Third Country
In data protection terms, a 'third country' generally refers to any country or territory outside the European Economic Area (EEA). When personal data is sent to such a country, additional safeguards typically apply because it sits beyond the EU's core legal framework. The exact meaning can differ depending on whether you are looking at the EU GDPR or the UK GDPR.
The term 'third country' is not expressly defined in the operative text of the EU GDPR; in practice it is understood to mean any country or territory outside the European Economic Area (EEA), and it becomes relevant primarily in the context of restrictions on transfers of personal data. Note that scope can vary between regimes: under the UK GDPR the term is specifically defined and reflects the UK's own position following its withdrawal from the EU, so the set of countries treated as 'third countries' may differ between the EU and UK frameworks. In broader EU migration and free-movement contexts, 'third country' is used to describe a state that is not a member of the EU (and, in some usages, whose nationals do not enjoy EU free-movement rights), but that usage should be distinguished from the data protection sense; practitioners should verify the applicable definition against the current EU GDPR, UK GDPR, and any relevant national implementing law, as transfer tools and adequacy positions evolve over time.
Why it matters
The concept of a 'third country' sits at the heart of the GDPR's restrictions on international data transfers. Once personal data leaves the EEA, it moves beyond the core legal framework that guarantees a consistent standard of protection, so the Regulation generally requires additional safeguards before such a transfer can lawfully take place. Identifying whether a destination is a third country is therefore usually the first analytical step in any cross-border transfer assessment, because it determines whether the transfer rules are engaged at all.
The practical stakes are heightened by the fact that the term is not expressly defined in the operative text of the EU GDPR, while it is specifically defined under the UK GDPR. This divergence means the set of countries treated as 'third countries' can differ between the EU and UK regimes, and an organisation operating across both must assess each transfer under the applicable framework rather than assuming a single answer. Adequacy positions and transfer tools also evolve over time, so a determination that is correct today should be revisited as the legal landscape changes.
There is also a risk of terminological confusion. 'Third country' is used in EU migration and free-movement contexts to describe a state that is not an EU member (and, in some usages, whose nationals do not enjoy EU free-movement rights). This usage should be kept distinct from the data protection sense, as conflating the two can lead to incorrect scoping of transfer obligations.
Who it's relevant to
Inside Third Country
Common questions
Answers to the questions practitioners most commonly ask about Third Country.