Third-country transfer / international data transfer

Data protection glossary · 1 minute read

A third-country transfer is the transfer of personal data to a recipient in a state outside the EU and the EEA or to an international organisation.

Two-stage test

First, the transfer as such must be lawful, meaning it must have a legal basis under Art. 6 GDPR. At the second stage, it must be checked whether the specific conditions of Arts. 44 et seq. GDPR are met.

Remote access from a third country, for example by a support service provider, also counts as a transfer.

Transfer tools

  • adequacy decision of the European Commission
  • standard contractual clauses
  • binding corporate rules
  • derogations for specific situations, for example explicit consent or performance of a contract

Since the Schrems II judgment, where standard contractual clauses are used, it must also be assessed whether the law of the recipient country undermines the protection (transfer impact assessment).

Arts. 44 to 46 GDPR
Principles, adequacy decisions and appropriate safeguards.
Art. 47 GDPR
Binding corporate rules.
Art. 49 GDPR
Derogations for specific situations.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.