Skip to main content
Category: Data Transfers

Third Country

Also known as: Non-EEA country
Simply put

In data protection terms, a 'third country' generally refers to any country or territory outside the European Economic Area (EEA). When personal data is sent to such a country, additional safeguards typically apply because it sits beyond the EU's core legal framework. The exact meaning can differ depending on whether you are looking at the EU GDPR or the UK GDPR.

Formal definition

The term 'third country' is not expressly defined in the operative text of the EU GDPR; in practice it is understood to mean any country or territory outside the European Economic Area (EEA), and it becomes relevant primarily in the context of restrictions on transfers of personal data. Note that scope can vary between regimes: under the UK GDPR the term is specifically defined and reflects the UK's own position following its withdrawal from the EU, so the set of countries treated as 'third countries' may differ between the EU and UK frameworks. In broader EU migration and free-movement contexts, 'third country' is used to describe a state that is not a member of the EU (and, in some usages, whose nationals do not enjoy EU free-movement rights), but that usage should be distinguished from the data protection sense; practitioners should verify the applicable definition against the current EU GDPR, UK GDPR, and any relevant national implementing law, as transfer tools and adequacy positions evolve over time.

Why it matters

The concept of a 'third country' sits at the heart of the GDPR's restrictions on international data transfers. Once personal data leaves the EEA, it moves beyond the core legal framework that guarantees a consistent standard of protection, so the Regulation generally requires additional safeguards before such a transfer can lawfully take place. Identifying whether a destination is a third country is therefore usually the first analytical step in any cross-border transfer assessment, because it determines whether the transfer rules are engaged at all.

The practical stakes are heightened by the fact that the term is not expressly defined in the operative text of the EU GDPR, while it is specifically defined under the UK GDPR. This divergence means the set of countries treated as 'third countries' can differ between the EU and UK regimes, and an organisation operating across both must assess each transfer under the applicable framework rather than assuming a single answer. Adequacy positions and transfer tools also evolve over time, so a determination that is correct today should be revisited as the legal landscape changes.

There is also a risk of terminological confusion. 'Third country' is used in EU migration and free-movement contexts to describe a state that is not an EU member (and, in some usages, whose nationals do not enjoy EU free-movement rights). This usage should be kept distinct from the data protection sense, as conflating the two can lead to incorrect scoping of transfer obligations.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to identify when data flows reach a third country because that classification determines whether transfer restrictions and additional safeguards are engaged. Where an organisation operates under both the EU and UK GDPR, they must assess each transfer under the applicable regime, since the set of countries treated as third countries can differ between the two frameworks.
Compliance and Legal Teams
Legal and compliance teams rely on the correct scoping of 'third country' to select an appropriate transfer mechanism and to document the basis for each cross-border flow. They should verify the definition against the current EU GDPR, UK GDPR, and any relevant national implementing law, and revisit determinations as adequacy positions and transfer tools evolve over time.
Engineers and Systems Architects
Those designing data storage, hosting, and processing infrastructure need to understand where personal data physically travels, because routing data to a location outside the EEA typically brings it within the transfer rules. Accurate mapping of data flows helps ensure that transfers to third countries are identified before they occur rather than after the fact.
Practitioners Working Across Legal Domains
Practitioners who also encounter 'third country' in EU migration or free-movement contexts should keep that usage distinct from the data protection sense. In migration usage the term describes a state that is not an EU member, and in some usages one whose citizens do not enjoy EU free-movement rights, which is a different concept from the transfer-related meaning under data protection law.

Inside Third Country

Definition
In GDPR terminology, a third country generally refers to any country outside the European Economic Area (EEA), meaning a jurisdiction not bound directly by the GDPR framework. The term is used primarily in the context of the Regulation's rules on international data transfers.
Relevance to international transfers
The concept is central to Chapter V of the GDPR, which governs transfers of personal data to third countries and international organisations. A transfer to a third country typically requires a lawful transfer mechanism in addition to a valid Article 6 (and, where relevant, Article 9) legal basis for the underlying processing.
Adequacy decisions
The European Commission may determine that a particular third country, a territory, or a sector within it ensures an adequate level of data protection. Where such a decision applies, transfers may generally proceed without an additional transfer tool. Adequacy decisions can be adopted, amended, suspended, or repealed over time, so their status should be verified against the current official position.
Transfer tools where no adequacy exists
Absent an adequacy decision, transfers to a third country typically rely on appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or on specific derogations for particular situations. These mechanisms are distinct instruments with different requirements and should not be treated as interchangeable.
Supplementary measures
Depending on the destination and applicable transfer tool, controllers and processors may need to assess the third country's legal environment and, where appropriate, apply supplementary technical, contractual, or organisational measures. The expectations in this area continue to evolve through regulatory guidance and case law.
UK-specific position
Following the UK's departure from the EU, the UK GDPR and UK national law apply their own approach to what constitutes a third country and to UK adequacy determinations. The EU and UK positions can diverge, so the applicable regime depends on which law governs the transfer.

