Skip to main content
Category: Supervisory Authorities & Enforcement

Suspension of Data Flows

Also known as: Order to Suspend Data Flows, Suspension of Data Transfers
Simply put

Suspension of data flows is a corrective measure a data protection regulator can use to stop personal data from being sent to a recipient in a country outside the EU or to an international organisation. It is typically applied when the regulator finds that a transfer does not meet the legal conditions for protecting that data. In practice, it can require an organisation to halt an ongoing transfer arrangement until issues are resolved.

Formal definition

Suspension of data flows refers to a corrective power exercisable by a supervisory authority to order that the transfer of personal data to a recipient in a third country or to an international organisation be halted. Under the GDPR, Article 58 lists the powers of supervisory authorities, and includes the power to order the suspension of data flows to a recipient in a third country or to an international organisation. This measure is generally directed at cross-border transfers that the authority assesses as failing to satisfy the applicable conditions or safeguards for such transfers, and it is one among several corrective tools available to regulators rather than an automatic or standalone sanction. The precise triggering circumstances, procedural requirements, and interaction with transfer mechanisms and any applicable adequacy considerations are context-dependent; readers should verify the current position, as transfer tools and supervisory practice evolve and may differ between the EU GDPR, the UK GDPR, and national implementing law. The scope described here is confined to personal data transfers under data protection law and should not be confused with the general-purpose IT sense of a 'data flow' (the movement of data between systems).

Why it matters

Suspension of data flows is one of the most consequential corrective measures a supervisory authority can deploy, because it can interrupt an organisation's ability to move personal data to recipients outside the EU. For businesses that rely on cross-border transfers to run cloud services, shared infrastructure, or intra-group operations, an order to halt a transfer arrangement can have significant operational impact until the underlying compliance issues are addressed. Unlike a monetary penalty, which is backward-looking, a suspension directly constrains ongoing processing activity, making it a forward-looking control on how and where data can be sent.

The evidence digest reflects that this power has been exercised in practice in the context of EU-US data transfers. Reporting in May 2023 described a sanction against Meta relating to breaches of the conditions governing transfers of personal data to third countries under the pan-EU regulation. This illustrates that suspension-related enforcement typically arises where a regulator concludes that the safeguards or conditions applicable to a transfer are not being met, rather than as an automatic consequence of any transfer.

Because transfer tools, adequacy considerations, and supervisory practice evolve over time and may differ between the EU GDPR, the UK GDPR, and national implementing law, organisations should treat any snapshot of the enforcement landscape as provisional. The current position should be verified against official sources, as the mechanisms available to legitimise transfers and the circumstances in which a regulator may order suspension are subject to change.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to understand suspension of data flows as a potential regulatory outcome when assessing the lawfulness of cross-border transfers. It is relevant to how they document transfer mechanisms, monitor evolving supervisory practice, and prepare for the operational consequences should a regulator find that a transfer does not meet applicable conditions.
In-House and External Privacy Counsel
Lawyers advising on international transfers should treat suspension as one of the corrective powers under Article 58 and advise clients on how it may interact with the transfer tool being relied upon and any applicable adequacy considerations. Given that the position can differ between the EU GDPR, the UK GDPR, and national law, counsel should verify the current framework rather than rely on a fixed snapshot.
Organisations Transferring Data to Third Countries
Any controller or processor sending personal data to recipients outside the EU or to international organisations has a direct interest in this power, because a suspension order can halt an ongoing transfer arrangement. Such organisations should assess the resilience of their transfer arrangements and their contingency planning for scenarios where flows may need to be paused.
Engineers and Data Infrastructure Teams
Technical teams responsible for the systems that move personal data across borders should be aware that a legal suspension of data flows differs from the general IT notion of a data flow. Understanding this distinction helps ensure that architecture and data routing can accommodate a regulatory requirement to halt specific transfers if one arises.

Inside Suspension of Data Flows

Supervisory Authority Power to Suspend
The corrective power, generally exercisable by a supervisory authority under the GDPR's enforcement framework, to order the suspension of data flows to a recipient in a third country or to an international organisation. This is one of several corrective measures available and is typically applied where a transfer cannot be brought into compliance by other means. Practitioners should verify the specific provisions against the current official text.
Trigger for Suspension
Suspension typically arises where a transfer mechanism is found inadequate to protect personal data, for example where the level of protection in the destination cannot be ensured, where supplementary measures are insufficient, or where an adequacy decision is invalidated or a transfer tool is successfully challenged. The precise trigger depends on the facts and the assessment of the case.
Relationship to Transfer Mechanisms
Suspension interacts with the transfer tools relied upon, such as adequacy decisions, Standard Contractual Clauses, and Binding Corporate Rules. Because adequacy decisions and transfer tools can evolve or be challenged, a mechanism valid at one point may later be affected, potentially leading to suspension. The status of any given mechanism should be checked against current guidance and decisions.
Controller and Processor Obligations
Both controllers and processors may be affected, but their roles differ. A controller generally bears primary responsibility for the lawfulness of a transfer and for assessing whether a mechanism provides adequate protection, while a processor typically acts on documented instructions. Suspension may require either party to halt onward transfers, subject to the terms of the applicable Data Processing Agreement (Article 28) and the underlying transfer arrangements.
Scope and Effect
Suspension halts the flow of personal data to a specified recipient or destination. It applies to personal data of individuals and does not, generally, govern anonymous data or data of legal entities. The geographic and legal scope may differ between the EU GDPR and the UK GDPR, and member state or national implementing law may vary the position.

