Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The GDPR Chapter V routes for international data transfers

International Data Transfers: Chapter V in Priority Order

International data transfers under the GDPR are governed by a chapter with a strict order of priority, and the route most organisations reach for when the others look difficult is the one the Regulation designed to be almost unusable.

Chapter V is also broader than people assume: international data transfers include onward transfers, and the rules bind processors as well as controllers.

The general principle for international data transfers

Article 44 sets the frame. Any transfer to a third country or international organisation may take place only if the conditions in Chapter V are complied with by the controller and processorincluding for onward transfers from that third country or organisation to another.

Two consequences follow immediately.

Your processor’s transfers are in scope. Chapter V does not stop at your own contract. If your supplier moves the data on, that onward transfer needs a basis too.

And the closing sentence of Article 44 is the interpretive rule for everything after it: all provisions in the chapter shall be applied in order to ensure that the level of protection guaranteed by this Regulation is not undermined. Where a route looks technically available but would hollow out that protection, that sentence is the answer.

The order of routes for international data transfers

The GDPR Chapter V routes for international data transfers

Adequacy first. This is the cheapest route for international data transfers. Article 45 lets the Commission decide that a third country, a territory, a specified sector within a country, or an international organisation ensures an adequate level of protection. Where an adequacy decision applies, the transfer needs no specific authorisation. Nothing else to do — which is why the first question in any transfer analysis is whether adequacy covers this destination and this sector.

Then appropriate safeguards. Article 46 applies in the absence of an adequacy decision, and it carries a condition that is easy to skim past: safeguards work on condition that enforceable data subject rights and effective legal remedies for data subjects are available. That condition sits above the list, not inside it.

Article 46(2) lists the safeguards available without any specific authorisation: binding corporate rules; standard data protection clauses adopted by the Commission; standard clauses adopted by a supervisory authority and approved by the Commission; an approved code of conduct or an approved certification mechanism, each together with binding and enforceable commitments from the party in the third country; and a legally binding instrument between public authorities.

Article 46(3) covers the routes that do need supervisory authority authorisation: bespoke contractual clauses, and provisions inserted into administrative arrangements between public authorities. Writing your own clauses is possible — it is simply not a shortcut.

Article 49 derogations are situational, not structural

Article 49(1) applies only in the absence of adequacy or appropriate safeguards, and lists seven conditions: explicit consent after being informed of the possible risks arising from the absence of adequacy and safeguards; necessity for a contract with the data subject or pre-contractual measures at their request; a contract concluded in the data subject’s interest; important reasons of public interest; the establishment, exercise or defence of legal claims; vital interests where the person is physically or legally incapable of consenting; and transfers from a public register.

Read them as what they are — specific situations, not a general licence. Consent under (a) requires the person to have been told about the missing adequacy decision and safeguards specifically, which is a very different conversation from a tick box. Contract necessity under (b) means necessary, not convenient: routing data through an overseas support desk is rarely necessary for performing the contract itself.

The route that is designed to be hard

The second subparagraph of Article 49(1) is the one organisations discover when everything else has failed, and it is deliberately narrow. It applies only where the transfer could not be based on Article 45 or 46 — including binding corporate rules — and no derogation applies. Then a transfer may take place only if all of the following hold:

  • it is not repetitive;
  • it concerns only a limited number of data subjects;
  • it is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject; and
  • the controller has assessed all the circumstances surrounding the transfer and, on the basis of that assessment, provided suitable safeguards.

Then two disclosures, both mandatory: the controller shall inform the supervisory authority of the transfer, and shall inform the data subject of the transfer and of the compelling legitimate interests pursued — in addition to the usual Article 13 and 14 information.

“Not repetitive” and “a limited number of data subjects” together rule out any ongoing operational flow. This is a route for an exceptional, bounded transfer — and telling your regulator about it is part of the price.

Where international data transfers land in your paperwork

International data transfers surface in documents you already maintain, and inconsistency between them is a common audit finding.

Document What it must say about transfers
Records of processing Article 30 requires transfers to be recorded with the third country or organisation identified — and for Article 49(1) second subparagraph transfers, the documentation of suitable safeguards
Access requests Article 15(2) gives the person the right to be informed of the Article 46 safeguards relating to the transfer
DPIA Where transfers contribute to high risk, the assessment and the safeguards belong there too
DPDP Act India’s rule 15 governs transfers out of India on a different model. Mapping flows once serves both

Where to start with international data transfers

  1. Map the flows, including your processors’ onward transfers. Article 44 covers them and most registers do not.
  2. Check adequacy first — for the country, the territory and the sector, since decisions can be partial.
  3. Use an Article 46(2) safeguard if adequacy does not apply, and confirm enforceable rights and effective remedies are genuinely available.
  4. Treat Article 49 as situational. If the flow is ongoing, a derogation is the wrong instrument.
  5. Do not plan around the second subparagraph. Not repetitive, limited numbers, regulator notified — it is not an operating model.
  6. Reconcile your record, your privacy notice and your access-request response so all three describe the same transfers.

This guide reflects Regulation (EU) 2016/679 as published on EUR-Lex, read at 16 August 2026. Adequacy decisions are added, amended and repealed over time — check the current list before relying on one.

The GDPR Toolkit provides 100+ editable templates including the transfer register and transfer risk assessment, the records of processing, the DPIA template and the data subject rights procedures.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.