A transfer impact assessment of third country laws is the part of the exercise that most teams find hardest. Mapping transfers and choosing a transfer tool such as standard contractual clauses are administrative. Deciding whether the destination country’s laws and practice let the recipient honour those clauses takes legal analysis, and it is where poor assessments are either too thin to be credible or so long that nobody finishes them.
This guide explains how to carry out a transfer impact assessment of third country laws in a way that is proportionate: what the European Data Protection Board expects, which questions to ask, what evidence to gather and how to record a conclusion.
Why the transfer impact assessment of third country laws exists
In its Schrems II judgment of July 2020, the Court of Justice of the European Union held that transfers relying on standard contractual clauses must in practice give data an essentially equivalent level of protection to that in the EU. Exporters must check, case by case, whether the law of the destination country undermines the clauses, and add supplementary measures where it does. The EDPB turned that requirement into practical guidance in its Recommendations 01/2020, with a final version adopted in June 2021. You can find them on the EDPB website.
The assessment is therefore not optional paperwork. It is the exporter’s own responsibility, and it applies to each transfer or group of similar transfers. If you rely on an adequacy decision, this analysis is generally not needed for the covered transfer; our note on the Data Privacy Framework and TIAs explains how that interacts with the process.
Where the third country laws step fits in the roadmap
The EDPB roadmap has six steps. A transfer impact assessment of third country laws is the third.
| Step | What you do |
|---|---|
| 1 | Know your transfers: map what is sent, to whom and where |
| 2 | Identify the transfer tool you rely on |
| 3 | Assess whether the tool is effective given the destination’s law and practice |
| 4 | Adopt supplementary measures if needed |
| 5 | Take any procedural steps the measures require |
| 6 | Re-evaluate at appropriate intervals |
Steps one and two feed the assessment. If you have not yet mapped transfers, start with our overview of international data transfers.
The European Essential Guarantees for third country laws
To judge whether a country’s surveillance and public-authority access laws respect the essence of fundamental rights, the EDPB relies on four European Essential Guarantees. They give a structure for the analysis.
- Clear, precise and accessible rules. Processing by public authorities should follow published rules that people can understand.
- Necessity and proportionality. Access must be limited to what is necessary for a legitimate objective.
- Independent oversight. An independent body should supervise access.
- Effective remedies. Individuals need a practical way to seek redress.
Apply them to the laws that could reach the data you send: national security and intelligence laws, law enforcement access powers and any rules that compel the importer to disclose data. A transfer impact assessment of third country laws should say which laws were reviewed and how each guarantee is met or not.
Gathering evidence for the assessment
The EDPB says the assessment should consider the law and also how it is applied in practice. Useful sources include the text of the legislation, official and academic analyses, decisions of independent courts, reports of oversight bodies, transparency reports from providers and the importer’s own written statement on whether it has ever received such requests. The importer’s answers are an input, not a conclusion, so test them against public sources.
Where you lack the expertise to read the local law, seek an opinion from local counsel or use published assessments from a reputable source, and record which you relied on. Reusing a well-founded assessment across similar transfers to the same country is sensible, as long as you check that your data and the recipient’s role do not make your case different. Our transfer impact assessment example shows how a record can reuse country analysis while still assessing each transfer.
Deciding what the transfer impact assessment of third country laws concludes
There are three usual outcomes. First, the laws and practice do not impinge on the effectiveness of your transfer tool in your specific circumstances, so you can proceed. Second, they do, but supplementary measures can restore protection, so you adopt them; see our guide to supplementary measures for data transfers. Third, no combination of measures is enough, and you must not begin the transfer or must suspend it.
The conclusion should be tied to the actual data. The same laws may pose a low risk for business contact details and a high risk for sensitive data that an authority might wish to obtain. Encryption where only the exporter holds the key can change the outcome, whereas encryption where the importer holds the key generally cannot if the importer must decrypt the data to use it.
Who should carry out the assessment
Legal or privacy counsel usually leads, with input from the business owner of the transfer, security for the technical measures and procurement for the contract terms. The exporter stays accountable even when the analysis is prepared by an outside adviser or the importer, so someone in your organisation must read it, challenge it and approve the conclusion in their own name.
Proportionality and scale
Not every transfer deserves the same depth. Routine, low-sensitivity transfers to a country you have already analysed can rely on a short record that points to the country analysis and confirms the data and recipient role. Save the detailed work for sensitive data, large volumes, importers who are electronic communications providers and destinations with laws that plainly raise concern. Write down the criteria you use to decide depth, so the reasoning is visible.
Recording the assessment and reviewing it
Write down the transfer, the tool, the laws reviewed, the guarantees analysis, the evidence, the conclusion, any measures, the approver and the date. Set a review date and triggers such as a change of law, a new request report from the importer, a court ruling or a change in what you transfer. Step six of the roadmap expects re-evaluation, and a stale assessment is easy to criticise.
The related question of how a transfer risk assessment differs from a transfer impact assessment is covered in our comparison of transfer risk assessment and TIA, which is useful if you also transfer data from the United Kingdom.
Free transfer impact assessment
Can this transfer of personal data go ahead?
Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.
A hypothetical example of assessing third country laws
The following is a hypothetical example invented for illustration. A European company uses a support-ticket platform whose provider processes customer names, emails and message content in a third country. The company relies on standard contractual clauses. It reviews the country’s public-authority access laws against the four guarantees and finds that one law allows broad access with limited independent oversight.
The provider states in writing that it has received no such requests in the past three years and publishes a transparency report showing the same. Message content can be sensitive, so the company decides ordinary clauses are not enough. It adopts supplementary measures: it pseudonymises customer identifiers before transfer, restricts the fields sent, and requires the provider to challenge unlawful requests and notify the company. It records the conclusion as acceptable with measures and sets a review for twelve months or earlier if the provider reports a request.
Common weaknesses in third country law assessments
Frequent problems include copying a generic country memo without checking it against the actual data, relying only on the importer’s assurance, ignoring law enforcement access, describing laws without applying the four guarantees, never reviewing the assessment and failing to record the reasoning. Another is treating the outcome as pass or fail when the honest answer is often conditional on specific measures that must then be verified as actually in place.
A structured report for the transfer impact assessment of third country laws
A consistent record helps you show the reasoning and reuse country analysis. The Transfer Impact Assessment Report and Workbook provides a report and workbook for documenting transfers, tools, legal analysis and measures. Whichever format you use, keep the same headings across every assessment.
Transfer impact assessment of third country laws FAQ
Do we need a TIA for every transfer?
Where you rely on a tool such as standard contractual clauses, you need to assess whether it is effective for each transfer. Similar transfers to the same country can share the country analysis, but the data and importer role should be checked each time.
Can we rely on the importer’s statement about government access?
It is useful evidence but should be checked against public sources. The EDPB expects an assessment of law and practice, not only a supplier’s assurance.
What are the European Essential Guarantees?
Four benchmarks: clear, precise and accessible rules; necessity and proportionality; independent oversight; and effective remedies. They structure the review of a country’s public-authority access laws.
What if the laws are problematic and no measure helps?
Then the transfer should not start, or must be suspended, because the tool cannot provide essentially equivalent protection in practice.
How often should the assessment be reviewed?
At intervals you set and when triggers occur, such as a change of law, a relevant court ruling, a request report from the importer or a change to the data transferred.