Common questions

Answers to the questions practitioners most commonly ask about Suspension of Data Flows.

Does a supervisory authority ordering the suspension of data flows mean the transfer mechanism itself has been invalidated?
No. A suspension order directed at a specific controller or processor addresses the lawfulness of that particular transfer arrangement in its context; it does not, by itself, invalidate the underlying transfer tool (such as Standard Contractual Clauses) for all users. Broad invalidation of a mechanism generally arises from a different route, for example a court ruling or the withdrawal or annulment of an adequacy decision. You should distinguish between an individual enforcement measure affecting your arrangement and a general legal change affecting the tool, and verify the scope of any order against its actual terms.
Is suspension of data flows a permanent prohibition on transferring the data in question?
Not necessarily. Suspension is typically a measure that halts transfers pending remediation, reassessment, or the introduction of adequate safeguards or supplementary measures. Depending on the circumstances and the regulator's decision, flows may resume once identified deficiencies are addressed, though in some cases a suspension may be maintained or escalated. The duration and conditions depend on the specific order and applicable procedures, so the outcome should be treated as context-dependent rather than automatically final.
How should an organisation respond when it receives an order to suspend a data flow?
In general terms, an organisation would review the precise scope of the order (which data, which transfers, which recipients), identify the legal basis and reasoning cited, and assess what remediation is required. Practical steps typically include engaging internal stakeholders such as the data protection officer and legal team, considering whether affected processing can lawfully continue in another form, and preparing a response to the authority. Because procedural rights and timelines vary by regulator and national implementing law, you should verify the applicable process against the relevant authority's guidance and current official text.
What alternatives might allow processing to continue if a particular transfer flow is suspended?
Options depend on the facts, but organisations commonly consider whether the processing can be performed within the relevant jurisdiction, whether an alternative transfer tool or additional supplementary measures could address the concerns, or whether the affected activity can be paused or restructured. The availability and adequacy of any alternative is subject to assessment and cannot be assumed to cure the underlying issue. Any change should be documented and evaluated against the reasons for the suspension.
What records or documentation are useful to maintain in anticipation of a possible suspension?
It is generally advisable to maintain a clear record of the transfer mechanism relied upon, the transfer risk assessment and any supplementary measures, the categories of data and recipients involved, and the mapping of relevant data flows. Such documentation can support a timely and accurate response to a supervisory authority and help scope any remediation. The specific expectations may differ between regulators and national law, so requirements should be verified rather than assumed.
How does a suspension affect ongoing processing by a processor or sub-processor abroad?
Where a flow to a processor or sub-processor is suspended, the parties typically need to consider what happens to data already held, whether further processing must stop, and how return, deletion, or continued storage should be handled. These matters are usually addressed in the data processing arrangement governing controller-processor obligations, and the practical response should align with both that arrangement and the terms of the suspension. Because outcomes depend on contractual terms and the specific order, the position should be assessed case by case.

Common misconceptions

Suspension of data flows is a permanent ban that ends all transfers to a country.
Suspension is generally a corrective measure directed at particular transfers or recipients and is context and risk dependent. It may be lifted where compliance can be re-established, for example through effective supplementary measures or a change in the applicable transfer mechanism. It should not be read as a fixed or blanket prohibition.
Relying on Standard Contractual Clauses guarantees that data flows can never be suspended.
Use of a transfer tool such as SCCs does not by itself insulate a transfer from suspension. Where supplementary measures are insufficient or the destination cannot ensure an adequate level of protection, a supervisory authority may still order suspension. The adequacy of any tool is subject to ongoing assessment as decisions and guidance evolve.
Only the receiving organisation in the third country is responsible when flows are suspended.
Responsibility typically rests significantly with the exporting controller, and processors have distinct obligations. Conflating these roles can lead to misallocated accountability; the correct allocation depends on the parties' roles and the terms of the relevant agreements.

Best practices

Maintain an up-to-date inventory of cross-border transfers, identifying the mechanism relied upon for each and the controller and processor roles involved.
Conduct and document transfer risk assessments for destinations, considering whether supplementary measures are needed and whether the level of protection can be ensured; revisit these assessments as guidance and decisions evolve.
Monitor developments affecting adequacy decisions and transfer tools, since a mechanism valid today may later be affected, and verify the current status against official sources rather than relying on a past snapshot.
Ensure Data Processing Agreements and transfer arrangements include clear provisions for halting or suspending flows and allocate responsibilities between the parties in a way that reflects their actual roles.
Prepare contingency plans for suspension scenarios, including alternative transfer mechanisms, data localisation options, or cessation of the affected processing, so a suspension order can be actioned promptly.
Distinguish carefully between EU GDPR and UK GDPR positions and account for possible member state or national law variations when planning transfer strategies.