Common questions

Answers to the questions practitioners most commonly ask about Third Country.

Does 'third country' just mean any country outside the European Union?
Not exactly. In the GDPR sense, a 'third country' is generally a country outside the EU/EEA that is not covered by the Regulation's territorial framework in the same way as member states. Because the EEA (which extends beyond EU membership) is relevant to the analysis, treating 'third country' as simply 'non-EU' can be imprecise. You should confirm the current status of a given jurisdiction against the official position, as the treatment of specific territories can be nuanced.
If a country is a 'third country', does that automatically mean transfers there are prohibited?
No. Classification as a third country does not, by itself, make a transfer unlawful. It means the transfer must rely on an appropriate legal mechanism or condition for transfers to countries outside the EU/EEA. Where an adequacy decision applies, transfers may generally proceed on that basis; otherwise, appropriate safeguards or specific derogations may be available, subject to assessment. Prohibition is not the default; the correct framing is that additional requirements apply.
How do we determine whether a transfer to a third country is permitted?
Typically you first identify whether the destination benefits from an adequacy decision. If it does, transfers may generally proceed on that basis. If not, you assess whether an appropriate transfer tool (such as recognized contractual safeguards or intra-group arrangements) applies, and whether supplementary measures are needed following an assessment of the destination's legal environment. In limited cases, specific derogations may be relied upon. The exact mechanisms and their conditions evolve, so verify against the current official text and guidance.
What should we do when a country has no adequacy decision?
In most cases you would consider one of the available transfer tools designed for transfers to countries without adequacy, and then carry out an assessment of whether that tool provides sufficient protection in light of the destination's laws and practices. Where gaps are identified, supplementary measures may be required, and if adequate protection cannot be ensured, the transfer may need to be reconsidered. Because the toolkit and expectations can shift, confirm the current position before relying on any single mechanism.
Does the UK follow the same third-country analysis as the EU?
The UK operates its own regime under the UK GDPR and national implementing law, which addresses transfers to countries outside the UK. While the concepts are broadly comparable, the specific determinations (including which countries are treated as offering adequate protection and which transfer tools are recognized) may differ from the EU position and can diverge over time. Assess EU and UK requirements separately where both apply, and verify each against its current official source.
How often should we revisit our third-country transfer arrangements?
Transfer arrangements are generally best treated as subject to periodic review rather than a one-time decision, because adequacy decisions, recognized transfer tools, and expectations around supplementary measures can change, and regulator positions may diverge. It is prudent to reassess when there are relevant legal or factual changes in the destination country, changes to the transfer mechanism relied upon, or updated guidance. This entry does not prescribe a fixed interval; align your review cycle with current guidance and your own risk assessment.

Common misconceptions

A third country simply means any country outside the EU.
For GDPR transfer purposes, the relevant boundary is generally the EEA rather than the EU alone, since EEA states outside the EU are bound by the GDPR framework. Practitioners should also confirm the applicable regime, as the UK now applies its own approach as a separate matter.
If a country has an adequacy decision, data can flow there permanently without further attention.
Adequacy decisions reflect an assessment at a point in time and can be amended, suspended, or repealed. Their scope may be limited to a territory or sector, so status and coverage should be verified against the current official text rather than assumed to be settled.
Standard Contractual Clauses are sufficient on their own for any third-country transfer.
SCCs are one transfer tool and, depending on the destination's legal environment, may need to be accompanied by a transfer risk assessment and supplementary measures. SCCs, Binding Corporate Rules, and derogations are distinct instruments, and the appropriate choice is subject to assessment.

Best practices

Confirm whether a proposed destination is a third country under the applicable regime (EEA-based for the GDPR, and the UK's separate approach where UK law governs) before designing the transfer.
Check the current status and scope of any relevant adequacy decision against the official source, rather than relying on a past snapshot, since these can be amended, suspended, or repealed.
Where no adequacy applies, select the correct transfer tool for the situation and treat Standard Contractual Clauses, Binding Corporate Rules, and derogations as distinct instruments with different requirements.
Ensure a valid legal basis for the underlying processing (Article 6, plus an Article 9 condition for special category data) exists in addition to the transfer mechanism, as these are separate requirements.
Assess the destination country's legal environment and consider whether supplementary technical, contractual, or organisational measures are needed, documenting the assessment.
Monitor evolving guidance and case law on transfers and re-review arrangements periodically, noting where regulators may diverge, and verify specific dates, figures, and article references against the current official text.