This free transfer impact assessment tool works the way a TIA has to: one transfer of personal data out of the EEA or the UK, assessed before it starts, in the order of the six steps the European Data Protection Board sets out. Instead of a blank template, it asks the questions in turn, checks your answers as you go and tells you what a supervisory authority would still ask for.
It covers both regimes. For the EU, it follows the EDPB’s Recommendations 01/2020 on supplementary measures and the assessment Clause 14 of the Standard Contractual Clauses requires. For the UK, it follows the ICO’s approach to the transfer risk assessment, where the test is whether protection is not materially lower. It is free, and your answers save as you go.
Premium report
See what the premium transfer impact assessment report looks like
A worked TIA for a fictional organization: the screening result, the transfer and its tool, the laws and practice of the destination, every transfer risk with its supplementary measures, the importer's input and sign-off, every finding with what closes it, an AI-assisted analysis with a 30/60/90-day roadmap, plus the live Excel workbook.
Other free risk assessments: Information Security Risk Assessment (ISO 27001) Privacy Risk Assessment (ISO 27701) Business Continuity Risk Assessment (ISO 22301) Enterprise Risk Assessment (ISO 31000) AI Risk Assessment (ISO 42001) Data Protection Impact Assessment (GDPR) AI System Impact Assessment (ISO 42005) Legitimate Interests Assessment (GDPR) Third-Party Risk Assessment (ISO 27001)
What this transfer impact assessment covers

- Screening. Whether this is a restricted transfer at all, whether an adequacy decision or the Data Privacy Framework covers it, and whether an Article 49 exception is relied on, with the verdict and a note of your reasoning.
- Scope and criteria. The transfer you are assessing, and likelihood and severity scales that describe the harm to the people whose data is transferred, not to the organization.
- What the transfer involves. The personal data, the people it is about, the importer and its sub-processors, the destination countries, the services it runs through and each transfer flow.
- The transfer and the destination. Parties and roles, the SCC module or UK transfer tool, the format of the data, how it is accessed, onward transfers (EDPB steps 1 and 2), and ten questions on the laws and practice of the destination (step 3).
- Transfer risks. Scenarios from compelled disclosure and bulk interception to remote access in clear, sub-processors abroad and changes in the law, each rated for the people concerned.
- Supplementary measures. Technical, contractual and organisational measures for each risk (step 4), from encryption with keys you hold to challenge commitments and importer due diligence, with an owner, a date and the level expected afterwards.
- Advice and sign-off. The DPO’s advice, the importer’s input under Clause 14(c), the outcome and the re-evaluation date (steps 5 and 6).
What you get from this transfer impact assessment, free
The screening verdict, a heat map of the transfer risks, the check that tells you whether High or Critical risk remains once your supplementary measures are in place (and so whether the transfer tool can be relied on), a process score out of 100, and the findings a regulator or auditor would raise, such as a destination problem with no measure against it or no input from the importer. Sign in and it stays in your account, ready for the re-evaluation.
The full TIA report writes it all up in the order of the six steps, with the supplementary measures by owner and due date, the sign-off, an AI-assisted analysis with a 30/60/90-day roadmap, and the whole transfer impact assessment as a live Excel workbook.
Where this fits
A transfer impact assessment looks at one transfer. If the processing behind it is likely to be high risk, it may also need a DPIA, and the two share much of the same description. To see privacy risk across everything you do, run the privacy risk assessment. Our guide to international data transfers explains the rules the TIA sits within, and the GDPR Toolkit includes the procedure for international transfers.
Frequently asked questions
When is a transfer impact assessment required?
When personal data leaves the EEA or the UK for a country without an adequacy decision, and the transfer relies on an Article 46 safeguard such as the EU SCCs, binding corporate rules, the UK IDTA or the UK Addendum. Transfers covered by adequacy, including US recipients certified to the Data Privacy Framework, do not need one; transfers relying on an Article 49 exception do not either, but exceptions are read narrowly.
Does this transfer impact assessment work for UK transfers?
Yes. Choose UK GDPR, or both, at the start. The same questions then answer the UK test: whether the protection for the people whose data is transferred is not materially lower than under UK law.
What if the destination’s laws are a problem?
Each “no” in the destination questions is a reason the transfer tool may not work on its own. You then need supplementary measures that close the gap, usually technical ones such as encryption with keys you hold. If High or Critical risk remains after them, the tool tells you the transfer tool is not effective, and the transfer should not go ahead or should be suspended.
Is this a substitute for legal advice?
No. It is a structured self-assessment built from the information you enter, and Governance Docs does not review or verify it. Assessing a foreign country’s laws often needs input from the importer and published legal analysis; record your sources in the tool.
What happens to the information I enter?
It is stored with your assessment so you can come back to it, and it is never shared. Describe the data by category rather than entering any real personal data. You can delete an assessment permanently from your account at any time.
