UK GDPR, and national implementing law, organisations should treat any snapshot of the enforcement landscape as provisional. The current position should be verified against official sources, as the mechanisms available to legitimise transfers and the circumstances in which a regulator may order suspension are subject to change.
Who it's relevant to
Inside Suspension of Data Flows
Common questions
Answers to the questions practitioners most commonly ask about Suspension of Data Flows.